Last updated: 31 August 2026
Effective date: 31 August 2026
Shipthis Inc. (“Shipthis,” “we,” “us” or “our”) provides a cloud-based freight management platform for freight forwarders, logistics providers and related businesses. Our services support freight and warehousing operations, quotations, customer and supplier management, accounting, documents, communications, reporting and business workflows.
This Privacy Policy explains how we handle personal data in connection with our websites, applications, customer portals, APIs, integrations, subscription services, implementation and other professional services, and support services (together, the “Services”). It covers website visitors, prospective clients, business contacts, platform users and people whose information our clients process through the Services.
A “Client” is an organization using the Services. “Authorised Users” are people the Client permits to use the Services. “Client Data” includes information submitted or otherwise provided by a Client or its Authorised Users, information processed or created on the Client's behalf, and data derived from that information, consistent with the applicable client agreement. Examples include shipment records, documents, accounting information and connected operational communications.
This policy describes personal-data practices. Contractual confidentiality and ownership protections may also apply to information that is not personal data.
Responsible entity. Shipthis Inc., a Delaware corporation with its office at 200 Continental Drive, Suite 401, Newark, Delaware 19713, United States, is the entity responsible for the processing described in this policy and the contracting party under our Master Services Agreement. Our affiliate Onder Shipthis Technologies Private Limited, a company incorporated in India with its registered office in Bengaluru, Karnataka, provides engineering, implementation and support services to Shipthis Inc. Personnel of that affiliate access personal data only on behalf of Shipthis Inc., under its instructions and confidentiality obligations; the affiliate does not independently determine the purposes for which Client Data is processed. [Confirm that an intra-group services and data-transfer agreement is in place between the two entities, and confirm that no Client contracts with the Indian affiliate directly; if any does, add “or, where your agreement is with Onder Shipthis Technologies Private Limited, that entity” to this paragraph.]
For personal data processed on a Client's behalf, the Client generally determines the purposes of processing, the information submitted, authorized access, enabled integrations and business workflows. Shipthis acts as a processor or equivalent service provider under the applicable agreement and documented instructions. Where a Client itself processes information for another organization, Shipthis's role depends on the applicable processing arrangement.
For our own business-contact, subscription-billing, website, marketing and corporate-administration activities, Shipthis acts as a controller to the extent that we determine the purposes and means of processing. Account administration, support and security activities are not automatically independent controller activities; their classification depends on whose purposes they serve.
Client Data is processed under the applicable Master Services Agreement (“MSA”), order form, statement of work and any executed Data Processing Agreement (“DPA”). This policy does not grant Shipthis additional ownership or unrestricted reuse rights in Client Data, amend a signed contract, or reduce an individual's statutory rights. Any contractual precedence is determined by the applicable agreements and law. Obligations imposed by connected-service providers also continue to apply to data obtained through those services.
A person whose information is controlled by a Client should ordinarily contact that Client about privacy requests. We assist as required by our processing obligations and applicable law.
Account and business-contact information. Names, business email addresses, telephone numbers, organization, job title, branch or department, user identifiers, permissions, authentication information and account preferences.
Client operational information. Shipment and booking information; shipper, consignee, agent, carrier, customer and supplier contacts; transport documents; customs and trade documents; quotations, rates, invoices, payment references and accounting records; warehouse records; tasks, approvals and audit histories. These records may include personal information about people who do not use Shipthis themselves.
Connected communications and files. Information made available through authorized mailbox integrations, including correspondence, message metadata, attachments and other permitted mailbox information; uploaded documents; and information extracted or generated for a Client's workflows. Message bodies and attachments from a personal mailbox are not retained as a Shipthis record unless they are incorporated into an operational workflow or record, or the user manually enters or saves the information in Shipthis. Section 6 explains connected email, including shared group mailboxes, in more detail.
Our billing, sales and support information. Subscription details, billing contacts, invoices, payment status, transaction references, enquiries, support tickets, feedback and troubleshooting materials. A Client's financial records stored in its Shipthis environment remain distinct from Shipthis's own subscription-billing records. Payment providers may process payment details under their own notices where applicable.
Technical and usage information. IP addresses, browser and device information, timestamps, session and authentication events, API activity, feature usage, performance measurements, errors and security logs. Diagnostic records containing Client Data are subject to the protections applicable to that data; calling information a “log” does not remove those protections.
