Privacy Policy
Last updated: March 1, 2026
The Last Drop Ltd. (“we”) operates The Last Drop. This policy explains what personal data we collect, why, and what rights you have. We collect as little as we can: this is a discretion-sensitive product and we treat it that way.
Who is responsible
The data controller is The Last Drop Ltd., 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, company number 00000000. Contact: contact@the-last-drop.com.
What we collect
- Purchase information. The email address you enter at checkout, the Stripe session, customer and payment-intent identifiers, the amount charged, the currency, and the order status.
- Payment details. Collected and processed directly by Stripe. Card numbers never reach our servers and we never store them.
- Support correspondence. If you email us, we keep the message and our reply so we can help you.
- Usage data. Aggregate, non-identifying page views and interaction events (page viewed, call-to-action clicked, checkout started, checkout completed, download clicked). We do not build advertising profiles and we do not sell data.
- Campaign attribution. If you arrive from an advertisement, we record which campaign sent you and store it alongside any resulting order, so we can tell which advertising is worth continuing.
- Server logs. Our hosting provider records standard request logs, including IP address, for security and abuse prevention.
We do not ask for your name, address, phone number, date of birth, or any health information, and you should not send us health details by email.
Why we use it, and our legal basis
- To deliver what you bought — sending your download link and honouring your licence. Basis: performance of a contract.
- To provide support and handle refunds. Basis: performance of a contract, and our legitimate interest in running a service people can rely on.
- To keep financial records. Basis: compliance with a legal obligation.
- To understand how the site is used and prevent abuse. Basis: legitimate interests, balanced against your privacy — which is why this data is aggregate rather than individual.
We do not send marketing email. The only email we send you is transactional: your receipt and your download link.
Who we share it with
We use a small number of processors, and only for the purposes above:
- Stripe — payment processing and fraud prevention.
- Our email provider — delivering your download link.
- Our hosting and database providers — running the site.
- Advertising measurement providers (Google, Taboola) — receiving the fact and value of a purchase, so campaign performance can be measured. They do not receive your email address.
We may disclose data if legally required to do so. We never sell personal data and we never share it with advertisers.
International transfers
Some processors operate outside your country. Where data leaves the UK or EEA, it is transferred under an adequacy decision or the applicable Standard Contractual Clauses.
How long we keep it
- Order records: 7 years, as required by tax and accounting rules.
- Support email: 24 months from the last message.
- Server logs: typically 30 days.
- Aggregate analytics: retained without identifiers.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, export it, restrict or object to processing, and to withdraw consent where consent is the basis. Email contact@the-last-drop.com and we will respond within 30 days. You can also complain to your data protection authority — in the UK, the Information Commissioner’s Office.
Note that we may need to keep order records even after a deletion request, because tax law requires it. In that case we restrict the data to accounting use only.
Cookies and similar technologies
We use a small number of cookies and similar technologies:
- Campaign attribution (first-party). If you arrive from an advertisement or a link carrying campaign parameters, we store the campaign source, medium, name, and click identifier in a first-party cookie for 30 days, together with the page you landed on. This lets us tell which campaigns lead to purchases. It contains no personal data and is not used to build a profile of you.
- Advertising measurement (third-party). When advertising is running, we load conversion tags from Google (Google Ads and, if enabled, Google Analytics 4) and Taboola. These record that a purchase happened and its value, so we can measure which advertising works. They may set their own cookies and are subject to those providers’ privacy policies.
- Payment. Payment happens on Stripe’s hosted checkout, where Stripe sets the cookies it needs to process the transaction and prevent fraud.
- Vercel Web Analytics. Our host provides aggregate page-view statistics. It is cookieless, does not track visitors across sites, and does not collect personal data.
We do not run retargeting or build advertising audiences from your visit, and we do not share your email address or purchase details with advertising networks. Conversion reporting sends the order reference and amount, not who you are.
You can block these at the browser level without affecting your purchase or download — the download link is tied to your order, not to any cookie.
Security
Traffic is encrypted in transit. Download links are signed, expiring tokens tied to a specific paid order, and the product file is never exposed at a public URL. Order records are reviewed directly in Stripe and in the database, not through a public interface.
Children
The site is not intended for anyone under 18, and we do not knowingly collect their data.
Changes
We will update this page if our practices change, and revise the effective date at the top. See also our Terms of Service and Medical Disclaimer.