Skip to content

Privacy Policy

Last updated: 19 July 2026

1. About this Privacy Policy

Drum Software Inc. is a company incorporated in Delaware, United States (referred to as “Drum”, “we”, “us” or “our”). We provide the Drum website, web application and related services (collectively, the “Services”).

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit getdrum.com, use the Drum application, contact us or otherwise interact with our Services. It also explains how we handle information that customers and their authorised users enter, upload, import or generate through Drum (“Customer Data”).

“Customer” means the organisation that subscribes to Drum. “User” means an individual authorised to use a Customer’s account. A Customer controls the Customer Data submitted to its account and is responsible for ensuring that it has the authority to provide that data to Drum.

You should read this Privacy Policy together with our Terms of Service, Data Management and Security summary, Subprocessors page and Cookies Policy.

2. Information we collect

The personal information we collect depends on how you interact with Drum and may include:

  • Account and contact information: your name, email address, telephone number, job title, organisation, profile details and login information.
  • Subscription and billing information: your subscription, billing contact, billing address, payment status and transaction details. Payment card information is collected and processed by Stripe; Drum receives only limited payment information.
  • Customer Data: information entered or imported into Drum, including information about a Customer’s staff, clients and contacts, projects, opportunities, time entries, costs, invoices, financial records, emails, documents and attachments.
  • Support and communications information: information you provide when you request support, book a demonstration, respond to a survey or communicate with us by email, telephone, chat or another channel.
  • Device and usage information: IP address, browser and device type, operating system, approximate location, pages viewed, links clicked, feature usage, timestamps, diagnostic data, standard server logs and, where enabled, recordings of interactions with the Services.
  • Marketing information: your communication preferences and information about how you interact with our website, advertisements and marketing communications.

We collect information directly from you, from a Customer or account administrator, through your use of the Services, from services you choose to connect to Drum and from service providers that help us operate and improve Drum.

3. Customer Data, imports and connected services

Customers and Users may connect Drum to third-party services. These include Google services for identity, Gmail and calendar features; Microsoft services for identity, Outlook email and calendar features; and accounting services such as Xero, MYOB and QuickBooks. When you enable an integration, Drum exchanges the information needed to provide it in accordance with your settings, the permissions you grant and the third party’s terms and privacy practices. You can disconnect an integration through Drum or the relevant third-party service.

When Drum assists with onboarding or an import, we may upload Customer-provided source data to Google Sheets or use other Google services to review, validate, map, transform and import that data into Drum. We use that material only to perform the requested onboarding or import and handle it as Customer Data under this Privacy Policy.

Customers may also use Drum’s API or configure webhooks that send selected Customer Data to destinations they control. The Customer is responsible for selecting and authorising those destinations and for the recipient’s handling of the data.

Drum includes optional AI-assisted features. We use OpenAI as a service provider to:

  • extract opportunity information from emails and create opportunity records in Drum; and
  • extract cost information from receipts and supplier invoices and create cost records in Drum; and
  • extract and structure project or proposal budget information from spreadsheets and other documents submitted to an AI-assisted feature.

When a User chooses to use one of these features, the relevant email, receipt, invoice, spreadsheet, document or extracted content is sent to OpenAI for processing. Drum uses the result to provide the requested feature and stores the resulting Customer Data in the Customer’s Drum account. Customers should ensure that they are authorised to submit any personal, confidential or third-party information contained in that material.

4. How we use information

We use Customer Data only to operate, provide, secure, monitor, maintain, support and improve the Services, provide integrations and features requested by a Customer or User, follow a Customer’s instructions, and comply with applicable law.

We use account, contact, billing, support, device, usage and marketing information to:

  • provide, operate and maintain the Services;
  • create and administer accounts, subscriptions and payments;
  • respond to support requests and communicate about the Services;
  • protect Drum, our Customers and Users from fraud, abuse and security threats;
  • monitor performance, diagnose problems and improve the usability and reliability of the Services;
  • send product updates and marketing communications, where permitted, which you can opt out of at any time;
  • comply with legal obligations, resolve disputes and enforce our agreements; and
  • create aggregated or de-identified insights that do not identify an individual or Customer.

We do not sell personal information or Customer Data. We do not use Customer Data for third-party advertising.