Sensitive information. Documents or communications supplied by Clients may contain identifiers, financial information or other information treated as sensitive under applicable law. Clients should limit such information to what is necessary and lawfully permitted for their operations. The Services must not be used for information prohibited by the applicable agreement, including ITAR-controlled information where that contractual restriction applies.
We receive information directly from users and business contacts, from the Client or its Authorised Users, through authorized integrations, and through the operation of the Services. A Client may provide information about its employees, customers, suppliers, carriers, shippers, consignees or other contacts.
Website interactions, application activity and security systems may generate technical information. We may also receive information from service providers supporting our business, subject to the applicable purposes and permissions. Client Data is not treated as a source of contacts for Shipthis's unrelated marketing.
We process Client Data to deliver the contracted Services and implement lawful Client instructions. This includes operating logistics and accounting workflows, processing documents, linking communications to business records, providing enabled reporting and automation, maintaining authorized integrations, and providing support, security, maintenance, migration and recovery services.
We use our own business-administration information to manage enquiries, contracts, subscriptions, billing, service communications and legal obligations. Where lawful, we use separately obtained business-contact information to communicate about Shipthis products and events. Recipients can opt out of promotional communications.
Where a legal basis is required for Shipthis's controller activities, it may be contractual necessity where the individual is party to the relevant contract; legitimate interests in operating, supporting and securing our business, subject to balancing individuals' rights; compliance with legal obligations; or consent where required. Contracting with an organization does not automatically make contractual necessity the basis for every use of its employees' personal information.
For Client-directed processing, the Client is responsible for its legal basis and required notices and permissions, while Shipthis remains responsible for its own applicable obligations. An OAuth authorization permits specified access to a connected service; it is not blanket consent for unrelated uses or a substitute for any legal requirements that also apply.
Clients can use supported email integrations to manage operational communications inside Shipthis. Depending on the integration, granted permissions and enabled functionality, we process mailbox identity, sender and recipient addresses, CC and BCC fields where available, subjects, message bodies, headers, timestamps, attachments, conversation identifiers, folders or labels, categories, message status and permitted sending identities (together, “Connected Email Data”).
Users can access messages in their logistics context and use supported functions to send or reply, organize messages, synchronize mailbox state and associate correspondence with shipments, quotations, customers, suppliers, invoices or tasks. Where enabled, classification, extraction and AI assistance are described in Section 9.
We obtain connected-service access through the applicable authorization process. OAuth integrations provide authorization credentials rather than the user's Google or Microsoft password. We request permissions for implemented features, not merely for possible future functionality.
The business purpose of the integration does not mean that a provider's mailbox permission technically excludes personal or non-operational messages. Shipthis may access email content made available through an authorized integration, within the permission granted and the synchronization and selection rules described below, to provide the enabled functionality. Shipthis does not retain the content of a personal mailbox's messages (bodies and attachments) as a Shipthis record unless the content is incorporated into an operational workflow or record, the message was composed and sent from Shipthis, or the user manually enters or saves the information in Shipthis; message metadata, and the messages of a shared group mailbox, are stored as described below. Any temporary processing or caching required to provide the integration is subject to applicable retention and security requirements.
Connecting a mailbox and sharing its contents with colleagues are different actions. Access within Shipthis depends on the disclosed connection type, Client configuration, applicable user authorization and Shipthis access controls. We obtain any additional consent required before exposing private connected-service content to other users or services. Access to Gmail does not, by itself, authorize access to Google Drive or Calendar, and access to Outlook mail does not, by itself, authorize other Microsoft services.
Consent before connection. A user cannot connect a personal mailbox until they have read and accepted a consent notice describing this processing, and an administrator accepts the organisation-level notice on behalf of the Client when the integration is enabled. Group mailboxes can be connected only by a member of the group, and only where the Client has enabled shared mailboxes.
What we synchronize. A connected mailbox is synchronized for its Inbox and Sent Items only (for Gmail, the Inbox and Sent labels, excluding chats). We do not request or synchronize drafts, spam or junk, deleted items or trash, archive folders, or any other folder or label. Because a provider's mailbox permission covers the whole mailbox, this limitation is enforced by our synchronization rules rather than by the permission itself.
Initial synchronization. When a user connects a personal mailbox, they choose how far back the first synchronization reaches, up to 30 days, and no message dated earlier than the day before the user gave consent is synchronized. A group mailbox synchronizes the previous 30 days when it is connected. A synchronization run covers at most 2,000 messages.
