ShipShop is a multi-courier shipping aggregator for Indian sellers. This policy
explains, in plain language, what personal data we collect, why we use it, who we share it with,
how we secure and retain it, and the rights you have over it. It applies to our website, merchant
dashboard, mobile apps, and connected-store integrations at
shipshop.in.
We take a data-minimisation approach: we collect only what we need to book couriers, move parcels,
handle payments, and support you. We do not sell your personal data, and we do
not use it for advertising or to train AI models. Where this policy uses "personal
data", it means information that identifies, or can reasonably be linked to, an identifiable person
— including the recipients of the parcels you ship.
1. Who we are
ShipShop ("ShipShop", "we", "us", "our") operates a courier-aggregation platform at
shipshop.in that lets Indian merchants compare rates across
multiple licensed couriers, book shipments, print labels, collect cash-on-delivery (COD), and track
parcels through to delivery. We are an intermediary: we book licensed courier
companies on your behalf. We are not a courier ourselves — pickup, transport, and
delivery are performed by the courier partner you select.
For personal data you upload about your customers (order recipients), you are the principal
decision-maker (the "data fiduciary" / controller) and ShipShop processes that data on your behalf
as your service provider (processor) to fulfil your shipments. For the account, KYC, wallet, and
billing data we collect about you as our merchant, ShipShop is the data fiduciary.
2. Scope & the people this covers
This policy applies to everyone who interacts with ShipShop, including:
Merchants (sellers) and their sub-users.
Franchise partners, agencies, and affiliates in our partner programs.
Delivery agents and pickup staff who use our mobile apps.
Order recipients — the customers your parcels are addressed to.
Visitors to our public website and rate-calculator / tracking pages.
3. Information we collect
We collect the following categories of data, only as needed to run the service you use:
3.1 Account & business information
Name, email address, phone number, and password (stored only as a secure hash).
Company / trade name, business address, and GSTIN and other tax identifiers.
Role and permission settings (merchant, sub-user, franchise, agency, affiliate, agent, admin).
3.2 KYC & verification documents
To transact, you must complete Know-Your-Customer (KYC). This may include identity documents and
business-registration documents (for example, PAN, GST certificate, and address proof). KYC data is
access-restricted and used only to verify eligibility and to comply with legal and courier
requirements.
3.3 Order & recipient personal data
For each shipment you create, import, or sync, we process the recipient's:
Name and contact phone number.
Full delivery address, pincode, city, and state.
Order reference, payment type (prepaid or COD), and any delivery instructions.
3.4 Parcel details
Weight, dimensions, declared/invoice value, and contents category.
Pickup address and preferred courier, used to quote rates and check serviceability.
3.5 Wallet & payment information
Prepaid wallet balance and the full ledger of top-ups, freight debits (including
GST), refunds, and adjustments.
Top-up transactions processed through our payment gateway, Easebuzz. Card /
bank / UPI credentials are handled by the gateway — ShipShop does not store full payment
instrument numbers.
Credit-facility usage, where an optional credit line has been enabled for your account.
3.6 COD collection & remittance
Amounts collected on delivery, the remittance schedule, early-payout requests, and the resulting
credits to your wallet.
3.7 Tracking & proof of delivery
Courier AWB numbers and the tracking events (in-transit, out-for-delivery, delivered, NDR, RTO).
Proof of delivery captured at pickup, delivery, or return — a recipient
signature and mobile number tied to the specific order and event.
3.8 Device, usage, cookies & analytics
Log data such as IP address, browser and device type, pages viewed, and timestamps.
Cookies and similar technologies for sign-in sessions and preferences (see
Cookies & analytics).
Product-analytics events via Microsoft Clarity and
Google Analytics 4 (GA4).
3.9 Connected-store data
Shopify — order webhooks and the Admin-API access token needed to import orders
and write fulfilment/shipping updates on your behalf.
WooCommerce — orders imported over the WooCommerce REST API from a store URL you
provide (validated to prevent server-side request forgery).
We use the data above to operate and improve the aggregation service, specifically to:
Create your account, verify KYC, and enable the roles and permissions you are granted.
Calculate and compare courier rates, check serviceability, and show live rates at checkout.
Book shipments with the courier you select, generate labels, and pass the recipient details the
courier needs to deliver.
Debit freight (including GST) from your wallet at the quoted rate, process top-ups, and refund the
charged amount on cancellation or booking failure.
Collect COD and remit it to your wallet on schedule, including any approved early payout.
Track parcels, surface NDR/RTO events, and record proof of delivery.
Provide support, respond to tickets and grievances, and send service and transactional messages
(email / SMS / WhatsApp) about your account, shipments, and payments.
Keep the platform secure — detect and prevent fraud, abuse, and unauthorised access — and meet
tax, accounting, and other legal obligations.
Understand aggregate usage to improve performance and reliability (analytics), never to build
advertising profiles of individuals.
5. Legal bases for processing
We process personal data on one or more of the following bases:
Contract
To provide the service you signed up for — booking couriers, running your wallet, remitting COD, and supporting you.
Consent
Where you give it — e.g. optional communications, certain cookies/analytics, and connecting a third-party store.
Legal obligation
To meet KYC, tax/GST, accounting, and record-keeping duties under Indian law.
Legitimate use
To secure the platform, prevent fraud and abuse, and reconcile shipments and payments.
When you upload your customers' details to ship to them, you confirm you have a lawful basis to do so
and to have ShipShop and the courier process that data to complete delivery.
