← Back to shiplyst.co
First-pass draft. This document is under legal review. Some references in square brackets (e.g. [LEGAL ENTITY NAME], [STATE OF FORMATION]) will be replaced before the public launch. For questions, contact support@shiplyst.co.

Shiplyst Privacy Policy

Last Updated: June 18, 2026 Effective Date: [LAUNCH DATE]

1. Introduction

This Privacy Policy explains how [LEGAL ENTITY NAME] d/b/a Shiplyst ("Shiplyst", "we", "us", "our") collects, uses, discloses, and protects information when you use our peer-to- peer shipping marketplace, consisting of the Shiplyst mobile applications (iOS and Android), the website at https://shiplyst.co, and any related services (the "Service").

Shiplyst is offered to residents of the United States only. By using the Service you confirm that you are at least 18 years old and located in the United States.

If you have questions, contact us at privacy@shiplyst.co. For EEA-related inquiries (e.g., if you are a U.S. resident currently traveling in Europe), our data protection contact is dpo@shiplyst.co.

2. Roles

For purposes of GDPR and similar laws, Shiplyst is the data controller for the information described in this Policy. The third-party processors listed in §4.2 act as data processors on our behalf, except where they act as independent controllers (Stripe, the financial-institution payment networks, identity-verification agencies, and the platform you used to install the app), in which case their own privacy policies apply to their independent processing.

3. Information We Collect

The categories below are aligned with our Apple App Store privacy nutrition label and our iOS Privacy Manifest. We do not use any of this information for cross-app or cross-site tracking (see §10).

3.1 Information You Provide

  • Name. Your full name as entered at sign-up or imported from a social sign-in provider.
  • Email Address. Required for account creation, transactional communication, and account recovery.
  • Phone Number. Required for SMS one-time-code verification, Job-related contact between Shippers and Transporters, and account-recovery flows.
  • Password / authentication credentials. Stored using industry- standard one-way hashing; never transmitted to us by social-login providers.
  • Profile information. Optional avatar photo, display preferences, notification preferences, and saved pickup / dropoff addresses.
  • Payment information. Card details and bank-account details are collected directly by Stripe through Stripe's secure UI components and tokenized; we receive only a payment-method identifier, the last four digits, the card brand, and the authorization / capture / refund status. We never see, store, or transmit your full card number or CVC. For Transporters, Stripe Connect onboarding collects additional KYC information (legal name, DOB, last-four of SSN, address) that is transmitted directly to Stripe and not retained by us.
  • Verification documents. Government ID, driver's license, vehicle photos, and (for Transporters) insurance and inspection documents that you upload through the in-app onboarding flow.
  • Photos and other user content. Photographs of items to be shipped, photos taken at pickup and delivery, messages you send to other users, in-app reviews, support tickets and attachments.

3.2 Information Collected Automatically

  • Precise location. With your permission and only while the app is in the foreground, we collect device GPS coordinates to (a) show you nearby Jobs (Transporters), (b) display pickup and dropoff routes, and (c) update Job milestones (e.g., en-route, near destination). We do not collect background location and do not declare the iOS "Always" or Android background-location permissions.
  • Device and app information. Device model, operating-system version, app version, language, time zone, and a randomly- generated app install identifier (not the IDFA). Used for troubleshooting, push-notification delivery, and aggregated analytics.
  • Log data. IP address, request timestamps, requested URLs, HTTP status codes, and similar server-side telemetry, used for security monitoring, abuse detection, and operational troubleshooting.
  • Performance and diagnostic data. Crash reports (stack traces with source-mapped symbols), uncaught exception details, and performance metrics (screen-load timings, API latency), collected through Sentry and PostHog. See §4.2 for the processors.
  • Product-interaction analytics. Page / screen views, button taps, feature usage, and similar event-level analytics, collected through PostHog and aggregated to inform product decisions.

3.3 Information from Third Parties

  • Social sign-in. If you sign in with Apple or Google, we receive the basic profile data those services share (typically name and email, or a private relay email for Sign in with Apple).
  • Stripe. We receive transaction confirmations, payout confirmations, dispute notifications, and onboarding-verification status (e.g., charges-enabled, payouts-enabled).
  • Background checks (Transporters only). Shiplyst does not presently engage a consumer reporting agency. If and when we do, the FCRA-required written disclosures and authorization will be presented during onboarding before any report is procured. Today, Transporter eligibility is verified through admin review of identification and supporting documentation submitted in-app (see §4.2 for processors involved in storage and KYC).

