1. Introduction
Shipra (“Shipra”, “we”, “us” or “our”) is a cloud-based logistics, order management, warehouse management, inventory management, shipping and e-commerce integration platform operated by{" "} Al Qayid Al Abqari Information Technology LLC, United Arab Emirates.
This Privacy Policy explains how we collect, use, process, store, disclose, transfer and protect personal information when individuals and businesses use Shipra’s websites, applications, APIs, integrations, software and related services (collectively, the “Services”).
2. Our role in processing personal data
Shipra as Controller
We generally act as a controller for information relating to Shipra account holders, prospective customers, website visitors, billing contacts, administrators, partners and people communicating directly with Shipra.
Shipra as Processor
When a merchant, retailer, seller, fulfillment provider, logistics company or other Shipra customer uses the Services to process information about its customers, recipients, buyers, suppliers, employees or other individuals, the customer generally acts as controller and Shipra acts as processor or service provider on that customer’s behalf.
3. Information we collect
Account information
- Name, company, business address, email and telephone number
- Usernames, account identifiers, roles and permissions
- Authentication information, login activity and account preferences
Order and customer information
- Recipient name, address, city, state/province, country and postal code
- Telephone number, email address and delivery instructions
- Order number/date, items, quantities, order value and payment status
- COD amount, shipping charges, tracking, returns and fulfillment status
Technical and usage information
- IP address, browser, operating system and device information
- Session data, API activity, audit logs, errors and security events
- Pages or features accessed and authentication events
4. Marketplace and e-commerce data
Shipra may connect with e-commerce platforms, marketplaces, ERP systems, warehouse systems, payment services and other applications authorized by customers. Depending on the integration and permissions granted, we may receive orders, products, SKUs, inventory, prices, marketplace identifiers, store data, fulfillment data, customer information, returns, shipment information, tracking information and authorization identifiers.
We access only information reasonably necessary to provide the requested integration and Services.
5. Amazon Selling Partner API data
Where a customer authorizes an Amazon integration, Shipra may receive information through the Amazon Selling Partner API (SP-API), including Amazon order data, seller and marketplace identifiers, product/listing information, inventory, fulfillment, shipment, tracking and, where authorized, recipient information.
Certain Amazon information may constitute personally identifiable information or otherwise restricted information. Shipra processes Amazon information only for authorized purposes and in accordance with applicable Amazon agreements, security requirements and data-protection requirements.
6. Shipping, carrier and warehouse data
When a shipment is created or managed through Shipra, necessary information may be transmitted to the shipping carrier, freight provider, fulfillment company, postal operator or delivery partner selected or authorized by the customer.
This may include recipient contact details, addresses, shipment dimensions and weight, product descriptions, declared values, COD amounts, customs information and other information required for delivery or clearance.
Warehouse functionality may process warehouse locations, inventory quantities, SKUs, barcodes, serial numbers, lots/batches, expiry dates, stock movements, picking/packing records and inventory transaction history.
7. How we use personal information
We may use personal information to create and manage accounts, authenticate users, import and process orders, manage inventory and warehouses, create shipments and labels, communicate with carriers, provide tracking, process returns, synchronize marketplace information, provide support, maintain audit trails, prevent fraud, investigate security incidents, administer subscriptions and comply with legal obligations.
We do not use personal information for purposes materially incompatible with the purposes for which it was collected unless permitted by law.
8. Legal bases for processing
Where applicable law requires a legal basis, Shipra may rely on contractual necessity, legitimate interests, consent, compliance with legal obligations or another lawful basis permitted by applicable law.
Legitimate interests may include platform security, fraud prevention, service improvement, technical support, operational administration and protecting legal rights. We consider affected individuals’ rights and interests when relying on legitimate interests.
10. Data security
Shipra maintains administrative, organizational, physical and technical safeguards designed to protect information against unauthorized access, loss, misuse, disclosure, alteration or destruction.
No electronic system can guarantee absolute security, but Shipra seeks to maintain safeguards appropriate to the nature and sensitivity of the information processed.
11. Data retention
We retain personal information only for as long as reasonably necessary to provide the Services, fulfill customer instructions, maintain required records, resolve disputes, maintain security and audit records, satisfy contractual obligations and comply with law.
Information obtained through third-party platforms or APIs may be subject to additional retention limitations imposed by those platforms. When information is no longer required, it may be securely deleted, anonymized, aggregated or otherwise rendered inaccessible.
12. International data transfers
Because Shipra is a cloud platform that integrates with international services, personal information may be processed in countries other than where it was collected. Where required, Shipra uses legally appropriate transfer mechanisms and safeguards, which may include contractual safeguards, Standard Contractual Clauses, adequacy decisions or other permitted mechanisms.
13. Data subject rights
Depending on applicable law and jurisdiction, individuals may have rights to access, correct, delete, restrict or object to processing; withdraw consent; request portability; opt out of certain sales or sharing; limit certain uses of sensitive information; and lodge a complaint with a competent authority.
If your information was provided to Shipra by a merchant, seller, retailer, logistics provider or other customer, that organization is generally responsible for responding to your privacy request. Shipra will reasonably assist its customers where required.
14. California privacy rights
Where the CCPA/CPRA applies, California residents may have rights to know categories and specific pieces of personal information collected, request deletion or correction, opt out of covered sale or sharing, limit certain uses of sensitive personal information and exercise rights without unlawful discrimination.
Where Shipra acts solely as a service provider or contractor for a customer, requests concerning information controlled by that customer should generally be submitted to that customer.
15. European Economic Area and United Kingdom
Where GDPR or UK GDPR applies, individuals may have rights including access, rectification, erasure, restriction, objection, portability, withdrawal of consent and lodging a complaint with the relevant supervisory authority. Where required, Shipra will provide information regarding legal bases and applicable international-transfer mechanisms.
17. Children’s privacy
Shipra is a business-to-business platform and is not designed or directed toward children. We do not knowingly solicit personal information directly from children for the purpose of creating Shipra accounts. If we become aware of unlawful collection, we will take appropriate steps to delete or otherwise lawfully process the information.
18. Data breach and incident response
Shipra maintains procedures for identifying, investigating, containing and responding to suspected security incidents. Measures may include isolating affected systems, disabling unauthorized access, rotating credentials, reviewing security logs, determining scope, applying patches or configuration changes, restoring validated backups and implementing corrective actions.
Where an incident constitutes a legally reportable personal-data breach, Shipra will provide notifications to affected customers, individuals, authorities or other parties as required by applicable law or contract.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, integrations, applicable laws, regulatory requirements, security practices or operations. The revised version will be published with an updated “Last Updated” date and, where required, additional notice of material changes.
20. Contact and privacy requests
Requests relating to privacy rights should include sufficient information for us to understand and process the request. We may need to verify identity or authority before fulfilling certain requests. We will respond within the timeframe required by applicable law.
Privacy & Data Protection
Shipra
Operated by Al Qayid Al Abqari Information Technology LLC
United Arab Emirates
Email: admin@shipra.io
Website: shipra.io