Drucker

Privacy Policy

Effective May 7, 2026

Run on Rails, Inc. (“Drucker,” “we,” “us,” or “our”) operates getdrucker.com and the Druckerservices (collectively, the “Service”). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our website, join the waitlist, or otherwise interact with us. By using the Service, you agree to the practices described here.

Drucker is currently pre-launch. The only personal information we collect today is the email address you provide when joining the waitlist. As we add product functionality, the categories of information we process will expand and we will update this Policy accordingly.

1. Definitions

The following terms are used throughout this Policy:

  • Personal information(or “personal data”) means any information that identifies, relates to, describes, or could reasonably be linked to a particular individual or household.
  • Processing means any operation performed on personal information, such as collection, storage, use, disclosure, or deletion.
  • Controller means the party that determines the purposes and means of processing personal information.
  • Processor(or “service provider”) means a party that processes personal information on behalf of a controller and only on its documented instructions.
  • Subprocessor means a third party engaged by a processor to assist in processing personal information.
  • Customer content means data that you or your users upload, enter, or generate while using the Service (available post-launch).

For waitlist visitors today, Run on Rails, Inc. acts as a controller of your email address. Once Drucker launches, customers will typically be controllers of their own customer content, and Run on Rails, Inc. will act as a processor under a Data Processing Addendum (DPA).

2. Information we collect

Information you provide. When you join the waitlist, contact us, or — once available — create an account and use the Service, we collect information you submit directly:

  • Contact information — email address, and later, name and job title.
  • Account information — credentials, billing details, and workspace settings (post-launch only).
  • Customer content — data you upload or enter into the Service in the course of using it (post-launch only).
  • Communications — messages, replies to our emails, and support tickets you send to us.

Information collected automatically. When you visit our website or use the Service, our infrastructure providers automatically receive standard request metadata, which may include IP address, browser type and version, device identifiers, referring URL, pages viewed, and timestamps. This information is used for security, abuse prevention, and to operate and improve the Service.

Information from third parties. We do not currently obtain personal information about you from third parties. If that changes, we will update this Policy.

We follow the principle of data minimization: we collect the minimum information reasonably necessary for the purposes described in this Policy.

3. Categories of personal information (CCPA notice at collection)

The table below describes the categories of personal information we collect, the sources, the business and commercial purposes for which each category is used, the categories of recipients, and how long we retain each category.

CategorySourcesPurposesRecipientsRetention
Identifiers (e.g., email, name)YouProvide and operate the Service; communicate with you; respond to inquiriesSubprocessorsUntil you request deletion or unsubscribe
Internet or other electronic network activity (e.g., IP address, browser data, page views)Automatically from your deviceSecurity, fraud prevention, debugging, analytics in aggregateSubprocessors30–90 days for raw logs
Commercial information (e.g., subscription, transactions) — post-launchYouProcess payments, manage your accountSubprocessors (payments)Term of account + as required by law
Customer records (e.g., name, billing address) — post-launchYouOperate the Service, billing, supportSubprocessorsTerm of account + as required by law
Geolocation (general, derived from IP)Automatically from your deviceSecurity, regional service deliverySubprocessorsSame as request logs
InferencesWe do not currently draw inferences about you
Sensitive personal informationWe do not collect sensitive personal information (e.g., government IDs, precise geolocation, account credentials beyond authentication, biometric or health data)

We do not sell or share personal information as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit such use.

4. How we use information

We use personal information to:

  • Operate, maintain, and secure the Service.
  • Notify you about the Drucker launch and send product updates you have asked to receive.
  • Respond to your inquiries and provide customer support.
  • Process transactions and manage your account.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with our legal obligations and enforce our terms.
  • Improve the Service, including by analyzing how it is used in aggregate.

5. AI and machine learning

We do not train AI or machine learning models on customer content. If we use AI features within the Service (for example, to summarize your data or suggest actions), customer content will be processed only to provide that feature to you and will not be used to train, fine-tune, or otherwise improve any model — ours or a third party’s.

Where AI functionality is provided through a third-party model provider, we will engage providers that contractually commit to the same restriction (zero-data-retention or no-training terms) and will list those providers in our subprocessor list.

We may use anonymous, aggregated usage signals (such as feature counts, error rates, and latency) to evaluate and improve our own product. See Aggregated and de-identified data.

6. Aggregated and de-identified data

We may create and use aggregated, anonymized, or de-identified data — information that cannot reasonably be used to identify you — for any lawful purpose, including to evaluate and improve the Service, conduct research, and publish reports. When we maintain such data in de-identified form, we will not attempt to re-identify it and will require recipients to commit to the same.

8. How we share information

We share personal information only as described below. We do not sell personal information to third parties.

