Privacy Policy
How Shipgate collects, uses, and protects your information.
Last updated: March 1, 2026
Overview
Shipgate ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, CLI tools, and related services (collectively, the "Services").
Information We Collect
Information You Provide
- Account information: If you create an account, we collect your name, email address, and authentication credentials.
- Contact information: When you contact us or request support, we collect your name, email, and the content of your message.
- Payment information: For paid plans, payment processing is handled by third-party providers. We do not store full payment card details.
Information Collected Automatically
- Usage data: We may collect anonymized usage patterns, such as CLI command invocation (e.g., verify vs. gate), to improve our product.
- Device and browser data: When you visit our website, we may collect IP address, browser type, and device information for security and analytics.
Repository and scan data
Shipgate is local-first by default. The Tier‑1 CLI command shipgate next runs verification without sending your repository to ShipGate's API (see open-source docs/data-handling.md). If you use dashboard features (account login, VS Code with a PAT, shipgate scan without --no-upload, or provenance upload), we may receive metadata from your projects (for example file paths, finding messages, verdicts, and attribution summaries). That is not a full source-code mirror, but it can be sensitive. Optional CLI analytics are off by default and are described in the same document.
How We Use Your Information
- To provide, maintain, and improve the Services
- To respond to your inquiries and support requests
- To send product updates, security alerts, and (with your consent) marketing communications
- To comply with legal obligations and enforce our terms
Legal Basis for Processing (GDPR)
Where the GDPR applies, we process personal data on the following bases:
- Contract: To provide the Services you have signed up for (account management, verification, billing)
- Legitimate interest: Product improvement, security, fraud prevention
- Consent: Marketing communications (you may withdraw at any time)
- Legal obligation: Where required by law
Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service providers: Hosting, analytics, and support tools that assist in operating our Services (under contractual data protection obligations)
- Legal requirements: When required by law, court order, or governmental authority
Subprocessors
We use a limited set of subprocessors to operate the Services. Each is bound by data protection terms. The current list is published on our Security & Compliance page. We notify customers of material changes to subprocessors.
Data Processing Agreement (DPA)
Enterprise customers may request a Data Processing Agreement. Contact privacy@shipgate.dev for a copy.
Data Retention
We retain your information only for as long as necessary to fulfill the purposes described in this policy or as required by law. Specifically:
- Account data: Retained while your account is active and for a reasonable period after closure
- Audit logs: Retained for at least 12 months for compliance and incident review
- Payment records: Retained as required by applicable tax and financial regulations
You may request export or deletion of your data at any time by contacting privacy@shipgate.dev.
Security
We implement industry-standard security measures to protect your data, including encryption in transit and at rest where applicable. For more details, see our Security page.
Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Object to or restrict processing
- Data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority (if you are in the EEA/UK)
To exercise these rights, contact us at privacy@shipgate.dev. We will respond within 30 days (or such shorter period as required by applicable law).
International Transfers
If you access our Services from outside the United States, your data may be transferred to and processed in the U.S. or other jurisdictions. We ensure appropriate safeguards (e.g., standard contractual clauses) where required by applicable law.
Children
Our Services are not intended for individuals under 16. We do not knowingly collect personal information from children under 16.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
Cookies
We use essential cookies for authentication (session cookies). We may use analytics cookies with your consent. You can manage cookie preferences through your browser settings.
Contact Us
For questions about this Privacy Policy or our data practices, contact us at privacy@shipgate.dev.