Privacy Policy

Effective Date: 22 June 2026

Last Updated: 5 July 2026

1. Introduction

Welcome to shippin.io ("Platform", "we", "us", or "our"). shippin.io is operated by an individual based in Mumbai, India. We are committed to protecting your personal information and your right to privacy.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit and use shippin.io (the "Platform"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Platform.

This policy applies to all users worldwide, including users in the European Union (GDPR), the United Kingdom (UK GDPR), California (CCPA/CPRA), and India (Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023).

For any privacy-related questions, contact us at: legal@shippin.io

2. Information We Collect

2.1 Information You Provide Directly

Account Registration (Email/Password)

  • Full name
  • Email address
  • Password (stored as a cryptographic hash — we never store your plain text password)
  • Username (chosen by you)

Account Registration (Google OAuth)

  • First name and last name
  • Email address
  • Google profile picture
  • Google account identifier

Profile Information (optional, provided by you)

  • Profile bio
  • Avatar image
  • Website URL
  • Twitter/X handle
  • LinkedIn URL

Product Listings

  • Product name, tagline, description, and website URL
  • Product logo and cover image
  • Product category, pricing model
  • Developer notes
  • Screenshots (up to 3)
  • Revenue information (manual entry or processor-connected)
  • Open-for-acquisition status and asking price (USD), when set by a Builder subscriber
  • Scheduled launch date and relaunch date
  • Moderation status (pending, published, or flagged)
  • Archive status and timestamp (when a listing is hidden from public view)
  • Social handles for the product (Twitter/X, LinkedIn)

Acquisition Interest (signed-in users)

  • Optional message (up to 500 characters)
  • Whether you chose to share your email with the product owner
  • Product submitted and timestamp

Payment Processor Connection (Builder plan users only)

  • Read-only API key for DodoPayments or Stripe (encrypted using AES-256-GCM before storage — we never store your key in plain text)

Promotional Slot Purchases

  • Billing period selected (weekly or monthly)
  • Amount paid (stored in cents for accounting purposes)
  • DodoPayments payment reference ID
  • Ad slot expiry date and time
  • Product selected for promotion (linked to your product listing)
  • Checkout hold status (temporary — auto-deleted after 60 minutes if checkout is not completed)
  • Early termination requests via Settings → Billing ("End promotion") — we update the slot expiry immediately; no refund is issued for unused time

Communications

  • Any information you provide when contacting us at legal@shippin.io

2.2 Information Collected Automatically

Usage and Analytics Data

We use Vercel Analytics to collect anonymised usage data including:

  • Pages visited and navigation patterns
  • Referring URLs
  • Browser type and operating system
  • General geographic region (country/region level — not precise location)
  • Device type

We collect IP addresses for rate limiting and abuse prevention across the Platform. IP addresses are processed transiently in Upstash Redis (rolling time-window buckets) and are not stored persistently in our database beyond the rate-limit window. They are not used for analytics, profiling, or tracking.

Engagement Data

We track the following engagement signals on product listings to power our ranking algorithm:

  • Product page views (anonymised)
  • Outbound clicks to product websites (anonymised)
  • Upvotes (associated with your account)

These signals are temporarily stored in Upstash Redis before being flushed to our database on an hourly basis.

Session Data

When you log in, we store a session cookie via Supabase Auth to keep you authenticated. This cookie is essential for the Platform to function and cannot be opted out of while using an authenticated session.

2.3 Information We Do Not Collect

  • Payment card numbers, bank account details, or full payment instrument data (handled entirely by DodoPayments — we never see or store your card details)
  • Precise geolocation
  • Date of birth
  • Sensitive personal information (racial or ethnic origin, religious beliefs, health data, biometric data)

3. How We Use Your Information

We use the information we collect for the following purposes:

