Privacy Policy

1. Who we are

ShipLedger is a Shopify embedded app operated by Shenzhen Yunqi Era Technology Co., Ltd., registered at Room 505, Building B, Guoren Building, No. 5 Keji Middle 3rd Road, Maling Community, Yuehai Subdistrict, Nanshan District, Shenzhen, Guangdong 518057, China ("we", "us"). It reconciles your 3PL's invoices against your contract rate card and your Shopify order facts, and shows you where a line was billed differently from what was agreed. This policy explains what data we process on your behalf as a merchant, why, and how long we keep it.

2. What we process

From you: the 3PL invoices (PDF / CSV / Excel) you upload or forward to your dedicated forwarding address, the contract or rate card you upload, and the parameters you set in Settings.

From your Shopify store (Protected Customer Data, Level 1): order-level facts only — order id, created and fulfilled timestamps, line SKUs and quantities, shipment and item counts, cancellations, and the shipping destination's province / state, city and country; plus store-level inventory snapshots (quantity per SKU, not tied to any customer or order).

What we do not read or store: your customers' names, email addresses, phone numbers, street addresses, or postal / zip codes. We do not request these fields from Shopify. You can repeat this sentence to your customers.

If you use the order CSV import (before Shopify's app review unlocks the Orders API for your store), the same rule applies: the file is parsed in a stream, only the columns listed above are kept, and the original file is not stored.

3. Why we process it

  • To reconstruct each invoice into a readable view and match billed quantities against your actual shipments and returns.
  • To compare billed rates against your confirmed rate card and flag lines that do not match it.
  • To track how each fee code's unit price moves month over month.
  • To send you the monthly report and the operational emails described in the app (parsing done, parsing handed to our team, renewal reminders).

We do not use your data for other purposes, do not sell it, and do not share it with your 3PL. Findings are suggestions for you to confirm; we do not write to your store and do not send anything to your 3PL on your behalf.

4. Who else touches it

  • Hosting and database: Render (render.com), region United States (Oregon) — web app, background worker, PostgreSQL database and the job queue run there. The database, its replicas and its backups are encrypted at rest with AES-256; connections from the public internet are encrypted in transit with TLS.
  • Invoice column recognition: DeepSeek (API). The first time we see an invoice layout from your 3PL (no stored column map for it yet), we send the column headers, up to the first 20 lines of that invoice as a sample (free-text cells cut to 80 characters) and the descriptions of the lines our rules could not classify; the rest of the invoice stays on our servers. No Shopify order facts are sent.
  • Email (sending, and receiving of forwarded invoices): Resend. Inbound invoice emails and attachments are fetched from Resend and stored on our side; the temporary download links Resend issues expire on their own.
  • Shopify: we receive order facts through the Admin API and the mandatory compliance webhooks.

5. How long we keep it, and how to delete it

  • While the app is installed, your invoices, contract and order facts stay so that history, back-fill and renewal summaries keep working.
  • Delete everything, any time: Settings → Delete all data. Your invoices, contract, order facts, findings and billing questions are hard-deleted.
  • Uninstall: access tokens and sessions are revoked immediately; your data is hard-deleted after Shopify sends the shop/redact request (48 hours after uninstall), within 7 days of that request (Shopify allows up to 30 days).
  • Your customers' requests: when a customer asks your store for their data or for erasure, Shopify forwards the request to us; we export or delete the order-level facts we hold for the listed orders within 30 days.
  • Compliance log: for each compliance request (uninstall, shop/redact, a customer's data or erasure request, or your own Delete all data) we keep one record of what was done and whether it succeeded (a compliance audit entry). It names your store but holds no invoice, order or contract data — it exists so that you and Shopify can check that the request was honoured.
  • What remains after deletion: aggregate, de-identified knowledge about 3PL fee codes (for example, that a given fee code at a given 3PL is a surcharge, and how many merchants classified it that way). It carries no merchant identifier and cannot be traced back to you.

6. Security

Access is limited to what the app needs (the Shopify access scopes shown on the app listing). Webhook requests are HMAC-verified and rejected with 401 when the signature does not match. Data at rest — the database, its replicas and its backups — is encrypted with AES-256 by our hosting provider. Backups are point-in-time recovery snapshots that roll off within 7 days, so deleted data leaves the backups no later than 7 days after it leaves the live database.

7. Contact and changes

Questions or requests: write to hello@maxshipledger.com. Changes are posted on this page.