Privacy Policy
Effective Date: 22 June 2026
Last Updated: 5 July 2026
1. Introduction
Welcome to shippin.io ("Platform", "we", "us", or "our"). shippin.io is operated by an individual based in Mumbai, India. We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit and use shippin.io (the "Platform"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Platform.
This policy applies to all users worldwide, including users in the European Union (GDPR), the United Kingdom (UK GDPR), California (CCPA/CPRA), and India (Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023).
For any privacy-related questions, contact us at: legal@shippin.io
2. Information We Collect
2.1 Information You Provide Directly
Account Registration (Email/Password)
- Full name
- Email address
- Password (stored as a cryptographic hash — we never store your plain text password)
- Username (chosen by you)
Account Registration (Google OAuth)
- First name and last name
- Email address
- Google profile picture
- Google account identifier
Profile Information (optional, provided by you)
- Profile bio
- Avatar image
- Website URL
- Twitter/X handle
- LinkedIn URL
Product Listings
- Product name, tagline, description, and website URL
- Product logo and cover image
- Product category, pricing model
- Developer notes
- Screenshots (up to 3)
- Revenue information (manual entry or processor-connected)
- Open-for-acquisition status and asking price (USD), when set by a Builder subscriber
- Scheduled launch date and relaunch date
- Moderation status (pending, published, or flagged)
- Archive status and timestamp (when a listing is hidden from public view)
- Social handles for the product (Twitter/X, LinkedIn)
Acquisition Interest (signed-in users)
- Optional message (up to 500 characters)
- Whether you chose to share your email with the product owner
- Product submitted and timestamp
Payment Processor Connection (Builder plan users only)
- Read-only API key for DodoPayments or Stripe (encrypted using AES-256-GCM before storage — we never store your key in plain text)
Promotional Slot Purchases
- Billing period selected (weekly or monthly)
- Amount paid (stored in cents for accounting purposes)
- DodoPayments payment reference ID
- Ad slot expiry date and time
- Product selected for promotion (linked to your product listing)
- Checkout hold status (temporary — auto-deleted after 60 minutes if checkout is not completed)
- Early termination requests via Settings → Billing ("End promotion") — we update the slot expiry immediately; no refund is issued for unused time
Communications
- Any information you provide when contacting us at legal@shippin.io
2.2 Information Collected Automatically
Usage and Analytics Data
We use Vercel Analytics to collect anonymised usage data including:
- Pages visited and navigation patterns
- Referring URLs
- Browser type and operating system
- General geographic region (country/region level — not precise location)
- Device type
We collect IP addresses for rate limiting and abuse prevention across the Platform. IP addresses are processed transiently in Upstash Redis (rolling time-window buckets) and are not stored persistently in our database beyond the rate-limit window. They are not used for analytics, profiling, or tracking.
Engagement Data
We track the following engagement signals on product listings to power our ranking algorithm:
- Product page views (anonymised)
- Outbound clicks to product websites (anonymised)
- Upvotes (associated with your account)
These signals are temporarily stored in Upstash Redis before being flushed to our database on an hourly basis.
Session Data
When you log in, we store a session cookie via Supabase Auth to keep you authenticated. This cookie is essential for the Platform to function and cannot be opted out of while using an authenticated session.