5. When we disclose information

We disclose information only as reasonably necessary to operate Drum, follow a Customer’s instructions, protect the Services or comply with law. Recipients may include:

  • DigitalOcean, which provides our Sydney application hosting, databases, caches and file storage;
  • Cloudflare, which provides network, proxy, load-balancing and security services;
  • Stripe, which processes subscription payments, billing information and payment fraud signals;
  • Postmark, which receives incoming emails directed to Drum and delivers transactional and service emails;
  • Bento, which provides onboarding and lifecycle communications;
  • Intercom, which provides customer support, chat and service communications;
  • OpenAI, which processes selected content when a User uses the AI-assisted features described above;
  • Google, which provides Drum-managed assisted onboarding and import tools, website analytics and related technology services;
  • PostHog, which provides product analytics and, where enabled, session recording;
  • Rollbar and Scout APM, which provide error diagnostics and application performance monitoring;
  • other website analytics, advertising and embedded-content providers, including LinkedIn, as described in our Cookies Policy;
  • third-party services that a Customer or User chooses to connect to Drum;
  • professional advisers, regulators, courts, law enforcement or other parties where disclosure is required or permitted by law; and
  • a purchaser, investor or successor in connection with a proposed or completed merger, financing, sale or reorganisation of all or part of our business, subject to appropriate confidentiality protections.

We limit the information provided to service providers to what is reasonably necessary for their role and require them to protect that information in accordance with their contractual obligations and applicable law. Our current provider list and a description of their roles is available on our Subprocessors page.

6. Data hosting and international processing

Drum’s primary production application, databases, caches and file storage are hosted by DigitalOcean in Sydney, Australia. Drum Software Inc.’s incorporation in the United States does not mean that core Customer Data is stored in the United States.

Personal information and, depending on the feature, Customer Data may be processed outside Australia by our service providers or by a third-party service that a Customer chooses to connect to Drum. This may include processing in the United States and other countries in which those providers operate. For example, this can occur when a User submits content to an AI-assisted feature, sends or receives email through Drum, requests support, participates in assisted onboarding, or uses a connected service.

Where personal information is disclosed outside Australia, we take reasonable steps to ensure that it is handled consistently with this Privacy Policy and applicable privacy law.

7. Security and confidentiality

We use reasonable administrative, technical and organisational safeguards designed to protect personal information and Customer Data from misuse, interference, loss and unauthorised access, modification or disclosure. These safeguards include encryption in transit, access controls and limiting access to personnel and contractors who need the information to operate, secure or support the Services and who are subject to confidentiality obligations.

As a rule, we do not review Customer Data. We may access it where reasonably necessary to provide support requested by a Customer, maintain or secure the Services, investigate a suspected breach of our Terms, or comply with law. Where available, authorised support access uses account-access tools designed to record who accessed the account and why.

No method of electronic storage or transmission is completely secure. If we become aware of a data breach, we will investigate it and notify affected Customers, individuals or regulators where required by applicable law or our contractual obligations.

8. Retention and deletion

We retain personal information and Customer Data for as long as reasonably necessary to provide the Services, fulfil the purposes described in this Privacy Policy, comply with legal and accounting obligations, resolve disputes and enforce our agreements.

Cancellation of a subscription does not by itself necessarily delete the Customer’s account. When an account is deleted, active Customer Data is deleted as part of that process. Where applicable, limited copies may remain temporarily in backup or disaster-recovery systems until they are overwritten or expire through their normal lifecycle. We may retain particular information for longer where required by law, to establish or defend legal claims, or to protect the security and integrity of the Services.

Customers should export any Customer Data they require before requesting account deletion. A Customer may contact us to request deletion, subject to applicable legal, security and technical requirements.

9. Cookies and website analytics

We use cookies and similar technologies for website functionality, analytics, customer support and marketing. These technologies may collect device and usage information and help us understand how our website and communications are used.

You can control cookies through your browser and, where available, the controls provided by the relevant service. Disabling some cookies may affect how the website or Services function. See our Cookies Policy for more information.

10. Access, correction and choices

You may ask to access or correct personal information that Drum holds about you. You may also ask us to delete information where applicable. We may need to verify your identity and may decline a request where permitted or required by law. We will explain our decision and respond within a reasonable timeframe.

If your information forms part of Customer Data, please contact the Customer that controls the relevant Drum account first. Where appropriate, we will assist the Customer in responding to your request.

You can opt out of promotional emails by using the unsubscribe link in the message. You will continue to receive essential account, billing, support and security communications.

11. Children

Drum is a business service and is not intended for use by children under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to Drum, please contact us so that we can take appropriate action.

12. Complaints and contact details

If you have a question, want to exercise a privacy right or wish to complain about how we have handled personal information, please contact us:

Drum Software Inc.
2140 South Dupont Highway
Camden, Delaware 19934
United States
Email: support@getdrum.com

We will investigate privacy complaints and respond within a reasonable timeframe. If you are not satisfied with our response and the Australian Privacy Act applies, you may be entitled to contact the Office of the Australian Information Commissioner.

13. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our Services, business practices or legal obligations. We will publish the updated policy on this page and change the “Last updated” date above. Where required by law or where a change is material, we will provide additional notice.