This Privacy Policy explains how Ryan Almasu, operating as Shipflash (“Shipflash,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal information when you visit the Shipflash website, create or use an account, contact us, join a waitlist, purchase Shipflash, access customer-facing services, or otherwise interact with Shipflash.
Privacy Policy
Explain collection, storage, and protection of personal information.
Shipflash is operated from Indonesia.
For purposes of applicable data-protection law, Ryan Almasu is responsible for personal information processed through Shipflash where Shipflash determines the purposes and means of that processing.
Privacy and support requests may be sent to support@mail.shipflash.dev.
Information We Collect
Account Information
When you create or use a Shipflash account, we may process information such as your name, email address, authentication identifiers, avatar, locale, timezone, account role, preferences, activity dates, and other profile information you voluntarily provide.
Authentication and session information may be processed using providers such as Supabase and may be stored in authentication cookies or similar technologies.
Contact and Support Information
When you contact us, we may collect information such as your name, email address, company, subject, message, account identifier, support history, and related information reasonably necessary to respond to your request.
Bot-protection or anti-abuse information may be processed when forms or public endpoints use those protections.
Waitlist and Attribution Information
If you join a Shipflash waitlist or submit a lead form, we may process information such as your name, email address, company, use case, signup source, status, UTM parameters, referral information, landing-page information, and related attribution or conversion information.
We may also maintain limited internal notes or status information reasonably necessary to administer the waitlist or respond to your request.
Purchase and Billing Information
When you purchase Shipflash, we may receive and process information relating to the transaction, including your name, email address, payment-provider customer identifier, checkout identifier, payment or order identifier, product identifier, payment status, amount, currency, invoice or receipt information, refund or dispute status, entitlement information, and provider webhook identifiers.
Shipflash does not directly store complete payment-card numbers or complete payment-method credentials. Those details are processed by the applicable payment provider.
Product and Repository Access Information
Eligible Shipflash purchases may include access to a private GitHub repository.
For the current Shipflash Lifetime delivery flow, repository entitlement delivery is managed through Dodo Payments together with GitHub.
Shipflash may receive or maintain purchase, entitlement, webhook, account, and operational information necessary to determine whether an eligible purchase exists, associate the purchase with a Shipflash customer account, provide support, or investigate access problems.
The Shipflash Dodo checkout flow does not require you to enter a GitHub username directly into Shipflash. Where GitHub repository delivery is handled through the Dodo Payments GitHub integration, GitHub account linking, authorization, invitation, and related repository-access processing are handled through Dodo Payments and GitHub.
If you voluntarily provide a GitHub username or other GitHub information to Shipflash in a support request, we may process that information as necessary to investigate the request.
Communications
We may maintain records of transactional, security, purchase, authentication, support, and operational communications sent to or received from you.
This may include delivery status, notification status, timestamps, error information, and related identifiers needed to maintain reliable communication or troubleshoot problems.
Technical, Security, and Analytics Information
When you use Shipflash, we may collect technical information such as pages or routes visited, session and request identifiers, referral and landing-page information, browser or user-agent information, device and performance information, IP-address or IP-derived security information, authentication events, audit information, webhook activity, errors, rate-limit records, and analytics events.
We may use first-party analytics or configured third-party analytics services to understand website usage and performance.
Information From Third Parties
We may receive information from third parties when necessary to provide Shipflash.
For example, a payment provider may send us verified transaction information through signed webhooks. An authentication provider may provide account identifiers and session information. GitHub or an entitlement provider may provide information relevant to repository-access status or support.
The information available to Shipflash depends on the provider, its configuration, and the permissions used.
How We Use Information
We may use personal information to operate and maintain Shipflash; create and authenticate accounts; process and verify purchases; associate purchases with customer accounts; maintain product entitlements; provide support; administer waitlists; send transactional, authentication, billing, security, and operational messages; detect fraud, spam, abuse, or unauthorized activity; apply rate limits; maintain audit and financial records; troubleshoot errors; analyze website performance; improve Shipflash; comply with legal obligations; and enforce our Terms and Commercial License.
We do not use personal information for an unrelated purpose merely because the underlying Shipflash codebase contains functionality that could be configured by a customer for that purpose.
