The ShipBack to home

YOUR DATA & YOUR CHOICES

Privacy policy

Last updated September 8, 2026

The Ship turns order and shipping emails into an order dashboard, delivery history, and spending analytics. This policy explains how The Ship handles information when you use its website and mobile app.

1. Who to contact

The Ship operates this service. For privacy questions, requests to access or delete your information, or help with a connected inbox, contact theshiptracker@gmail.com. Do not send passwords, access tokens, or verification codes.

2. Information we collect

  • Account information: your email address, account identifier, authentication information, and preferences needed to provide your workspace.
  • Connected inbox information: your mailbox email address, provider, connection status, sync settings, message identifiers, and sync history. Google connections use authorization tokens. IMAP connections use the server details and credentials you supply.
  • Order information: retailer and order numbers, products and images, quantities, prices, dates, shipping and delivery status, tracking numbers, recipient names and addresses, account email addresses, and payment brand or last four card digits when present in order emails.
  • Technical and support information: connection errors, sync progress, service logs, and information you choose to send when requesting help. Hosting and authentication providers process network and device information to deliver and protect the service.

3. Gmail access and use

Connecting Gmail is optional. With your permission, The Ship requests your Google account identity and email address and read-only Gmail access (gmail.readonly). This permission technically allows reading messages in the connected mailbox. The Ship uses searches and filters to identify likely order, receipt, cancellation, and shipping messages, then reads candidate message headers and content to extract order details. Filters can sometimes match a message that is not an order.

We use this information to import and match orders, update delivery progress, avoid duplicate imports, calculate spending summaries, and keep your dashboard current. Background sync and Gmail change notifications can continue while you are away from the app until you disconnect or revoke access.

The Gmail connection does not grant permission to send email, delete messages, or change your mailbox. Your Google password is entered with Google, not with The Ship. Full candidate emails are processed on the server; the application stores parsed results and message identifiers rather than a full raw-email archive. Parsing caches can also record that a checked message contained no order.

4. Sharing and service providers

Supabase provides authentication, database storage, credential storage, and server processing. The website is hosted through OpenAI Sites on Cloudflare infrastructure. Google provides Gmail authorization, message access, and change notifications. These providers process the information needed to operate their part of the service.

If you enable Discord webhook notifications, The Ship sends order or delivery summaries to the Discord channel you select. People with access to that channel can see those summaries. Retailer and image hosts may receive requests when product images are downloaded or displayed. Following an external carrier or retailer link takes you to that provider, whose privacy policy applies.

We do not sell Google user data, use it for advertising, or use it to train general-purpose AI or machine-learning models. Google user data is used to provide the features you request. Access by a person is limited to cases such as help you specifically request and consent to, security investigations, or legal obligations.

The Ship’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Storage and protection

Account and order records are stored in the service’s backend, rather than only on your device. Google refresh tokens, IMAP credentials, and Discord webhook credentials are stored encrypted in a server-side vault. Access controls restrict account data to the appropriate user and authorized service operations. Network connections use HTTPS or encrypted mailbox connections.

Your browser or mobile app stores session information so you can remain signed in. Service providers may process data outside your country. No storage or transmission method can guarantee absolute security.

6. Retention and deletion

We retain your account and imported order information to provide your order history while you use The Ship. Credentials are kept while the corresponding connection remains configured. Sync records and parsing caches support reliable imports and troubleshooting.

  • Disconnect an inbox: open Inboxes and choose Disconnect. This removes the stored connection credentials and associated mailbox data. An order also found in another connected inbox may remain linked to that other inbox.
  • Revoke Google access: remove The Ship from your Google Account connections. Revoking access stops future authorized access; it does not by itself erase order information already imported into The Ship.
  • Delete your account: on the website, open Settings and choose Delete account in the danger zone. This removes your account and its connected mailbox records and credentials. Contact us if you cannot access this control or need help with deletion.

Deletion from the active application does not recall exports, screenshots, or notifications already sent to a channel you chose. Cached images, operational logs, and provider backups may remain for their applicable retention periods. Contact us for help with retained data or a request involving those copies.

7. Your choices

You choose which inboxes to connect and can adjust available sync filters. You can review imported orders in the app, disable optional notification events, disconnect an inbox, or request access, correction, or deletion by contacting us. We may need to verify that a request concerns your own account before acting on it.

8. Changes to this policy

We will update this page when our data practices change and revise the date above. If a change materially affects how we use Google user data, we will provide notice in the service and obtain any additional consent required before using that data for a new purpose.