← Back to ShipStacked

Legal

Privacy Policy

ShipStacked · Last updated: 5 April 2026


1. Who We Are

ShipStacked is operated by ShipStacked, Ronda de Sant Pere 52, 08010 Barcelona, Spain.

For any privacy-related questions or requests, contact us at privacy@shipstacked.com.


2. What Data We Collect

2.1 Data you give us directly

When you create an account:

  • Email address
  • Password (stored as a secure hash — we never see your plain-text password)
  • Account type (builder or employer)

When you build your profile (builders):

  • Full name, role, bio, location, profile photo
  • Skills, projects, day rate, availability, timezone, languages
  • Links to GitHub, X, LinkedIn, personal website

When you build your profile (employers):

  • Company name, about, logo, location, website, industry, team size

When you use the platform:

  • Build Feed posts and their content
  • Messages sent and received on the platform
  • Job listings you create
  • Builds you apply to

When you connect GitHub:

  • GitHub username and public repository count
  • Commit activity (90-day window, includes private repo commit counts via OAuth — no code is accessed)

When you pay (employers):

Payment is processed entirely by Stripe. We receive confirmation of payment and your subscription status. We do not store card numbers or payment details.

When you use the Builder API:

  • API keys you generate (stored as a one-way hash — the raw key is never stored)
  • Requests made via your API key (logged for rate limiting and last-used tracking)

2.2 Data we collect automatically

  • IP address and approximate location
  • Browser type and operating system
  • Pages visited and time spent on the platform
  • Referring URL

We use this data to operate and improve the platform. We do not sell it.


3. How We Use Your Data

PurposeLegal basis
Providing the platform — creating your account, showing your profile, enabling messagingPerformance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Sending transactional emails (welcome, verification, message notifications)Performance of a contract
Auto-verification of builder profilesPerformance of a contract
Calculating Velocity ScoresPerformance of a contract
Displaying your public profile to employers and visitorsLegitimate interests
Improving the platform through usage analyticsLegitimate interests
Complying with legal obligationsLegal obligation

We do not use your data for advertising. We do not sell your data to third parties. ShipStacked is ad-free.


4. Who We Share Your Data With

We share data only with the service providers necessary to operate the platform:

ProviderPurposeLocation
SupabaseDatabase and file storageEU (AWS eu-west-1)
VercelHosting and edge functionsGlobal CDN
StripePayment processingUSA (EU Standard Contractual Clauses apply)
ResendTransactional email deliveryUSA (EU Standard Contractual Clauses apply)
GitHubOAuth authentication and commit dataUSA (EU Standard Contractual Clauses apply)

We do not share your personal data with any other third parties unless required by law.

Public profile data: Builder profiles marked as published are publicly accessible and may be indexed by search engines. This includes your name, role, bio, location, skills, projects, and Build Feed posts. You control this — set your profile to unpublished at any time from your dashboard.

Employer access: Paid employers can view your published profile and message you directly. They cannot export or bulk-download your data.


5. Data Retention

Data typeRetention period
Active account dataRetained for as long as your account is active
Deleted account data30 days after deletion, then permanently deleted
Payment records7 years (required by EU tax law)
MessagesDeleted with your account (30-day retention applies)
API key hashesDeleted immediately on revocation

When you delete your account, your public profile is removed immediately. All other data is permanently deleted after 30 days. Payment records are retained for 7 years as required by law — this data is held by Stripe.


6. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights:

Right of access: You can request a copy of all personal data we hold about you.

Right to rectification: You can correct inaccurate data from your dashboard at any time, or by contacting us.

Right to erasure: You can delete your account at any time. We will permanently delete your data within 30 days, except where required by law.

Right to restriction: You can ask us to restrict processing of your data while a dispute is resolved.

Right to data portability: You can request your data in a machine-readable format.

Right to object: You can object to processing based on legitimate interests.

Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, email privacy@shipstacked.com. We will respond within 30 days. You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) at aepd.es.


7. Cookies

ShipStacked uses strictly necessary cookies only:

  • Session cookie: Keeps you logged in during your session
  • Authentication cookie: Supabase Auth session token

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not use Google Analytics. Because we only use strictly necessary cookies, we do not require a cookie consent banner under GDPR.


8. Data Security

We take reasonable technical and organisational measures to protect your data:

  • All data in transit is encrypted via HTTPS
  • Passwords are hashed using bcrypt (handled by Supabase Auth)
  • API keys are stored as one-way SHA-256 hashes — the raw key is never stored
  • Database access is restricted to server-side code using service role keys
  • Profile photos are stored in Supabase Storage with public read access (intentional — they are profile photos)

No system is completely secure. If you become aware of a security issue, please contact privacy@shipstacked.com.


9. International Transfers

ShipStacked is based in Spain (EU). Some of our service providers process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses. See Section 4 for details of our providers.


10. Children

ShipStacked is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact privacy@shipstacked.com and we will delete the account.


11. Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes by email. The date at the top of this document reflects when it was last updated.


12. Contact

ShipStacked
Ronda de Sant Pere 52, 08010 Barcelona, Spain
privacy@shipstacked.com

For complaints, you may also contact the Spanish Data Protection Authority:
Agencia Española de Protección de Datos (AEPD)
aepd.es

See also: Terms of Service