shippp

Privacy Notice

Last updated: 1 July 2026

How Shippp collects and processes personal data, under the GDPR (Regulation (EU) 2016/679, Arts. 13–14) and the Hungarian Info Act (Act CXII of 2011).

1. Controller

Data controller: Dipatch Bt. — see the Legal Notice.

Data-protection contact: hello@shippp.ai

For content that a workspace owner or their members create inside a workspace, the workspace owner is typically the controller and Shippp acts as a processor on their behalf (see our Data Processing Agreement). Shippp is the controller for account, authentication, billing and site-analytics data.

2. What we process, why, and on what lawful basis

Account & authentication

Email, hashed password, name, email-verification and session data. Purpose: to create and secure your account and provide the Service. Lawful basis: performance of a contract (Art. 6(1)(b)).

Billing & invoicing

Workspace billing details (legal name, country, address, tax/VAT number, VIES status), subscription and payment status, and issued invoices. Purposes: to take payment, apply the correct VAT and issue legally-required invoices. Lawful bases: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c), HU accounting & tax law).

Product / workspace content

Files, designs, components, comments and uploaded assets. Purpose: to provide the collaborative design tool. Lawful basis: contract; where Shippp acts as processor, the workspace owner’s instructions.

AI-assisted features (BYOK)

When you use AI features with your own provider API key (bring-your-own-key), the relevant workspace content is sent to the AI provider you selected (OpenAI, Anthropic, Google, xAI, DeepSeek or OpenRouter) to produce a result. Lawful basis: contract / your instruction. Because BYOK runs on your own key and account, the controller for that provider relationship may be you. Several providers are outside the EEA (see transfers below). If AI egress is disabled for your workspace, no such transfer occurs.

Marketing & early-access list (landing site)

Email address and (optionally) company details submitted to the early-access list, plus your marketing-consent record. Purpose: to send you the “registration is open” message and product news. Lawful basis: consent (Art. 6(1)(a)) / soft opt-in for the specific service you requested; you can withdraw at any time via any email’s unsubscribe link.

Website analytics & cookies (landing site)

Usage data via Google Analytics, only where you consent. Lawful basis: consent (Art. 6(1)(a)); see the Cookie Policy. Strictly-necessary cookies (session, security) rely on our legitimate interest / the ePrivacy exemption and need no consent.

3. Recipients & processors (subprocessors)

We share personal data with the service providers below, who process it on our behalf under a data-processing agreement, or who receive it as part of a feature you use:

Recipient / processorPurposeLocationTransfer safeguard
Stripe (Stripe Payments Europe, Ltd.)Payment processing & subscription billingIreland / United StatesSCCs / EU-US Data Privacy Framework
Neon, Inc.Managed Postgres database hostingEU region / United StatesSCCs
Resend (Plus Five Five, Inc.)Transactional & marketing email deliveryUnited StatesSCCs
Cloudflare, Inc. (PartyKit)Realtime collaboration infrastructureUnited States / global edgeSCCs
Cloudflare R2Asset / file storageEU / globalSCCs
KBOSS.hu Kft. (e-invoicing provider)Invoice issuance & Hungarian Tax Authority (NAV) reportingHungary (EU)Within the EU
Google Ireland Ltd. (Google Analytics)Website analytics (consent-gated)EU / United StatesSCCs / EU-US Data Privacy Framework
Vercel, Inc.Application & website hostingUnited States / global edgeSCCs / EU-US Data Privacy Framework
OpenAI, Anthropic, Google, xAI, DeepSeek, OpenRouter (AI providers, BYOK)AI-assisted canvas features — receive user/workspace content when AI is used with your own API keyUnited States (DeepSeek: China) / globalInternational transfer; under BYOK the controller for the provider relationship may be you (the user)

4. International transfers

Some recipients are located outside the European Economic Area (notably the United States; DeepSeek is in China). Where personal data is transferred outside the EEA, we rely on an adequacy decision (e.g. the EU-US Data Privacy Framework where applicable) or on the European Commission’s Standard Contractual Clauses with supplementary measures. For BYOK AI providers, the transfer results from your own use of your own key; you should review that provider’s terms.

5. Retention

  • Account & workspace data: for the life of the account, then deleted on erasure (see below).
  • Invoices & accounting records: retained for 8 years as required by Hungarian tax and accounting law, even after account erasure (legal obligation).
  • Consent records (cookie, marketing): kept as proof of consent for the applicable limitation period.
  • Analytics: per the Google Analytics retention configuration.
  • Early-access / marketing list: until you unsubscribe or ask us to delete you.

6. Your rights

Under the GDPR (Arts. 15–22) you have the right to access, rectification, erasure, restriction, data portability, and to object, as well as to withdraw consent at any time (without affecting prior processing). To exercise these rights, contact hello@shippp.ai; we respond within one month. The app also offers self-serve data export and account deletion — note that invoices are retained for 8 years under the legal-obligation basis above.

You have the right to lodge a complaint with the Hungarian supervisory authority, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu.

7. Automated decision-making & data source

We do not carry out automated decision-making that produces legal or similarly significant effects (Art. 22). Where we obtain data other than from you directly (Art. 14) — e.g. a workspace member added by an owner — the source is the relevant workspace owner or the invitation flow.

8. Security

We apply appropriate technical and organisational measures (Art. 32): encrypted transport, hashed passwords, access controls, and processor agreements. In the event of a personal-data breach likely to result in a risk to rights and freedoms, we notify NAIH within 72 hours and affected users as required.