Privacy Policy
Effective date: 2026-06-19
This Privacy Policy explains how ShipThanks LLC ("ShipThanks," "we," "us") handles personal data in connection with the ShipThanks platform (the "Service"). It covers everyone whose personal data flows through the Service:
- Company representatives — the admins and billing/messaging-compliance contacts at an organization (a "Company") that subscribes to ShipThanks. We are the controller (see §2).
- Sellers — the individual sales representatives who record and send thank-you videos. We are the controller, and we share much of this data with the Seller's Company (see §3).
- End customers — the shoppers who receive thank-you messages. The Company is the controller and ShipThanks is the processor, acting on the Company's instructions (see §4).
Sections §5–§12 (sharing, AI, transfers, retention, security, rights, changes, contact) apply across all three groups.
1. Roles at a glance
| Whose data | Examples | Our role |
|---|---|---|
| Company representatives | admin/billing/compliance-contact identity; org & 10DLC registration details | Controller |
| Sellers | seller identity; content created; activity / performance | Controller (shared with the Company) |
| End customers | customer records; order/shipment data; message transcripts; engagement events | Processor (the Company is the controller) |
2. Company account data (we are the controller)
What we collect
- Organization & business details — org name, slug, status, and the 10DLC messaging registration data you submit: legal business name, business type, EIN, industry, website, business address, and authorized-representative name, email, phone, and title.
- Authorized-user identity — Org Admin name, email, phone, and authentication identifiers via our identity provider (Clerk).
- Billing data — your Stripe customer and subscription identifiers and billing contact details. Card/bank details are collected and stored by Stripe, not by us.
- Consent-attestation records — who attested customer-messaging consent, when, and the version of the attestation text agreed to (kept as compliance evidence).
- Usage, security, and support data — log data, IP addresses, session records, API-credential metadata (name, last-used time — never the secret), support communications, and audit events.
How we use it
To provide, secure, and support the Service; to register and operate your messaging (10DLC); to bill and collect fees; to authenticate users and protect against fraud, abuse, and security incidents; to communicate about the Service; to maintain compliance records; and to comply with law. Our legal bases (where GDPR/UK GDPR applies) are performance of our contract with you, our legitimate interests in operating and securing the Service, and legal obligations.
3. Seller data (we are the controller; shared with the Company)
Two controllers, one tool. ShipThanks and your Company both have roles in a Seller's data. We process it to run the Service (and we share much of it with the Company, which uses it to run and measure its program). How your Company uses your information for its own purposes — performance management, your engagement with it, etc. — is governed by your Company's policies and your relationship with it, not by us.
What we collect about Sellers
- Identity & contact — your name, mobile phone number, email, and authentication identifiers from our identity provider (Clerk), including your verified phone (we verify your number by SMS one-time passcode at sign-up).
- Membership & role — which Company/organization you belong to, your role (Seller), your status (e.g., invited/active), your rep identifier within the Company, and your notification opt-out status.
- Content you create — the thank-you videos and images you record, generated previews (e.g., GIFs), and the messages and replies you send to customers.
- Activity & performance data — which orders you were prompted on, when you tapped a record link, the thank-yous you sent and when, conversations and your reply times, send rates, leaderboard standing, and whether you have sent videos.
- Device, log & security data — IP address, session records, and usage/audit logs.
If you use the accountless first-send link (recording without an account), we process your phone number, the order context, and the content you send for that one action; we may create a phone-only identity for you that becomes a full account if you sign up later.
How and why we use it
We use your personal data to:
- provide the Service — route record prompts to your phone, let you record and send thank-yous, deliver them, and run your two-way conversations with customers;
- send you operational SMS (record prompts, customer-reply alerts) and account communications;
- authenticate you, secure the Service, and prevent fraud and abuse;
- generate the analytics and performance metrics that are part of the Service; and
- comply with law and enforce our terms.
Where GDPR/UK GDPR applies, our legal bases are performance of our terms with you, our (and your Company's) legitimate interests in operating and measuring the program, your consent for operational messaging, and legal obligations.
Your information is shared with your Company
This is central to how the Service works: your Company can see your activity and content. That includes the thank-yous you send, your customer conversations, your response times, your send rates, your leaderboard position, and whether you've been active. We provide this to your Company as part of the Service. Your Company is a separate controller of that information and uses it under its own policies.
Messaging choices (Sellers)
Seller SMS notifications are optional and off unless you turn them on. You choose whether to receive them by opting in through a separate checkbox during onboarding — it is never required to create an account or use the Service. If you opt in, you can reply STOP to a Company's messaging number to stop Seller notifications from that Company (and START to resume, HELP for help). Opting out stops the texts; pending thank-yous then wait in your dashboard queue instead. The Text Message Program page describes the program in full.
No sharing of mobile opt-in data. The mobile information and SMS opt-in consent we collect (your phone number and the fact that you agreed to receive texts) are not shared with third parties or affiliates for their own marketing or promotional purposes, and we do not sell them. Phone numbers are disclosed only to the service providers that help us deliver the messages (see §5), solely to operate the messaging program.
4. Customer data (the Company is the controller; we are the processor)
When a Company uses the Service, it and its Sellers and integrations submit and generate personal data about the Company's end customers, and we process it on the Company's behalf and on its instructions to provide the Service. This includes:
- Customer records — name, mobile phone number, email, external IDs (e.g., Shopify customer ID), and any consent metadata provided (consent source, timestamp, reference).
