Our role
ShipShark is a checkout overlay and orchestration layer for Indian D2C merchants. We are not a payment aggregator, bank, or wallet. We do not hold, settle, or route customer funds.
Merchant funds
Online payments settle directly between the buyer, your Razorpay account, and your merchant settlement. ShipShark never receives or stores settlement balances.
Card and UPI credentials are entered inside your payment provider’s hosted iframe or redirect. ShipShark does not store full card numbers or CVV data.
PCI posture
Because sensitive payment data stays in your gateway’s iframe, merchants typically remain in a PCI SAQ-A scope for the checkout overlay path. Your gateway account and store configuration remain your responsibility — we help keep card data out of ShipShark systems.
Data protection
- TLS encryption for data in transit between buyers, merchants, and ShipShark APIs.
- Encrypted storage for secrets such as API keys and gateway credentials at rest.
- Least-privilege access controls for production systems and operational tooling.
- India-focused hosting and infrastructure vendors under processing agreements.
Availability
We target 99.9% platform availability and publish live gateway reachability on our status page. Incidents affecting checkout are communicated there when we become aware of them.
Reporting issues
Security questions or responsible disclosure: hello@shipsharklogistic.com. We aim to respond within 1 business day for merchant support requests.
See also our Privacy Policy and Data deletion process.