Privacy Policy
How shipd handles personal information for visitors and customers in the US and EU.
Who we are
This Privacy Policy describes how shipd (the service operated at useshipd.com, app.useshipd.com, and related domains — together, the “Service”) collects, uses, discloses, and protects personal information.
shipd does not yet operate under a separately registered legal entity. References to “shipd,” “we,” “us,” or “our” mean the operators of the Service. When a legal entity is formed, this policy will be updated to name that entity as the controller (or equivalent) of personal information.
Contact for privacy requests: privacy@useshipd.com.
Scope
This policy covers personal information processed when you visit our marketing sites, create or use an account, use the dashboard, SDKs, CLI, APIs, documentation, or otherwise interact with shipd.
It is intended to address requirements applicable to individuals in the United States (including state privacy laws such as the CCPA/CPRA) and in the European Economic Area, United Kingdom, and Switzerland (including the GDPR and UK GDPR). Where local law provides stronger rights, those rights control.
Information we collect
We may collect:
- Account and contact data — name, email address, password or auth credentials, organization and project details, role, and communications you send us.
- Billing data — billing contact details, plan selection, and payment metadata processed by our payment providers (we do not store full card numbers).
- Product and usage data — configuration, flags, environments, audit events, API and SDK activity, device/browser information, IP address, and approximate location derived from IP.
- Customer content — data you submit to the Service (for example targeting attributes or identifiers you choose to send). You determine what end-user data, if any, you include.
- Cookies and similar technologies — as described in our Cookie Policy.
How we use information
We use personal information to:
- Provide, operate, secure, and improve the Service
- Create and manage accounts, organizations, and access controls
- Process transactions and send transactional notices
- Provide support and respond to requests
- Monitor abuse, debug, and maintain integrity and availability
- Analyze aggregated or de-identified usage to improve the product
- Send product or marketing communications where permitted (you can opt out)
- Comply with law and enforce our Terms of Service
Legal bases (EEA / UK / Switzerland)
Where GDPR or UK GDPR applies, we process personal information under these bases:
- Contract — to provide the Service you request
- Legitimate interests — to secure and improve the Service, prevent abuse, and communicate about relevant product updates, balanced against your rights
- Consent — for optional cookies, certain marketing, or other processing where consent is required (you may withdraw at any time)
- Legal obligation — where we must retain or disclose information to comply with law
International transfers
shipd may process information in the United States and other countries, including through the subprocessors we engage. When we transfer personal information from the EEA, UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses (or UK equivalent), plus supplementary measures where required.
Retention
We retain personal information only as long as needed for the purposes described in this policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and context. When no longer needed, we delete or de-identify information where feasible.
Security
We implement technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information; restrict or object to certain processing; withdraw consent; and lodge a complaint with a supervisory authority.
EEA / UK / Switzerland: You may exercise GDPR rights by emailing privacy@useshipd.com. You may also contact your local data protection authority.
United States (including California and other state privacy laws): You may request to know/access, correct, delete, or obtain a copy of personal information we hold about you, and to opt out of sale or sharing of personal information and certain targeted advertising, to the extent those concepts apply. We will not discriminate against you for exercising privacy rights. Submit requests to privacy@useshipd.com. We may need to verify your identity before fulfilling a request. Authorized agents may submit requests where permitted by law.
If you use shipd as part of an organization account, some requests may need to go through your organization administrator.
Children
The Service is not directed to children under 16 (or the higher age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
Customer responsibility for end-user data
If you use shipd to process data about your own end users, you are responsible for providing appropriate notices and obtaining any required consents under applicable law. shipd acts as a processor / service provider for customer content you submit, except where we process information as an independent controller (for example, account administration and our own marketing site analytics).
Changes
We may update this policy from time to time. We will post the revised version with an updated effective date and, when changes are material, provide additional notice as required by law.
Contact
Privacy questions and requests: privacy@useshipd.com
General contact: hey@useshipd.com