Legal
Privacy Policy
This Privacy Policy explains what personal data ShipCred collects, why, and what rights you have. It forms part of our Terms of Service.
Who we are. ShipCred is operated by Veeraj Jain, a sole proprietor operating as “ShipCred”(“we”, “us”, “our”), based in India. For any privacy question or request, contact support@shipcred.app.
1. What we collect
a) Information you give us
- Account: your email address (used to sign in — we use passwordless magic-link login, so we do not store any password).
- Profile (public): username, display name, avatar image, bio, location, and links you add (e.g. website, X/Twitter, GitHub). Anything you put in your profile is intended to be publicly visible.
- Content (public): the products you submit — name, tagline, description, logo, screenshots, links.
- Communications: if you email us or submit feedback.
- Waitlist / newsletter: your email address, if you join the waitlist or subscribe to our newsletter.
b) Information we collect automatically
- Usage & activity: pages and product pages you view, upvotes, follows, and similar interactions.
- Approximate location: we derive your country from your IP address (via our hosting provider) for analytics. We do not store your IP address in our analytics records — the IP is used only momentarily to determine country and to prevent abuse (rate-limiting), and is not retained by us.
- Referrer: the page or site you arrived from.
- Technical/device data processed by our infrastructure and analytics providers, such as browser type and device information.
c) Payment information
- Payments are handled by Dodo Payments, our payment processor and merchant of record. We never receive or store your full card number or payment credentials — Dodo processes them directly. We receive only confirmation of your purchase and subscription status.
2. Why we use your data (and our legal bases)
| Purpose | Legal basis (GDPR terms) |
|---|---|
| Create and operate your account and profile | Performance of a contract |
| Display your products, profile, upvotes, and rankings publicly | Performance of a contract |
| Process subscriptions and payments (via Dodo) | Performance of a contract |
| Send service emails (magic links, receipts, important notices) | Performance of a contract |
| Send the newsletter / marketing email | Consent (you opted in; unsubscribe anytime) |
| Measure usage and improve the Service (analytics) | Legitimate interests / consent where required |
| Detect abuse, spam, and vote manipulation; keep the Service secure | Legitimate interests |
| Comply with law | Legal obligation |
Under India's DPDP Act, we process your personal data based on your consent and for legitimate uses as permitted by that Act.
3. Who we share it with (our processors)
We do not sell your personal data. We share it only with the service providers that run ShipCred, each acting on our behalf under their own security and privacy terms:
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Tokyo (ap-northeast-1) |
| Vercel | Website hosting, request routing, country geolocation | Global edge / US |
| Dodo Payments | Payment processing (merchant of record) | Global |
| Resend | Transactional and newsletter email | US |
| PostHog | Product analytics | US (or EU) |
| Sentry | Error monitoring | US |
We may also disclose data if required by law, to enforce our Terms, or to protect our rights, users, or the public.
4. Public information — please note
ShipCred is a public directory. Your username, display name, avatar, bio, links, submitted products, upvotes, and rankings are visible to anyone, including people who are not logged in, and may be indexed by search engines or included in our newsletter, share cards, and social posts. Do not put anything in your public profile or product content that you want to keep private. Your email address is not shown publicly.
5. Cookies & similar technologies
We use a small number of cookies and similar storage:
- Essential: to keep you signed in (authentication session) and to remember your light/dark theme preference. These are required for the Service to work.
- Analytics: PostHog sets cookies/identifiers to understand usage. These are non-essential.
Where required by law (e.g. for visitors in the EU/EEA/UK), we will ask for your consent before setting non-essential analytics cookies, and you can withdraw consent at any time. You can also control cookies through your browser settings.
6. International data transfers
We and our providers may store and process your data in countries outside your own, including the United States and, for our database and storage, Tokyo, Japan (Supabase / AWS ap-northeast-1). Where data is transferred out of the EU/EEA, UK, or India, we rely on appropriate safeguards (such as the providers' standard contractual clauses).
7. How long we keep it
- Account & profile data: for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep some records (e.g. payment/tax records) for longer as required by law.
- Analytics: retained on a rolling basis and periodically aggregated or deleted.
- Waitlist / newsletter: until you unsubscribe or ask us to remove you.
- Backups: residual copies may persist in backups for a limited period before being overwritten.
8. Your rights
Depending on where you live (India DPDP Act, EU/UK GDPR, California CCPA/CPRA), you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data (you can edit most of it in your profile/settings).
- Deletion / erasure — ask us to delete your data (you can delete your account yourself).
- Portability — receive your data in a portable format.
- Withdraw consent — for anything based on consent (e.g. the newsletter).
- Object / restrict — object to certain processing (e.g. analytics).
- Grievance redressal / nominate (India DPDP) — raise a grievance with our Grievance Officer, and nominate another person to exercise your rights in case of death or incapacity.
- Non-discrimination (California) — we will not discriminate against you for exercising your rights.
To exercise any right, email support@shipcred.app. We will respond within the timeframe required by applicable law. We do not sell or “share” personal data for cross-context behavioural advertising as defined by California law.
9. Children
ShipCred is restricted to users aged 18 and overand is not directed to children. Under India's DPDP Act, a “child” is a person under 18; because the Service is 18+, we do not knowingly process children's personal data and do not require parental-consent mechanisms. We do not knowingly collect data from anyone under 18, and if we learn that we have, we will delete it and terminate the account. If you believe a minor has provided us data, contact support@shipcred.app.
10. How we protect your data
We use industry-standard measures to protect your data, including encryption in transit (HTTPS), database access controls (row-level security), restricted service credentials, and reputable infrastructure providers. No system is perfectly secure, but we work to keep your data safe. If a data breach affecting your personal data occurs, we will notify you and the relevant authorities as required by law.
11. Grievance Officer (India)
In accordance with Indian law, our Grievance Officer is: Veeraj Jain — support@shipcred.app. We will acknowledge complaints within 24 hours and endeavour to resolve them within 15 days.
12. Changes to this policy
We may update this Privacy Policy. If we make material changes, we will update the “Last updated” date and, where appropriate, notify you (e.g. by email or an in-app notice). Continued use after the changes take effect means you accept the updated policy.
13. Contact
For any question about this policy or your data: support@shipcred.app.