Skip to content

Privacy Policy

How Shipbell handles personal data: as the controller for developer accounts, our website and billing, and as a processor for the feedback that people send through the apps and boards of our customers.

Last updated

In short

  • Shipbell handles personal data in two roles.
  • For the developers who use Shipbell, and for our website and billing, we decide how data is used. We are the controller.
  • For the people who use our customers' apps and boards, the app's developer decides. We process that data for them. For requests about it, go to the app's developer first.
  • We collect as little as we can. Diagnostics are scrubbed and never public, IP addresses are not stored in readable form, and there are no profile pictures or public profiles.
  • We use no analytics or advertising cookies, and we do not sell personal data.
  • You have rights over your data. Write to info@shipbell.app.

Who we are

Shipbell (shipbell.app) is provided by [legal-entity-name], registered at [registered-address], registration number [registration-number]. In this policy, "Shipbell", "we" and "us" mean [legal-entity-name].

For anything about privacy, write to info@shipbell.app.

Our two roles

  • As a controller: for developers and their team members who use Shipbell, for visitors to our website, for billing, and for messages sent to us. The sections from "Data about developers and visitors" to "How long we keep it" cover this.
  • As a processor: our customers use Shipbell to collect feedback from the people who use their apps ("end users"). For that data, the customer is the controller, and we process it only on the customer's instructions, under our Data Processing Agreement. The section "If you use an app or board that runs on Shipbell" explains this data.
  • We are also a controller of some end-user data for a few purposes of our own: keeping the service secure and free of abuse, and meeting our own legal duties, such as dealing with notices about illegal content.

Data about developers and visitors

  • Account data: your email address, your name if you give it, and your password, which we store only as a hash. If you add a passkey, we store only what is needed to check it, such as its public key, and the name you give it. Backup codes are stored only as hashes.
  • Sign-in with Google: if you choose to sign in with your Google account, we receive your name, email address and account identifier from Google. To offer this option, the sign-in and sign-up pages, the dialog that asks you to confirm it is you when it offers Google, and the dialog that connects Google load Google's sign-in button from Google, so Google receives technical data such as your IP address and browser details when they open, even if you then sign in or confirm another way.
  • Workspace data: your workspace and project names and addresses, branding, settings, team members and their roles, and your public developer page if you publish one.
  • Security data: records of your sessions (when they started and were last used, your browser type and a hashed IP address), and an audit log of important actions in your workspace, such as sign-ins, changes to keys, exports and erasures.
  • Billing data: your plan, invoices and payment records, and the billing details you give us, such as your billing name, address and tax ID. Your payment details are handled by our payment processor.
  • Messages: what you write to us, for example at info@shipbell.app or support@shipbell.app, and our replies.
  • Technical data: when you visit shipbell.app, the admin or a board, our servers and our network provider process technical data, such as your IP address, your browser type and the pages you request, to deliver the pages and to protect the service. Some forms, such as sign-up and sign-in, use a check run by our network provider that tells people from bots. It processes technical data such as your IP address and browser details. The provider also uses these signals to improve its bot detection, under its own privacy notice. We use no analytics tools.

You need to give us an email address to create an account; without it we cannot provide the service. The rest of this data comes from your use of Shipbell and, if you choose Google sign-in, from Google.

  • To create and run your account and workspace, sign you in and provide the service: this is needed for our contract with you (Article 6(1)(b) GDPR).
  • To bill you, keep invoices and meet tax and accounting duties: our contract with you, and our legal obligations (Article 6(1)(b) and (c)).
  • To send you service emails, such as sign-in codes, security notices, invitations, billing messages and notices of important changes: our contract with you, and our legitimate interest in keeping you informed (Article 6(1)(f)).
  • To keep the service secure, prevent abuse and fraud, and keep an audit log: our legitimate interest, and yours, in a safe service.
  • To find and fix errors in our service: our legitimate interest in a service that works.
  • To answer your messages: our legitimate interest in helping you, or steps you ask for before a contract.
  • To enforce our terms, deal with notices about illegal content and defend legal claims: our legal obligations and our legitimate interests.
  • To send you news about Shipbell, if we do: our legitimate interest, or your consent where the law requires it. You can unsubscribe in every such email.

