PRIVACY POLICY

Last updated 5 August 2026 · Effective 5 August 2026

The short version. DRIPSUP has not launched yet. The only personal information we hold is what you type into the join form — your name, your email address and, if you choose to give it, your phone number. We use it for one thing: to tell you when Drop_001 goes on sale. We do not sell it, we do not trade it, and you can have it deleted at any time by emailing [email protected].

1. Who we are

DRIPSUP ("DRIPSUP", "we", "us", "our") is a clothing brand operating from Los Angeles, California, United States. This policy covers the website at dripsup.com and any signup form on it.

Data controller
[[LEGAL ENTITY NAME]]
Registered address
[[BUSINESS ADDRESS]]
Privacy contact
[email protected]

2. What we collect

Information you give us

When you submit the join form or the "hold my tee" form, we collect:

These details are stored in our own database on our own server. They are not passed to a third-party form service.

Information collected automatically

Our web host records standard server logs when any page loads: your IP address, browser and device type, the page you requested, the page you arrived from, and the date and time. These logs exist for security and to keep the site running. We do not use them to build a profile of you.

What we do not collect

We do not take payment details, because nothing is for sale yet. We do not collect your date of birth, your precise location, or any special category data (health, race, religion, politics, biometrics, sexual orientation). We do not run advertising pixels or third-party analytics on this site at present. If that changes, this policy changes first.

3. Why we use it, and our legal basis

To email or text you about the launch
Legal basis: your consent, given by ticking the box on the form. You may withdraw it at any time.
To count demand for each print
Legal basis: legitimate interests — deciding how much stock to produce. This is done in aggregate.
To keep the site secure and working
Legal basis: legitimate interests — preventing abuse, spam and fraud.
To meet our legal obligations
Legal basis: legal obligation — for example, keeping proof of consent.

4. Who we share it with

We do not sell, rent or trade your personal information. We share it only with the service providers we need to operate, and only for that purpose:

That is the complete list. The site loads no third-party resources at all — the typefaces are served from our own domain rather than from Google Fonts, so loading a page does not reveal your IP address to any company other than our host.

We may also disclose information if we are legally required to — for example, in response to a valid court order — or to protect our rights or someone's safety.

5. Cookies

This site sets no cookies of its own and runs no tracking scripts. The full detail, including what third parties may do, is in our Cookie Policy.

6. How long we keep it

7. Your rights

If you are in the UK, EU or EEA (UK GDPR / GDPR)

You have the right to: access the personal data we hold about you; correct it if it is wrong; have it erased; restrict or object to how we use it; receive it in a portable format; and withdraw consent at any time without affecting anything done before you withdrew it. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk).

If you are in California (CCPA / CPRA)

You have the right to know what personal information we collect and why, to request its deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information, and we have not done so in the preceding twelve months. We will not discriminate against you for exercising any of these rights.

How to exercise any of them

Email [email protected]. We will respond within 30 days. We may need to confirm your identity first — usually by replying from the address you signed up with. Every email we send also carries a one-click unsubscribe link.

8. International transfers

We operate from the United States, and our service providers may store data in the United States or elsewhere. If you are in the UK, EU or EEA, your information may therefore be transferred outside your country. Where that happens we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or the provider's certification under the EU–US Data Privacy Framework.

9. Children

This site is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their details, email [email protected] and we will delete them.

10. Security

The site is served over HTTPS and form submissions are encrypted in transit. Access to the mailing list is limited to the people who need it. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify you and the relevant authority without undue delay if a breach affects your rights.

11. Changes to this policy

If we change this policy we will update the date at the top of this page. If the change is significant — for example if we start using analytics or advertising tools — we will tell the people on our list by email before it takes effect.

12. Contact

Questions, requests or complaints: [email protected].