ShipOps
Back to ShipOps
Legal

Privacy Policy

What data ShipOps collects when you install it on your Shopify store, why we collect it, who we share it with, and how it gets deleted.

Last updated: 3 September 2026
On this page
Who we are What we access Why we use it Who we share with Website analytics Storage & security Retention & deletion Your rights Contact

Who we are

ShipOps ("ShipOps", "we", "us") is a Shopify app operated by Smart Agent (SMC-Private) Limited, contactable at support@shipops.app. ShipOps helps merchants manage cash-on-delivery (COD) logistics: tracking parcels with courier partners (e.g. PostEx, TCS), confirming orders and updating customers by automated call, SMS and WhatsApp, and reconciling courier payout receipts.

What data we access and store

From your Shopify store (via the Shopify Admin API)

  • Order data: order numbers, line items, totals, payment and fulfillment status, tags, and timestamps.
  • Customer contact data needed to complete a COD delivery: customer name, phone number, and shipping address. We do not collect customer email.
  • We store a curated, PII-minimized copy of order data for sync — city only, with no street address on the Shopify-sourced record.

From your courier partner (e.g. PostEx), using your own courier API token

  • Parcel tracking data: tracking number, delivery status and history, attempt counts, destination city, and COD amount.
  • Customer name, phone, and delivery address as recorded by the courier, used to identify and act on the parcel.

Messages and calls we send and receive on your behalf

  • WhatsApp: when you connect your own WhatsApp Business Account, the messages ShipOps sends from your number (order confirmations, tracking updates, delivery-attempt notices, review requests) and the replies your customers send back — their text, button taps and delivery receipts. Message content is stored encrypted at rest.
  • SMS: the status texts and abandoned-cart reminders ShipOps sends from your sender name, and whether they were delivered.
  • Automated calls: which number was called, when, how long it lasted and the key the customer pressed (confirm / cancel / call back). We do not record the customer's voice.
  • Consent and opt-outs: whether a customer agreed to marketing messages at checkout, and any "stop" they send — kept as a one-way hash of the number so it is honoured permanently on every channel.

Your configuration

  • Your courier API token and your WhatsApp Business Account access token, stored encrypted at rest (AES-256-GCM). When you connect WhatsApp through Meta's Embedded Signup, that token is a business token Meta issues to ShipOps for your account, scoped to your WhatsApp Business Account only. We use it solely to send and receive messages on your number, register the number, create and check your message templates, and read the number's quality rating and messaging limit. Alongside it we store your WhatsApp Business Account id, phone-number id, and the Meta user id of the person who connected it — so that a later "remove app" in Facebook can be matched to your connection.
  • Your WhatsApp and SMS sender identities, message templates, calling hours, and app settings.

Why we use it

Solely to provide the app's COD delivery-operations features: showing the parcel action inbox; confirming new orders and updating customers by automated call, SMS and WhatsApp in your name; letting your staff read and answer customer replies in one inbox; writing delivery status back to Shopify; and reconciling courier payout receipts. Marketing messages (for example an abandoned-cart reminder over WhatsApp) go only to customers who opted in at checkout, and every channel honours a "stop" permanently. We do not sell personal data, and we do not use it for advertising or profiling.

AI-assisted features (optional)

If you switch them on, two features send a redacted copy of data to a large-language-model provider: the address check (a shipping address and city, to flag ones a courier is likely to fail) and suggested WhatsApp replies (the customer's recent messages and the status of the orders they asked about). Names, phone numbers, emails and long digit strings are removed before anything is sent; the provider is contractually barred from training on it; and the model can only choose among facts we give it — it never invents an address, a tracking number or a promise. Every AI-suggested reply is either shown to your staff first ("shadow" mode) or sent only after your explicit switch to live mode.

A third optional feature, payment-screenshot verification, is off unless you switch it on. When a customer posts a bank-transfer screenshot to your WhatsApp line, ShipOps sends that image to the AI provider to read the amount, the recipient, the status and the reference off it, together with the amounts the order could be paid at and the name and last four digits of your own bank account so the model can say whether the payment went to you. The image cannot be redacted, so it is sent as posted. If you connect the mailbox your bank's alerts land in (an address, an app password and the label your bank's emails are filed under), ShipOps reads new emails under that label only — never the rest of the mailbox — and sends the text of each (with email addresses and phone numbers removed; it may still carry the payer's name) to the same provider to be read. The app password is stored encrypted and is used for nothing else; disconnecting the mailbox deletes it. The provider is contractually barred from retaining or training on either; we store what was read, never the image. An order is never marked paid from a screenshot alone — only a matching credit in your own bank's alert, or a member of your staff, can do that.

Who we share it with

  • Your courier partner (e.g. PostEx): we call the courier's API using your token to fetch tracking and submit delivery instructions. Tracking numbers and delivery-advice notes are sent; we do not send customer PII to the courier (the courier already holds it as the delivering carrier).
  • WhatsApp / Meta Platforms: two ways. Click-to-chat opens WhatsApp on a staff member's own device with a pre-filled message and involves ShipOps in nothing further. If you connect your WhatsApp Business Account (through Meta's Embedded Signup, or by entering your own credentials), ShipOps sends and receives messages through Meta's WhatsApp Business Platform on your number: the customer's phone number and the message content pass through Meta under WhatsApp's Business Terms. Meta bills you directly for messages at Meta's published rates; ShipOps adds no markup and never collects those charges.
  • SMS gateway (a Pakistan-based provider): the customer's phone number and the text of each SMS we send in your name.
  • Automated-call provider (a Pakistan-based provider): the customer's phone number and the recorded prompt played in your store's name; the key pressed comes back to us.
  • AI providers (Anthropic; OpenAI as fallback), only for the optional AI features above and only with the redacted data described there.
  • Email delivery (Zoho ZeptoMail): the notifications ShipOps sends to you — never to your customers.
  • Infrastructure providers: our hosting and database provider, Contabo (Germany, European Union).
  • We do not otherwise share personal data with third parties.

