Privacy Policy
Version 2.0 · Effective 2026-08-12 · [LEGAL ENTITY — TO BE DETERMINED] ("ShipOverpay", "we", "us")
This describes what the product actually does today. Where something is not yet built, it says so rather than describing an intention as a practice.
1. What we collect
Account data. Name, work email, company name, password (stored hashed, never in readable form), role in your organization, and the times you signed in.
Invoice data you upload. The file itself and everything parsed from it: tracking numbers, service types, ship and delivery dates, origin and destination city, state, postal code and country, weights and dimensions, zones, and every charge line with its amount. Carrier invoices routinely contain the names and addresses of your recipients. We do not seek that information, we do not use it for anything other than analyzing your invoice, and we never sell it.
Analysis data. Findings, their classification, the amounts, which reviewer confirmed or dismissed them and when, and the rule version that produced them.
Recovery data. Claims filed, carrier references and responses, amounts at each stage, and who confirmed a credit from what source.
Payment references. We never receive or store your full card number. Stripe holds it; we keep a customer reference, a payment method reference, the card brand and the last four digits, and records of charges made.
Technical and security data. IP address and browser user agent at sign-in, at legal acceptances, and in server logs; audit logs of significant actions.
Founding 100 applications. What you tell us on the form, plus the campaign source that brought you, if any.
2. Why we use it
- To run the service you asked for: analyze invoices, produce findings and reports, file claims you authorized.
- To bill you correctly and prove what you agreed to.
- To send transactional email about your invoices, results, recoveries and payments.
- To keep the service secure and diagnose faults.
- To improve our detection rules. Where we use your invoices for this, we work from the data itself, not from your identity.
We do not sell personal information, and we do not share it for advertising.
3. Artificial intelligence
No AI provider is enabled today. No customer data has been sent to one.
If we enable one, it will be to draft explanatory text only. An AI system will never determine a monetary figure, a finding, or a recovery amount — those come from deterministic rules and human review. We will name the provider here before any customer data reaches it.
4. Who processes data for us
| Processor | What it handles | Where |
|---|---|---|
| Hosting (dedicated server, WHM/cPanel) | The application, database, uploaded invoices | Canada |
| Backblaze B2 | Encrypted backup copies only — never the decryption key | Canada (ca-east) |
| Stripe | Payments, saved payment methods | United States |
| Outbound mail relay (currently the same server; Amazon SES planned) | Transactional email delivery | United States |
We use no advertising networks and no third-party analytics scripts today. There is no tracking pixel in the product.
5. How long we keep it
Retention is governed by these principles. Exact periods are still being finalized, and this section will state them once they are:
- Account data: while the account exists, then deleted on request.
- Invoice files and parsed data: while the account exists, so you can go back to what we found.
- Recovery and billing records: retained after deletion of the rest, because we need to be able to substantiate a charge, a credit and a consent. The period is set against applicable tax and limitation periods.
- Legal acceptances: retained as evidence of consent.
- Server logs: rotated on a standard schedule.
6. Deleting your data
Write to support@shipoverpay.com. We have a
documented procedure for removing a customer's data
(docs/sop/remove-customer-data.md), which distinguishes what is deleted from
what must be retained as a financial or consent record, and tells you which is
which.
7. Security, described honestly
What is true today:
- Transport is encrypted (HTTPS).
- Passwords are hashed; we cannot read them.
- Uploaded invoices are encrypted at rest. Each file is encrypted with AES-256-GCM before it touches the disk, with a key held in the server environment and never in the database. The storage location is authenticated as part of the encryption, so a file moved between accounts cannot be read rather than being silently served to the wrong customer.
- Uploaded files are stored outside any web-accessible directory and are served only through an authorized application route.
- Uploads are scanned for malware, and a file is rejected if the scanner is unavailable rather than accepted unscanned.
- Access to customer data by our team is limited to staff accounts and significant actions are logged.
- Databases and uploaded documents are backed up daily. Every backup is encrypted with AES-256 before it leaves the machine, then stored with an independent provider in Canada that never receives the decryption key.
- The restore procedure is tested weekly, and the test is a real one: it downloads the encrypted copy from that provider, decrypts it, restores it into a scratch database and counts the rows. It does not assume the backup would work.
What is not true today, stated plainly:
- Disk-level encryption is provided by the hosting layer only; our own encryption covers uploaded documents and every backup, not the live database file itself.
- We have no formal penetration test and no 24/7 on-call rota.
- We hold no certification: not SOC 2, not ISO 27001, not PCI DSS beyond Stripe handling card data. We will not claim otherwise.
8. Your rights
Depending on where you and your business are located, you may have rights to access, correct, delete or obtain a copy of personal information we hold, and to complain to a regulator.
California. California law grants residents rights of access, deletion and correction in respect of personal information, subject to the scope of the law and to exceptions. The product keeps the records needed to answer such a request, and we will honour any request we are required to honour. We do not claim an exemption we have not established.
To exercise a right, write to support@shipoverpay.com.
9. Email
We separate two kinds of message:
- Transactional: your scan is ready, a review is needed, a credit is confirmed, a fee was charged. These are part of the service.
- Marketing: anything promotional, which carries an unsubscribe link and our postal address once we have one.
We do not put marketing content inside transactional messages about your money.
10. Children
The service is for businesses and is not directed to anyone under 18.
11. Changes
We publish new versions with an effective date, and keep the exact text of every version on record.
12. Contact
What changed in 1.2
Backups are now held off-site, encrypted, with an independent provider that never receives the key, and the restore test runs against that off-site copy. Version 1.1 said this was not yet true; it is now.
Nothing about what we collect, why, or who we share it with has changed. Both 1.1 and 1.2 describe stronger protection of the same data, so neither asks anyone to accept anything again.