6. Who we share your information with
We share personal data only with the parties needed to run the service, under appropriate contractual
and security safeguards. Our sub-processors and recipients are:
Licensed couriers
India Post, Delhivery, DTDC, Blue Dart, Xpressbees, Ekart, Shadowfax, Amazon Shipping, Ecom Express, and other partners you select receive the recipient's name, phone, and address in order to deliver the parcel.
Payment gateway
Easebuzz processes wallet top-ups; it receives the transaction data required to take payment.
Cloud hosting
Our infrastructure providers host and run the platform on our behalf.
Communications
Email, SMS, and WhatsApp providers deliver transactional and service notifications.
Shopify
Where you connect a Shopify store, order and fulfilment data flows between Shopify and ShipShop to sync your orders and shipping status.
Legal & safety
Authorities, regulators, or advisors where disclosure is required by law or to protect rights, safety, and the integrity of the service.
7. No sale, no advertising, no AI training
Our commitment.
ShipShop does not sell or rent your personal data. We do not use it
for third-party advertising, individual profiling, or to train artificial-intelligence models. The
only parties that receive personal data are the sub-processors listed above, and only to perform the
service you asked for.
8. Cookies & analytics
We use cookies and similar technologies for three purposes:
Essential — sign-in sessions, security, and keeping the app working. These cannot
be switched off without breaking core functionality.
Preferences — remembering choices you make.
Analytics — Microsoft Clarity (usage and interaction insights)
and Google Analytics 4 (aggregate traffic and performance). These help us make
the platform faster and easier to use.
You can control cookies through your browser settings. Blocking essential cookies may prevent you from
signing in or using parts of the service. Analytics providers process data under their own privacy
terms.
9. Connected stores (Shopify & WooCommerce)
If you connect a store, you authorise ShipShop to read your orders and write shipping / fulfilment
updates solely to provide the service. For Shopify, we receive order webhooks and use an Admin-API
access token scoped to what we need; we verify every webhook with an HMAC-SHA256 signature. For
WooCommerce, we import orders over the REST API from the store URL you supply, which we validate to
block requests to internal or private addresses (SSRF protection). You can disconnect at any time by
uninstalling the app or revoking access, after which we stop importing new orders.
10. How we protect your data
All traffic is served over HTTPS/TLS.
Inbound webhooks are verified with HMAC-SHA256 signatures.
Sensitive tokens and keys are encrypted at rest and kept in secured server
configuration, never in source code.
Access is protected by scoped authentication and role-based access control (RBAC),
so users and staff see only what their role permits.
Access to personal data (PII) is audited.
Records are soft-deleted — retired rather than immediately purged — so history can
be reconciled and recovery is possible, subject to the retention rules below.
No method of transmission or storage is perfectly secure, but we work continuously to protect your
data using measures appropriate to its sensitivity.
11. Data retention & deletion
We keep personal data only as long as needed for the purposes it was collected, or as required by law.
Order, shipment, wallet, COD, and invoice records are retained to support tracking, reconciliation,
dispute resolution, and tax / accounting obligations under Indian law. KYC records are kept for the
period required by applicable regulations.
For connected Shopify stores, we honour Shopify's mandatory compliance webhooks:
customers/data_request — we compile the personal data we hold for the customer so the
store owner can respond to an access request.
customers/redact — we redact / anonymise that customer's recipient data, subject to
records we must retain for legal and tax purposes.
shop/redact — on uninstall, we stop accessing the store and redact its data in line
with our retention obligations.
When we no longer need personal data and have no legal duty to retain it, we delete or irreversibly
anonymise it.
12. Your rights
In line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and other
applicable laws, you have the right to:
Access — obtain a summary of the personal data we hold about you and how it is
processed.
Correction — have inaccurate or incomplete data corrected or updated.
Erasure — request deletion of personal data that is no longer needed and not
subject to a legal retention requirement.
Withdraw consent — where processing relies on consent, withdraw it at any time
(this does not affect processing already carried out).
Grievance redressal — raise a concern and have it addressed (see below).
Nominate — nominate another individual to exercise your rights in the event of
death or incapacity, as provided under the DPDP Act.
To exercise any right, contact us using the details in Contact us. We may need
to verify your identity first, and store owners' customer requests are handled through the store owner
and the Shopify webhooks above.
13. India-specific & cross-border processing
ShipShop is operated for the Indian market and aligns its practices with the DPDP Act 2023 and the
Information Technology Act, 2000 and its rules. Some of our sub-processors (for example, hosting,
analytics, or communications providers) may process data outside India; where they do, we rely on
appropriate contractual safeguards and only for the purposes described in this policy.
14. Children
ShipShop is a business service intended for users aged 18 and over. We do not
knowingly collect personal data from children. If you believe a child's data has been provided to us,
contact us and we will take appropriate steps to delete it.
15. Grievance Officer
In accordance with Indian law, we have designated a Grievance Officer to address questions or
complaints about this policy or our handling of personal data. You can reach the Grievance Officer at
shipshop.official2020@gmail.com. We aim to
acknowledge and resolve grievances within the timelines prescribed by applicable law.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the
"Last updated" date at the top of this page and, where appropriate, notify you. Your continued use of
ShipShop after an update means you accept the revised policy.
17. Contact us
For any privacy question, request, or grievance, email
shipshop.official2020@gmail.com or visit
shipshop.in. Please include enough detail for us to identify your
account and understand your request.