What we do with your data
Short and verifiable. If something is missing here, ask and we will answer with specifics.
Shopper data is never stored
Names, addresses, phone numbers and shopper emails are dropped while the invoice is parsed, before anything reaches the database. Only 3PL identifiers survive: order number, SKU, warehouse, carrier, zone. Without those a finding cannot be proven. This is checked by an automated test on every build, not by a promise in this text.
Raw invoices are encrypted and live for 90 days
Source files and API responses sit in object storage encrypted with AES-GCM: a separate key per object, and that key is itself encrypted by a master key kept apart from the data. After 90 days the raw material is deleted. Findings stay; they hold no personal data.
Access tokens
A 3PL token is encrypted the same way. The interface shows only the last four characters: neither our admin view nor our logs hold the full token. For ShipBob a read-only token is enough, and you can revoke it after the audit. We recommend exactly that.
You can skip tokens entirely
CSV upload is a first-class path, not a fallback: the same rules, the same report. Half of our accounts work this way only.
There are no passwords
Sign-in is a one-time link that lives 15 minutes and works once. There is nothing to steal here: a password database does not exist.
What we do not do
- We do not write to your 3PL account; billing access is read-only.
- We do not email your 3PL on your behalf. The dispute text goes to you, and you send it.
- We do not pass your data to third parties and do not train models on it. There are no models in the audit core at all, only deterministic rules.
Deleting the account
Deletion removes every invoice, line, finding and raw file in one cascading operation. There is no please-wait-30-days.