Where we rely on legitimate interests, we have weighed them against your rights and interests. You can object at any time (see "Your rights").

One automatic rule can affect your workspace: if email from your projects causes too many bounces or spam complaints, email sending can be paused automatically. Write to info@shipbell.app and a person will review it.

Who receives this data

  • Our service providers, who process data for us under contract: cloud hosting and network providers, storage and backup storage, email delivery, error monitoring, payment processing, and our business email provider.
  • The other members of your workspace, who see your account details, your role and the actions you take.
  • The public: what you choose to publish, such as your developer page, your boards, your team's public replies and your changelog entries.
  • Professional advisers, such as lawyers and accountants, where needed.
  • Authorities, courts and others, when the law requires it or to protect rights and safety.

We do not sell personal data, and we do not use it for advertising.

You can ask us for the names of our current service providers at info@shipbell.app.

International transfers

Shipbell's servers are in the European Union. Some of our providers may process data outside the European Economic Area (EEA). When they do, we use appropriate safeguards: [transfer-mechanism]. You can ask us for a copy of them at info@shipbell.app.

How long we keep it

  • Account and workspace data: while your account exists. After you delete it, we delete this data within [account-deletion-period].
  • Sessions: until they expire, plus 7 days.
  • Hashed IP addresses: 30 days.
  • Audit log: 1 year.
  • Billing records: as long as tax and accounting law requires.
  • Messages you send us: as long as we need them to deal with your message and keep a record of it.
  • Records of the emails we send: 90 days. The address and the content are cleared as soon as delivery has finished.
  • Our email delivery service keeps a record of each message for 30 days. The address and content in it are stored encrypted and wiped once no more delivery attempts can happen. The provider that finally delivers the email keeps its own delivery logs.
  • Backups: deleted after 30 days, plus the period during which they are locked against deletion ([backup-lock-period]).

We may keep data for longer when the law requires it, or to establish or defend legal claims.

If you use an app or board that runs on Shipbell

Many apps use Shipbell so that you can report problems, suggest ideas and follow their progress. When you do this, the app's developer is the controller of your data, and we process it for them. The developer decides, within what Shipbell allows, what is collected, which parts can be public and how long data is kept. The developer's legal basis for this is explained in its own privacy notice.

For questions and requests about this data, such as seeing, correcting or deleting it, please contact the app's developer. Its privacy notice is linked as "Privacy" at the bottom of every board page. If you write to us instead, we pass your request to the developer or tell you how to reach them.

The next sections describe what Shipbell itself does with this data, so you know what to expect.

How you sign in, and what the app shares

  • You do not create a Shipbell account. The app you use vouches for you: its server sends us a signed confirmation that you are signed in to the app. Some boards also let you sign in with a one-time code sent to your email address, and some apps let you send a report with just your email address.
  • From the app we receive an identifier for you, and we may receive your email address and whether it is verified, your first and last name, your language, and a few extra details that the developer chooses, such as the plan you use in the app. These extra details are limited in size.
  • We never receive your password for the app. We store no profile pictures, and there are no public profiles.
  • Signing in to a board sets a session cookie. See our Cookie Policy.

Your public name

  • Ideas, comments and public reports show a public name, never your email address.
  • By default, your public name is the app's name followed by "user". Before your first public post, you can switch to your first name and the initial of your last name, if the app shared your name, or choose another name.

Problem reports: public or private

  • When you send a report, you choose who can see it: Public (other people can see it and add "me too") or Private (only you and the app's team). The developer decides which choice is selected at first, and can make all reports private.
  • A public report shows its text, the platform it came from and your public name. Its screenshot is shown only if you allow it for that report. Diagnostics are never public.
  • You can make a report private, or public again, at any time in "Your reports" on the board. The team can also make a report private, hide its screenshot or replace its public text, for example to remove personal details, and can lock it as private. The team can never make your report public; only you can.
  • When a report becomes private, its page disappears from the board, and its public comments and "me too" votes are hidden.
  • Please do not put personal details in a public report.

Diagnostics

Reports sent from inside an app include technical details that help the team fix the problem. Before you send, you can see exactly what is included, under "Included with your report (only the team sees this)". Only the app's team can see diagnostics, whatever the report's visibility. Reports sent from a board page carry no automatic diagnostics.

