ShipMsg
Legal centerSecurityContact legal

Legal

Privacy Policy

This notice explains how ShipMsg handles personal data when businesses and their authorized users use our websites, applications, APIs, and support services.

Effective September 3, 2026

Our role

ShipMsg is the controller for account, commercial, security, and website data used to operate the service. For message content, contacts, consent records, and other data a customer submits through the service, the customer is the controller and ShipMsg acts as its processor. Meta and other communications providers process data under their own terms. This notice does not replace a customer business's duty to give its recipients its own privacy notice.

Data we process

  • Account data, including names, business contact details, roles, and authentication events.
  • Customer content, including contact identifiers, consent evidence, messages, media, templates, and Flows data.
  • Provider data, including WhatsApp Business Account and phone-number identifiers, capabilities, delivery events, and quality signals.
  • Usage, billing, support, audit, device, network, and security telemetry needed to provide and protect the service.

We receive data from customers and their users, recipients who communicate with a customer, connected providers and integrations, payment and identity providers, support communications, and ordinary browser, device and network interactions. We do not require government identifiers, health records, biometric templates or payment-card numbers in message content, and customers must not submit regulated data without an expressly authorized use case.

Why we use data

We use data to provide contracted services, authenticate users, route and reconcile communications, prevent fraud and abuse, secure the platform, calculate charges, provide support, comply with law, and improve reliability. We do not sell personal data or use customer message content for advertising.

Where a legal basis is required, we rely on performance of a contract and pre-contract steps, legitimate interests in operating and securing the service, compliance with legal obligations, protection of legal rights, and consent where the law requires it. A customer determines the legal basis for the customer-controlled contacts and communications it sends through ShipMsg.

Sharing and international transfers

We disclose data only to the customer, its authorized users, communications providers, payment and email providers, infrastructure subprocessors, professional advisers, and authorities when legally required. Our current subprocessors are published on the Subprocessors page. When data crosses borders, we use contractual and technical safeguards appropriate to the transfer.

We do not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not disclose mobile opt-in or consent information to third parties or affiliates for their own marketing. A corporate transaction may transfer information subject to applicable notice and continued protection.

Retention and deletion

Customer-configured retention controls apply where available. We keep account, billing, audit, security, and legal records only as long as needed for the stated purpose or a legal obligation. Deletion requests enter a tracked workflow, respect active legal holds, and produce completion evidence. See our Data Deletion instructions.

Default category periods, including the 35-day protected-backup window, are published in the Data Retention Schedule. Legal holds, disputes, fraud and security investigations, and mandatory accounting or audit records may require narrower information to be retained longer.

Your choices and rights

Depending on location, individuals may request access, correction, deletion, portability, restriction, or objection and may appeal a denied request. End recipients should normally contact the business that messaged them; we assist that business with verified requests. Authorized ShipMsg users can use the privacy controls in the service or contact us.

Depending on applicable law, rights may include confirmation, access, correction, deletion, portability, restriction, objection, withdrawal of consent, and opting out of sale, targeted advertising or qualifying profiling. ShipMsg does not currently sell or use personal data for targeted advertising. We authenticate requests, respond within the applicable period, and do not discriminate for exercising a right. If we deny a request, our response explains the reason and available appeal. Send an appeal with the original request reference and “ShipMsg privacy appeal” in the subject. Texas residents may also complain to the Texas Attorney General; California residents may contact the California Privacy Protection Agency.

Automated processing

ShipMsg applies automated security, abuse, consent, rate-limit, routing and provider-health controls to protect recipients and the service. These controls can delay, reject, quarantine or pause communications, but ShipMsg does not use account data to make decisions that produce legal or similarly significant effects about individuals. Customer businesses remain responsible for any decisions they make using their message data.

Security and children

We use access controls, encryption, isolation, signed audit evidence, monitoring, and tested recovery controls. ShipMsg is a business service and is not directed to children. Customers may not knowingly use it to collect personal data from children under 13 or the higher local minimum age without a signed agreement and all legally required parental or guardian authorization.

Changes to this notice

We may update this notice as ShipMsg or applicable law changes. We will update the effective date and provide additional notice through the service or account contact when a change materially reduces privacy protections or changes how personal data is used.

Contact

ShipMsg legal questions: legal@shipmsg.com. Privacy questions and rights requests: privacy@shipmsg.com. ShipMsg support questions: support@shipmsg.com. Do not email passwords, payment-card data, message content, or identity documents; ShipMsg will provide a secure verification channel when needed.

© 2026 ShipMsg.All legal documents