3.4 Sensitive Personal Information

For purposes of the California CPRA, the information we collect that may be considered "sensitive personal information" is limited to (a) account credentials, (b) precise geolocation (only while the app is in the foreground), and (c) for Transporters, the limited identity data required by Stripe for Stripe Connect KYC. We use this information solely for the purposes for which it was collected and do not use it to infer characteristics about you.

3.5 Information We Do Not Collect

  • We do not collect the iOS Advertising Identifier (IDFA) or the Android Advertising ID for advertising purposes.
  • We do not include expo-tracking-transparency and we do not display the iOS App Tracking Transparency prompt.
  • We do not access your contacts, calendar, microphone, or health data.
  • We do not record video or audio. The camera is used only for still photos of items being shipped.

4. How We Use and Share Your Information

4.1 How We Use Information

We use the information described in §3 to:

  • Operate the marketplace — register your account, authenticate you, match Shippers and Transporters, hold escrow, surface Jobs on the map, deliver push notifications, and resolve disputes.
  • Process transactions — collect payment, calculate Service Fees, release escrow, and pay out Transporters via Stripe Connect.
  • Communicate with you — send SMS verification codes, push notifications, transactional emails (receipts, status updates, dispute notifications, account-security alerts), and respond to support requests.
  • Power the AI photo-analysis feature — when you upload item photos, the photos may be sent to our automated vision service (currently OpenAI; see §4.2.4) to suggest a category, title, and approximate dimensions. The suggestions are advisory; the resulting Job description is yours.
  • Improve and secure the Service — analyze aggregated usage, monitor for fraud and abuse, debug crashes, A/B test features, and protect against unauthorized access.
  • Comply with law — respond to lawful requests, satisfy tax reporting (e.g., IRS Form 1099-K), maintain audit-able records.
  • Send marketing communications — if you have opted in and applicable law permits.

4.2 How We Share Information

We share information only as described below. We do not sell your personal information as that term is defined under CCPA/CPRA, nor do we "share" it for cross-context behavioral advertising.

4.2.1 With Other Users

  • Shippers see Transporters' display names, profile photos, vehicle details, public ratings and reviews, completion stats, and Job-relevant information (current bid, vehicle, ETA, en-route location during an active Job).
  • Transporters see Shippers' display names, profile photos, public ratings and reviews, item descriptions and photos, pickup and dropoff addresses (after a Bid is accepted), and Job-relevant messages.
  • Phone numbers and exact email addresses are not exchanged directly; in-Job communication is routed through the in-app chat and (where supported) through SMS template messages.

4.2.2 With Service Providers (Processors)

We share the minimum data necessary with the third-party processors listed below. Each is contractually bound to use the data only to provide its service to us.

VendorPurposeData shared
Stripe, Inc.Payment processing, escrow, Connect payouts, KYCName, email, phone, billing address, card token (via Stripe Elements / PaymentSheet — full PAN never reaches us), bank account (Transporters), KYC fields
Supabase, Inc.Database, authentication, file storage, edge-function runtimeAll Service data at rest (database rows, uploaded photos and documents, auth records)
Twilio Inc.SMS one-time codes and Job-related SMS templatesPhone number, message body
Mapbox, Inc.Map tiles, geocoding, routing, place searchApproximate location (for tile loading and search relevance), search queries
OpenAI, L.L.C.AI item-photo analysis (suggested category, title, dimensions)Item photos (and, where applicable, the signed storage URLs that reference them) submitted at Job-creation. No name, email, phone, or other profile field is included in the request.
SendGrid (Twilio)Transactional email deliveryEmail address, message body
PostHog, Inc.Product analytics and feature flags (mobile apps only)Anonymous app install identifier, event names, event properties, app version, device class. Session replay is OFF. The web property does not run PostHog.
Sentry (Functional Software, Inc.)Crash reporting and error monitoringStack traces, exception messages, app version, OS version, breadcrumbs (no message bodies, no payment data)
Expo (650 Industries, Inc.)Push-notification delivery via the Expo Push API to APNs (iOS) and FCM (Android); OTA delivery for JavaScript bundle updatesExpo push token, notification payload (title + body of the notification), JS bundle download requests
Apple, Inc.Apple Push Notification service; Sign in with AppleDevice push token, notification payload; Sign-in identity tokens
Google LLCFirebase Cloud Messaging (Android pushes); Google Sign-InDevice push token, notification payload; Sign-in identity tokens
Vercel, Inc.Hosting + edge networking for the web property (shiplyst.co and the admin app)HTTP request metadata (IP address, timestamps, request paths, user-agent), all data submitted through web forms

If we engage additional processors in the future, we will update this list. Material additions will be brought to your attention by in-app notice or email.