From a website, diagnostics can include:

  • the widget version, and the release and environment names the site gives;
  • the site's address and the path of the page, without query strings or fragments;
  • your browser's user agent and brand, your languages and your time zone;
  • the size of the window and the screen, the pixel ratio, your colour scheme and reduced-motion settings, whether the site runs as an installed app, and whether you are online;
  • up to 20 recent errors on the page, each with a message of at most 300 characters and the address of the file where it happened, without its query string. The developer can choose to send no error messages;
  • references to errors in the app's own error-tracking service, if the app provides them.

From an iOS app, diagnostics can include:

  • the app's version, build and bundle identifier, and the version of the Shipbell package;
  • the system name and version, the device model and type, and whether the app runs on a Mac;
  • your locale, preferred language and time zone;
  • your text size, VoiceOver, Reduce Motion and colour scheme settings;
  • Low Power Mode, the device's thermal state, and whether the network is available, expensive or constrained;
  • recent errors the app records, and references to errors in the app's own error-tracking service.

The app can also add details of its own ("context"). You see them before you send, and the team sees them marked as reported by the app and not checked. If the app gives references to errors in its own error-tracking service, we look up only the matching issue and keep only a reference to it.

What is never sent:

  • the address of the page you came from (the referrer), and the query strings and fragments of page addresses;
  • anything the app writes to its console;
  • on iOS, the advertising identifier and the identifier for vendor.

Email addresses, sign-in tokens and long secret-looking strings are masked in the app before sending, and again on our servers. Fields that Shipbell does not know are removed.

Diagnostics are deleted 180 days after the report is closed, unless the developer sets another period.

Screenshots

  • You decide whether to attach a screenshot. You always see it first and can remove it.
  • In iOS apps, the app can capture the screen for you. Parts of the screen that the app marks as private are painted over before you see the preview.
  • We accept only common image formats. Our servers re-encode every image and limit its size. Re-encoding removes the image's metadata, such as EXIF data and location.
  • Screenshots are private to you and the app's team. A screenshot is shown on the board only if its report is public and you allow it for that report. If you withdraw that permission, it stops being shown on the next page load; a link that was already opened keeps working for at most 60 seconds.
  • Screenshots can show personal details. Check yours before you share it publicly.
  • Screenshots are deleted 90 days after the report is closed, unless the developer sets another period.

Ideas, votes, comments and follows

  • The developer decides who can see a board: everyone, everyone with the link, or only signed-in users of the app. Ideas, comments and public reports are visible to them, under your public name.
  • Vote counts are public, but there is no public list of who voted. The app's team can see who voted.
  • Voting, saying "me too" and commenting also make you follow the item, so that you hear about its progress. You can stop following at any time.
  • Automatic rules hold some posts for review, for example posts with several links. A held post stays hidden until a person on the app's team reviews it.

Emails you receive

  • Emails about an app are sent in that app's name. Replies go to the app's support address, and each email says where to reply.
  • "Your reports": replies from the team and updates on the reports you sent.
  • "Items you follow": updates on ideas you posted, and on items you voted on, said "me too" to, commented on or follow.
  • "What's new": the app's changelog, only after you ask for it and confirm your address.
  • New apps from the developer: the developer may email the people who use its apps when it launches a new one. You are told about this the first time you sign in, with a one-tap "Don't send me these", and every such email lets you unsubscribe.
  • You can turn off one list, or all email from that app, with the link in any email or on the board's email settings page. For new-app emails, this covers all email from that developer.
  • Sign-in codes and confirmations you ask for, and notices about your content that the law requires, are still sent, because they are not subscriptions.
  • If an email to your address bounces, or you mark one as spam, our email delivery providers may stop delivering to that address. This is a delivery block, not a setting you chose; the app's support can help.