Website analytics & advertising

Our public website at shipops.app uses Microsoft Clarity to understand how visitors use the pages — which sections are read, where people click, and where they get stuck. Clarity sets cookies and records anonymised page interactions (clicks, scrolling, mouse movement) on this website only. It is not loaded inside the ShipOps app, and it never has access to your Shopify store data, your customers' details, or your courier data. See Microsoft's privacy statement. You can opt out by enabling "Do Not Track" or blocking cookies in your browser.

This website also loads the Meta Pixel so that we can measure whether our Facebook and Instagram ads bring people here, and show follow-up ads to people who have visited. The pixel records that a page was viewed, and that you clicked one of our calls to action (for example the Install button, a WhatsApp link, or our support email address) together with which section of the page it was in and whether you were on a phone or a computer — not what you typed or who you are. We count each of these at most once per visit. If you use the short fit check on our site, the pixel also receives your three answers (platform, order-volume range, courier) — nothing you typed, and no way to identify you. Product demo videos on this site are embedded from YouTube in privacy-enhanced mode (youtube-nocookie.com): nothing loads from YouTube until you press play on a demo, and from that point YouTube's own privacy policy applies inside the player. It also receives the standard technical details any website receives (IP address, browser, device) and a cookie identifier. We do not send Meta your name, email, phone number, store data, customer details, or courier data. Like Clarity, it runs on this marketing website only and is not loaded inside the ShipOps app. See Meta's privacy policy. You can opt out by blocking cookies or third-party scripts in your browser, or by adjusting your Meta ad preferences.

Separately, when you visit our listing on the Shopify App Store, Shopify reports the page view and any resulting install to the same Meta advertising account. That happens on Shopify's own domain and under Shopify's privacy terms, not ours.

Where it's stored & security

Data is stored in a database hosted by Contabo (Germany, European Union). Data in transit is encrypted with TLS. Customer names, phone numbers, addresses, message content and all API tokens are encrypted at rest (AES-256-GCM); the encryption key is held separately from the database and the application refuses to start without it. Access is limited to authorized operators, and every action your staff take in ShipOps is attributed in an activity log.

Retention & deletion

  • On a customer deletion request (Shopify customers/redact): we erase that customer's name, phone, and address — the raw courier payload containing them, and the content of messages exchanged with them — from our records. Their opt-out, if any, is kept as a one-way hash so we can keep honouring it.
  • On uninstall: background syncing stops immediately, and Shopify sends a shop/redact request about 48 hours later, at which point we permanently delete all data we hold for that store. The one exception is a minimal installation record: the store's myshopify.com domain and the dates it first installed and last uninstalled ShipOps. It holds no customer or order data; we keep it so plan limits — which count orders placed after a store's first install — stay consistent if a store reinstalls.
  • On a data-access request (customers/data_request): we compile the data we hold about that customer and make it available to the store owner within 30 days.
  • Message content (WhatsApp, SMS and call records): kept while your store has ShipOps installed, so your staff can see the history of each order, and erased with the customer on customers/redact, with the store on shop/redact, or earlier on your request.
  • Disconnecting WhatsApp: use Disconnect in ShipOps Settings → WhatsApp, or remove ShipOps from your connected apps in Meta Business settings. We then unsubscribe from your account's notifications at Meta and discard the access token, and ShipOps can no longer send or receive on your number. Existing conversations stay with your store's data until they are erased as above.
  • Meta data-deletion requests: if you remove ShipOps in your Facebook settings and ask for your data to be deleted, Meta sends us a signed deletion request. We record it, return a confirmation code and a status page (app.shipops.app/meta/deletion) you can check, and disconnect every WhatsApp connection made with that Facebook account within 30 days. Orders and conversations belong to the store and are erased through the store's own uninstall or a request from the store owner.
  • You can also request deletion at any time by contacting support@shipops.app.

Your rights

Depending on jurisdiction, customers may have rights to access, correct, or delete their personal data. Such requests should be made to the merchant (the data controller); ShipOps acts as the merchant's processor under our Data Processing Agreement and will assist in fulfilling them.

Changes & contact

We may update this policy; the "last updated" date reflects the latest revision. Questions or requests: support@shipops.app.

ShipOps

The post-dispatch control room for cash-on-delivery Shopify stores. Track parcels, rescue deliveries, and recover the money your courier owes you.

Product
Rescue deliveries Recover money Roadmap Pricing
Resources
How it works FAQ Ask Founder WhatsApp us
Company & legal
Privacy policy Terms of service Data processing agreement Data protection Support
© 2026 ShipOps — a Smart Agent product. Not affiliated with Shopify or any courier. Built for COD sellers in Pakistan 🇵🇰