Privacy Policy

Last updated 17 July 2026

Draft — pending legal review. This policy describes how the service is actually built, but it has not been reviewed by a qualified adviser. Do not treat it as legal advice or as a final published policy.

Who we are

ShipRateAPI (“we”, “us”) provides a shipping rate calculation service for e-commerce stores. This policy explains what personal data we collect, why we collect it, and what rights you have over it. For anything not covered here, contact hello@shiprateapi.com.

What we collect
DataWhyLawful basis
Name, email address, company name, phone numberTo create and operate your account, and to contact you about the servicePerformance of a contract
Password — stored only as a one-way hash, never in readable formTo authenticate youPerformance of a contract
Billing details, handled by StripeTo take payment for a subscription. Card numbers are entered directly into Stripe and never reach our serversPerformance of a contract
Rate request logs — destination country and postcode, cart weight and value, and the rates returnedTo let you audit what your customers were quoted, and to diagnose problemsLegitimate interests
Contact form submissionsTo answer your enquiryLegitimate interests
Analytics data, if you accept cookiesTo understand how the site is usedConsent

A note on your customers' data.Rate requests carry a destination country and postcode, but we do not ask for — and have no use for — your customers' names, addresses, or contact details. Please do not send them. Where you are the data controller for your shoppers, we act as your processor for the request data described above.

Who we share it with

We do not sell personal data. We share it only with the processors that make the service work:

  • Stripe — subscription billing and payment processing
  • Amazon Web Services — hosting and database storage, and transactional email (password resets, contact form) via Amazon SES
  • Cloudflare — Turnstile, which protects our forms from automated abuse
  • Google Analytics — website usage analytics, loaded only if you accept cookies
Where we store it

Our production infrastructure runs in Amazon Web Services' London region (eu-west-2). Some processors listed above may process data outside the UK and EEA; where they do, transfers rely on the safeguards those providers offer, such as Standard Contractual Clauses.

How long we keep it
  • Account data — for as long as your account is open, and then for as long as we are required to keep records
  • Rate request logs — the admin portal exposes the last 30 days
  • Billing records — retained by Stripe, and by us for as long as tax and accounting law requires
Cookies

We use a strictly necessary cookie to keep you signed in — the service cannot work without it. Analytics cookies are set only if you accept them via the cookie banner, and you can decline without losing any functionality.

Your rights

If you are in the UK or EEA you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive a portable copy. You can also withdraw cookie consent at any time. To exercise any of these, email hello@shiprateapi.com. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk.

Security

Passwords are stored only as one-way hashes. API keys are stored hashed and shown in full once, at creation. Traffic is encrypted in transit, and our database and cache sit on a private network with encryption enabled. No system is perfectly secure, but we aim to keep our measures proportionate to the data we hold.

Changes

If we change this policy we will update the date at the top of this page, and tell you directly where the change is significant.

Questions? Get in touch.