Privacy Policy
Effective date: October 9, 2026
This Privacy Policy explains what information shipsite.sh ("the Service", "we", "us", "our") collects, how we use it, and who we share it with. It applies to the shipsite.sh website, the API, the account portal, and the MCP server. It does not cover the content of sites that users publish through the Service; those sites are controlled by their owners.
1. Information We Collect
We collect only what the Service needs to operate:
- Email address. Required to create an account, send sign-in links, and send billing notices.
- Billing details. Payment is handled by Stripe. We store your Stripe customer and subscription identifiers. We never see or store full card numbers.
- API keys. We store a salted hash of each API key, never the key itself.
- Deployed content. The files you upload and the metadata you attach to each site.
- Usage counts. How many sites you have active each day, which determines your bill, and how many requests each site receives each day, which enforces serving limits.
- IP addresses. Logged briefly when you create an account or request a sign-in link, to limit abuse. These logs are deleted automatically after a short window.
2. How We Track Usage
All tracking is done server-side on our own infrastructure. We do not run analytics scripts, tracking pixels, or advertising tags on shipsite.sh, in the account portal, or on sites hosted through the Service. We do not use third-party analytics or advertising services today.
We may add third-party analytics or similar tools in the future. If we do, we will update this policy and change the effective date at the top of this page before they take effect.
3. Cookies
The marketing site and API set no cookies. The account portal sets a single session cookie after you sign in, scoped to the portal, so you stay signed in. It is not used for tracking. Sites hosted through the Service do not receive cookies from us.
4. How We Use Information
- To provide, operate, and secure the Service.
- To authenticate you and your API requests.
- To calculate and collect payment.
- To enforce rate limits and prevent abuse.
- To respond to support, abuse, and legal requests.
We do not sell personal information, and we do not use it for advertising.
5. Service Providers
We rely on a small number of infrastructure providers that process data on our behalf, only as needed to run the Service:
- Cloudflare hosts the Service and stores account records and deployed files. As our network provider, Cloudflare processes request logs, including IP addresses, for security and performance.
- Stripe processes payments and stores your payment method.
- Resend delivers sign-in and account emails.
Beyond these providers, we do not share personal information with third parties except as described in Section 6.
6. Legal Disclosures
We may disclose account information when required by law, in response to valid legal process such as a court order or subpoena, or when we believe in good faith that disclosure is necessary to protect safety, prevent fraud or abuse, or enforce our Terms of Service.
7. Data Retention
- Account records and deployed content are kept while your account is active.
- Sites with an expiration are deleted automatically when they expire. Deleted sites are removed from storage.
- Daily usage counts are kept as long as needed for billing records.
- IP-based abuse logs and sign-in tokens are purged automatically within days.
When you close your account, we delete your deployed content and deactivate your API keys. We may retain billing records as required for tax and accounting purposes.
8. Security
All traffic to the Service is encrypted in transit. API keys and sign-in tokens are stored only as hashes. Access to production data is restricted to the operators of the Service. No system is perfectly secure, and we cannot guarantee absolute security.
9. Your Choices
You can view and update your email and billing details from the account portal. You can delete any site through the API at any time. To close your account or request a copy or deletion of your data, email us at the address below.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
11. Changes to This Policy
We may update this policy as the Service changes. Material changes, including the introduction of any third-party tracking, will be reflected by updating the effective date at the top of this page.
12. Contact
For privacy questions and data requests: support@shipsite.sh
For abuse reports: abuse@shipsite.sh