Privacy Policy

Last updated: August 16, 2026

This Privacy Policy explains how ShipmentBeat ("we", "us", "our") collects, uses, and protects personal information when you use shipmentbeat.com, app.shipmentbeat.com, and related services (the "Service"). This notice is provided at collection for users in the EEA/UK and the United States.

1. Who we are

ShipmentBeat operates a B2B ocean shipment tracking and maritime data workspace. For privacy requests, contact [email protected]. We will add our legal entity name and registered postal address here once they are published on this page.

2. Information we collect

Account and workspace profile: email, first name, last name, password (stored hashed), company name, company website, industry, company size, job title, monthly shipment volume, how you heard about us, and optional trial goals.

Shipment data you submit: tracking numbers (bill of lading, booking, or container), carrier, number type, optional internal references and notes. These identify commercial shipments; they are processed to provide the Service.

Usage and technical data: pages and features you use, IP address, browser and device information, and timestamps needed for security, rate limiting, and debugging. On the public website we also collect aggregated analytics via Google Analytics 4 (page views, referrer, device/browser, and coarse location derived by Google).

Communications: messages you send via the contact form or email, and records of transactional emails we send you (verification codes, password reset, billing and service notices).

Payment data: we do not store full card numbers. Checkout is handled by a third-party Merchant of Record (Creem.io or Waffo, depending on the checkout session assigned); we receive payment status, amount, and billing identifiers needed to credit your workspace.

3. How we use your information

To create and operate your account and organization workspace, verify your email, authenticate you, and keep the Service secure (including bot protection).

To run tracking requests, show results, maintain credit balances, and send service notices such as verification codes, password resets, billing receipts, quota or credit reminders, and shipment-alert emails you enable.

To improve reliability and understand aggregate product usage (debugging, performance, abuse prevention), including first-party website analytics.

To respond to support inquiries.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

4. Legal bases (GDPR / UK GDPR)

Contract (Art. 6(1)(b)): creating an account, verifying email, providing tracking and workspace features, billing credits, and sending transactional messages required to deliver the Service you requested.

Legitimate interests (Art. 6(1)(f)): security, fraud and bot prevention, service improvement, and aggregate analytics, balanced against your rights.

Legal obligation (Art. 6(1)(c)): tax and accounting records for paid transactions.

Consent (Art. 6(1)(a)): optional marketing or product-update emails, and any non-essential cookies if we introduce them. Consent is not pre-ticked, is separate from accepting these Terms, and can be withdrawn at any time without losing the Service.

5. Sharing and processors

We share data only with processors needed to run the Service: Creem.io and Waffo (payments as Merchant of Record, one assigned per checkout), our identity provider (Zitadel), Cloudflare (CDN, security, and Turnstile bot checks), Google Analytics 4 (first-party website analytics on www.shipmentbeat.com; IP anonymization enabled; not used for ads), cloud hosting and storage, and email delivery providers used to send verification and service mail.

Each processor receives only what it needs and is bound by a data-processing arrangement. We may disclose information if required by law or to protect the rights, safety, or property of ShipmentBeat or others.

6. International transfers

Our infrastructure and processors may be located outside your country, including outside the EEA/UK. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK addendum where applicable).

7. Retention

Account and workspace profile data are kept while the account is active and deleted or anonymized within 90 days after account deletion, except where we must keep records longer for legal, billing, security, or dispute purposes.

Shipment identifiers and tracking history stay with the workspace until you delete the shipment or the account, subject to the same legal holds.

Billing records are retained as required by applicable tax and accounting laws.

Email verification codes and password-reset tokens are short-lived and expire automatically.

8. Your rights

Depending on your location (including the GDPR, UK GDPR, and CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, restrict or object to certain processing, and withdraw consent.

California residents also have the right to know the categories of personal information we collect and the purposes, and to opt out of “sale” or “sharing” as those terms are defined by CPRA. We do not sell or share personal information for cross-context advertising, so there is no separate opt-out link for that activity.

To exercise any of these rights, email [email protected]. We respond within 30 days, or sooner if a shorter period is required by law. EEA/UK users may also lodge a complaint with their local supervisory authority.

9. Cookies and similar technologies

We use strictly necessary cookies and similar storage for authentication, session management, CSRF/security, and Cloudflare Turnstile. These are required to operate the Service and are not used for advertising.

On www.shipmentbeat.com we also load Google Analytics 4 to measure public-site traffic. This may set first-party analytics cookies. We anonymize IP addresses, do not send advertising identifiers, and do not use the data for cross-site ads. Embedded tracking pages (/embed) do not load analytics.

If we later add marketing cookies or advertising pixels, we will present a separate choice and will not bundle that choice with account creation.

10. Security

We protect your data with industry-standard measures including encryption in transit, access controls, and least-privilege infrastructure. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

11. Children

The Service is a business tool and is not directed at children under 16. We do not knowingly collect personal information from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a new revision date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy for future processing.

13. Contact

For any privacy question or request, contact [email protected].