Legal
Privacy Policy
Effective 2026-09-12
What Shipped collects
- Account
- Your email address, and your Google or GitHub account identifier if you sign in that way.
- Builder profile
- Your handle, display name, bio, and avatar image.
- Provider data
- When you connect Dodo Payments, RevenueCat, Stripe, Lemon Squeezy, Polar, or Paddle, Shipped stores the transactions and subscriptions it reads: amounts, currency, the provider-side opaque customer id, and an HMAC digest of the customer’s email - never the email itself. When you connect Google Search Console, GitHub, or Vercel Analytics, Shipped stores search, traffic, and commit day counts. Every provider credential is encrypted with AES-256-GCM before it is stored and is never logged.
- Cohort
- Cohort membership, and the projects you attach to a cohort.
- Marketplace
- Listing content, offers, deal room messages, checklist state, and the asset purchase summary for a deal you are party to.
- Images
- Uploaded project logos and ship log images, stored in Postgres.
- Logs and rate-limit records
- Operational records used to keep the service working and to slow down abuse - for example, how many sign-in links an email address requested recently.
- Cookies
- One session cookie, used to keep you signed in. Shipped sets no advertising or tracking cookies.
Why Shipped collects it
Account and profile data run the service you signed up for - signing you in and showing who a project belongs to. Provider data is what a project page, badge, board, and listing are built from; Shipped reads it because you connected the account and asked Shipped to show it. Cohort and marketplace data exist because you joined a cohort or took part in a listing. Logs and rate-limit records protect the service and the people using it. In short: everything Shipped stores is either something you gave it directly, something a provider you connected returned, or something the service needs to run and stay safe to use.
Google API Services User Data Policy
Shipped’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
GitHub and Vercel data
A GitHub connection reads commit activity to produce a day count; Shipped does not read your repository’s source. A Vercel Analytics connection reads traffic figures for the project you connect. Both are read-only, and both stop being read the moment you disconnect them.
Sub-processors
Shipped uses the following services to run. Each sees only the data its role requires.
| Service | Role |
|---|---|
| Railway | Hosts the application and the database. |
| Resend | Sends sign-in links and account email. |
| Google sign-in, and Google Search Console data when you connect it. | |
| GitHub | GitHub sign-in for source connections, and repository data when you connect it. |
| Vercel | Vercel Analytics data when you connect it. |
| Escrow.com | Only if you open an Escrow.com transaction from a deal room; Escrow.com then holds the funds, not Shipped. |
Retention
A provider credential is destroyed the moment you disconnect the provider, or the moment a project sells. Deleting your account destroys every credential you hold before anything else happens, then removes any project you own alone. Snapshots of a project’s figures - the record its public page and badge are built from - are kept as an immutable public record until the project itself is deleted; they are not editable after the fact, by you or by Shipped.
Your customers’ data
When you connect a payment provider, Shipped stores an opaque customer id and an HMAC digest of the customer’s email for each transaction - never the email itself, and nothing else about your customer. For that data, you are the controller and Shipped processes it on your behalf, the same way your payment provider does. If one of your customers wants to exercise a privacy right over their own data, they should contact you; Shipped holds no information that identifies them beyond what your provider already gave it.
Your rights
Wherever you are, you can ask Shipped to let you access the data it holds about you, correct it, delete it, export it, or object to how it is used. Account deletion is self-serve, in settings. For anything else, write to the contact address below and Shipped will respond within a reasonable time.
International transfers
Shipped is hosted in the United States. If you use Shipped from outside the United States, your data is transferred to and processed in the United States, and by the sub-processors listed above wherever they operate.
Children
Shipped is not for anyone under 18. Shipped does not knowingly collect data from anyone under 18; if you believe a child has created an account, contact us and we will remove it.
Changes to this policy
Shipped may update this policy. A material change will update the effective date above.
Contact
Questions about this policy, or a rights request: legal-pending@shipped.money.