2.3 Information We Do Not Collect
- Payment card numbers, bank account details, or full payment instrument data (handled entirely by DodoPayments — we never see or store your card details)
- Precise geolocation
- Date of birth
- Sensitive personal information (racial or ethnic origin, religious beliefs, health data, biometric data)
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| To create and manage your account | Performance of contract |
| To display your profile and active products publicly | Performance of contract / Legitimate interest |
| To process archive and unarchive requests (hide or restore listings) | Performance of contract |
| To enforce free-tier and Builder plan product limits, including automatic archiving when a subscription expires | Performance of contract |
| To process your Builder subscription via DodoPayments | Performance of contract |
| To generate and display revenue badges on product listings | Performance of contract |
| To power the product ranking algorithm using engagement signals | Legitimate interest |
| To generate semantic search embeddings via VoyageAI | Legitimate interest |
| To display product listings in search results | Performance of contract |
| To enforce our Terms of Service and moderate content | Legitimate interest / Legal obligation |
| To prevent fraud, abuse, and spam | Legitimate interest |
| To comply with applicable laws | Legal obligation |
| To improve the Platform via anonymised analytics | Legitimate interest |
| To process one-time promotional slot purchases via DodoPayments | Performance of contract |
| To manage ad slot availability, holds, and activations | Performance of contract |
| To issue automatic refunds when slots are unavailable or product becomes ineligible at payment time | Performance of contract / Legal obligation |
| To display your promoted product in the sidebar during the booked period | Performance of contract |
| To end an active promotional slot early when you use End promotion in Settings → Billing | Performance of contract |
| To relay acquisition interest to product owners via email | Performance of contract / Legitimate interest |
| To review submitted content via automated moderation | Legitimate interest / Legal obligation |
We do not use your information for targeted advertising. We do not sell your personal data to any third party.
Purpose Limitation: We will only use your personal data for the purposes described in this section. If we need to use your data for a materially different purpose, we will notify you and, where required by law, obtain your consent before doing so.
4. How We Share Your Information
4.1 Public Information
The following information is publicly visible on the Platform to all visitors including non-registered users:
- Your username, display name, bio, avatar, and public profile
- Products you have launched that are active (not archived), visible, and not hidden for moderation
- Archived product listings — hidden from the directory, search, sitemap, and public profile views; only you can access the archived product page while signed in
- Revenue badges on your products (if you have chosen to display revenue)
- Upvotes you have cast
- Your Twitter/X and LinkedIn handles if added to your profile or products
- If you have purchased a promotional sidebar slot, your product's name, tagline, and logo are displayed in the promoted sidebar visible to all visitors, including unauthenticated users and search engine crawlers, for the duration of the booked slot
- Open-for-acquisition status, asking price, and aggregate interest count on qualifying product listings (visible only while the owner holds an active Builder subscription)
Be aware: Any information you voluntarily add to your public profile or product listing is visible to everyone, including search engines and AI crawlers.
4.2 Third Party Service Providers
We share data with the following third party services solely to operate the Platform. Each provider is contractually bound to protect your data:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account data, product data, session tokens | Singapore |
| Google (OAuth) | Sign-in via Google | Authentication tokens | Global (Google infrastructure) |
| DodoPayments | Subscription billing and one-time promotional slot purchases | Email, name, subscription plan metadata, one-time payment amount and reference ID, ad booking metadata (product ID, billing period) | Per DodoPayments infrastructure |
| Stripe | Revenue verification for connected products (Builder plan) | Read-only API key (encrypted), payment metadata | Per Stripe infrastructure |
| Vercel | Platform hosting and analytics | Anonymised usage data | Global (Vercel infrastructure) |
| Upstash | Engagement data caching (Redis) | Anonymised engagement counters | Singapore |
| VoyageAI | Semantic search embeddings | Product text (name, tagline, description) — no personal data | Per VoyageAI infrastructure |
| OpenAI | Automated content moderation on product listings and user messages | Product text and images; acquisition interest messages — no account data beyond submitted content | Per OpenAI infrastructure |
| Inngest | Background job orchestration (revenue sync, email delivery) | Payment metadata for revenue sync; email address, name, and booking context for transactional email jobs | Per Inngest infrastructure |
| Plunk | Transactional email delivery | Email address, first name, and email body content (subscription, launch, relaunch, acquisition interest, ad booking, and account notifications) | Per Plunk infrastructure |
4.3 Legal Disclosures
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to:
- Comply with a legal obligation
- Protect the rights, property, or safety of shippin.io, our users, or the public
- Prevent or investigate fraud or security issues
4.4 Business Transfers
If shippin.io is acquired, merged, or its assets are transferred, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Platform before your data is transferred and becomes subject to a different privacy policy.
