Privacy Policy
Last updated: July 28, 2026
Shipyu ("we," "our," or "us") operates the shipping API and developer console at shipyu.com. Shipyu is a developer API that sits in front of a carrier gateway: you send us shipment and tracking requests, and we forward them to our upstream carrier provider and return the results. This Privacy Policy explains how we collect, use, and protect information when you use Shipyu.
1. Information We Collect
Account Information
- Your name, email address, and (if you enable it) two-factor authentication settings. Passwords are stored only as a one-way hash; we never store your password in plain text.
- Your API account details and API access requests, including company name and stated use case
Shipment and Tracking Data
- The shipment and tracking data you send through the API, such as tracking numbers, carrier identifiers, and shipment status
- Because you use Shipyu to create shipments and trackers, these requests can include the personal data of your end-recipients, such as recipient names, postal addresses, and phone numbers. Shipyu processes this data on your behalf to route it to the carrier gateway.
API Request and Response Logs
- Metadata for every API call: the HTTP method, endpoint path, response status code, response time, API key used, request ID, carrier, and originating IP address
- The request and response bodies of API calls, as described in Section 8 ("API Request and Response Body Storage")
Billing Information
- Usage counts (such as trackers created and labels purchased) used to generate invoices
- Payment processing is handled by Stripe. Shipyu stores a Stripe customer reference and invoice records, but does not store your full card number.
2. How We Use Information
We use collected data to:
- Route your API requests to the carrier gateway and return tracking and shipment results
- Authenticate your account and API keys and enforce rate limits and per-account permissions
- Meter usage and generate invoices for your API activity
- Debug problems, provide support, and investigate errors
- Send account and transactional email (such as verification, password reset, and two-factor codes)
- Maintain platform performance, reliability, and security, and prevent misuse
We do not use user data for advertising or data resale.
3. Legacy Integrations (Being Wound Down)
Some Shipyu accounts were created under our earlier merchant-dashboard product, which offered marketplace and email integrations (Amazon Seller Central, Shopify, and Gmail). These integrations are being wound down and are not part of the Shipyu API product. The sections that follow (Sections 4 through 6) continue to describe how that data is handled for as long as any of it is retained during the wind-down and export period.
Where these integrations remain available, access is granted only after explicit user authorization through secure authentication methods such as OAuth. We collect only the minimum data required to operate the feature, and Shipyu does not access or store payment credentials from connected platforms.
4. Amazon Seller Data (SP-API)
Shipyu integrates with Amazon Seller Central through the Selling Partner API (SP-API). When authorized, Shipyu may access:
- Order identifiers
- Shipment tracking information
- Fulfillment details
- Delivery status updates
- Limited shipping address data when required for shipment processing
Data Usage
- Used strictly for shipment tracking, logistics visibility, and operational features
- Never used for advertising, profiling, or resale
Security & Compliance
- Data is encrypted in transit and at rest
- Access is restricted using role-based access controls
- Systems are monitored for unauthorized access and anomalies
- Logs are retained for security auditing and incident response
Restrictions
- Shipyu does not expose Amazon data to unauthorized parties
- Data is only processed as necessary to provide the service
- All access follows Amazon SP-API data protection and acceptable use requirements
5. Shopify Data
Shipyu allows merchants to connect Shopify stores via secure OAuth authorization. When connected, Shipyu may access:
- Order identifiers
- Fulfillment status
- Carrier and tracking details
- Shipment-related metadata
Data Usage
- Used solely to provide shipment tracking, synchronization, and operational visibility
Limitations
Shipyu does not access:
- Payment information
- Billing details
- Store financial data
All Shopify data is processed in accordance with Shopify platform requirements and is limited to operational use.
6. Google (Gmail) Integration
Shipyu may allow users to connect their Google account to automatically detect shipment-related emails. When authorized, Shipyu requests limited Gmail access.
Data Access
- Read-only access to email content for identifying order and shipment information
- Extraction of tracking numbers, carriers, and related shipment data
Data Usage
- Used strictly to identify and import shipment tracking information into Shipyu
- Not used for advertising, profiling, or marketing
Data Protection
- Gmail data is not sold or shared with third parties
- Human access is restricted and only permitted when required for security or legal compliance
- Access complies with Google API Services User Data Policy, including Limited Use requirements
7. Data Security
Shipyu implements industry-standard protections including:
- Encryption in transit (HTTPS)
- Encryption at rest
- Role-based access control (RBAC)
- Secure infrastructure providers
- Continuous monitoring and anomaly detection
8. API Request and Response Body Storage
To help you debug integrations and to let us provide support, Shipyu stores the request and response bodies of certain API calls alongside the request logs described in Section 1.
What is captured
- Request bodies for calls that create or change data (POST, PUT, PATCH, and DELETE requests)
- Response bodies for those same calls, and the response bodies of any request that returns an error
- Because these bodies contain the shipment data you send, stored bodies may include the personal data of your end-recipients, such as recipient names, postal addresses, and phone numbers
Credentials are removed
- Before a body is stored, we automatically scrub sensitive fields such as passwords, secrets, tokens, API keys, and authorization values, and replace them with a redaction marker. Your API keys and other credentials are not stored in these bodies.
- Very large bodies are omitted rather than stored.
Retention and access
- Stored request and response bodies are deleted after 90 days.
- Within your organization, stored bodies are visible in the developer console only to members who have the admin role.
- Shipyu staff may access stored bodies when necessary to provide support, investigate errors, or maintain security.
9. Data Retention
Shipyu retains data only as long as necessary to provide the service, to bill for usage, and to maintain system integrity and security. The main retention periods are:
- API request logs and stored request/response bodies: 90 days
- Aggregated usage records used for analytics and billing: 365 days
- Webhook delivery records: 30 days
- Account information: kept while your account is active, and removed on request or after account closure
Users may request deletion of their account data.
10. Subprocessors and Data Sharing
Shipyu does not sell or trade user data. To operate the service, we share data with the following subprocessors, each only for the purpose described:
- EasyPost — carrier gateway. Shipment and tracking requests, including recipient details, are forwarded to EasyPost to obtain tracking and carrier results.
- Stripe — payment processing and billing.
- Neon — managed PostgreSQL database hosting where account, log, and shipment data is stored.
- Vercel — application hosting and scheduled jobs.
- Upstash — Redis service used for rate limiting.
- Resend — delivery of transactional email (such as verification, password reset, and two-factor codes).
- Sentry — error monitoring and diagnostics.
All subprocessors are required to maintain appropriate security controls. We may also disclose data when required by law or to protect the rights, safety, or property of Shipyu or others.
11. Data Processing
When you send shipment data through the Shipyu API, that data often includes personal data about your end-recipients. Shipyu handles this end-recipient data on your behalf and for the purpose of providing the service to you — routing your requests to the carrier gateway, returning results, metering usage, and supporting and debugging your integration. You are responsible for having a lawful basis to send this data to us and for telling your end-recipients how their data is used.
12. User Rights
Users have the right to:
- Access their data
- Correct inaccurate information
- Request deletion
- Opt out of communications
13. Authorization & Control
Where legacy integrations remain available, they require explicit user authorization, and users can revoke access at any time:
- Through Shipyu settings
- Through the connected platform
Once revoked, no new data is collected. Existing data is retained only as needed to support operational functionality.
14. Service Limitations
Shipyu relies on third-party systems. We are not responsible for:
- External outages
- API changes
- Data inaccuracies from third-party sources
15. Policy Updates
This Privacy Policy may be updated at any time. Continued use of Shipyu constitutes acceptance of updates. We will notify you of material changes via email.
16. Contact
For privacy-related inquiries, contact us at .