Privacy Notice
Last updated: 1 August 2026
The short version
- We use account, product, security, and payment data to provide and protect Elite Drops.
- We do not sell personal data or use advertising trackers.
- Community drops, votes, and request content may be public; do not put private information in them.
- You can export or delete your account data from the Account page.
- Google, Discord, Stripe, and PayPal process limited data to run sign-in, hosting, security, and payments.
This summary is for convenience. The complete notice below controls.
Who operates this service
Elite Drops is the operator of elitedrops.gg and the controller of the personal data described in this notice. Elite Drops is an independent fan-made service for planning Fortnite drop routes.
Elite Drops was previously published as the Fortnite Drop Calculator. The service, its operator, and the practices described here are unchanged.
This service is not affiliated with, endorsed by, or sponsored by Epic Games, Inc. Fortnite is a trademark of Epic Games, Inc.
Sources of personal data
We receive personal data from four main sources:
- From you — account choices, checkout country, saved drops, requests, Party actions, support messages, and other content you submit.
- From your browser or device — IP address, request and security logs, a random installation identifier used for Free Proof protection, and local preferences.
- From service providers — Discord identity facts; Stripe or PayPal payment, billing-country, refund, and dispute status; and Google App Check security signals.
- From other users — Party and teammate invitations, membership changes, votes, and content involving your account.
What we collect, and why
Anonymous visitors can browse the locked catalog and simplified demo. Live catalog calculations require an account. Data below is collected only in the circumstances described.
| Data | When | Why | Kept for |
|---|---|---|---|
| Account identifiers — Firebase user ID, email address, display name, profile photo URL, and which sign-in providers you used | If you sign in with Discord, or use the bounded migration flow for a legacy Google account | To create and recognise your account | Until you delete your account |
| Discord profile — Discord user ID, username, avatar | When you sign in with Discord | To sign you in, prevent duplicate identity links, show your avatar, and determine Free Proof eligibility. The readable Discord email is not stored in the identity record | Until account deletion; a keyed identity tombstone is then retained for 24 months for fraud prevention |
| Commerce records — offer, stable Home ID, amount, tax, currency, declared and verified billing country, payment-processor identifiers (Stripe Customer/Session/PaymentIntent/Charge, or PayPal order/capture, plus refund and dispute identifiers), receipt URL, policy versions, and entitlement dates. After PayPal approval, PayPal may provide a saved address for tax calculation; Elite Drops stores the country and tax result, not the street address or postal code. | If you open or complete checkout, receive a support entitlement, request a refund, or dispute a payment | Payment processing, tax, fulfillment, receipts, fraud prevention, support, accounting, and reconciliation | Product entitlements until expiry, retirement, refund, or account deletion. Pseudonymized financial records are retained for seven years |
| Support and audit records — Discord account details visible in a private ticket, ticket ID, request or appeal reason, relevant account or order ID, attachments you submit, action taken, and the operator account that took it | If you contact support or an operator applies a refund, access remedy, identity review, or other administrative action | To respond, protect account security, document refunds and disputes, prevent unauthorized changes, and demonstrate how a request was handled | For as long as needed to resolve and document the request and meet accounting, dispute, fraud-prevention, and legal obligations. Discord also retains ticket content under its own terms and settings |
| Calculation access records — Free Proof balance and reservations, location/target IDs, route hash, outcome, entitlement source, daily success counters, and idempotency key | When you request a live calculation | Fulfillment, correct free-use charging, retry safety, fair-use enforcement, and troubleshooting | Calculation runs expire after about seven days; daily counters after about three days; the lifetime free balance remains until used or the account is deleted |
| Free-access abuse signals — a random browser installation identifier stored locally, keyed hashes of that identifier and the platform-derived network address, and 30-day network identity velocity | When an account without paid or shared access requests Free Proof | To deter repeated Free Proof claims. A shared network alone produces an alert and is never the sole reason for blocking access; users may appeal through support | Keyed installation and network signals expire after 24 months |
| Aggregate commerce events — event type plus, when applicable, offer, country, access source, or lifecycle state; no account ID, Discord ID, coordinates, or payment identifier | When pricing is viewed or checkout, fulfillment, calculation, pass, refund, or dispute events occur | Reliability, conversion, contribution-margin, refund, dispute, and support-workload measurement | About 400 days |
| Profile record — display name, photo URL, preferences, saved location list | While signed in | To keep your settings across visits | Until you delete your account |
| Notification data — personal access updates, which announcements you have read, and whether live popups are enabled | While you are signed in and notifications apply to your account | To provide your notification inbox and remember your popup preference | Notification history and read receipts expire within 90 days; your preference remains until you change it or delete your account |
