Privacy Policy
Last updated 2026-09-17
This policy explains what ShipKit collects, why, and what you can do about it.
Who is responsible
The data controller for the personal data described here is Hongwei Wang, an individual based in China, reachable at support@shipkit.sh.
We have not appointed an EU or UK representative. Data protection questions go to support@shipkit.sh.
What we collect
- Account data — when you sign in with Google or GitHub we receive your name, email address and profile picture (an emailed code gives us only the address). We store these plus your language preference.
- License data — your order history, license status, and the GitHub username and account id that receive repository access.
- Technical data — standard server logs (IP address, browser, timestamps) kept briefly for security and debugging.
- Product analytics — which pages you visit and which features you use (for example that you signed up or started a checkout). We use PostHog for this. Before you sign in the data is tied to a random identifier stored in your browser; after you sign in it is tied to your account. Analytics never includes the content of your files, and we do not record your screen.
We do not see or store your card details. Payments are processed by our payment provider, which shares only the order outcome with us.
Why we use it
To provide the Service, bill you correctly, deliver repository access, send transactional email (welcome, receipts), keep the Service secure, understand how the Service is used so we can improve it, and comply with law. We do not sell your data and do not use it for advertising.
Cookies
We use only cookies the Service needs to work: a session cookie to keep you signed in, and small preference cookies for language and theme. No advertising cookies. Analytics does not set a cookie; it keeps its identifier in your browser's local storage, which you can clear at any time.
Where it lives and who sees it
Data is stored on Cloudflare's infrastructure. It is shared only with the providers required to run the Service — Google and GitHub (sign-in), GitHub (the repository invitation, which shares your GitHub username with the repository owner), our payment provider (billing), our email provider (transactional email) and PostHog (product analytics, hosted in the United States) — each under their own privacy terms.
Retention and deletion
We keep your data while your account exists. Deleting your account from Settings permanently removes your profile and license records from our systems; order records may be retained where accounting law requires.
Your rights
Depending on where you live you may have rights to access, correct, export or erase your data, or to object to processing. You can do most of this yourself in Settings; for anything else, email us and we will respond within 30 days.
Changes and contact
We will announce material changes to this policy before they take effect. Questions: support@shipkit.sh.
ShipKit