Privacy Policy
Last updated
We hold two kinds of data: your account, and the shipments you ask us to track. Shipment data includes your customers' tracking numbers and, where you give it to us, their email addresses. You choose how long we keep it — from 5 days to indefinitely — and you can delete any of it at any time. We do not sell data, we do not advertise, and we set no tracking cookies on the pages your customers see.
Who we are
Shipi Tracking is operated by Aarsiv Groups. For the data in your account, you are the controller and we are your processor — you decide what goes in and how long it stays. For your own account details, and for the free tools on this site, we are the controller.
Questions, requests or complaints: privacy@myshipi.com.
What we collect
Your account. Name, email address, hashed password, plan, and the domains you authorise widgets on. Payment is handled by our payment provider; we never see or store card numbers.
Shipments you track. Tracking numbers, carrier, status history, and — only where you provide them — an order number and your customer's email address. The email address exists so a customer can find their parcel without a tracking number; nothing else uses it.
Free tools. If you look up a tracking number on this site without an account, we process that number to answer the query and keep a short-lived rate-limiting record derived from your IP address. We do not build a profile from it.
Logs. Ordinary server logs — IP address, time, and what was requested — kept for 30 days for security and debugging.
Your customers' data
This is the part worth reading twice. When you track a parcel, the tracking number and any email address you attach belong to somebody who never signed up with us. Under UK and EU data protection law you are the controller of that data and we act on your instructions.
- We use it only to resolve parcel status and to answer lookups on your tracking page.
- We never contact your customers on our own behalf, and never market to them.
- A lookup on a public tracking page returns parcel status only — never an order number, reference number or email address, so a stranger guessing tracking numbers learns where a parcel is and nothing about whose it is.
- If one of your customers contacts us directly, we will tell them to contact you, and help you respond.
How long we keep it
You choose, at signup and in settings: 5, 10, 30 or 90 days, or for as long as you have an account. The setting applies to shipment records — tracking numbers, status history and customer emails — and we delete them on that schedule without being asked.
Account details are kept while your account is open and for 30 days after you close it, so an accidental closure can be undone. Invoices are kept for as long as tax law requires, currently six years.
Who we share it with
Carriers and tracking aggregators, in order to resolve a parcel — they receive the tracking number and nothing else. Our hosting and email providers, as processors under contract. Nobody else. We do not sell data, and we do not share it for advertising.
Where it is processed
Our servers are in the EU. Carriers are worldwide by nature, so resolving a parcel may send the tracking number outside the EU — to the carrier that is physically carrying it. Transfers rely on adequacy decisions or standard contractual clauses.
Cookies
The dashboard uses a session cookie to keep you logged in. That is the only cookie we set, and it is strictly necessary, so there is no consent banner to click through.
The widgets set no cookies at all. The tracking page and widgets your customers see carry no analytics, no third-party scripts and no fingerprinting. This is deliberate: a widget that quietly tracked your customers would make your cookie banner wrong, and that would be your legal problem, not ours.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict how we use it, or object to processing. Shipment data can be exported from the dashboard as CSV at any time, and deleted from the same screen.
Email privacy@myshipi.com and we will respond within 30 days. If you are unhappy with the response you can complain to your local data protection authority.
Security
Passwords are hashed, never stored in readable form. Traffic is encrypted in transit. Access to production data is limited to the people who need it. Widget keys are public by design — they appear in your page's own HTML — and are protected by the allowed-domains list on each widget, not by secrecy.
Changes
If we change this policy in a way that affects you, we will email you before it takes effect. The date at the top always reflects the current version.
See also our Terms of Service.
