Privacy Policy
Last updated 20 August 2026. This covers the Shippington website assistant, at shippington.co and on sites where the assistant is embedded.
The short version. We handle three things: the public pages of your website, the messages your customers type to your assistant, and the callback details they choose to leave. We do not sell any of it, do not publish it, and do not train models on it. Conversations are not stored; only a message someone deliberately leaves is kept.
What we collect
From a business that uses the service
- Your website address, and the text of a small number of its public pages. Up to six pages, fetched once when the assistant is built, honouring your robots.txt. We fetch nothing behind a login.
- Your email address, given when you claim an assistant. Used to send you your dashboard link, your captured messages, and notices about your assistant.
- Usage counts. How many messages your assistant handled and what they cost us to run, so we can keep the service inside its limits.
From a person talking to an assistant
- The messages they type, for as long as the conversation is open in their browser. These are sent to our provider to generate a reply and are not stored by us afterwards. Close the tab and the conversation is gone.
- A callback request, when a person chooses to leave one: their name, phone number, and a short description of what they need. This is stored, emailed to the business, and shown on that business's dashboard.
- A session identifier held in the browser tab. It exists so one visitor cannot exhaust a small business's monthly allowance. It is random, it is not linked to a person, and it is discarded when the tab closes.
The assistant is instructed never to collect card numbers, health details, dates of birth, insurance identifiers or account numbers, and to tell a person not to send them. If someone types one anyway it may be captured in the callback description. Do not send sensitive information to an assistant.
What we do not do
- We do not sell or rent any of it.
- We do not use your website content, your customers' messages, or captured leads to train models.
- We do not use advertising trackers or third-party analytics inside the assistant.
- We do not build profiles of the people who talk to assistants.
Who else is involved
Running the service means passing some data to a small number of providers:
- Anthropic generates the replies. Your website summary and the current conversation are sent to their API. They act as a processor for us and do not train on it.
- Google Cloud hosts the service and stores the data, in the United States.
- Resend sends transactional email: your dashboard link, and notification of each message captured.
That is the full list. If it changes we will update this page.
How long we keep things
- Conversations: not stored.
- Captured callback requests: until you delete them, or until 90 days after your assistant is switched off, whichever comes first.
- Your website summary and assistant configuration: until you delete the assistant.
- Usage counts: 13 months, aggregated, with no message content.
- Unclaimed samples we built and nobody claimed: deleted after 90 days, or immediately on request.
Your choices
Email vince@shippington.co for any of this and we will do it, usually the same day:
- A copy of everything we hold for your business.
- Deletion of your assistant and everything associated with it.
- Correction of anything in your assistant's summary.
- Removal of an assistant we built from your site that you never asked for.
Depending on where you live you may have rights under laws such as the GDPR or the CCPA. We honour those requests regardless of where you are, because the process is the same either way.
If you left a callback request with a business and want it removed, ask that business, since it is their record. You can also email us and we will pass it on.
Security
Data is encrypted in transit and at rest by our hosting provider. Assistant configuration, captured messages and email addresses are readable only by our server, never by a browser. The public identifier used by an embedded assistant carries nothing beyond the business name, its greeting, and a colour.
Dashboard access is a single unguessable link sent by email, with no password. Anyone with that link can see your captured messages and switch the assistant off, so treat it like a password. Ask us and we will issue a new one.
Fetching websites
Our fetcher identifies itself with an X-Shippington-Bot header pointing at shippington.co/bot, which explains what it is and how to block it. We honour robots.txt, fetch at most six pages of a site, once, and never crawl on a schedule.
Children
The service is for businesses. It is not directed at children and we do not knowingly collect information from anyone under 13.
Changes
If we change this policy in a way that materially affects you, we will email the address on your account before it takes effect.
Questions: vince@shippington.co.