Ongoing synchronization. After the initial synchronization we receive change notifications from the provider (Gmail push notifications for the Inbox and Sent labels; Microsoft Graph change notifications for the Inbox and Sent Items folders, which we renew every three days) and capture new incoming and outgoing messages as they arrive. We do not poll or scan the rest of the mailbox. [Gmail: add a label check to the change-notification path so that a message outside the Inbox and Sent labels, such as a draft or a spam message that arrives between two notifications, is not captured; today only the initial synchronization enforces the folder rule on Gmail.] If a connection's credentials expire or are revoked, synchronization stops until the mailbox is reconnected; for a group mailbox, the person who connected it is notified and the inbox shows that synchronization has stopped.
What we store. For every synchronized message we store its metadata: sender, recipients (To, Cc and Bcc where available), subject, date, conversation identifiers, the headers used for threading and bulk-mail detection, attachment names, sizes and types, and the classification described below. For a personal mailbox, we do not store the message body unless the conversation has been linked to a business record such as a shipment or quotation, or the message was composed and sent from Shipthis; until then the body is retrieved from the provider each time the user opens the message. When a conversation is linked to a record, its messages, including bodies, are saved with that record; when the last link is removed, the saved bodies are removed again. For a group mailbox, message bodies are stored. Attachment files are not copied during synchronization; they are retrieved from the provider when a user opens them and are stored in Shipthis only when a user or an authorized automation files them onto a record or submits them for document extraction.
Classification. Every synchronized message is classified as operational, notification, promotional, personal or unknown: first by rules (for example bulk-mail headers and known notification senders), and where rules do not decide, by an AI model that receives the sender, recipients, subject, attachment names and the message text (Section 9). Messages classified as personal or otherwise non-operational are kept as metadata, marked as ignored and shown only in the owner's own “All” and “Ignored” views; they are not deleted, and they are not hidden from the owner. Because classification happens after a message has been received, we do not claim to read only operational email. What we read is limited by the folder rules and the retention rules above.
Who can see a connected mailbox. A personal mailbox is visible only to the user who connected it. Colleagues and administrators do not see it through the inbox; a colleague sees the same message only if their own connected mailbox also received or sent it. There is no option to share a personal mailbox with other users. A group mailbox is visible to the members of the group it belongs to while the Client's shared-mailbox setting is enabled. Once a user links a conversation to a business record, the conversation becomes part of that record and is visible to users who are permitted to view the record. Support personnel can reach a Client's environment only under a Client-approved access grant (Section 13).
Email add-ins and extensions. Our Outlook add-in, Gmail add-on and Chrome extension work on the message the user currently has open. They send that message's content or attachments to Shipthis only when the user chooses to link it, create a record from it or upload its attachments.
Shipthis uses authorized Gmail access to provide its integrated email-client and operational-productivity features.
For a mailbox connection we request read access to Gmail and permission to send email from the user's address, in addition to the basic profile permissions used for sign-in. We do not request permission to modify or delete Gmail messages, and we do not request access to Google Drive, Calendar or any other Google service. We do not use domain-wide delegation or service accounts to access user mailboxes.
For information obtained from Google APIs, Shipthis complies with the Google API Services User Data Policy and its Limited Use requirements, together with the applicable Google Workspace user data and developer policy.
Shipthis may temporarily process Gmail content to provide the enabled email and workflow functionality. Message bodies and attachments from a personal Gmail mailbox are not retained as a Shipthis record solely because the mailbox is connected; message metadata is stored as described in Section 6, and the messages of a shared group mailbox are stored for that group. Where a user or authorized workflow incorporates email content into a shipment, customer, quotation, task or other operational record, that information becomes part of the applicable Client Data and is retained in accordance with the applicable agreement and retention requirements.
Google data is not sold, used for advertising, used for creditworthiness or lending, or used to train or improve general-purpose or cross-user AI models. Applicable restrictions continue to protect derived information.
Transfers are limited to permitted, consented user-facing functionality, necessary security purposes, legal requirements, or a business transfer with the user's explicit prior consent. Human review is limited to documented affirmative permission to view specific information, necessary security work, legal requirements, or aggregated and anonymized information used for permitted internal operations. Ordinary support needs do not create unrestricted permission to read messages.
Messages addressed to a Google Group can be processed when delivered to an authorized connected mailbox. That does not create independent access to the Group's archive or administration.
