ShipStatic ShipStatic

Privacy Policy

ShipStatic privacy policy.

Last updated August 21, 2026

Enhanced SRL (Tribunei 3, 550176 Sibiu, Romania; Trade Register J32/648/2008, CUI 23695110) operates ShipStatic and is the controller of your personal data. Write to privacy@shipstatic.com about anything on this page.

What we collect and why

When you sign in. You can sign in with Google or with an email sign-in link. From Google we receive your name and email address; with a sign-in link we only ever have your email address. We need this to give you an account, so we can perform our contract with you.

When you use the service. Cloudflare processes your IP address and request metadata to deliver the service and to keep it available. This is necessary to provide ShipStatic to you and to protect it from abuse.

When you deploy without an account, whether through the hosted MCP at mcp.shipstatic.com, the CLI without an API key, or the web app without sign-in, we collect the files you upload, take one screenshot of how the deployed site renders for the preview card, and record your IP address for rate-limiting and abuse prevention. We generate a deployment ID and a claim link so you can convert the deploy into a permanent, account-owned one within 3 days. No name, email, or profile data is collected on this path, because there's no account to attach them to.

Keeping the platform safe. The files you publish are scanned automatically for malware, phishing and other abuse, and a person reviews whatever the scan flags. We do this to meet our obligations as a hosting provider and to protect the people who visit sites hosted here. It applies to everything published through ShipStatic, including deploys made without an account.

When you pay. Paid plans are sold through Stripe, which is the merchant of record. Stripe collects your payment details and billing address, issues your receipt and invoice, and gives you a Link account to manage the subscription. Stripe acts as an independent controller for that data, under its own privacy policy. We never see or store card details. What reaches us is your email address, what you subscribed to, and whether the subscription is active.

Cookies and analytics

We use essential cookies for authentication. These are necessary for the service to function.

On this website, Google Analytics runs only if you accept it in the cookie banner, and you can withdraw that at any time from the same banner.

In the dashboard, once you have signed in, we use Google Analytics and Microsoft Clarity to understand how the product is used, including heatmaps and session recordings, and Sentry to catch errors. Anything you type is masked and never reaches them.

Email

We send you email you need in order to use the product: sign-in links, and service or security notices. These are part of the service and cannot be turned off while you have an account.

Separately, we may send product and lifecycle email. Every one of those carries a one-click unsubscribe link, and unsubscribing never affects your account.

Who sees your data

Who What for
Google Sign-in, and website analytics
Microsoft Product analytics, in the dashboard
Cloudflare Hosting, delivery, and email sending
Sentry Error tracking
Stripe Payments, invoicing, and tax, as merchant of record

We do not sell your data. Google, Microsoft, Cloudflare, Sentry and Stripe operate outside the EEA under Standard Contractual Clauses.

How long we keep it

Account data is kept until you delete your account. Activity records, such as your deploy and sign-in history, are routinely deleted after a limited period; IP addresses are removed from any records kept longer. Analytics and error logs are kept for 90 days. Session recordings are kept for 30 days, and heatmaps for up to 9 months. Unclaimed anonymous deploys, including files, screenshot, and metadata, are permanently deleted 3 days after creation. Records of payments are kept for as long as tax and accounting law requires.

Your rights

You can access, correct, delete, export, or restrict your data at any time by emailing privacy@shipstatic.com. We respond within 30 days. You also have the right to lodge a complaint with a data protection authority. In Romania, that is the ANSPDCP.

For data Stripe holds as merchant of record, you can also make requests to Stripe directly.


Questions? privacy@shipstatic.com