Privacy Policy
Last updated 17 July 2026
Draft — pending legal review. This policy describes how the service is actually built, but it has not been reviewed by a qualified adviser. Do not treat it as legal advice or as a final published policy.
Who we are
ShipRateAPI (“we”, “us”) provides a shipping rate calculation service for e-commerce stores. This policy explains what personal data we collect, why we collect it, and what rights you have over it. For anything not covered here, contact hello@shiprateapi.com.
What we collect
| Data | Why | Lawful basis |
|---|---|---|
| Name, email address, company name, phone number | To create and operate your account, and to contact you about the service | Performance of a contract |
| Password — stored only as a one-way hash, never in readable form | To authenticate you | Performance of a contract |
| Billing details, handled by Stripe | To take payment for a subscription. Card numbers are entered directly into Stripe and never reach our servers | Performance of a contract |
| Rate request logs — destination country and postcode, cart weight and value, and the rates returned | To let you audit what your customers were quoted, and to diagnose problems | Legitimate interests |
| Contact form submissions | To answer your enquiry | Legitimate interests |
| Analytics data, if you accept cookies | To understand how the site is used | Consent |
A note on your customers' data.Rate requests carry a destination country and postcode, but we do not ask for — and have no use for — your customers' names, addresses, or contact details. Please do not send them. Where you are the data controller for your shoppers, we act as your processor for the request data described above.
Who we share it with
We do not sell personal data. We share it only with the processors that make the service work:
- Stripe — subscription billing and payment processing
- Amazon Web Services — hosting and database storage, and transactional email (password resets, contact form) via Amazon SES
- Cloudflare — Turnstile, which protects our forms from automated abuse
- Google Analytics — website usage analytics, loaded only if you accept cookies
Where we store it
Our production infrastructure runs in Amazon Web Services' London region (eu-west-2). Some processors listed above may process data outside the UK and EEA; where they do, transfers rely on the safeguards those providers offer, such as Standard Contractual Clauses.
How long we keep it
- Account data — for as long as your account is open, and then for as long as we are required to keep records
- Rate request logs — the admin portal exposes the last 30 days
- Billing records — retained by Stripe, and by us for as long as tax and accounting law requires
Cookies
We use a strictly necessary cookie to keep you signed in — the service cannot work without it. Analytics cookies are set only if you accept them via the cookie banner, and you can decline without losing any functionality.
Your rights
If you are in the UK or EEA you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive a portable copy. You can also withdraw cookie consent at any time. To exercise any of these, email hello@shiprateapi.com. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk.
Security
Passwords are stored only as one-way hashes. API keys are stored hashed and shown in full once, at creation. Traffic is encrypted in transit, and our database and cache sit on a private network with encryption enabled. No system is perfectly secure, but we aim to keep our measures proportionate to the data we hold.
Changes
If we change this policy we will update the date at the top of this page, and tell you directly where the change is significant.
Questions? Get in touch.