Users can revoke access through their Google Account connections or by disconnecting the mailbox in Shipthis, which also asks Google to revoke the token. Retention and deletion are addressed in Section 12.
For supported Microsoft integrations, Shipthis accesses authorized mail data through Microsoft identity services and Microsoft Graph. Access depends on granted permissions and the connection's authorization model.
Authorization models we support. All three models rely on delegated permissions granted by a signed-in user; we do not use application permissions that would allow access to a mailbox without a signed-in user, and we never read mail with an app-only token.
Delegated access is constrained by both the application's permissions and the signed-in user's own mailbox rights. Where an organization's Microsoft administrator has restricted user consent, an administrator may need to approve the connection. The only application-level call we make to a Client's Microsoft tenant is to remove Shipthis's own permission grants for a user when they disconnect.
Microsoft API data, including derived information, is not used for advertising or marketing. Copies held in Shipthis are limited to what Section 6 describes and are updated, restricted and deleted as set out in Section 12, including on disconnection, user deletion and the end of the Client agreement.
Users can manage consent through Microsoft account permissions or Microsoft My Apps, as applicable; organization-managed permissions may require an administrator. Disconnecting in Shipthis deletes our change-notification subscriptions, removes Shipthis's permission grants for the user in the Client's tenant where the tenant allows it, and deletes the stored tokens. Section 12 explains Shipthis-side deletion of the data already captured.
Where enabled and disclosed, Shipthis may process authorized Client Data to classify communications, extract information from documents, summarize content, find relevant business records, answer user questions, draft responses, generate reports or assist with business workflows. Features operate within the applicable Client instructions and access permissions.
Information processed for an AI feature can include a user's request, relevant record or message content, attachments, retrieved context and the resulting output. Such information may be temporarily processed or transmitted to an authorized AI or document-processing provider where necessary to provide the enabled feature. Email content is not retained as a Shipthis record merely because it is processed by an AI feature. Search indexes or other derived representations containing or capable of revealing personal information remain protected data.
We do not use Client Data or Connected Email Data to train or improve general-purpose or shared cross-client AI models. We do not permit providers engaged to process that content for us to use it for their independent advertising or generalized model-training purposes. These restrictions are not waived merely by including an AI feature in a subscription or describing its output as a Deliverable. The one model we fine-tune is our own support assistant, trained on Shipthis help articles and support conversations from which customer names, email addresses and organization names have been removed; Client operational data and connected email content are not used for it.
AI and document-processing providers. The following providers process content for our AI features. Each is engaged under enterprise terms that prohibit use of our content to train the provider's models. Which provider handles a given request depends on the feature and on how the Client's environment is configured; there is no user-facing choice of provider.
ProviderServiceUsed forWhere processedMicrosoft (Azure OpenAI Service and Azure AI Foundry)GPT-family models; an xAI Grok model hosted by Microsoft; Whisper speech-to-textMost AI features: document extraction (Magic Drop), inbox agents, the Caeli assistant, Ask AI, drafting, cash-flow forecasting, transcription of WhatsApp voice notesUnited States [confirm the region of the production Azure resources]Amazon Web Services (Amazon Bedrock)Mistral Large; Anthropic Claude modelsInbox email classification (Mistral); Claude models where a Client's environment is configured to use them instead of AzureUnited States (N. Virginia)Google Cloud (Vertex AI)Gemini modelsDocument extraction and Ask AI for certain document typesUnited States (Iowa)Voyage AIText embeddingsIndexing descriptions of Shipthis's own report catalogue for the Caeli assistant; no Client Data is sentUnited StatesGoogle Cloud TranslationMachine translationTranslating interface labels; no Client Data is sentGlobal service
Documents submitted for extraction are converted to page images by a service we operate on Google Cloud (United States) and are sent to the model as images together with their extracted text; spreadsheets are sent as full row data. Inbox classification sends the sender, recipients, subject, attachment names and message text, including earlier messages in the same conversation. Inbox agents send the message subject and category together with excerpts of the business records they retrieve while working. The Caeli assistant sends the user's question, the conversation so far and the records it retrieves. Where a user chooses voice input in Caeli, the browser's own speech-recognition service (for Chrome, provided by Google) converts the audio to text before it reaches Shipthis.
Provider retention and human access. Under their published terms, the providers above do not use content we send to train their models. Some providers retain inputs and outputs for a limited period to monitor for abuse and may allow authorized provider personnel to review flagged content for that purpose. [Confirm whether Shipthis has been approved for Microsoft's modified abuse monitoring, which removes Azure OpenAI's 30-day retention; state the outcome here.] “Not used for training” does not, by itself, mean that a provider never retains or reviews data.
