Privacy Policy

Effective 2026-08-16 · Contact shipplus2025@gmail.com

ShipPlus (“we”, “us”) provides multi-carrier rate comparison, shipping-label printing and tracking for Canadian merchants. This policy explains what we collect, why, who we share it with, how long we keep it, and how you can exercise your rights.

What we collect

Account data: username, email, phone, company name and company address. Phone, company and address are required before you can ship — carriers must be able to reach the shipper, and we need to reach you if something goes wrong.

Recipient data: recipient name, company, address, phone and email that you enter or that we import from a store you connect. This data belongs to your customers; we process it on your behalf as your service provider.

Store integration data: if you connect Shopify, we read unfulfilled orders (order number, line items, shipping address) under the scopes you approve, in order to create labels, and we write the carrier and tracking number back to that order after purchase. We do not read your product catalogue, marketing data or financial reports.

Customs data: for shipments leaving Canada, the item descriptions, quantities, values, country of origin, HS codes and duty-payer you provide are submitted with the label to the carrier and customs authorities.

Payment data: online payments are handled by Stripe. We never receive or store full card numbers — we store the amount, time, status and the reference returned by Stripe. If you use a prepaid balance, we store top-up and deduction records.

Technical data: sign-in sessions, request logs (time, endpoint, status code, request reference), error reports and IP addresses. Developer API keys may be bound to an IP allow-list, and we record the IP a key was last used from.

Cookies: we use only what is necessary to keep you signed in and remember your language. We do not run advertising or tracking cookies.

Why we use it

To provide what you ask for: quote rates, create labels, hand parcels to carriers, return tracking, issue invoices and statements, process cancellations and returns, and file claims with carriers on your behalf.

Billing and compliance: charging, refunds, reconciling post-shipment carrier adjustments (re-weigh / re-measure), and tax records.

Operating and securing the service: troubleshooting, preventing abuse and fraud, monitoring availability.

We do not use recipient data for marketing, and we do not sell personal information.

Who we share with

Carriers and logistics providers: sender, recipient and parcel details must be passed on to deliver the shipment. Which carrier depends on the service you choose; a list of our current providers is available on request.

Customs and government authorities: customs details are submitted for cross-border parcels as required by law.

Service providers (processing only to run our service): Stripe (payments), MongoDB Atlas (database), Railway (backend hosting), Vercel (frontend hosting), Resend (transactional email), Sentry (error monitoring), Google Places and OpenStreetMap (address autocomplete and validation).

Legal requirements: we may disclose information where legally compelled, or where necessary to protect rights, property or safety.

For Shopify merchants

Consent and revocation: the scopes shown on the Shopify authorization screen are all the access we have. You can uninstall the app in your Shopify admin at any time, or remove the store connection on the ShipPlus “Store Integrations” page; either immediately invalidates the access token.

Data requests: on a Shopify customers/data_request we compile the records we hold for that customer and respond through the merchant within 30 days.

Deletion: on customers/redact we erase that customer's name, address, phone and email from imported orders; on shop/redact (sent by Shopify 48 hours after uninstall) we delete all imported orders for that store together with the store connection and its encrypted access token.

Retention exception: shipments for which a label was purchased are your own transaction and tax records; the Canada Revenue Agency requires them to be kept for six years, so they are not deleted when a store is disconnected.

How long we keep it

Shipments, invoices and financial records: six years from the transaction (tax and audit requirements).

Imported store orders that were never shipped: removable at any time in the app, and cleared as described above when a store is disconnected or the app uninstalled.

Account data: kept while the account is open; deleted when you close it, except financial records we are required to retain.

Technical logs and error reports: typically 30–90 days.

Security

All traffic is encrypted with HTTPS. Store and carrier credentials are encrypted at rest with AES-256-GCM and never shown in the interface or logs in clear text. Passwords are stored hashed. Developer API keys can be bound to an IP allow-list. We continuously monitor errors and availability.

No system is perfectly secure. If a breach affects your information, we will notify you and the relevant authorities within the time required by law.

Your rights

You may access, correct, export or ask us to delete your personal information, and you may withdraw consent (after which we may be unable to keep providing the service). Most data is visible and editable in your account and shipment pages; for anything else write to shipplus2025@gmail.com and we will respond within 30 days.

If you believe we have handled your data improperly, you may complain to the Office of the Privacy Commissioner of Canada (OPC). Users in the EU/UK additionally have GDPR rights of access, rectification, erasure, restriction and portability.

If you are a recipient rather than an account holder: your information was provided by the merchant who shipped to you — please contact them first. You may also contact us and we will help locate the record and act on the merchant's instruction.

Where data is stored

Our database and servers are located in Canada and the United States; the service providers listed above may also process data in the United States or the EU. Data held in a country may be subject to that country's laws and legal process.

Children

The service is for business users and is not directed to anyone under 16; we do not knowingly collect their personal information.

Changes to this policy

When we update this policy we change the effective date at the top; for material changes we will notify you by email or in-app.

See also Terms of Service