| Saved drops and votes — drop name, bus route, target coordinates, map source, optional notes, vote values, and your user ID | If you save a drop or vote | To store and rank community drops | Until you delete them or your account |
| Location requests: title, description, request type, map coordinates, status, support vote, and your user ID | If you request a location or support someone else's request | To prioritise missing locations, prevent duplicate requests, and notify you when status changes | Until you delete the request or your account; status notifications expire within 90 days |
| Persistent teammate data: the owner and teammate user IDs, the selected catalog location ID, assignment and change timestamps, and a hashed one-time invitation identifier | If you create, accept, leave, replace, or revoke a persistent teammate invitation | To enforce one teammate seat and one selected calculator, provide purchased-location access, and prevent rapid teammate or location rotation | The active relationship remains until either person ends it or deletes their account. A removed teammate's ID is cleared immediately. Invitation hashes expire within 48 hours and are cleared by scheduled cleanup. The selected location and its cooldown remain until changed or the owner deletes the account |
| Party room data — opaque room ID, Party Code, server-derived display name, colour, membership and join time, per-tab/device presence, and the Leader's current Route Solver plan | If you create or join a Party | To synchronize the Leader's plan, show who is online, reconnect devices, and recover leadership | Ended rooms are removed within about 15 minutes. Empty active rooms remain recoverable for up to two hours, then are deleted |
| Sign-in security records — a short-lived one-time state value and exchange code | During Discord sign-in | To prevent sign-in hijacking | 10 minutes and 2 minutes respectively, then deleted |
| Server logs — IP address, request identifier, timestamp, endpoint, and browser-reported security (CSP) violations | Whenever you use a server endpoint | Rate limiting, abuse prevention, security monitoring, and debugging | Per Google Cloud Logging retention (default 30 days) |
Sharing features and public areas
Persistent teammate sharing
An account with active paid Single Location or Elite Pass access may invite one teammate through a private, single-use link. The invitation secret stays in the link fragment, is removed from the browser address immediately, and is never stored by the service; only its one-way hash and expiry are stored. The owner selects one covered catalog location before creating the invitation, and the invitation is bound to that reviewed location. Acceptance links the two account IDs and gives the teammate access only to that calculator. An Elite Pass does not share all locations. Ownership does not transfer, Free Proof is never shared, and sharing is not transitive.
Admin-granted locations and locations received from another teammate are not shared onward. The owner can remove the teammate and the teammate can leave at any time; access ends immediately. Separate seven-day windows limit how quickly the seat can move to another person or the selected calculator can change. Removing a teammate or cancelling an invite resets neither window. If the selection is retired or no longer covered, it may be replaced immediately. Removing access cannot erase information the teammate already remembered or captured while it was visible.
Temporary Party target sharing
If a Party Leader selects a locked location they own, the service shares only that one active coordinate and label with current Party members. It does not share the protected location catalogue or alternate targets, and the temporary target is not placed in invite links, saved drops, exports, or local browser storage. Access ends when you leave, are kicked, the Party ends, or the room expires. A teammate can still remember or capture information that was already visible on their screen.
Please note: saved drops and votes are public
Community drops and votes are readable by anyone, and each record includes the user ID of the person who created it. Do not put anything private into a drop name or its notes.
Location-request titles, descriptions, map pins, status, and total support count are also public. Your account identity is not included in the public request response, but your Firebase user ID is stored privately so you can manage your request and so one account cannot cast repeated support votes. Do not put private information into a request.
Our reasons for processing data
Where data-protection law requires a legal basis, we rely on:
- Contract — to create your account, run calculations, save your choices, fulfill purchases, provide sharing features, and respond to support requests.
- Legitimate interests — to secure the service, prevent fraud and repeated Free Proof claims, debug failures, measure reliability in aggregate, and improve the product. We balance these interests against the impact on users.
- Legal obligations — for tax, accounting, payment disputes, lawful requests, and consumer-protection records.
- Consent — where required for an optional feature or local storage that is not strictly necessary. You may withdraw consent prospectively.
Data stored in your browser
The service does not use advertising or cross-site tracking cookies. It stores the following in your browser. Most stays on your device; where an item is transmitted, that is explained below. You can clear browser storage through your browser settings, although doing so may sign you out or reset preferences:
- Local storage — your personalisation settings (titles, labels, theme colours), map and terrain source choices, menu state, and saved route presets stay on the device. The random Free Proof installation identifier is sent only when requesting protected commerce or calculation endpoints; the server stores a keyed hash rather than the raw value.
- Session storage — sign-in state kept for the current tab, and whether your account has administrator access to the menu.