What we keep. AI outputs are stored in the Client's own environment. Extracted data is saved with the document or record it relates to, together with a cached copy of the model's response used to avoid re-processing the same file. Each inbox agent run is recorded with the decision taken, the tools used, token counts and short excerpts of the record data the agent consulted; prompt text is not stored. Caeli conversations are stored so that users can return to them. Usage records hold token counts and costs, not content.
AI-generated information can be inaccurate. Clients and users should apply appropriate review before relying on outputs for financial, customs, regulatory or other material decisions. Sending messages or changing records occurs according to the supported feature and the user's instruction or Client-authorized workflow; this policy does not imply that every action requires a separate manual approval.
The Client and its authorized recipients. We make Client Data available according to lawful instructions, permissions and enabled collaboration or portal features. Information sent to a carrier, customer, agent or another integration recipient is disclosed as part of the requested workflow, not for Shipthis's unrelated use.
Personnel and service providers. Necessary personnel, authorized affiliates, subcontractors and professional advisers may access information to carry out their assigned functions, subject to contractual permissions, confidentiality and applicable data-protection obligations. Hosting, database, storage, support, security, communications and approved AI or document-processing providers may support the Services. Provider categories do not grant a right to disclose every kind of Client Data to every provider.
We distinguish providers processing data on our behalf from independent services that a Client chooses to connect. Required subprocessor authorization and contractual protections are addressed in the applicable DPA or other binding processing terms. Google-specific human-access and transfer restrictions remain applicable.
Subprocessors. The providers that process Client Data on our behalf are listed in Annex A, with their purpose and processing location. We add a provider to that list only after confirming its contractual data-protection commitments, and we notify Clients of additions as provided in the applicable DPA. Services that a Client itself connects or directs us to send data to, such as carriers, customs authorities, e-invoicing gateways, tracking providers, payment gateways and messaging channels, receive data as the Client's chosen recipients and are not our subprocessors.
Legal disclosures. We disclose information when lawfully required and limit disclosure to what is required. For Client Confidential Information, we provide advance notice where required by the applicable agreement and legally permitted, so that the Client can seek protection.
Business transactions. Any disclosure connected with a proposed or completed corporate transaction remains subject to confidentiality, contractual restrictions, applicable law and provider-specific requirements. This paragraph does not create an unrestricted exception for Client Data or Google data.
We do not sell Client Data or Connected Email Data to advertisers, data brokers or information resellers. Permission to use an organization's name, logo or approved testimonial does not authorize disclosure of its private messages, documents or individuals' information for marketing.
Where permitted by the applicable agreement, we analyze the provision, use and performance of the Services for development, diagnostics, correction and improvement. Contractually permitted disclosures of such analytics to third parties are limited to aggregate or anonymized information and remain subject to confidentiality and data-ownership restrictions.
Information that is merely pseudonymized or linkable to an individual remains personal data. Information generated from Client Data does not automatically become unrestricted Shipthis data.
We do not rely on general analytics or improvement rights to sell private Client information, train general-purpose or shared cross-client models on Client Data, or bypass restrictions on Google or Microsoft data. Provider-specific restrictions continue to apply to derived, aggregated or anonymized information where those rules require it.
We retain Client Data for the contracted processing purposes and in accordance with lawful Client instructions, the applicable agreement and any additional provider-specific requirements. Retention takes account of the data's purpose, sensitivity, necessity and applicable legal obligations. A Client's own recordkeeping obligations do not automatically authorize Shipthis to retain all of its information indefinitely.
Return and deletion of Client Data are governed by the Client's executed agreement and applicable law. Under our standard MSA, Client Data is retained for a Retention Period of 30 days after the agreement expires or terminates and is then permanently deleted. The Client's own access to the Services ends when the agreement ends, so retrieval during the Retention Period is arranged through our support team: on request we provide exports of the Client's records in machine-readable form (CSV or Excel) and copies of its stored documents and files in their original formats. While the agreement is in force, Clients can export their records themselves through the list and report export functions of the Services and through the REST API, and are encouraged to do so before the agreement ends.
