Skip to content

Legal

Privacy policy

This document has not been written yet.

Shipstack is pre-launch. This page is a placeholder so the site's structure is complete; it is not a legal document and should not be relied on. It will be replaced before the service is generally available.

What this page will cover

The published policy will set out what personal data Shipstack processes, why, and for how long, in particular the recipient addresses and contact details that necessarily pass through the API in order to produce a shipping label, and what is shared with carriers to do so.

It will also cover the lawful basis for that processing, the rights available to data subjects, and how to exercise them.

What is already true

Two things about the architecture are settled regardless of what the final policy says:

  • Carrier credentials are encrypted with AES-256-GCM before storage and held as binary, so a database backup leak is not a credential leak.
  • This marketing site holds no shipping data and has no database credentials. It sets no analytics or advertising cookies, and it loads no third-party scripts.

In the meantime

If you need these documents before they are published, for a procurement review for example, get in touch through Shipstack Manager.