Written for what the live app actually does — the beta gate, the 11pm–4am lane, Stripe checkout, courier dispatch — not lifted from a generic template. No judgments. No resale. What we collect, who sees it, how long we keep it.
NightDrop delivers within a 30-mile radius of downtown San Diego between 11pm and 4am. To run that lane, we have to collect a small, specific set of things — your email and ZIP to put you on the invite list, your card details through Stripe to take payment, your delivery address to find you, and your phone number so your courier can text when they're two minutes out.
We share the minimum necessary with three outside services: Stripe (payment), your assigned courier (delivery), and our transactional email/SMS proxy (order notifications). Nothing is sold. Nothing is shared with advertisers, data brokers, social platforms, or analytics partners beyond a single anonymous page-view beacon. We don't profile you, and we don't infer anything about what you're ordering beyond what's needed to pack the box.
What you order is between you and your courier. The packaging is plain, the return label is generic, and the courier's view of your order is scoped to what they need to make the run — name, address, phone, and the items in the bag. They never see your card number, your email, or your account history.
No-judgment promise. We don't ask why you're ordering anything. We don't infer, analyze, or store anything about your motivations. The category of an item on the shelf (wellness, bath, aromatherapy, accessories) is what we list on the packaging slip — not anything about you.
Discreet packaging, by design. Every order ships in a plain, unmarked box or poly mailer with a generic return label and no store logo, product names, or category hints on the outside. We don't produce branded packaging; there is no NightDrop-branded box that could identify what's inside.
Here's every type of data the live app touches, broken out by where it comes from in the customer flow.
| Data | Where it comes in | Why we need it |
|---|---|---|
| Email address | Beta gate, order form, waitlist | Send invite + transactional order emails (confirmation, on-the-way, delivered, support replies) |
| ZIP code | Beta gate | Confirm you're inside our 30-mile delivery radius before we approve the invite |
| Phone number | Beta gate, order form | Courier text on approach; optional SMS invite channel for the beta promotion |
| Name, full delivery address | Checkout | Hand the order to the right person at the right door; appears on the courier's assignment |
| Order items (SKU + quantity) | Checkout | Pack the bag; show up in your /track view and order history |
| Payment method | Checkout (via Stripe) | Charge for the order. Card data is held by Stripe; we keep the PaymentIntent ID and last-4 only |
| Browser/IP data | Every page | Single anonymous page-view beacon (Polsia Analytics). No cookies, no persistent profile |
| Support replies (if you email us) | Inbound email | Auto-responder matches your message against order records; replied to in-thread, never shared onward |
We do not use any of the above to build a marketing profile. We do not retarget you after you leave. We do not enrich your record with data from any third party.
Three named recipients, and only the minimum each one needs to do their part of the delivery.
We do not sell, rent, lease, or otherwise transfer your data to advertisers, data brokers, social networks, or anyone outside the three above. We will disclose information only if compelled by valid legal process — and we'll tell you if we're ever asked to.
We launched closed-beta to keep the launch window sane. The gate captures your email, ZIP, and phone number, then sends you a single-use magic link via email (and optionally SMS). The link is a long random string, scoped to one row, and resolves to a short-lived signed cookie on success.
The first 100 signups auto-approve; additional signups land on a waitlist. Your row stays on file with status invited, waitlisted, or converted until you ask us to remove it. The invite cookie itself is short-lived and tied to one device.
Drivers sign in the same way — with a per-driver magic link emailed at assignment time. The driver code resolves to a signed cookie that gates only the courier dashboard, scoped to that driver's own assignments.
| Record | Retention |
|---|---|
| Beta gate signup | Until you ask us to delete it. Status flips to converted on first order. |
| Driver application | Retained while your driver account is active. Deleted within 30 days of deactivation. |
| Order record | Retained for 2 years for tax, accounting, and dispute resolution. After that, only anonymized aggregates are kept. |
| Sent emails / SMS log | Held briefly by the transactional proxy to confirm delivery. We do not retain message content long-term. |
| Magic-link cookie (customer) | Short-lived; expires automatically. Can be cleared instantly via /api/beta-signout. |
| Magic-link cookie (driver) | Short-lived; tied to the specific link code. Cleared when the courier signs out. |
| Stripe PaymentIntent ID + last-4 | Linked to the order row for the order's 2-year retention window. Full card details never reach our servers. |
California residents have additional rights under the CCPA/CPRA — we do not sell or share personal information as those terms are defined, so they don't materially change what you can already do here.
Data lives on a managed Postgres instance with TLS in transit. Access is scoped to the app server, the admin dashboard (password-gated), and the courier dashboard (magic-link gated). Stripe webhooks are signature-verified before any state change. Driver sign-in codes are stored hashed.
We use cookies only for the invite and courier sessions. We don't run third-party advertising trackers, Facebook pixels, or any cross-site retargeting. If you find a vulnerability, please report it to nightdropsdcontact@gmail.com.
NightDrop · San Diego, CA · 30-mile delivery radius
Email: nightdropsdcontact@gmail.com
Hours: 11pm – 4am Pacific, seven nights a week