At the end of the Retention Period we delete the Client's databases and stored files from production systems. Backup copies are overwritten in the ordinary backup cycle described in Section 12.4 and are not used to restore deleted Client Data into ordinary use. An extension of the Retention Period requires the Client's express request under the agreement, or a legal requirement; the agreement provides for retention required by law or for archival purposes only to the extent and for the period that law requires, with the data held in confidence and used for no other purpose. An earlier return or deletion request is handled under the applicable contractual and legal provisions.
Where an executed agreement contains different return or deletion terms, that agreement governs. This policy does not extend an agreed deletion deadline, and the arrangements for data retrieval do not, by themselves, extend the Client's subscription or general right to use the Services.
Disconnecting an integration, removing its authorization, requesting deletion of downloaded information and terminating a Shipthis subscription are different events. Disconnection stops further synchronization using that authorization once the disconnection is processed or revocation is detected. It does not delete the original mailbox maintained by Google or Microsoft.
When a user disconnects a mailbox in Shipthis. We immediately stop the Gmail notifications or delete the Microsoft Graph subscriptions, ask Google to revoke the token or remove Shipthis's permission grants for the user in the Client's Microsoft tenant, and delete the stored access and refresh tokens. Messages, conversations and attachments already captured are Client Data and remain in the Client's environment: message bodies from a personal mailbox are held only for linked conversations and are removed when the last link is removed; group-mailbox messages, conversations saved with business records and attachments filed onto records remain until the Client removes them or its environment is deleted at the end of the agreement. Activity-log entries that record message subjects are deleted after 30 days.
When access is revoked at Google or Microsoft. Synchronization stops as soon as the next request to the provider fails and the connection is marked as needing re-authorization. The stored credentials are no longer usable; they are cleared when the user reconnects or disconnects the mailbox, or when the user is deleted.
When a user leaves. Deleting a user deletes the stored credentials with the user's record, which ends synchronization. Disabling a user's login does not by itself disconnect their mailbox, so a Client should disconnect the mailbox before disabling the user, or delete the user. Captured messages remain part of the Client's environment as described above.
When a connection is abandoned. A connection whose credentials have expired is marked as needing re-authorization; after three consecutive failed renewals we stop attempting to renew it. Captured data is handled as described above.
At the end of the Client agreement. Captured messages, conversations, extracted data, agent records, stored attachments and remaining mailbox credentials are deleted with the Client's environment after the Retention Period in Section 12.2.
Retention of content deliberately incorporated into an operational record requires a continuing permitted purpose and must comply with the relevant contract, law, source-service policies and applicable deletion requests. Incorporating content into a shipment, report, summary or search index does not remove those restrictions. We retain connected-service data only as permitted for the authorized feature and honor the provider's applicable deletion obligations. A general MSA retention period does not independently authorize an incompatible period of retention for API-derived data.
Backup copies remain subject to applicable contractual deletion commitments. Our database provider takes automated, encrypted backups of production databases. Backup copies are used only to restore service after a failure, are held for a rolling period of [insert the configured MongoDB Atlas snapshot and continuous-backup retention] and are overwritten at the end of that period, so data deleted from production systems also disappears from backups within that period. A backup is never used to reintroduce deleted Client Data into ordinary use. Stored documents and files are held in Google Cloud Storage and are deleted with the Client's environment [confirm whether object versioning or soft delete is enabled on the storage buckets and, if so, state the additional retention period].
Application logs are held in Google Cloud Logging for [30] days [confirm the configured retention] and contain request metadata and user identifiers rather than document contents. Audit trails of changes to business documents and logs of email sent from the Services are kept for the life of the Client's environment so that the Client's records remain verifiable, and are deleted with the environment. Activity feeds are deleted after 30 days, and saved report-builder conversations in the Caeli assistant after 30 days. This policy does not create a separate indefinite backup or archival exception.
Where law requires retention, we limit the information, duration and use to that requirement. Our own subscription invoices, contracts and essential compliance records may have a different retention basis from a Client's operational database. Keeping those records does not justify keeping the entire Client environment.
For records that we hold as a controller we apply the following retention periods [confirm with finance and legal]: contracts, order forms, subscription invoices and payment records, for [seven] years after the end of the Client relationship, as required by tax and accounting law; support tickets and their attachments, for [three] years after closure; sales enquiries and business-contact records, for as long as we have an active relationship or a legitimate interest in contacting the person and no longer than [two] years after the last contact; website analytics and advertising data, for the periods set out in Section 16; security and access logs, for the log-retention period above.