PurposeLegal Basis (GDPR)
To create and manage your accountPerformance of contract
To display your profile and active products publiclyPerformance of contract / Legitimate interest
To process archive and unarchive requests (hide or restore listings)Performance of contract
To enforce free-tier and Builder plan product limits, including automatic archiving when a subscription expiresPerformance of contract
To process your Builder subscription via DodoPaymentsPerformance of contract
To generate and display revenue badges on product listingsPerformance of contract
To power the product ranking algorithm using engagement signalsLegitimate interest
To generate semantic search embeddings via VoyageAILegitimate interest
To display product listings in search resultsPerformance of contract
To enforce our Terms of Service and moderate contentLegitimate interest / Legal obligation
To prevent fraud, abuse, and spamLegitimate interest
To comply with applicable lawsLegal obligation
To improve the Platform via anonymised analyticsLegitimate interest
To process one-time promotional slot purchases via DodoPaymentsPerformance of contract
To manage ad slot availability, holds, and activationsPerformance of contract
To issue automatic refunds when slots are unavailable or product becomes ineligible at payment timePerformance of contract / Legal obligation
To display your promoted product in the sidebar during the booked periodPerformance of contract
To end an active promotional slot early when you use End promotion in Settings → BillingPerformance of contract
To relay acquisition interest to product owners via emailPerformance of contract / Legitimate interest
To review submitted content via automated moderationLegitimate interest / Legal obligation

We do not use your information for targeted advertising. We do not sell your personal data to any third party.

Purpose Limitation: We will only use your personal data for the purposes described in this section. If we need to use your data for a materially different purpose, we will notify you and, where required by law, obtain your consent before doing so.

4. How We Share Your Information

4.1 Public Information

The following information is publicly visible on the Platform to all visitors including non-registered users:

  • Your username, display name, bio, avatar, and public profile
  • Products you have launched that are active (not archived), visible, and not hidden for moderation
  • Archived product listings — hidden from the directory, search, sitemap, and public profile views; only you can access the archived product page while signed in
  • Revenue badges on your products (if you have chosen to display revenue)
  • Upvotes you have cast
  • Your Twitter/X and LinkedIn handles if added to your profile or products
  • If you have purchased a promotional sidebar slot, your product's name, tagline, and logo are displayed in the promoted sidebar visible to all visitors, including unauthenticated users and search engine crawlers, for the duration of the booked slot
  • Open-for-acquisition status, asking price, and aggregate interest count on qualifying product listings (visible only while the owner holds an active Builder subscription)

Be aware: Any information you voluntarily add to your public profile or product listing is visible to everyone, including search engines and AI crawlers.

4.2 Third Party Service Providers

We share data with the following third party services solely to operate the Platform. Each provider is contractually bound to protect your data:

ServicePurposeData SharedLocation
SupabaseDatabase, authentication, file storageAccount data, product data, session tokensSingapore
Google (OAuth)Sign-in via GoogleAuthentication tokensGlobal (Google infrastructure)
DodoPaymentsSubscription billing and one-time promotional slot purchasesEmail, name, subscription plan metadata, one-time payment amount and reference ID, ad booking metadata (product ID, billing period)Per DodoPayments infrastructure
StripeRevenue verification for connected products (Builder plan)Read-only API key (encrypted), payment metadataPer Stripe infrastructure
VercelPlatform hosting and analyticsAnonymised usage dataGlobal (Vercel infrastructure)
UpstashEngagement data caching (Redis)Anonymised engagement countersSingapore
VoyageAISemantic search embeddingsProduct text (name, tagline, description) — no personal dataPer VoyageAI infrastructure
OpenAIAutomated content moderation on product listings and user messagesProduct text and images; acquisition interest messages — no account data beyond submitted contentPer OpenAI infrastructure
InngestBackground job orchestration (revenue sync, email delivery)Payment metadata for revenue sync; email address, name, and booking context for transactional email jobsPer Inngest infrastructure
PlunkTransactional email deliveryEmail address, first name, and email body content (subscription, launch, relaunch, acquisition interest, ad booking, and account notifications)Per Plunk infrastructure

4.3 Legal Disclosures

We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation
  • Protect the rights, property, or safety of shippin.io, our users, or the public
  • Prevent or investigate fraud or security issues

4.4 Business Transfers

If shippin.io is acquired, merged, or its assets are transferred, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Platform before your data is transferred and becomes subject to a different privacy policy.

4.5 What We Never Do

  • We never sell your personal data
  • We never share your data for advertising or marketing by third parties
  • We never provide your encrypted API keys to anyone — they are stored encrypted and decrypted only within our secure background job infrastructure

5. Data Retention

Data TypeRetention Period
Account and profile dataRetained while your account is active. Deleted immediately upon account deletion request.
Product listings (active and archived)Retained while your account is active. Archived listings are kept in your account until you unarchive them or delete your account. Deleted immediately upon account deletion.
Revenue and payment metadataRetained while your account is active. Deleted immediately upon account deletion.
Encrypted payment processor API keysDeleted immediately upon disconnection or account deletion.
Subscription recordsRetained for 7 years for accounting and legal compliance purposes, even after account deletion.
Anonymised analytics and engagement dataRetained indefinitely in aggregated, anonymised form. Cannot be linked back to you after account deletion.
Email communications with usRetained for up to 2 years.
Active promotional slot booking recordsRetained until slot expires or you end the promotion early from Settings → Billing.
Historical ad payment records (amount, payment reference, dates)Retained for 7 years for accounting and legal compliance, even after account deletion.
Abandoned checkout holds (no payment completed)Auto-deleted after 60 minutes by the booking system.
Acquisition interest submissionsRetained while your account is active. Deleted immediately upon account deletion.

When you delete your account, all personally identifiable data is deleted immediately from our active databases. We do not offer a grace period or recovery after deletion.

Note on backups: Deleted data may persist in automated database backup systems for up to 30 days before being permanently overwritten as part of the normal backup rotation cycle. Backup data is used solely for disaster recovery, is not accessible for any operational purpose, and is not shared with third parties.

6. Data Security

We implement the following security measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted via TLS/HTTPS
  • Passwords are stored as cryptographic hashes — never in plain text
  • Payment processor API keys are encrypted at rest using AES-256-GCM encryption before database storage
  • Database access is governed by Row Level Security (RLS) policies — each user can only access their own data
  • Column-level access controls prevent sensitive fields from being exposed via API
  • Background infrastructure (Inngest functions, cron jobs) uses service-role credentials that are never exposed to users
  • Supabase infrastructure is hosted in Singapore with enterprise-grade security

Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

6.1 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law (e.g., GDPR)
  • Notify affected users without undue delay via email to their registered address, describing the nature of the breach, categories of data affected, likely consequences, and steps we are taking
  • Maintain an internal record of all breaches, including those that do not require external notification

Breach notifications will be sent to your registered email address. Keep your email address current in your account settings.

If you discover a security vulnerability, please report it responsibly to legal@shippin.io.

7. Cookies and Tracking Technologies

We use the following cookies:

CookiePurposeType
Supabase Auth session cookieKeeps you logged inEssential — cannot be disabled while logged in
Vercel AnalyticsAnonymised usage trackingAnalytics — no personal identifiers

We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

We do not currently display a cookie banner because our analytics cookies do not collect personal data. If this changes, we will implement appropriate consent mechanisms.

When you proceed to a promotional slot purchase or subscription checkout, you are redirected to DodoPayments' hosted payment page. DodoPayments may set their own cookies on their domain during checkout. Their data practices are governed by the DodoPayments Privacy Policy, not this Policy.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

8.1 All Users

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Correction: Update or correct your data directly in your account settings
  • Right to Deletion: Delete your account and all associated personal data immediately via the in-app deletion feature in your account settings, or by emailing legal@shippin.io
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time

8.2 EU/UK Users (GDPR / UK GDPR)

In addition to the above:

  • Right to Restrict Processing: Request that we limit how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Lodge a Complaint: File a complaint with your local supervisory authority (e.g. your national Data Protection Authority)

8.2.1 Automated Decision-Making

We use automated processes that affect your experience on the Platform:

  • A ranking algorithm that determines the visibility order of product listings, based on engagement signals (views, clicks, upvotes), recency, and subscription tier. The promoted sidebar rail is a separate paid placement mechanism — it is not determined by the ranking algorithm and operates on a first-come, first-served purchase basis
  • An automated report threshold that may temporarily hide products or profiles when they receive a sufficient number of community reports, pending manual review

These processes do not produce legal effects or similarly significant effects on you as defined under Article 22 GDPR — they affect content visibility on our Platform, not legal rights, employment, credit, or similar matters. Article 22 full safeguards therefore do not apply. However, you have the right to request human review of any automated moderation decision affecting your content by contacting legal@shippin.io with the subject line "Moderation Review Request."

8.2.2 EU Digital Services Act (DSA)

shippin.io is a micro/small enterprise under the EU Digital Services Act. We comply with DSA obligations applicable to our size, including:

  • Maintaining a notice-and-action mechanism for illegal content (see our Terms of Service §6.5)
  • Providing a single point of contact for DSA-related communications at legal@shippin.io
  • Responding to orders from relevant authorities regarding illegal content or information

We do not currently have a Data Protection Officer (DPO) as we do not meet the threshold requiring one. For all GDPR requests, contact legal@shippin.io.

8.3 California Users (CCPA/CPRA)

You have the right to:

  • Know what personal information we collect and how it is used
  • Delete your personal information
  • Opt-out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising your rights

To submit a CCPA request, email legal@shippin.io with the subject line "CCPA Request."

Global Privacy Control (GPC): We do not currently implement automated recognition of GPC browser signals. California residents who wish to opt out of any future data sharing for cross-context behavioural advertising may do so by emailing legal@shippin.io with the subject line "GPC Opt-Out Request." We do not currently sell or share personal information for targeted advertising.

8.4 Indian Users (DPDP Act, 2023)

Under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access information about your personal data being processed
  • Correct inaccurate or incomplete personal data
  • Erasure of personal data that is no longer necessary
  • Grievance redressal

To submit a request under the DPDP Act, contact our designated Grievance Officer:

Grievance Officer: Jayesh Padhiar

Email: legal@shippin.io

Subject line: "DPDP Grievance — [your name]"

We will acknowledge your grievance within 48 hours and respond substantively within 30 days of receipt.

We will respond to all verified data requests within 30 days.

9. Children's Privacy

shippin.io is available to users aged 13 and above. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will delete it immediately.

If you believe a child under 13 has registered on our Platform, please contact us at legal@shippin.io.

For users between 13 and 16 in the EU: GDPR requires verifiable parental or guardian consent for processing personal data of children in this age group. By creating an account as a user aged 13-16 in the EU, you represent that your parent or legal guardian has reviewed and consented to your use of the Platform and the processing of your personal data as described in this Policy. We reserve the right to suspend or delete accounts where we become aware that verifiable parental consent was not obtained.

Parents or guardians who wish to review, correct, or delete personal data associated with a child's account, or who wish to withdraw consent, should contact legal@shippin.io. We will action such requests within 30 days.

10. International Data Transfers

shippin.io is operated from India. Our infrastructure is primarily hosted in Singapore (Supabase, Upstash). By using the Platform, you consent to your data being processed in Singapore and other jurisdictions where our service providers operate.

For EU/UK users: when your data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place through our service providers' Standard Contractual Clauses (SCCs) or equivalent mechanisms.

GDPR Article 27 — EU Representative: shippin.io is not established in the EU or EEA. We have assessed that our processing of EU personal data is occasional in nature, limited in scope, and unlikely to result in a risk to the rights and freedoms of natural persons. On this basis, we claim exemption from the obligation to appoint an EU representative under Article 27(2)(a) of the GDPR. If you have questions about this assessment or wish to exercise your rights, contact us directly at legal@shippin.io.

11. Third Party Links

Product listings on shippin.io contain links to external websites. This Privacy Policy does not apply to those external sites. We are not responsible for the privacy practices of third party websites. We encourage you to review their privacy policies before providing any personal data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the "Last Updated" date at the top of this page
  • For material changes, we will notify you via email to your registered address at least 14 days before the change takes effect
  • Continued use of the Platform after the effective date constitutes acceptance of the updated policy

Previous versions of this policy will be archived and available upon request.

13. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: legal@shippin.io

Operator: shippin.io (Individual operator)

Location: Mumbai, India