Exporting and deleting your data

  • Ask the app's developer. The developer can export or erase your data with Shipbell's tools.
  • An export is a file with your profile, your posts with their visibility history, your comments, votes and "me too", and your attachments. Export files are kept for 7 days.
  • Erasure deletes your reports, public and private, with their threads, diagnostics and screenshots, as well as your comments, votes, follows, email settings, sessions and profile. Ideas you posted stay, because other people voted on and discussed them, but they are shown as posted by "Former user", and the team can edit their text to remove personal details.
  • Erased content disappears from the board on the next page load. Backups expire as described below, and if a backup is ever restored, the erasures made after it are applied again.

How long end-user data is kept

These are Shipbell's default periods. A developer can set different periods for its project.

  • Screenshots: 90 days after the report is closed.
  • Diagnostics: 180 days after the report is closed.
  • Report text and its thread: 24 months after the report is closed, unless erased earlier. This also applies to public reports: their page, public comments and "me too" votes go with them.
  • Ideas and the public comments on them: until they are erased or the project is deleted, because other people's votes and replies depend on them.
  • Sessions, sign-in links from apps and sign-in codes: until they expire, plus 7 days.
  • Records that stop the same request, such as a report, from being processed twice: 24 hours.
  • Hashed IP addresses: 30 days.
  • Records of the emails sent: 90 days. The address and the content are cleared as soon as delivery has finished.
  • Email addresses given with notices about content: 1 year.
  • Export files: 7 days.
  • Backups: deleted after 30 days, plus the period during which they are locked against deletion ([backup-lock-period]).

IP addresses

We do not store IP addresses in readable form. To limit abuse and protect accounts, we keep only a keyed hash of an IP address, made with a key that changes every month, and we delete it after 30 days. Our network provider and our servers process IP addresses to deliver pages and to block attacks.

Notices about illegal content

Anyone can report content on a board with the Report content form, without signing in. We ask for the address of the page, a reason and an explanation, and optionally your email address, so that we can contact you about it. The notice goes to the board's team, and we may review it too. We handle notices to meet our legal obligations as a hosting service. We keep the email address you give for 1 year.

Some forms, such as this one, may use a check that tells people from bots, run by our network provider.

Security

  • All connections to Shipbell use HTTPS.
  • Each customer's data is kept separate, with checks in the database itself as well as in our code.
  • Passwords, session tokens and secret API keys are stored only as hashes.
  • Apps prove who their users are with keys that only the app holds; we store only the public keys.
  • Team accounts are protected by strong sign-in, and sensitive actions, such as exports and erasures, ask you to sign in again.
  • Diagnostics are scrubbed, IP addresses are hashed, and images are re-encoded and shown only through short-lived links after an access check.
  • Important actions are recorded in an audit log that cannot be changed.
  • Our servers are not directly reachable from the internet.
  • Backups are kept in separate storage that is protected against deletion, and we test restoring them.

No system is perfectly secure. If a personal data breach affects you, we tell you and the authorities where the law requires it.

Your rights

Under data protection law, you have the right to:

  • get a copy of your personal data and information about how we use it;
  • have incorrect data corrected;
  • have your data deleted;
  • have its use restricted;
  • receive your data in a machine-readable format and have it sent to someone else;
  • object to our use of your data based on legitimate interests, and to direct marketing at any time;
  • withdraw your consent at any time, where we rely on it. This does not affect what we did before.

To use these rights for data we control, write to info@shipbell.app. We may ask you to confirm who you are. We answer within one month. If a request is complex, we may take up to two more months, and we tell you why.

For data that an app's developer controls, contact the developer, as described above.

Complaints

If you think we handle your data unlawfully, you can complain to a data protection supervisory authority, in particular where you live or work or where the problem happened. Our lead supervisory authority is [supervisory-authority]. We would like to try to solve the problem with you first: info@shipbell.app.

Cookies

We use only cookies that are strictly necessary, and one cookie that remembers the appearance you choose on a board. We use no analytics or advertising cookies. Our Cookie Policy lists them.

Children

Shipbell is a service for businesses and is not directed at children. Developer accounts are for adults who act for a business. The apps that use Shipbell decide who may use them. If you think a child has given us personal data without the permission the law requires, write to info@shipbell.app.

Changes to this policy

We may update this policy. The date at the top shows the current version. We tell workspace owners by email about significant changes. Our Terms of Service explain how changes to the terms work.

Contact

[legal-entity-name], [registered-address]. Email: info@shipbell.app.