4.2.3 For Legal Reasons

We may disclose information when we believe in good faith that disclosure is necessary to (a) comply with a subpoena, court order, or other valid legal process; (b) protect the rights, property, or safety of Shiplyst, our users, or the public; (c) detect or prevent fraud, security incidents, or violations of our Terms of Service; or (d) respond to a verified emergency involving risk of death or serious physical injury.

4.2.4 AI Photo Analysis Disclosure

When you upload item photos as part of creating a Job, the photos (and, in some cases, signed storage URLs that reference them) may be transmitted to OpenAI's vision API for the limited purpose of generating an automated suggestion of the item's category, title, and approximate dimensions. No name, email, phone, or other profile field is included in the request body. Under OpenAI's standard API data-use commitments, content submitted through the API is not used to train OpenAI's models. Retention of API inputs and outputs on OpenAI's side is governed by our then-current OpenAI plan tier.

Suggestions are returned to your device for you to accept, edit, or reject. If you prefer not to use the AI suggestion, simply edit or overwrite the fields before posting the Job — the underlying photos remain attached to your Job (so Transporters can see them) but no further AI analysis is performed.

4.2.5 Business Transfers

If Shiplyst is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your information may be transferred to the successor entity. We will provide notice (e.g., a banner in the app and an email) before personal information becomes subject to a different privacy policy.

4.2.6 With Your Consent

We may share information for other purposes with your explicit consent, including aggregated or de-identified information that cannot reasonably be linked to you.

5. Your Rights and Choices

5.1 Account Information

You can review and edit your account information through the in-app Profile screen at any time.

5.2 Location Information

You can revoke location permission at any time through your device settings (iOS: Settings → Shiplyst → Location; Android: Settings → Apps → Shiplyst → Permissions → Location). Some features (Job map, real-time milestones, route optimization) require foreground location and will degrade or be unavailable without it.

5.3 Notifications

Push notifications can be disabled in your device's notification settings. SMS verification codes are required to use the Service; SMS-based status updates can be tuned in the in-app Profile → Notification Preferences screen. Marketing emails, if any, include an unsubscribe link.

5.4 Cookies and Similar Technologies (Web)

The Shiplyst website at shiplyst.co uses cookies and similar technologies for (a) authenticated sessions and CSRF protection (strictly necessary), (b) preferences (such as theme), and (c) first-party analytics through PostHog. We do not run third-party advertising or tracking cookies. You can manage cookies through your browser settings, though strictly-necessary cookies are required to remain signed in.

5.5 Downloading a Copy of Your Data

You can request a copy of your data at any time from the in-app Profile → Account & Privacy → Download my data screen.

  • We assemble a single JSON file containing every row we store under your account across approximately 25 tables (your profile, items, jobs, bids, messages you sent, payments, payouts, reviews, disputes, support tickets, and more).
  • The file is uploaded to a private storage bucket and we email you a download link. The same link is shown in the app on the past-exports list.
  • The link expires in 7 days. After that the file auto-deletes from our storage and the link will not resolve. You can request a new export at any time.
  • Photos and document files are not included. Only their storage paths. You already have the originals on your device; we don't ship 10× the file size for negligible portability gain.
  • Other users' personal information is not included. Where you and another user interacted (bids, jobs, messages you sent, reviews, disputes), the archive references the other user only by their opaque user ID. Their names, emails, and phone numbers are not in your file — those belong to their right of access, not yours.
  • You can request up to one export per day.

This satisfies the right of access under GDPR Article 15 and the right to know / right to portability under CCPA §1798.100 and §1798.110.

5.6 Account Deactivation and Deletion

Shiplyst offers a two-tier account closure model that you can trigger from the in-app Profile → Account & Privacy screen at any time.

Deactivation (reversible, indefinite). When you deactivate your account:

  • Your profile is hidden from other users and rendered as "Inactive user" in any chat or review your counterparties retain access to.
  • Your active job postings (status posted or bidding) are paused; bids you placed are withdrawn.
  • Push notifications are disabled and all sessions are signed out.
  • No data is deleted. You can reactivate at any time by logging back in. The next successful login automatically clears the deactivation flag and restores your listings.

