Legal
Privacy Policy
How Haqqman Technology Limited handles personal data across Droplet.
Last updated: September 2, 2026
1. Scope and controller
This Privacy Policy explains how Haqqman Technology Limited (“Haqqman”, “we”, “us”, or “our”) processes personal data when you visit Droplet, create an account, use the Droplet platform, contact us, or otherwise interact with our services.
Droplet is a Haqqman product. Haqqman is the data controller for account, billing, support, security, and website data that we process for our own purposes. Where you use Droplet to deploy or manage an application, you may be the controller of data contained in that application and we may process it as your service provider or processor, subject to your instructions and our agreement with you.
Haqqman Technology Limited
Haqqman, Trans Engineering, Dawaki, Abuja, NG, 901101
Privacy contact: privacy@haqqman.com
2. Personal data we collect
Depending on how you use Droplet, we may process the following categories of information:
- Account data: name, email address, account identifiers, verification status, authentication events, and profile details you provide.
- Application data: application name, repository URL, branch, detected stack, deployment configuration, compute-engine selection, domains, team membership, and application status.
- Repository data: GitHub account and repository metadata required to connect and deploy a repository. We do not request or store your GitHub password.
- Deployment data: deployment identifiers, commit references, build status, URLs, timestamps, errors, and deployment logs required to operate and troubleshoot deployments.
- Environment data: environment-variable names, values, notes, and environment scope submitted for an application. Sensitive values are encrypted in Droplet and are not intentionally displayed in clear text.
- Domain data: domain names, DNS/provider identifiers, registration details, renewal settings, verification records, and—when you purchase a domain—registrant contact information required for registration.
- Billing data: plan, subscription, transaction, payment status, authorization references, and limited payment-method details returned by Paystack. We do not store complete card numbers or CVV data.
- Support data: support requests, descriptions, attachments or identifiers you submit, and communications needed to respond.
- Technical data: IP address, browser and device characteristics, request timestamps, authentication and security logs, cookies, and similar operational information.
- Usage and provider data: deployment, storage, domain, analytics, and service events received from providers in order to display and operate Droplet features.
3. Why we use personal data
We process personal data only for specific, necessary purposes, including:
- creating and securing accounts, verifying identity, and preventing abuse;
- providing deployments, domains, object storage, monitoring, team access, support, and related platform features;
- connecting authorised repositories and synchronising provider state;
- initialising, confirming, renewing, and reconciling application subscriptions and payments;
- sending transactional messages such as verification codes, billing notices, deployment notices, and support responses;
- maintaining security, reliability, fraud prevention, auditability, backups, and service performance;
- understanding aggregate product usage, improving Droplet, and planning capacity;
- complying with legal obligations, enforcing agreements, and responding to lawful requests; and
- communicating product, service, or policy changes. We do not sell personal data.
4. Lawful bases
Depending on the circumstances, our lawful basis is performance of a contract with you, steps taken at your request before entering a contract, compliance with a legal obligation, our legitimate interests in securing and improving Droplet, or your consent where consent is required. You may withdraw consent at any time where processing relies on consent; withdrawal does not affect processing that occurred before withdrawal or processing supported by another lawful basis.
5. Customer application content and team access
Droplet is an application management platform. You control the repositories, code, environment variables, domains, objects, logs, and other content that you submit or connect. We process that content to provide the requested service, keep it secure, enforce access permissions, reconcile provider state, and comply with law.
Application owners are responsible for inviting the right people and configuring roles. Members may be able to view or manage application resources according to their assigned role. Do not place sensitive personal data in repositories, logs, environment variables, support requests, or public application content unless you have a lawful reason to do so.
6. Service providers and disclosures
We disclose data only when needed to provide Droplet, protect users, or comply with law. Our service providers may include:
- Neon and Neon Auth for authentication and database services;
- Cloudflare for edge delivery, Pages, Workers where enabled, domains/DNS, analytics, security, and R2-backed object storage;
- GitHub when you authorise repository connection and deployment workflows;
- Paystack for payment processing, payment-method authorisation, subscriptions, and transaction verification;
- Postmark for transactional email delivery; and
- hosting, monitoring, security, and professional advisers who process data under appropriate contractual or legal safeguards.
We may also disclose information to courts, regulators, law enforcement, or other parties where legally required or necessary to protect rights, safety, security, or the integrity of Droplet. We do not disclose customer application content for advertising.
7. International transfers
Haqqman and our service providers may process personal data in Nigeria and other countries where they operate. Where data leaves Nigeria or the European Economic Area, we use a lawful transfer mechanism and appropriate safeguards required by applicable law, which may include contractual protections, adequacy decisions, or another recognised safeguard. You may contact us for information about the safeguards relevant to a particular transfer.
8. Retention
- Account and application records are retained while the account or application is active and for a reasonable period afterwards for security, recovery, dispute resolution, and legal obligations.
- Deployment history and logs are subject to Droplet’s configured retention limits and provider availability. We do not promise indefinite access to logs.
- Billing, transaction, domain-registration, and tax records are retained for the periods required for accounting, legal, fraud-prevention, and dispute purposes.
- Support communications are retained for as long as needed to resolve the request and maintain service records.
- Backups may retain deleted data for a limited period until they are rotated or securely overwritten.
9. Security
We use administrative, technical, and organisational measures appropriate to the risk, including encrypted transport, access controls, role-based application access, protected secrets, provider security controls, logging, monitoring, and least-privilege practices. No internet service is completely secure. You are responsible for safeguarding credentials, reviewing team access, and promptly reporting suspected compromise.
11. Your rights
Subject to applicable law and reasonable verification, you may have the right to:
- request access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion of data where there is no continuing lawful reason to retain it;
- request restriction of processing in appropriate circumstances;
- object to processing based on legitimate interests or to direct marketing;
- receive portable data where the right applies;
- withdraw consent where consent is the lawful basis; and
- complain to the Nigeria Data Protection Commission or, where applicable, an EU/EEA supervisory authority.
To exercise a right, contact privacy@haqqman.com. We may ask for information needed to verify your identity and protect another person’s data. We aim to respond within the period required by applicable law. Some requests may be limited where retention is required, rights of others are affected, or the request would compromise security.
12. Children
Droplet is intended for business and developer use and is not directed to children. We do not knowingly collect personal data from a child in a way prohibited by applicable law. If you believe a child has provided personal data, contact us so we can review and take appropriate action.
13. Automated decisions
Droplet may use automated checks for authentication security, abuse prevention, stack detection, deployment routing, plan entitlements, and payment status reconciliation. These checks support service operation; we do not use solely automated processing to make decisions producing legal or similarly significant effects without appropriate safeguards and a way to request human review where required.
14. Changes to this policy
We may update this policy when Droplet, our providers, or applicable privacy requirements change. We will publish the revised version here, update the “Last updated” date, and provide additional notice where required. Continued use after an update means the revised policy applies to future processing.