Who we are
ShipShark (“we”, “us”) provides a checkout overlay and related APIs for Indian D2C merchants. This policy explains what we collect when you visit our site, use our merchant tools, or check out as a buyer on a merchant store that uses ShipShark.
Data we collect
Depending on how you use ShipShark, we may process:
- Buyer checkout data — phone number, OTP verification status, delivery address, order totals, payment method choice (COD or online), and delivery/risk signals used for COD decisions.
- Merchant account data — name, work email, store domain, platform, API keys we issue, and integration settings.
- Technical data — IP address, device/browser metadata, request logs, and session identifiers needed to secure and operate the service.
- Marketing contact data — email and optional phone, store URL, and message when you submit our contact form.
Card numbers and other sensitive payment credentials are entered in your payment provider’s iframe (for example Razorpay). ShipShark does not store full card data.
How we use data
- Authenticate buyers with OTP and prefill or confirm delivery addresses.
- Place orders with the merchant’s store and payment gateway.
- Score COD risk using logistics and delivery outcomes where configured.
- Operate, secure, debug, and improve the service.
- Respond to merchant and prospect enquiries.
- Meet legal, tax, and fraud-prevention obligations.
Sharing
We share data only as needed to run checkout:
- Merchants — order and buyer details required to fulfil the purchase.
- Store platforms — such as WooCommerce or Shopify bridges you connect.
- Payment providers — to create and reconcile payments on the merchant’s account.
- Logistics / risk providers — when enabled for pincode or delivery outcome lookups.
- Infrastructure vendors — hosting, email/SMS delivery, monitoring, under processing agreements.
- Authorities — when required by law or to protect rights and safety.
We do not sell personal data.
Retention
We keep checkout, order, and account records for as long as needed to provide the service, resolve disputes, meet accounting and legal requirements, and then delete or anonymise them according to our retention schedules.
Security
We use industry-standard controls such as encryption in transit, access controls, and least-privilege keys. No method of transmission or storage is perfectly secure; please protect your merchant credentials.
Your choices
Merchants can update account details through onboarding and admin tools. Buyers should contact the merchant for order-specific requests; you may also reach us via our contact form for privacy questions about ShipShark itself.
To request deletion of personal data we hold, see our data deletion process.
Children
ShipShark is intended for merchants and adult buyers. We do not knowingly collect data from children.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the service after an update means you accept the revised policy.
Contact
Questions about privacy: Contact ShipShark.