Clients can contact support@shipthis.co to request data retrieval or deletion under their agreement. Individuals can use the privacy-request process in Section 15. Requests concerning organization-controlled records are handled with the relevant Client, without limiting any obligations Shipthis has directly under law or connected-service policies.
We maintain appropriate administrative, physical and technical safeguards to protect Client Data, consistent with our contractual obligations. Access is limited to authorized functions and confidentiality duties continue as required after the service relationship ends.
Our safeguards include the following.
No system is completely secure. Clients and users are responsible for securing their devices and credentials and managing authorized access, including access for departing personnel. These responsibilities do not remove Shipthis's own obligations. Ordinary internet email is not necessarily end-to-end encrypted; transport encryption and end-to-end encryption are different protections.
The Services involve processing by Shipthis and authorized providers in more than one country.
Where Client environments run. Each Client organization is assigned to a hosting region when it is set up, and its operational database, log database and application servers run in that region on Google Cloud: United States (Iowa), India (Mumbai), Belgium, Germany (Frankfurt), Australia (Sydney) or South Africa (Johannesburg). Clients on a dedicated plan have their own database cluster.
Shared components. Some components serve every region from one location. The configuration and identity databases that hold user accounts, sign-in sessions and organization settings, the authentication service, and our internal document-conversion, file-upload, integration and sanctions-screening services run on Google Cloud in the United States (Iowa). Uploaded documents and files are held in Google Cloud Storage [state the bucket location]. The AI providers in Section 9 process in the United States. The live channel of our in-app help widget runs on Microsoft Azure in the United States. Email sent from the Services is delivered through Mailgun [state the Mailgun region in use, United States or European Union]. Our track-and-trace service runs on servers in Germany (Nuremberg) with backups in Finland (Helsinki) [confirm that this cluster is the production home of the track-and-trace service and whether the realtime notification service also runs there; the realtime host currently answers from Google Cloud]. Session-replay tools, where a Client has opted in, process in the European Union [and confirm the location of the Shipthis-operated replay service].
Where our people work. Shipthis Inc. personnel and personnel of our Indian affiliate provide engineering and support from [the United States and India]. Support access to a Client environment is always subject to Section 13.
Where law requires a mechanism for transferring personal data internationally, the relevant processing must be covered by a legally valid mechanism and any required supplementary safeguards. For personal data subject to European Economic Area, United Kingdom or Swiss data-protection law, our Data Processing Agreement incorporates the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers to Shipthis and its subprocessors outside those areas. [Confirm that the DPA template in use contains the Standard Contractual Clauses and the UK Addendum; if there is no such template yet, prepare one before publication and offer it to existing Clients.] A Client that has not yet executed a DPA can request one from support@shipthis.co. A Client's general agreement to use a cloud service is not a substitute for a required transfer mechanism.
Individuals and Clients can contact us for information about relevant safeguards and how to obtain a copy, subject to appropriate protections for confidential information.
Depending on the applicable law and our role, individuals may have rights to access, correct, delete or obtain a portable copy of personal data; restrict or object to processing; withdraw consent; or exercise applicable opt-outs. Some jurisdictions also provide rights concerning targeted advertising, certain profiling, sensitive information and appeals of denied requests. These rights are subject to their legal conditions and exceptions.
To make a request concerning processing for which Shipthis is responsible, contact support@shipthis.co. We may request information reasonably necessary to verify identity and authority. Authorized agents may act where permitted by law. We respond within the applicable legal timeframe and explain a refusal or available appeal route where required. We do not unlawfully discriminate against people for exercising their rights.
For information processed on a Client's behalf, contact that Client or identify it in your request to us. We may refer the request to the Client and assist it as required. Withdrawal of a connected-service authorization stops the relevant future access but does not automatically resolve every retention question; Section 12 explains the separate processes.
Regional information.
Our public website (www.shipthis.co). The website runs on Webflow and loads Google Tag Manager, through which the following technologies are used: Google Analytics 4 (visitor and traffic measurement; _ga and _ga_* cookies, up to 2 years); Google Ads conversion tracking and remarketing (_gcl_au, 3 months, and Google advertising cookies such as IDE, up to 13 months); Hotjar (heatmaps and session recordings of website visits; _hjSession*, 30 minutes, and _hjSessionUser*, 1 year); LinkedIn Insight Tag (li_sugr, bcookie, lidc, up to 2 years); Meta Pixel (_fbp, 3 months); the X (Twitter) pixel (muc_ads, personalization_id, up to 2 years); Drift (website chat; driftt_aid, up to 2 years); and Factors.ai (identification of the companies visiting our site for sales follow-up). The website also uses Google reCAPTCHA on forms (_GRECAPTCHA, 6 months), Google Fonts, and script libraries served from content-delivery networks, which receive the visitor's IP address but set no cookies. Embedded YouTube videos set YouTube's cookies when played.