Deletion (30-day grace period, then permanent). When you request account deletion:

  • Your account is immediately placed in the deactivated state described above and a deletion is scheduled 30 days out. You will receive an email confirmation.
  • Any successful login during the 30-day grace window automatically cancels the deletion and restores your account. This protects against rage-deletes, compromised-account self-deletion, and lost-device panic deletes.
  • After 30 days elapse, an automated job runs the permanent deletion within approximately one hour. The following data is hard-deleted:
    • Name, email, phone, avatar, saved addresses, push tokens, devices, preferences, blocks, vehicles, verification documents, in-app notifications.
  • The following data is anonymized in place and retained indefinitely (the user reference is severed; the row is kept for tax, dispute resolution, and aggregate marketplace metrics):
    • Payment transactions, payouts, disputes, bids, jobs, items, reviews, and conversations attached to completed or disputed jobs.
  • Stripe records. We attempt to delete your Stripe customer record (shippers) and Stripe Connect account (transporters) at deletion time. Some records may persist on Stripe's side per Stripe's own retention policy — see Stripe's privacy notice.
  • Other parties' data. Message content you sent to other users may remain in their conversation history with your sender attribution removed. If you want specific messages gone, delete them individually before requesting account deletion.
  • 24-hour administrative archive. During the first 24 hours after permanent deletion completes, a small administrative archive containing your name, email, phone, and account-creation timestamp is retained for fraud investigation, regulatory inquiry, and limited account-recovery requests (e.g., where the deletion was demonstrably mistaken or coerced). After 24 hours the archive is purged and recovery is impossible.

Active obligations block. If you have an in-flight job (as either shipper or transporter) or an unresolved dispute, you cannot deactivate or schedule deletion until those obligations are resolved (delivered, cancelled, refunded, or adjudicated). The in-app flow lists the blocking items.

Immediate erasure (GDPR Article 17). If you have a genuine right-to-erasure need that the 30-day grace period would not satisfy, contact privacy@shiplyst.co. An administrator can force-purge bypassing the grace period.

You also have the right to request a copy of your personal information, request correction of inaccurate information, and object to certain processing of your information. To exercise these rights, contact us at privacy@shiplyst.co.

6. Data Retention

We retain your information only as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Concrete retention behavior on account deletion is described in Section 5.6 above; the table below summarizes by data category:

CategoryOn account deletion
Profile PII (name, email, phone, avatar, addresses)Hard-deleted within ~1 hour of the 30-day grace period ending.
Device tokens, push tokens, sessions, preferences, blocks, vehiclesHard-deleted at the same time.
Verification / KYC documentsHard-deleted at the same time.
Payment transactions, payouts, platform feesAnonymized in place (user reference NULLed). Retained indefinitely to comply with IRS §6001 and equivalent state tax-record retention requirements (typically 6+ years) and for investor / aggregate marketplace reporting.
Disputes and dispute evidenceAnonymized in place. Retained indefinitely for chargeback / arbitration record.
Bids, jobs, items attached to completed or disputed transactionsAnonymized in place.
Conversations and messages tied to completed jobsConversation preserved for the other party; your sender reference is severed.
Items, drafts, conversations attached only to never-paid jobsDeleted entirely.
Stripe customer and Connect account recordsDeletion requested via the Stripe API at finalization. Retention beyond that is governed by Stripe.
Administrative archive of PII — limited to name, email, phone, and account-creation timestamp (for fraud investigation / limited account-recovery requests)Retained for 24 hours after finalization, then purged.

If you have not deleted your account, we retain your information for as long as your account remains active, plus a reasonable wind-down period if you become inactive without explicit closure.

7. Security

We implement administrative, technical, and physical safeguards designed to protect your information, including:

  • TLS 1.2 or higher for data in transit (as enforced by our hosting and database providers); encryption at rest for database storage and uploaded files.
  • Hardware-backed credential storage on device (iOS Keychain, Android Keystore) for session tokens.
  • Row-level security (RLS) policies on every Service-data table to enforce per-user access at the database layer, independent of the application code, and enforced by a continuous integration check that fails the build if a new table is added without RLS.
  • Multi-factor authentication required for administrative accounts; available to all users.
  • Stripe handles all card data; full PAN never touches our systems.
  • Logging, monitoring, and alerting on authentication anomalies and cross-tenant access attempts.