  • Service providers (subprocessors). We share information with vendors who process information on our behalf under written agreements that require them to protect it and use it only for the services we have retained them for. Our current subprocessors are:
    • Resend — waitlist storage and transactional email delivery. Privacy policy
    • Vercel Inc. — website hosting and request handling. Privacy policy
    We will maintain an up-to-date subprocessor list, and we will provide reasonable advance notice to customers before engaging a new subprocessor that processes their customer content. A Data Processing Addendum (DPA) is available to customers on request after launch.
  • Legal and safety. We may disclose information if we believe in good faith that doing so is necessary to comply with applicable law, valid legal process, or government request; to enforce our agreements; or to protect the rights, property, or safety of Drucker, our users, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected users by email or a prominent notice on the Service before personal information becomes subject to a different privacy policy.
  • Affiliates. We may share information with current or future affiliates and subsidiaries of Run on Rails, Inc. for the purposes described in this Policy.
  • With your consent. We may share information for any other purpose with your consent.

9. Cookies and similar technologies

Our website does not currently use analytics, advertising, or tracking cookies. We may set strictly necessary cookies that are required to operate the Service (for example, to maintain a session once accounts are introduced). You can control cookies through your browser settings. If we add optional cookies in the future, we will request your consent where required by law and update this Policy.

10. Data retention

We retain personal information only for as long as we need it for the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Waitlist email addresses are retained until you ask us to remove you, you unsubscribe, or we decide not to launch Drucker.
  • Account and customer content (post-launch) will be retained for the term of your account and for a reasonable period afterward consistent with applicable law.
  • Server logs and similar technical data are typically retained for a short period (generally 30–90 days) before being deleted or aggregated.

11. Data security and breach notification

We use technical and organizational measures designed to protect personal information from unauthorized access, loss, misuse, or alteration. These include encryption in transit (TLS), access controls limiting access to information on a need-to-know basis, and ongoing review of our security practices. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

If we become aware of a security incident affecting your personal information, we will notify the relevant supervisory authority within 72 hours where required (for example, under the GDPR), and we will notify affected individuals without undue delay where required by applicable law.

12. International data transfers

Run on Rails, Inc. is based in the United States. Personal information we collect may be processed in the United States or in any other country where we or our service providers operate. The data protection laws in these countries may differ from those in your country.

Where required, we rely on appropriate safeguards for international transfers, including the European Commission’s Standard Contractual Clauses and equivalent UK and Swiss mechanisms. You may contact us for a copy of these safeguards.

13. Your privacy rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your personal information.
  • Receive a copy of your personal information in a structured, commonly used, machine-readable format (such as JSON or CSV).
  • Object to or restrict certain processing.
  • Withdraw consent where we rely on consent.
  • Unsubscribe from marketing emails at any time using the link in any message or by emailing us. Transactional and account-related messages are not affected by an unsubscribe.

To exercise any of these rights, email help@getdrucker.com. We may need to verify your identity before responding, generally by confirming your control of the email address associated with the request. We will respond to verifiable requests:

  • Within 45 days for California residents (extendable by an additional 45 days with notice), as required by the CCPA.
  • Within one month for individuals in the EEA, UK, or Switzerland (extendable by up to two months for complex requests with notice), as required by the GDPR.
  • Within the time period required by other applicable laws, and without undue delay in any case.

Automated decision-making. We do not make decisions about you based solely on automated processing that produces legal or similarly significant effects on you.

Authorized agents.You may use an authorized agent to submit a request on your behalf. We will require written proof of the agent’s authority and may also verify your identity directly.

EEA, UK, and Switzerland. You may also lodge a complaint with your local data protection authority. We would, however, appreciate the opportunity to address your concerns first.

California. California residents have all of the rights described above and are also entitled to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under California law.

Other U.S. states. Residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas, and others) may have similar rights. We honor verifiable requests under applicable state law on the same basis described above.

14. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, please contact us and we will delete the information. Parents and guardians of California minors under 18 may also request deletion of any content posted to the Service by emailing us at help@getdrucker.com.

16. Do Not Track and Global Privacy Control

Some browsers transmit “Do Not Track” (DNT) signals. Because there is no consistent industry standard for how to respond to DNT, we currently do not respond to DNT signals. We do not track you across third-party websites for advertising purposes.

We treat Global Privacy Control (GPC) signals from your browser as a valid request to opt out of the “sale” or “sharing” of personal information for residents of California and other states that recognize GPC.

17. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Effective” date above and, where appropriate, provide additional notice (for example, by emailing waitlist subscribers or posting a notice on the Service) before the changes take effect. Your continued use of the Service after the changes become effective means you accept the revised Policy.

18. Contact us

If you have questions about this Policy or our privacy practices, contact us at:

help@getdrucker.com

Run on Rails, Inc.Attn: Privacy1045 E. Atlantic Ave #202Delray Beach, FL 33483