4.5 What We Never Do
- We never sell your personal data
- We never share your data for advertising or marketing by third parties
- We never provide your encrypted API keys to anyone — they are stored encrypted and decrypted only within our secure background job infrastructure
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile data | Retained while your account is active. Deleted immediately upon account deletion request. |
| Product listings (active and archived) | Retained while your account is active. Archived listings are kept in your account until you unarchive them or delete your account. Deleted immediately upon account deletion. |
| Revenue and payment metadata | Retained while your account is active. Deleted immediately upon account deletion. |
| Encrypted payment processor API keys | Deleted immediately upon disconnection or account deletion. |
| Subscription records | Retained for 7 years for accounting and legal compliance purposes, even after account deletion. |
| Anonymised analytics and engagement data | Retained indefinitely in aggregated, anonymised form. Cannot be linked back to you after account deletion. |
| Email communications with us | Retained for up to 2 years. |
| Active promotional slot booking records | Retained until slot expires or you end the promotion early from Settings → Billing. |
| Historical ad payment records (amount, payment reference, dates) | Retained for 7 years for accounting and legal compliance, even after account deletion. |
| Abandoned checkout holds (no payment completed) | Auto-deleted after 60 minutes by the booking system. |
| Acquisition interest submissions | Retained while your account is active. Deleted immediately upon account deletion. |
When you delete your account, all personally identifiable data is deleted immediately from our active databases. We do not offer a grace period or recovery after deletion.
Note on backups: Deleted data may persist in automated database backup systems for up to 30 days before being permanently overwritten as part of the normal backup rotation cycle. Backup data is used solely for disaster recovery, is not accessible for any operational purpose, and is not shared with third parties.
6. Data Security
We implement the following security measures to protect your data:
- All data transmitted between your browser and our servers is encrypted via TLS/HTTPS
- Passwords are stored as cryptographic hashes — never in plain text
- Payment processor API keys are encrypted at rest using AES-256-GCM encryption before database storage
- Database access is governed by Row Level Security (RLS) policies — each user can only access their own data
- Column-level access controls prevent sensitive fields from being exposed via API
- Background infrastructure (Inngest functions, cron jobs) uses service-role credentials that are never exposed to users
- Supabase infrastructure is hosted in Singapore with enterprise-grade security
Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
6.1 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law (e.g., GDPR)
- Notify affected users without undue delay via email to their registered address, describing the nature of the breach, categories of data affected, likely consequences, and steps we are taking
- Maintain an internal record of all breaches, including those that do not require external notification
Breach notifications will be sent to your registered email address. Keep your email address current in your account settings.
If you discover a security vulnerability, please report it responsibly to legal@shippin.io.
7. Cookies and Tracking Technologies
We use the following cookies:
| Cookie | Purpose | Type |
|---|---|---|
| Supabase Auth session cookie | Keeps you logged in | Essential — cannot be disabled while logged in |
| Vercel Analytics | Anonymised usage tracking | Analytics — no personal identifiers |
We do not use advertising cookies, tracking pixels, or third-party marketing cookies.
We do not currently display a cookie banner because our analytics cookies do not collect personal data. If this changes, we will implement appropriate consent mechanisms.
When you proceed to a promotional slot purchase or subscription checkout, you are redirected to DodoPayments' hosted payment page. DodoPayments may set their own cookies on their domain during checkout. Their data practices are governed by the DodoPayments Privacy Policy, not this Policy.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
8.1 All Users
- Right to Access: Request a copy of the personal data we hold about you
- Right to Correction: Update or correct your data directly in your account settings
- Right to Deletion: Delete your account and all associated personal data immediately via the in-app deletion feature in your account settings, or by emailing legal@shippin.io
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time
8.2 EU/UK Users (GDPR / UK GDPR)
In addition to the above:
- Right to Restrict Processing: Request that we limit how we process your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Lodge a Complaint: File a complaint with your local supervisory authority (e.g. your national Data Protection Authority)
8.2.1 Automated Decision-Making
We use automated processes that affect your experience on the Platform:
- A ranking algorithm that determines the visibility order of product listings, based on engagement signals (views, clicks, upvotes), recency, and subscription tier. The promoted sidebar rail is a separate paid placement mechanism — it is not determined by the ranking algorithm and operates on a first-come, first-served purchase basis
- An automated report threshold that may temporarily hide products or profiles when they receive a sufficient number of community reports, pending manual review
These processes do not produce legal effects or similarly significant effects on you as defined under Article 22 GDPR — they affect content visibility on our Platform, not legal rights, employment, credit, or similar matters. Article 22 full safeguards therefore do not apply. However, you have the right to request human review of any automated moderation decision affecting your content by contacting legal@shippin.io with the subject line "Moderation Review Request."
