Skip to content

Privacy

What we collect, why, who else sees it, and what you can ask us to do about it.

Last updated 22 September 2026

Who this is for

Shipina is software a freight forwarder uses to run their own business, so there are two kinds of people in it. There is the forwarding company that holds the account, along with its staff; and there are that company's own customers and partners, who sign in to a portal the forwarder invited them to.

The shipment data inside an account belongs to the forwarder, not to us. We hold it on their behalf and only do with it what running the service requires. If you reached a portal through a forwarder, they decide what is in your record — this page explains what we do with it once it is here.

It also covers the public website: the landing page, the pricing and contact sections, and the help centre, which anyone can read without an account.

What we collect

  • Account details: your name, email address, the company you belong to, and the role it gave you.
  • What you put in: quotes, bookings, invoices, the customers and partners you record, and any document you upload.
  • Technical records kept while serving a request: your IP address, the browser you used, and what was asked for and when — the ordinary server log, which is also how abuse and break-in attempts are noticed.
  • Product analytics and error reports, described below, and only where they are allowed.

That is the whole list. There is no advertising identifier, no tracking pixel from anybody else, and nothing bought from a data broker. We do not sell anything we hold, and there is no arrangement under which we could.

Cookies and what is kept in your browser

  • A sign-in cookie, which is what keeps you signed in. It cannot be read by any script, and signing out ends it on the server as well as in the browser.
  • A short-lived access token, your company's sign-in name, and your light-or-dark preference, kept in the browser's own storage rather than sent anywhere.
  • Your answer to the analytics question on this site, so we do not ask again on every page.

The first three are what the app is made of; without them it cannot sign you in or remember how you like it to look. None of them is an advertising cookie, and nothing here is shared with an advertising network.

Product analytics and error reports

We use PostHog to see which parts of the product are used and to be told when something breaks. On the public pages it does not start at all until you accept it: decline, or simply never answer, and nothing is loaded, nothing is stored in your browser, and no identifier is created for you. Inside the app it is part of the service, under the agreement with the company that holds the account.

What an event can carry:

  • Which page you were on, as its shape rather than its contents — a booking page, not which booking.
  • An action we named on purpose, such as a quote being sent. Clicks and keystrokes are not collected at large.
  • An error, with the technical detail needed to find it: what failed, and where in the code.
  • Your browser and device type, and the country your IP address suggests. The address itself is not kept alongside the event.
  • When you are signed in, which account and company the event belongs to, so a fault can be traced back to the person who hit it and fixed for them.

What is never collected: recordings of your screen or session, the contents of forms, the words you type, and the commercial detail in them — prices, customer names, shipment references. The tool is configured to refuse those rather than trusted to avoid them.

Who else processes it

  • PostHog, for the analytics and error reports above, on their European cloud so the data stays in the EU.
  • Resend, which delivers the only email we send: confirming an address, inviting somebody, and resetting a password. It carries the recipient's address and the link, and nothing about your shipments.
  • Cloudflare, which carries traffic between your browser and the application.

The application and its database run on hardware we operate ourselves. Your shipment data is not handed to a cloud provider to store, and none of the three above receives it.

How long it is kept

  • Account and shipment data: for as long as the account exists. Close it and we delete it, other than anything we are required to keep.
  • Your company's own audit trail, which records who changed what: for the window your plan states, shown on the page that displays it.
  • Backups: a rolling window of encrypted copies, so a deletion is fully gone once the last copy that predates it has rolled off.
  • Analytics events and error reports: on PostHog's own retention, which is shorter than the account's.

Your choices

You can change your mind about analytics at any time, in either direction, using the control below or the link at the foot of every public page. Withdrawing stops collection immediately and drops the identifier that was created for you.

You can also ask for a copy of what we hold about you, for a correction, or for deletion. If you use Shipina through a forwarder's portal, your record is theirs — ask them first, and we will help them answer.

How it is protected

  • Passwords are stored only as a hash, and changing one ends every session that was open.
  • Sign-in tokens are short-lived and can be revoked; the platform operators sign in through a separate system from tenants, on separate credentials.
  • Each company's data is isolated from every other company's, enforced in the application rather than left to a query being written correctly.
  • Backups are encrypted before they leave the machine.

Changes to this page

If what we do changes, this page changes with it, and the date at the top moves. Where a change materially affects people already using Shipina, we say so in the app rather than relying on anyone to re-read it.

Getting in touch

Questions about any of this, or a request about your own data, reach us through the contact form.