- A sign-in cookie (
__session) — used only during Discord sign-in to tie the request to your browser. - Location-request draft — an unfinished request can remain in session storage for up to two hours so signing in does not erase it.
- Party reconnect data — the current opaque Party room ID and Party Code can remain in local storage so the same browser can reconnect. They are removed when the Party client clears the room, or when you clear browser storage.
- Firebase Authentication also stores your sign-in session locally so you stay signed in.
Because we do not use behavioral advertising or sell data, the service does not currently respond differently to browser "Do Not Track" signals. Where a legally recognized opt-out preference applies, we will honor it as required.
Who we share data with
We do not sell your data or share it for cross-context behavioral advertising. We disclose it only as described here:
- Google (Firebase / Google Cloud) — authentication, databases, file storage, server functions, hosting, and logging. Data may be processed on Google infrastructure outside your country.
- Google reCAPTCHA (via Firebase App Check) — verifies that requests come from the genuine app rather than an automated script. reCAPTCHA collects device and interaction signals under Google's own privacy policy.
- Discord — Discord sign-in and, if you contact support, the private ticket, messages, and attachments you choose to provide.
- Stripe — Checkout, card payment processing, tax calculation for all orders, receipts, refunds, disputes, and reconciliation. Elite Drops does not receive full card details. Stripe calculates tax even when PayPal takes the payment; for those orders it receives the order amount and the country, state, and postal code supplied by PayPal, but no PayPal login or funding-source details.
- PayPal — if you choose to pay with PayPal: hosted approval, payment processing, refunds, and disputes. Elite Drops does not receive your PayPal login or funding-source details. PayPal may share the country associated with your PayPal account so we can confirm we are permitted to sell there.
We may also disclose the minimum necessary information to comply with law, protect users or the service, investigate fraud or security incidents, establish or defend legal claims, or complete a genuine merger, financing, acquisition, or sale. A successor must honor this notice for data it receives, and we will provide notice where required.
International processing
Our providers may process data in the United States and other countries whose laws differ from yours. Where required, the operator will use an approved transfer mechanism, including provider contractual safeguards or another mechanism recognized by applicable law. Information about the relevant safeguard is available through a privacy request.
Your rights and how to use them
Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict its processing. Two of these are built directly into the product:
- Export — sign in and use Download my data on the Account page. You get a machine-readable JSON file containing your profile, personal notifications, notification read state, preferences, drops, votes, location requests and support votes, your own Party membership entries, and file list. Broadcast announcements are shared product content and are not included as personal data. The export contains only your own data, never other players' profiles or plans.
- Deletion — sign in and use Delete my account on the Account page. This permanently removes your profile, personal notifications, notification receipts and preferences, drops, votes, location requests and support votes, Party memberships and rooms you lead, stored files, and your sign-in record. It is immediate and cannot be undone. For your security you may be asked to sign in again first.
The export also includes your Discord identity facts, Home and Elite entitlements, and a minimized purchase history. Account deletion removes live product data and forfeits remaining paid access without a refund. Pseudonymized financial records are retained for seven years and a keyed fraud-prevention identity tombstone for 24 months.
For correction, objection, or any other request, contact us using the details below. Note that server logs and backups may retain some records for a short period after deletion before they age out.
You may also have the right to withdraw consent, appeal a decision about your request, and complain to a privacy or data-protection regulator. We do not discriminate against you for exercising a privacy right. We may need to verify your identity and authority before acting, and an authorized agent may submit a request where local law permits. We will respond within the period required where you live.
Automated checks
Free Proof and commerce requests use automated rate, account-age, installation, network, entitlement, and payment-integrity checks. These checks may delay or withhold free access or checkout when a rule is not met. A shared network address by itself is not a reason for a ban. If a result is wrong, you may ask support for human review. Elite Drops does not use these checks to make decisions about employment, credit, housing, insurance, or similarly significant matters.
Children
Elite Drops is not directed to children under 13, and they may not create or use an account. If you are under the age of legal majority where you live, a parent or legal guardian must agree to the Terms for you. We do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data, contact us and we will investigate and delete it as required.
Security
Access to stored data is restricted by server-enforced authorisation rules, the site is served over HTTPS with a strict Content Security Policy, and requests to server endpoints are rate limited. No online service can be perfectly secure. To report a vulnerability, see our security contact.
Changes to this notice
If this notice changes materially, the "last updated" date above will change and, where required, we will notify signed-in users.
Contact
Submit privacy questions or rights requests through a private Elite Drops support ticket, or email nickhardy3@gmail.com. Include "Privacy request" and the Discord ID associated with your account, but do not send passwords, payment credentials, or full card details. We may need to verify your identity before disclosing or deleting account data.