Shiplab Inc. Privacy Policy

Last updated: August 14, 2026

This Privacy Policy explains how Shiplab Inc. (“Shiplab,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Information when you visit or use our websites, products, and services.

1. Services Covered by This Policy

This Privacy Policy applies to Shiplab’s:

  • Public website at https://www.shiplab.com;
  • Management Portal at https://app.shiplab.com;
  • Application programming interfaces, including the Organization Management API at https://api.shiplab.com;
  • Model Context Protocol server at https://mcp.shiplab.com and integrations that allow customers to connect Shiplab to AI clients such as Claude, Codex, and other compatible clients;
  • Data collection and integration services;
  • Data Lake, storage, file delivery, download, search, and export features; and
  • Related support, billing, communications, and services.

We refer to these collectively as the “Services.”

This Privacy Policy does not replace a customer agreement, order form, or data processing agreement. If a customer agreement contains different terms governing our processing of Customer Data, the customer agreement controls for that Customer Data.

2. Our Role When Processing Customer Data

Shiplab processes data collected from customer-authorized systems and data sources on behalf of our business customers. This may include invoice, shipment, tracking, charge, manifest, order, warehouse, fulfillment, and related operational data. We refer to this information as “Customer Data.”

When we process Customer Data on behalf of a customer, the customer generally determines why and how the information is processed. The customer acts as the controller or business, and Shiplab acts as its processor or service provider, as those terms are defined under applicable privacy laws.

Customers are responsible for providing any notices and obtaining any rights or permissions needed for Shiplab to access and process Customer Data on their behalf. If your Personal Information appears in Customer Data maintained by a Shiplab customer, you should ordinarily direct privacy requests to that customer. We will assist customers with those requests as required by applicable law and our agreements.

Shiplab acts as a controller or business with respect to information we collect for our own purposes, such as website visitor information, account information, billing records, and business communications.

3. Information We Collect

Depending on how you interact with Shiplab, we may collect the following categories of information.

Account and organization information
We may collect your name, business email address, telephone number, job title, organization name, organization profile, billing contact, subscription information, and account preferences.

Authentication and security information
We may collect or process user identifiers, authentication tokens, sign-in events, IP addresses, multi-factor authentication settings, access permissions, and other information used to authenticate users and secure accounts. Authentication services may be provided through a third-party identity provider, such as Amazon Web Services.

External-system connection and configuration information
When authorized by a customer, we may collect account information, usernames, passwords, API keys, access tokens, endpoints, account numbers, file-transfer details, and related configuration fields needed to connect to systems and data sources the customer is authorized to access.

These systems and data sources may include carriers, manifest systems, warehouse management systems, transportation management systems, fulfillment platforms, marketplaces, file-transfer locations, and other customer-selected systems.

We use this information to establish and maintain the requested connection, collect Customer Data, monitor connector status, and troubleshoot connection issues. Source-system credentials are not included in MCP tool results or disclosed to other Shiplab customers.

Credentials should be provided through the Shiplab Management Portal or another Shiplab-approved setup method, not through an AI conversation or MCP tool request.

Customer Data
At a customer’s direction, we may collect and process invoice records, shipment and tracking information, charges and adjustments, manifest records, order information, warehouse or fulfillment records, account information, source files, connector status, and other data made available through customer-authorized systems and data sources.

Depending on the system and source data, Customer Data may contain Personal Information concerning senders, recipients, employees, customers, or other individuals, such as names, business contact information, shipment addresses, or tracking and delivery information.

API and access information
We may collect information about API tokens, access permissions, API requests, endpoints used, response status, timestamps, organization identifiers, and other technical information needed to provide and secure programmatic access to the Services.

MCP and AI connector information
When you connect Shiplab to Claude, Codex, or another AI client, we may receive:

  • Authentication and authorization information needed to connect your Shiplab account;
  • Structured tool requests and parameters transmitted to the Shiplab MCP server;
  • Information identifying the user and organization making the request;
  • The Shiplab tool being requested;
  • Authorized tool results returned to the AI client; and
  • Connection, status, error, and security logs associated with the request.

Shiplab does not use the MCP server to request, retrieve, or reconstruct your complete AI chat history, AI memory, conversation summaries, or unrelated files. We receive only the information the AI client transmits as part of an authenticated Shiplab tool request or information you separately provide to Shiplab.

Do not include passwords, API keys, multi-factor authentication codes, payment-card information, government identifiers, protected health information, or other unnecessary sensitive information in an AI prompt or MCP tool request.