No system is perfectly secure. If you become aware of a security issue with the Service, please email security@shiplyst.co immediately.

8. Children's Privacy

The Service is not directed to and is not intended for use by anyone under eighteen (18) years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe a child has provided us with personal information, contact privacy@shiplyst.co.

9. International Data Transfers

The Service is intended for use only in the United States. Our servers and most of our processors are located in the United States. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States, which may have data-protection laws different from those of your country of residence.

10. Tracking, Advertising, and the iOS ATT Prompt

Shiplyst does not engage in cross-app or cross-site tracking. Specifically:

  • We do not collect the iOS Advertising Identifier (IDFA) or the Android Advertising ID for advertising purposes.
  • We do not embed third-party advertising SDKs.
  • We do not share or sell personal information for cross-context behavioral advertising.
  • The app is not bundled with expo-tracking-transparency and does not display Apple's App Tracking Transparency permission prompt.

Product-interaction analytics (PostHog, mobile apps only) and crash reporting (Sentry) are first-party and are scoped to the operation and improvement of the Service. PostHog session replay is disabled. The web property does not run PostHog or any other third-party analytics SDK.

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"):

  • Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties to whom we disclose it. See §3 and §4 of this Policy, which together satisfy the categories disclosure on a standing basis.
  • Right of access — a copy of the personal information we hold about you. See §5.5 (Download my data).
  • Right to delete the personal information we hold about you, subject to legally permitted exceptions (tax, fraud, recordkeeping). See §5.6.
  • Right to correct inaccurate personal information.
  • Right to limit the use and disclosure of sensitive personal information. As described in §3.4, we use the limited sensitive PI we collect only for the purposes for which it was collected.
  • Right to opt out of sale or sharing. We do not sell your personal information and we do not share it for cross-context behavioral advertising. As we do not engage in either practice, no opt-out mechanism is required; if at any future date we begin to sell or share personal information, we will provide a "Do Not Sell or Share My Personal Information" link in compliance with Cal. Civ. Code §1798.135 and notify you in advance.
  • Right to non-discrimination for exercising any of the above rights.

To exercise these rights, email privacy@shiplyst.co with the subject line "CCPA Request". We will verify your identity using the email and phone associated with your account (or, where account information is not available, by other reasonable means) before acting. You may designate an authorized agent in writing.

Categories of personal information disclosed for a business purpose (12-month look-back): identifiers, customer records, commercial information, geolocation, internet/network activity, payment information, and sensitive PI as defined in §3.4 — disclosed to the processors listed in §4.2.

12. European Privacy Rights (for visitors from the EEA / UK)

Although the Service is offered to U.S. residents, if you are physically located in the European Economic Area, the United Kingdom, or Switzerland while using the Service, you have rights under the General Data Protection Regulation (GDPR) / UK GDPR including the rights of access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent. You also have the right to lodge a complaint with your local data protection authority.

Our legal bases for processing are:

  • Contract performance — to provide the Service you have asked to receive (Art. 6(1)(b)).
  • Legitimate interests — to keep the Service secure, prevent fraud, and improve the product (Art. 6(1)(f)). You may object at any time on grounds relating to your particular situation.
  • Consent — for optional processing such as marketing emails or optional location sharing (Art. 6(1)(a)). You may withdraw consent at any time.
  • Legal obligation — to comply with tax, anti-fraud, and other legal requirements (Art. 6(1)(c)).

To exercise any of these rights, contact dpo@shiplyst.co.

13. Changes to This Privacy Policy

We may update this Policy from time to time. We will post the updated Policy at https://shiplyst.co/privacy with a new "Last Updated" date. For material changes, we will provide additional notice such as an in-app banner or email at least thirty (30) days before the change takes effect (or such shorter period as required by law or to address security or legal compliance). Your continued use of the Service after the effective date of any change constitutes your acceptance.

14. Contact Us

For any questions, requests, or complaints related to this Policy or to our handling of your personal information:

Email (general): privacy@shiplyst.co Email (EEA / data protection): dpo@shiplyst.co Email (security disclosure): security@shiplyst.co Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]

If you have a complaint that we have not satisfactorily resolved, you may also (a) contact your state attorney general or, for California residents, the California Privacy Protection Agency; (b) contact your supervisory authority if you are protected by the GDPR / UK GDPR; or (c) pursue the dispute-resolution mechanisms described in our Terms of Service.


By using Shiplyst, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described above.

Privacy Policy — Shiplyst