Legal

Privacy Policy

Effective 2026-09-12

What Shipped collects

Account
Your email address, and your Google or GitHub account identifier if you sign in that way.
Builder profile
Your handle, display name, bio, and avatar image.
Provider data
When you connect Dodo Payments, RevenueCat, Stripe, Lemon Squeezy, Polar, or Paddle, Shipped stores the transactions and subscriptions it reads: amounts, currency, the provider-side opaque customer id, and an HMAC digest of the customer’s email - never the email itself. When you connect Google Search Console, GitHub, or Vercel Analytics, Shipped stores search, traffic, and commit day counts. Every provider credential is encrypted with AES-256-GCM before it is stored and is never logged.
Cohort
Cohort membership, and the projects you attach to a cohort.
Marketplace
Listing content, offers, deal room messages, checklist state, and the asset purchase summary for a deal you are party to.
Images
Uploaded project logos and ship log images, stored in Postgres.
Logs and rate-limit records
Operational records used to keep the service working and to slow down abuse - for example, how many sign-in links an email address requested recently.
Cookies
One session cookie, used to keep you signed in. Shipped sets no advertising or tracking cookies.

Why Shipped collects it

Account and profile data run the service you signed up for - signing you in and showing who a project belongs to. Provider data is what a project page, badge, board, and listing are built from; Shipped reads it because you connected the account and asked Shipped to show it. Cohort and marketplace data exist because you joined a cohort or took part in a listing. Logs and rate-limit records protect the service and the people using it. In short: everything Shipped stores is either something you gave it directly, something a provider you connected returned, or something the service needs to run and stay safe to use.

Google API Services User Data Policy

Shipped’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

GitHub and Vercel data

A GitHub connection reads commit activity to produce a day count; Shipped does not read your repository’s source. A Vercel Analytics connection reads traffic figures for the project you connect. Both are read-only, and both stop being read the moment you disconnect them.

Sub-processors

Shipped uses the following services to run. Each sees only the data its role requires.

ServiceRole
RailwayHosts the application and the database.
ResendSends sign-in links and account email.
GoogleGoogle sign-in, and Google Search Console data when you connect it.
GitHubGitHub sign-in for source connections, and repository data when you connect it.
VercelVercel Analytics data when you connect it.
Escrow.comOnly if you open an Escrow.com transaction from a deal room; Escrow.com then holds the funds, not Shipped.

Retention

A provider credential is destroyed the moment you disconnect the provider, or the moment a project sells. Deleting your account destroys every credential you hold before anything else happens, then removes any project you own alone. Snapshots of a project’s figures - the record its public page and badge are built from - are kept as an immutable public record until the project itself is deleted; they are not editable after the fact, by you or by Shipped.

Your customers’ data

When you connect a payment provider, Shipped stores an opaque customer id and an HMAC digest of the customer’s email for each transaction - never the email itself, and nothing else about your customer. For that data, you are the controller and Shipped processes it on your behalf, the same way your payment provider does. If one of your customers wants to exercise a privacy right over their own data, they should contact you; Shipped holds no information that identifies them beyond what your provider already gave it.

Your rights

Wherever you are, you can ask Shipped to let you access the data it holds about you, correct it, delete it, export it, or object to how it is used. Account deletion is self-serve, in settings. For anything else, write to the contact address below and Shipped will respond within a reasonable time.

International transfers

Shipped is hosted in the United States. If you use Shipped from outside the United States, your data is transferred to and processed in the United States, and by the sub-processors listed above wherever they operate.

Children

Shipped is not for anyone under 18. Shipped does not knowingly collect data from anyone under 18; if you believe a child has created an account, contact us and we will remove it.

Changes to this policy

Shipped may update this policy. A material change will update the effective date above.

Contact

Questions about this policy, or a rights request: legal-pending@shipped.money.

Back to legal