Strictly necessary technologies run when a page loads, including a session cookie set by our edge network provider Cloudflare (_cfuvid, deleted when the browser closes). Analytics, functionality and advertising technologies are used only after the visitor accepts them in the cookie notice; the choice is stored in the browser (accepted_cookies) and can be changed by clearing site data. [Before publication, configure Google Tag Manager consent mode so that analytics and advertising storage are denied until the visitor accepts, and add a “Reject” option to the notice; today the tags load on page load regardless of the choice.] Visitors can also use the vendors' own controls: Google Ads Settings, the Google Analytics opt-out add-on, Hotjar opt-out, LinkedIn, Meta and X advertising preferences, and browser settings that block or delete cookies. Our separate Cookie Policy lists the same technologies [update it, last revised in 2021, to match this section before publication].
Our applications (the Shipthis platform, customer, vendor and supplier portals and mobile apps). We do not use advertising or marketing technologies, and Shipthis does not run Google Analytics, in our applications. Shipthis does not set cookies of its own, apart from short-lived security cookies that our edge network provider (Cloudflare) may set; sign-in tokens, the selected organization, location and language, theme and similar preferences are kept in the browser's local storage until the user signs out or clears site data. Our main application loads Google Tag Manager only to load our in-app help widget and, for organizations that have opted in to session replay, the tools described below; our portals do not load Google Tag Manager. Third-party components are loaded only when a feature needs them: Stripe.js when a payment card is entered (__stripe_mid, 1 year, and __stripe_sid, 30 minutes, set by Stripe), the Balance checkout where a Client has chosen that payment provider, Mapbox for maps, Unlayer for the email-template editor, Google reCAPTCHA on customer-portal sign-up, and Google Fonts. A Client may enable its own Google Analytics for its portal or environment through its settings; the Client is the controller of that analytics data. Our mobile apps use Firebase Cloud Messaging for push notifications only and contain no analytics or crash-reporting SDKs.
Session replay (opt-in). For organizations whose administrator has enabled analytics access, sessions in the platform may be recorded with Smartlook (hosted in the European Union) and with a session-replay service operated by Shipthis, to diagnose problems and improve the product. Recording is off by default. Keyboard input, numbers, email addresses, email content and user names are masked before a recording leaves the browser. [Confirm the hosting location and retention period of the Shipthis-operated replay service and add them here.]
Support widget and support sites. The in-app help widget identifies the signed-in user (name, email and organization) so that tickets are attributed correctly; its live-chat channel is operated by Shipthis on Microsoft Azure. Our help site (help.shipthis.co) sets no tracking cookies. Our status page (status.shipthis.co) is hosted by UptimeRobot under its own privacy notice.
Promotional communications use separately obtained business-contact information, not private Client email content. Users can unsubscribe from promotional emails or contact us. Essential account, billing, security and service communications may continue.
Public-website tracking practices are distinct from processing within authenticated Client environments. A statement that we do not sell Client Data does not, by itself, describe whether public-website advertising technologies constitute a regulated sale, sharing or targeted-advertising activity; Section 15 addresses that question.
The Services are intended for business users and are not directed to children. We do not knowingly solicit children's information for individual consumer accounts. If information about a child has been provided in circumstances prohibited by applicable law or the relevant agreement, contact us so that we can assess the appropriate response with the responsible Client where applicable.
We update the dates above when this policy changes. Changes are communicated to Clients through a service announcement or an email to the Client's registered primary contact, consistent with the applicable MSA.
Where required, we provide additional notice and obtain affirmative consent before introducing a new data use or materially different connected-service processing. Continued use of the Services does not substitute for consent where affirmative consent is required. We do not use a policy update to remove statutory rights or avoid agreed contractual amendment requirements.
Shipthis Inc.
200 Continental Drive, Suite 401
Newark, Delaware 19713
United States
Affiliate (engineering and support): Onder Shipthis Technologies Private Limited, Bengaluru, Karnataka, India
Privacy enquiries and requests: support@shipthis.co