Privacy Policy
What data ShipOps collects when you install it on your Shopify store, why we collect it, who we share it with, and how it gets deleted.
Who we are
ShipOps ("ShipOps", "we", "us") is a Shopify app operated by Smart Agent (SMC-Private) Limited, contactable at support@shipops.app. ShipOps helps merchants manage cash-on-delivery (COD) logistics: tracking parcels with courier partners (e.g. PostEx), messaging customers about deliveries over WhatsApp, and reconciling courier payout receipts.
What data we access and store
From your Shopify store (via the Shopify Admin API)
- Order data: order numbers, line items, totals, payment and fulfillment status, tags, and timestamps.
- Customer contact data needed to complete a COD delivery: customer name, phone number, and shipping address. We do not collect customer email.
- We store a curated, PII-minimized copy of order data for sync — city only, with no street address on the Shopify-sourced record.
From your courier partner (e.g. PostEx), using your own courier API token
- Parcel tracking data: tracking number, delivery status and history, attempt counts, destination city, and COD amount.
- Customer name, phone, and delivery address as recorded by the courier, used to identify and act on the parcel.
Your configuration
- Your courier API token, stored encrypted at rest (AES-256-GCM).
- Your WhatsApp sender number, notification templates, and app settings.
Why we use it
Solely to provide the app's COD delivery-operations features: showing the parcel action inbox, letting your staff contact customers about pending or failed deliveries (WhatsApp click-to-chat and phone), writing delivery status back to Shopify, and reconciling courier payout receipts. We do not sell personal data, and we do not use it for advertising or profiling.
Who we share it with
- Your courier partner (e.g. PostEx): we call the courier's API using your token to fetch tracking and submit delivery instructions. Tracking numbers and delivery-advice notes are sent; we do not send customer PII to the courier (the courier already holds it as the delivering carrier).
- WhatsApp / Meta: messaging is operator-initiated — a staff member clicks a link that opens WhatsApp with the customer's number and a pre-filled message, sent from your own WhatsApp account.
- Infrastructure providers: our hosting and database provider, Contabo (Germany, European Union).
- We do not otherwise share personal data with third parties.
Website analytics & advertising
Our public website at shipops.app uses Microsoft Clarity to understand how visitors use the pages — which sections are read, where people click, and where they get stuck. Clarity sets cookies and records anonymised page interactions (clicks, scrolling, mouse movement) on this website only. It is not loaded inside the ShipOps app, and it never has access to your Shopify store data, your customers' details, or your courier data. See Microsoft's privacy statement. You can opt out by enabling "Do Not Track" or blocking cookies in your browser.
This website also loads the Meta Pixel so that we can measure whether our Facebook and Instagram ads bring people here, and show follow-up ads to people who have visited. The pixel records that a page was viewed, and that you clicked one of our calls to action (for example the Install button, a WhatsApp link, or our support email address) together with which section of the page it was in and whether you were on a phone or a computer — not what you typed or who you are. We count each of these at most once per visit. If you use the short fit check on our site, the pixel also receives your three answers (platform, order-volume range, courier) — nothing you typed, and no way to identify you. Product demo videos on this site are embedded from YouTube in privacy-enhanced mode (youtube-nocookie.com): nothing loads from YouTube until you press play on a demo, and from that point YouTube's own privacy policy applies inside the player. It also receives the standard technical details any website receives (IP address, browser, device) and a cookie identifier. We do not send Meta your name, email, phone number, store data, customer details, or courier data. Like Clarity, it runs on this marketing website only and is not loaded inside the ShipOps app. See Meta's privacy policy. You can opt out by blocking cookies or third-party scripts in your browser, or by adjusting your Meta ad preferences.
Separately, when you visit our listing on the Shopify App Store, Shopify reports the page view and any resulting install to the same Meta advertising account. That happens on Shopify's own domain and under Shopify's privacy terms, not ours.
Where it's stored & security
Data is stored in a database hosted by Contabo (Germany, European Union). Data in transit is encrypted with TLS. Courier API tokens are encrypted at rest. Access is limited to authorized operators.
Retention & deletion
- On a customer deletion request (Shopify
customers/redact): we erase that customer's name, phone, and address — and the raw courier payload containing them — from our records. - On uninstall: background syncing stops immediately, and Shopify sends a
shop/redactrequest about 48 hours later, at which point we permanently delete all data we hold for that store. The one exception is a minimal installation record: the store'smyshopify.comdomain and the dates it first installed and last uninstalled ShipOps. It holds no customer or order data; we keep it so plan limits — which count orders placed after a store's first install — stay consistent if a store reinstalls. - On a data-access request (
customers/data_request): we compile the data we hold about that customer and make it available to the store owner within 30 days. - You can also request deletion at any time by contacting support@shipops.app.
Your rights
Depending on jurisdiction, customers may have rights to access, correct, or delete their personal data. Such requests should be made to the merchant (the data controller); ShipOps acts as the merchant's processor under our Data Processing Agreement and will assist in fulfilling them.
Changes & contact
We may update this policy; the "last updated" date reflects the latest revision. Questions or requests: support@shipops.app.