- Order & shipment data — order/shipment identifiers, value, status, carrier, tracking number, seller attribution identifiers.
- Messaging content — the thank-you videos/images and generated previews, message bodies, and the full two-way SMS conversation transcripts between Sellers and Customers.
- Engagement events — link taps, video watch/play events (timestamps, seconds watched, device), delivery status, and the analytics derived from them.
Our commitments as processor. We process Customer data only to provide and support the Service, to secure it, and as otherwise instructed by the Company or required by law; we do not sell it; and we make it available for the Company's export and deletion as described in §8. Where required, our processing of Customer personal data is also governed by a Data Processing Addendum, which controls over this Policy to the extent of any conflict for that data.
The Company's responsibility. The Company is the controller of Customer data. It is responsible for the lawfulness of collecting it, for obtaining and maintaining required messaging consent (the "Model A" attestation), for honoring opt-outs, and for providing any privacy notices to its customers. The Service supports and honors STOP/START/HELP and per-recipient opt-out and blocking, but compliance is the Company's.
5. How we share and disclose data
We share data with sub-processors and service providers that help us run the Service, under contracts that limit their use of the data:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication & identity | Company-rep and Seller identity (name, email, phone, auth IDs) |
| Stripe | Billing & payments | Company billing identifiers and payment details (held by Stripe) |
| Twilio + carriers | SMS/MMS delivery, 10DLC registration | Seller and customer phone numbers, message content, registration data |
| Amazon Web Services | Hosting, database, and video/asset storage (S3) | All Company, Seller, and Customer data at rest/in transit |
We may also disclose data: to comply with law or valid legal process; to enforce our agreements; to protect rights, safety, and security; and in a merger, acquisition, or asset sale (with continued protection of personal data). We do not sell personal data, and we do not use it for third-party advertising. We may create and use aggregated or de-identified data that does not identify any Company, Seller, or Customer to operate and improve the Service.
6. AI and machine learning
We may use data and content processed in the Service — including Company Data, Seller content (the videos, images, and messages you create), and message content and transcripts — to develop, train, evaluate, and improve features of the Service, including machine-learning and generative-AI features (for example, message/reply suggestions, summaries, quality and safety classification, and analytics). Where feasible we aggregate or de-identify data before using it for these purposes.
- Your control. A Company (for its own and its Customers' data) or a Seller (for their data) may opt out of having that data used to train or improve our models by contacting privacy@shipthanks.com. An opt-out applies going forward; it does not reverse training already performed or remove data already incorporated into a trained model.
- Customer personal data. Where the Company is the controller of Customer personal data, the Company is responsible for ensuring its own notices and consents cover this use; we de-identify where feasible and honor the Company's opt-out and individual deletion requests.
- No sale; provider limits. We do not sell personal data, and our AI/ML service providers and sub-processors are contractually prohibited from using your data to train their own general-purpose models.
7. International transfers
We and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers of personal data. Note: A2P 10DLC messaging is a US/North-American framework; consider this before sending to recipients outside supported regions.
8. Data retention and deletion
- Customer deletion requests (e.g., CCPA/CPRA, GDPR). On the Company's instruction, we will delete or anonymize a customer's personal data. Anonymization nulls identifying fields (phone, email, name, external ID, metadata) and redacts that person's message content, while keeping non-identifying rows and timestamps so counts, funnels, and retention cohorts stay consistent. Today this is a documented operational process performed on request rather than self-serve.
- Seller data. We use soft deletion for user and conversation records so the Company's history and analytics remain consistent; some Seller data may be anonymized rather than fully deleted so that program statistics stay intact. Content a Seller sent and conversation history are part of the Company's records and retained subject to the Company's data. Sellers can request deletion or anonymization at privacy@shipthanks.com; because the Company is also a controller, we may need to coordinate with it.
- Org offboarding. On request within 30 days of contract end, we make the Company's data available for export; we then hard-delete the org's data within 30 days, excluding de-identified/aggregated data and copies in routine backups or required by law.
- General retention & secrets. We retain personal data for as long as needed to provide the Service, meet legal/compliance obligations (including messaging-consent and audit records), resolve disputes, and enforce agreements. Session secrets are short-lived; API token secrets are never stored (only a hash).
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, tenant isolation (every record is scoped to an organization and queries are org-scoped at the application layer), hashed/secret-minimized credential storage, access controls, and audit logging. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or object to the processing of your personal data (e.g., under GDPR/UK GDPR or CCPA/CPRA). We will not discriminate against you for exercising them.
- Company representatives — contact us at privacy@shipthanks.com for your account data.
- Sellers — to exercise rights against ShipThanks, contact privacy@shipthanks.com; for your Company's own use of your information, contact your Company.
- End customers — rights over Customer data are directed to the controller (the Company); we assist the Company in responding as its processor.
- Messaging choices — STOP/START/HELP and per-recipient opt-out are supported on the messaging itself.
- Account choices — Org Admins can manage members and credentials in the dashboard; Sellers can manage their profile and notification settings there.
11. Changes to this Policy
We may update this Policy. For material changes we'll provide reasonable notice (e.g., email to Org Admins, in-product, or by SMS/email to Sellers). The "Effective date" above reflects the latest version.
12. Contact
Privacy questions or requests: privacy@shipthanks.com. Other support: support@shipthanks.com.