Legal
Privacy policy
1Who we are
ShipVia is a software application that connects Shopify stores to fulfillment services such as Amazon Multi-Channel Fulfillment. ShipVia is operated by Andrei Antonov, an individual based in Georgia (“ShipVia”, “we”, “us”).
This policy explains what information ShipVia collects when you visit this website or use the ShipVia app, how we use it, and the choices you have. You can reach us at shipvia.app@gmail.com.
2Our role
When you use ShipVia, we handle two kinds of personal information:
- Information about your customers, the people who order from your store. You decide which orders ShipVia fulfills, so you are the controller of this information, and ShipVia processes it on your behalf only to provide the service.
- Information about you as our user, such as your name, email address and store details. For this information, ShipVia is the controller.
3Information we collect
From your Shopify store
After you install ShipVia and approve its access through Shopify, we access:
- your store name, domain and the store owner’s contact email;
- products and variants, including titles, SKUs and barcodes;
- inventory levels and locations;
- orders you route to fulfillment: order number, items, quantities, shipping method, and the recipient’s name, shipping address and phone number.
ShipVia does not access payment card details.
From your Amazon seller account
After you authorize ShipVia through the Amazon Selling Partner API, we access:
- your selling partner ID and marketplaces;
- Fulfillment by Amazon inventory levels for your SKUs;
- fulfillment previews, order status, shipment and tracking details for the orders ShipVia creates.
ShipVia does not request access to information about buyers of orders placed on Amazon.
From Walmart
If you connect Walmart Multichannel Solutions once it’s available, we access equivalent inventory and fulfillment information through Walmart’s official APIs.
Information you give us
Your name, email address, messages you send to support by email or in the app’s chat, and settings such as SKU matches and routing rules.
Technical information
Server logs with IP addresses, timestamps and error details, used to run and secure the service. This website sets no cookies and uses no analytics or advertising tools. The app uses only the session tokens Shopify requires to sign you in.
4How we use information
We use information to:
- connect your accounts and provide the service: send orders to fulfillment, sync inventory and post tracking;
- show fulfillment errors and help you resolve them;
- respond to support requests;
- keep the service secure, prevent abuse and investigate incidents;
- manage billing through Shopify;
- comply with legal obligations.
We do not sell personal information, use it for advertising, or use your customers’ information for anything other than fulfilling your orders. We do not use customer information to train machine learning models.
5Legal bases
Where the GDPR or similar laws apply, we rely on the performance of our contract with you, our legitimate interest in keeping the service secure and reliable, compliance with legal obligations, and your consent where the law requires it. We process your customers’ information on your documented instructions, as your processor.
7Retention
- Recipient names, shipping addresses and phone numbers are deleted within 30 days after an order is delivered or canceled.
- Fulfillment records without personal information are kept while your account is active, so you can see your order history.
- Account information is deleted within 30 days after you uninstall ShipVia or ask us to delete it, unless the law requires us to keep it.
- Security logs are kept for up to 12 months and don’t include recipient addresses.
We act on Shopify’s customer data and erasure requests, and on Amazon’s data deletion notices, within the time those platforms require.
8Security
We protect information with measures that include:
- encryption in transit (TLS 1.2 or higher) and at rest, including backups;
- multi-factor authentication and least-privilege access for anyone who can reach production systems;
- encrypted storage and regular rotation of API credentials;
- separate test and production environments;
- access logging, monitoring and a documented incident response plan.
If a security incident affects your information, we will notify you without undue delay, and notify Amazon and Shopify as their policies require. No method of transmission or storage is completely secure, but we review our safeguards regularly.
9International transfers
ShipVia is operated from Georgia, and our infrastructure providers may process information in other countries. When information moves across borders, we use the safeguards applicable law requires, such as contractual protections.
10Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, and to restrict or object to how we process it. To make a request, email shipvia.app@gmail.com. We respond within 30 days.
If you are a customer of a store that uses ShipVia, please contact that store first. We will help the store respond to your request.
You can also complain to your local data protection authority.
11Children
ShipVia is a business tool and isn’t directed to anyone under 16. We don’t knowingly collect information about children.
12Changes
When this policy changes, we’ll update this page and the date above. If a change is significant, we’ll tell you by email or in the app before it takes effect.
13Contact
Questions and requests: shipvia.app@gmail.com. ShipVia is operated by Andrei Antonov, Georgia.