Payment and subscription information
Our payment processors may collect payment-card and billing information when you purchase a subscription. Shiplab may receive limited billing information, such as billing contact information, subscription status, payment status, transaction identifiers, and limited card details supplied by the payment processor. We do not request payment-card numbers through our MCP server or AI connectors.

Website and device information
When you visit our website or use the Services, we may automatically collect your IP address, browser and device type, operating system, referring pages, pages viewed, approximate location derived from your IP address, and information about how you interact with the Services.

We may collect this information through cookies, log files, pixels, tags, analytics services, and similar technologies.

Communications and support information

We collect information you provide when you contact us, request support, participate in a trial, respond to a survey, schedule a demonstration, or otherwise communicate with Shiplab. This may include the contents of your communications and files or diagnostic information you choose to provide.

4. How We Use Information

We may use Personal Information and Customer Data to:

  • Provide, maintain, and administer the Services;
  • Create and manage user and organization accounts;
  • Authenticate users and limit access to the appropriate organization and permissions;
  • Establish and operate connections to customer-authorized systems and data sources;
  • Collect, process, store, search, and deliver Customer Data;
  • Provide APIs, MCP tools, Data Lake access, file delivery, exports, and download links;
  • Process subscriptions, payments, and billing records;
  • Provide customer support and respond to requests;
  • Monitor connector health and Service availability;
  • Detect, investigate, and prevent fraud, unauthorized access, security incidents, and misuse;
  • Debug, maintain, analyze, and improve the performance and reliability of the Services;
  • Communicate about accounts, Service changes, security, support, and administrative matters;
  • Send product or marketing communications where permitted by law;
  • Comply with legal obligations and enforce our agreements; and
  • Protect the rights, safety, and property of Shiplab, our customers, and others.

We do not use Customer Data, source-system credentials, or API tokens for advertising.

5. How We Disclose Information

We may disclose information to the following categories of recipients.

Service providers
We use service providers to support cloud hosting, identity management, authentication, storage, security, monitoring, communications, analytics, customer support, and billing. These providers may process information on our behalf subject to contractual and confidentiality obligations.

For example, we use Amazon Web Services for portions of our infrastructure, authentication, and storage.

Customer-authorized systems and data sources
We may transmit credentials and related connection information to an external system or data source as needed to authenticate the customer, operate the requested connection, and collect or deliver data at the customer’s direction.

AI client platforms selected by customers
When you enable Shiplab through Claude, Codex, or another AI client, authorized Shiplab tool results are transmitted to that AI client at your direction. Those results may contain Customer Data responsive to your request.

The AI platform’s own terms and privacy policy govern its processing of information after it receives that information. Shiplab does not control how an independently selected AI provider processes information within its service.

Payment processors
We disclose billing and transaction information to payment processors as needed to process subscriptions and payments.

Customer organizations and administrators
Organization owners and administrators may access information about users associated with their organization, including account status, roles, permissions, and Service activity.

Professional advisers
We may disclose information to lawyers, accountants, auditors, insurers, and other professional advisers when reasonably necessary to obtain their services or protect our rights.

Legal and safety disclosures
We may disclose information when we reasonably believe disclosure is required by law, legal process, or governmental request, or when needed to protect the rights, property, security, or safety of Shiplab, our customers, users, or others.

Business transactions
Information may be disclosed or transferred in connection with a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to appropriate confidentiality protections.

At your direction
We may disclose information to another party when you or your organization direct us to do so or provide consent.

Shiplab does not sell Personal Information or identifiable Customer Data. We do not disclose one customer’s identifiable Customer Data, source-system credentials, or API tokens to another customer.

6. Aggregated and De-identified Information

We may create, use, and disclose aggregated or de-identified information that cannot reasonably be used to identify an individual or customer. We may use and disclose this information for lawful business purposes, including understanding Service usage, measuring performance, developing and improving products and services, improving reliability, and protecting the Services.

We maintain de-identified information in de-identified form and do not attempt to re-identify it except where permitted by law to evaluate our de-identification methods. We will not disclose aggregated or de-identified information in a manner that could reasonably identify an individual or customer.

7. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, meeting contractual commitments, maintaining security, resolving disputes, and satisfying legal, accounting, and regulatory obligations.

Our general retention practices are:

  • Account and organization information: Retained while the account or customer relationship is active and afterward as needed for account closure, billing, legal obligations, dispute resolution, and enforcement of agreements.
  • Customer Data: Retained for the duration of the customer’s subscription and any additional retention or retrieval period stated in the applicable plan or customer agreement. Following that period, Customer Data is returned, deleted, or de-identified in accordance with the agreement and our ordinary deletion and backup cycles.
  • Source-system credentials: Retained while the applicable connection remains active or until the customer removes, replaces, or revokes the credentials. Residual copies may remain temporarily in protected backups until those backups are overwritten through the normal backup cycle.
  • API and connector tokens: Retained until they expire, are revoked, or are no longer needed to provide authorized access.
  • MCP, API, operational, and security logs: Retention varies depending on the type of log and the purpose for which it is maintained. We retain logs only for as long as reasonably necessary to operate, secure, monitor, and troubleshoot the Services. Logs are deleted or de-identified when no longer reasonably necessary for those purposes, unless a longer period is needed to investigate a security incident, prevent abuse, resolve a support issue, comply with law, or establish, exercise, or defend legal claims.
  • Export files and download links: Export files are retained according to the applicable plan, agreement, destination configuration, or delivery schedule. Signed download links expire automatically according to their configured expiration period.
  • Billing and transaction records: Retained for the period required by applicable tax, accounting, and legal requirements.
  • Support and business communications: Retained for as long as reasonably necessary to provide support, maintain business records, resolve disputes, and comply with legal obligations.

We may retain information for a longer period when required by law, subject to a legal hold, or necessary to establish, exercise, or defend legal claims.

8. AI Client Controls

Connecting Shiplab to an AI client is optional. When supported by the applicable client, you may:

  • Enable or disable the Shiplab connector for a particular conversation;
  • Disconnect the connector through the AI client;
  • Revoke the connector’s authorization through Shiplab;
  • Revoke or replace an API or access token; and
  • Contact Shiplab to request assistance with disconnection or account deletion.

Disconnecting an AI client prevents future access through that connection. It does not necessarily delete information previously transmitted to or retained by the AI provider. Requests concerning that information should be directed to the applicable AI provider.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

No method of transmission or storage is completely secure. Customers and users are responsible for protecting their credentials, maintaining appropriate access permissions, and notifying Shiplab promptly if they suspect unauthorized access.

10. Privacy Rights and Choices

Depending on where you reside and applicable law, you may have the right to:

  • Request access to Personal Information we maintain about you;
  • Request correction of inaccurate Personal Information;
  • Request deletion of Personal Information;
  • Request a portable copy of certain Personal Information;
  • Object to or request restriction of certain processing;
  • Withdraw consent where processing is based on consent;
  • Opt out of certain marketing communications; and
  • Appeal a decision concerning a privacy request where applicable.

To exercise a privacy right, contact us at info@shiplab.com. We may need to verify your identity and authority before completing a request.

Some information may be exempt from a request under applicable law. We may also retain information needed to provide the Services, comply with law, protect security, maintain transaction records, or establish or defend legal claims.

If your request concerns Personal Information contained in Customer Data, please contact the Shiplab customer that controls that data. If you submit the request to us, we may refer the request to the appropriate customer.

You may unsubscribe from marketing emails using the unsubscribe link in the message. You may still receive transactional, security, billing, or Service-related communications.

11. Cookies and Analytics

We and our service providers may use cookies and similar technologies to operate the website, remember preferences, understand website usage, measure marketing performance, and maintain security.

You can control cookies through your browser settings and any cookie controls made available on our website. Disabling some cookies may affect website or Service functionality.

We do not provide Customer Data, source-system credentials, or API tokens to advertising or website analytics providers.

12. International Processing

Shiplab is based in the United States. We and our service providers may process information in the United States and other countries where privacy laws may differ from those in your location.

Where required by applicable law, we use appropriate safeguards for international transfers of Personal Information.

For individuals in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing Personal Information may include performance of a contract, compliance with legal obligations, consent, and our legitimate interests in providing, securing, supporting, and improving the Services.

You may also have the right to submit a complaint to your local data protection authority.

13. Children

The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect Personal Information directly from children through the Services.

14. Third-Party Services and Links

The Services may contain links to or integrate with third-party services. This Privacy Policy does not govern the privacy practices of third parties, including external data sources, payment processors, AI platforms, or customer-selected delivery destinations. We encourage you to review their applicable privacy policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to the Services, our practices, or applicable legal requirements.

When we make changes, we will update the “Last updated” date above. If a change materially affects how we process Personal Information or Customer Data, we will provide additional notice where required by law or our agreements.

16. Contact Us

For questions, privacy requests, or complaints concerning this Privacy Policy or Shiplab’s privacy practices, contact:

Shiplab Inc.
Greenville, North Carolina, United States
Email: info@shiplab.com