1. Introduction
Welcome to ShipTo, operated by Welcome Associated Services Limited (Company Number 07874666). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our transport and delivery marketplace platform at shipto.uk.
ShipTo operates as a marketplace connecting customers who need items transported with professional transporters. We are the data controller for the personal information we collect through our platform.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at [email protected].
2. Information We Collect
2.1 Information You Provide
We collect information that you voluntarily provide when using ShipTo:
- Account Information: Name, email address, password, phone number, and account type (customer or transporter)
- Profile Information: Business name, profile photo, bio, and insurance verification documents (for transporters)
- Job Information: Pickup and delivery locations, item descriptions, dimensions, weight, preferred dates, photos of items
- Communication: Messages exchanged through our platform between customers and transporters
- Payment Information: Payment processing is handled by PayPal. We store transaction references but not your full payment card details
- Reviews and Ratings: Feedback you provide about completed jobs
2.2 Information Collected Automatically
When you access ShipTo, we automatically collect:
- Usage Data: Pages visited, time spent, links clicked, and features used
- Device Information: IP address, browser type, operating system, device identifiers
- Location Data: Approximate location based on IP address and postcodes you enter for jobs
- Cookies and Tracking: Session cookies for authentication and functionality (see Cookie Policy below)
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 To Provide Our Services
- Create and manage your account
- Process job postings and bids
- Facilitate communication between customers and transporters
- Process payments and commission (15% platform fee)
- Display reviews and ratings
- Send transactional emails (account verification, password resets, job notifications)
3.2 To Improve and Secure Our Platform
- Monitor and analyze usage patterns
- Detect and prevent fraud, abuse, and security incidents
- Verify transporter insurance documentation
- Improve features and user experience
3.3 Legal Obligations
- Comply with legal requirements and regulations
- Respond to legal requests and prevent harm
- Enforce our Terms and Conditions
4. Legal Basis for Processing (UK GDPR)
Under UK GDPR, we process your personal data based on:
- Contract Performance: Processing necessary to provide our marketplace services
- Legitimate Interests: Improving our platform, preventing fraud, and ensuring security
- Legal Obligation: Compliance with UK laws and regulations
- Consent: Where you have given explicit consent (e.g., marketing communications)
5. How We Share Your Information
5.1 With Other Users
To facilitate transactions, we share relevant information between customers and transporters:
- Job details are visible to transporters when bidding
- Your name, approximate location, and communication are shared after a bid is accepted
- Full contact details (email, phone) are shared only after payment is made
- Reviews and ratings are publicly displayed
5.2 With Service Providers
We share data with trusted third-party service providers:
- Payment Processing: PayPal processes all payments on our behalf
- Email Services: Resend for transactional email delivery
- Cloud Storage: AWS S3 for storing uploaded photos and documents
- Hosting: Cloud infrastructure providers for platform hosting
5.3 For Legal Purposes
We may disclose your information if required by law, to respond to legal process, to protect our rights, or to investigate fraud or security issues.
6. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations:
- Active Accounts: Information is retained while your account is active
- Transaction Records: Financial records are kept for 7 years for tax and accounting purposes
- Deleted Accounts: After account deletion, we retain limited information for legal compliance and fraud prevention
- Communications: Messages are retained for dispute resolution and platform safety
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Restriction: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption of data in transit (HTTPS/SSL)
- Secure password hashing (bcrypt)
- Regular security assessments and updates
- Access controls and authentication requirements
- Secure cloud infrastructure with industry-standard protections
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Cookies and Tracking
ShipTo uses essential cookies to provide authentication and maintain your session. We do not use tracking cookies for advertising purposes.
Types of Cookies We Use:
- Strictly Necessary Cookies: Required for authentication and security (session management via NextAuth)
- Functional Cookies: Remember your preferences and settings
You can control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.
10. Third-Party Links
Our platform may contain links to third-party websites (such as PayPal). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Children's Privacy
ShipTo is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
12. International Data Transfers
Your personal data may be transferred to and processed in countries outside the UK where our service providers operate. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the UK ICO
- Ensuring service providers comply with UK GDPR standards
- Adequacy decisions recognizing equivalent data protection laws
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top indicates when the policy was last revised.
We will notify you of material changes by email or through a prominent notice on our platform. Your continued use of ShipTo after changes become effective constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
UK Information Commissioner's Office
If you have concerns about how we handle your data, you can contact the UK data protection authority:
ICO Website: https://ico.org.uk
Helpline: 0303 123 1113