8.2.2 EU Digital Services Act (DSA)
shippin.io is a micro/small enterprise under the EU Digital Services Act. We comply with DSA obligations applicable to our size, including:
- Maintaining a notice-and-action mechanism for illegal content (see our Terms of Service §6.5)
- Providing a single point of contact for DSA-related communications at legal@shippin.io
- Responding to orders from relevant authorities regarding illegal content or information
We do not currently have a Data Protection Officer (DPO) as we do not meet the threshold requiring one. For all GDPR requests, contact legal@shippin.io.
8.3 California Users (CCPA/CPRA)
You have the right to:
- Know what personal information we collect and how it is used
- Delete your personal information
- Opt-out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your rights
To submit a CCPA request, email legal@shippin.io with the subject line "CCPA Request."
Global Privacy Control (GPC): We do not currently implement automated recognition of GPC browser signals. California residents who wish to opt out of any future data sharing for cross-context behavioural advertising may do so by emailing legal@shippin.io with the subject line "GPC Opt-Out Request." We do not currently sell or share personal information for targeted advertising.
8.4 Indian Users (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access information about your personal data being processed
- Correct inaccurate or incomplete personal data
- Erasure of personal data that is no longer necessary
- Grievance redressal
To submit a request under the DPDP Act, contact our designated Grievance Officer:
Grievance Officer: Jayesh Padhiar
Email: legal@shippin.io
Subject line: "DPDP Grievance — [your name]"
We will acknowledge your grievance within 48 hours and respond substantively within 30 days of receipt.
We will respond to all verified data requests within 30 days.
9. Children's Privacy
shippin.io is available to users aged 13 and above. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will delete it immediately.
If you believe a child under 13 has registered on our Platform, please contact us at legal@shippin.io.
For users between 13 and 16 in the EU: GDPR requires verifiable parental or guardian consent for processing personal data of children in this age group. By creating an account as a user aged 13-16 in the EU, you represent that your parent or legal guardian has reviewed and consented to your use of the Platform and the processing of your personal data as described in this Policy. We reserve the right to suspend or delete accounts where we become aware that verifiable parental consent was not obtained.
Parents or guardians who wish to review, correct, or delete personal data associated with a child's account, or who wish to withdraw consent, should contact legal@shippin.io. We will action such requests within 30 days.
10. International Data Transfers
shippin.io is operated from India. Our infrastructure is primarily hosted in Singapore (Supabase, Upstash). By using the Platform, you consent to your data being processed in Singapore and other jurisdictions where our service providers operate.
For EU/UK users: when your data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place through our service providers' Standard Contractual Clauses (SCCs) or equivalent mechanisms.
GDPR Article 27 — EU Representative: shippin.io is not established in the EU or EEA. We have assessed that our processing of EU personal data is occasional in nature, limited in scope, and unlikely to result in a risk to the rights and freedoms of natural persons. On this basis, we claim exemption from the obligation to appoint an EU representative under Article 27(2)(a) of the GDPR. If you have questions about this assessment or wish to exercise your rights, contact us directly at legal@shippin.io.
11. Third Party Links
Product listings on shippin.io contain links to external websites. This Privacy Policy does not apply to those external sites. We are not responsible for the privacy practices of third party websites. We encourage you to review their privacy policies before providing any personal data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last Updated" date at the top of this page
- For material changes, we will notify you via email to your registered address at least 14 days before the change takes effect
- Continued use of the Platform after the effective date constitutes acceptance of the updated policy
Previous versions of this policy will be archived and available upon request.
13. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data: