Legal
Privacy policy
Last updated 4 September 2026.
Who this policy is about
Shipstack ("we", "us") is a UK sole trader operating under the Shipstack trading name.
Scope
This policy covers personal data processed across the Shipstack platform: this marketing site, Shipstack Manager (the account dashboard), and the Shipstack API. It applies to Shipstack customers, the people on their teams, and the recipients named on a shipment booked through Shipstack.
This marketing site does not itself store your account or shipment data — that lives in Shipstack Manager, which is where you sign in and where the data described below is actually held.
Information we collect
We process the following categories of personal data:
- Account data. Name, email address, and password (stored hashed, never in plain text) for you and anyone you invite to your team, plus your role (owner, admin, or member).
- Courier credentials. The API credentials for the carrier accounts you connect. These are encrypted and never stored as plain text.
- Shipment and recipient data. Whatever a label requires: recipient name, address and contact details, parcel contents and value, and — for international shipments — customs information such as HS codes and IOSS/EORI numbers. This is necessarily shared with the courier you choose for that shipment (see our supported couriers).
- Billing data. Subscription and payment information is handled by Stripe, our payment processor. We do not store your card details ourselves.
- Contact form submissions. If you write to us via our contact form, we process the name, email address and message you provide in order to reply. We don't keep a copy beyond what's needed to respond.
- Technical logs. Standard access logs, such as IP address and timestamp, kept briefly to detect abuse and debug problems.
How we use it
We use personal data to:
- Provide the service: quote, book, print and track shipments through the couriers you enable.
- Operate your account: authentication, two-factor verification, team roles and invitations.
- Bill your subscription and metered usage through Stripe.
- Respond to support and contact requests.
- Secure the platform: detect fraud, abuse and unauthorised access.
- Meet our legal and accounting obligations.
Legal basis
Under UK GDPR, we rely on:
- Contract — to create your account, process shipments, and provide the service you've signed up for.
- Legitimate interests — to secure the platform, prevent fraud, and respond to enquiries, balanced against your right to privacy.
- Legal obligation — for example, retaining billing records for tax purposes.
- Consent — only where we ask for it specifically; we do not rely on consent for the processing above.
Who we share it with
We share personal data only where it's necessary to run the service:
- Couriers. Recipient and parcel details go to the specific carrier you book with — that's how a label gets produced.
- Stripe. Billing and payment processing.
- Service providers. The hosting and email delivery providers that help us run the platform and send account notifications.
- Law enforcement or regulators, where we're legally required to.
We do not sell personal data, and we do not share it for third-party advertising.
International transfers
Shipstack supports couriers across the UK, Europe and beyond, so recipient data is necessarily transferred internationally as part of fulfilling a delivery — that's inherent to shipping a parcel abroad. Where we transfer personal data outside the UK, we do so on the basis of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.
How we protect it
- Courier credentials are encrypted and never stored as plain text.
- Data is encrypted in transit.
- Every Manager account requires two-factor authentication.
- Access to production data is limited to what's needed to operate the service.
Data retention
We keep account and shipment data for as long as your account is active. After closure, we delete account and shipment data within 90 days, except for billing records, which UK tax law requires us to keep for 6 years. Contact form messages are kept only in the recipient mailbox, subject to normal email retention.
Cookies and similar technologies
This marketing site sets no analytics or advertising cookies and loads no third-party tracking scripts. It uses your browser's own local storage — not a cookie sent to us — to remember a light or dark theme choice; that never leaves your device. Where a page includes a form, a strictly-necessary session cookie is set to protect the submission. Shipstack Manager, the account dashboard, sets its own session cookie to keep you signed in; that's covered by this same policy.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted, where we don't have a legal reason to keep it.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
To exercise any of these, contact us using the details below.
Children
Shipstack is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
We'll update this page if how we handle personal data changes, and update the date at the top when we do. Material changes will also be announced in Shipstack Manager.
Contact us
For anything about this policy or your data, write to [email protected] or use our contact form.