Legal Bases for Processing
Where applicable law requires a legal basis, we process personal information based on one or more legally recognized grounds, which may include performance of a contract, steps requested before entering into a contract, compliance with a legal obligation, consent, legitimate interests, or another basis permitted by applicable law.
The appropriate basis depends on the information and the purpose for which it is processed.
Payments and Dodo Payments
Shipflash currently uses Dodo Payments for the Shipflash Lifetime checkout flow.
When you complete a purchase through a third-party payment or merchant-of-record provider, that provider processes transaction and payment information under its own terms and privacy practices.
Shipflash may receive information necessary to verify the purchase, create billing records, maintain account or entitlement information, provide customer support, reconcile payments, process or record refunds and disputes, detect fraud, and satisfy accounting or legal obligations.
Shipflash does not receive or directly store complete card credentials simply because a purchase is made through the provider.
GitHub Repository Delivery
An eligible Shipflash purchase may include repository access delivered using Dodo Payments' GitHub entitlement functionality.
When that delivery method is used, you may be asked by the provider to link or authorize your GitHub account through an OAuth process and to accept a GitHub invitation.
Dodo Payments and GitHub may process information required to perform that account linking and repository delivery under their own privacy practices.
Shipflash may receive entitlement-related webhook events, provider identifiers, status information, or support information where necessary to operate or troubleshoot the associated purchase.
Repository delivery through the provider is separate from creation of a Shipflash customer account.
Anonymous Purchases and Account Linking
Shipflash may allow a purchase to be completed before a Shipflash account has been created.
For an anonymous purchase, the payment provider may collect the purchaser's email address during checkout.
After a verified successful purchase, Shipflash may use the purchase email received from the provider to send an authentication invitation, magic link, or other passwordless sign-in communication so the purchaser can establish or access a Shipflash customer account.
After authentication, we may associate eligible billing or entitlement records with the verified Shipflash account where the records correspond to the same normalized email or otherwise satisfy our account-linking controls.
Cookies, Local Storage, and Similar Technologies
Shipflash may use cookies, local storage, and similar technologies to maintain authentication and session state, remember preferences, protect accounts and service boundaries, maintain attribution information, detect fraud or abuse, and measure website usage or performance.
Some technologies are necessary for authentication, security, or core service functionality.
Optional analytics technologies are used according to their configuration and applicable legal requirements. Where applicable law requires prior consent, technologies requiring that consent should not be activated before the required consent is obtained.
You can also manage browser cookies and local storage through your browser, although disabling necessary technologies may prevent parts of Shipflash from operating correctly.
Third-Party Services
Shipflash may use third-party providers for payment processing, authentication, databases, hosting, email delivery, repository delivery, analytics, bot protection, logging, and other operational infrastructure.
These may include services such as Dodo Payments, GitHub, Supabase, Resend, Vercel, Netlify, Cloudflare, Google Analytics, or other providers actually configured for Shipflash.
A provider may process personal information as necessary to perform its service and under its own applicable terms and privacy practices.
The inclusion of an integration inside the Shipflash source-code product does not necessarily mean that Shipflash uses that provider to process visitors' or customers' personal information on the Shipflash website.
How We Share Information
We do not sell personal information.
We may disclose information to service providers that help operate Shipflash, payment providers handling a transaction, authentication providers, GitHub or an entitlement provider where necessary for repository delivery, communications providers, analytics or security providers, professional advisers where reasonably necessary, or governmental or legal authorities where disclosure is required or permitted by law.
We may also disclose information when reasonably necessary to investigate fraud, abuse, security incidents, payment disputes, or violations of our agreements, or to establish, exercise, or defend legal claims.
If Shipflash or relevant business assets are transferred through a merger, financing, acquisition, restructuring, or similar transaction, information may be transferred subject to applicable legal requirements.
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy or as required or permitted by law.
Retention periods vary depending on the information involved and may take into account whether an account or product license remains active, contractual and repository-access requirements, payment and tax obligations, support and dispute requirements, security and fraud-prevention needs, applicable limitation periods, legal obligations, and requests to delete information.
Operational logs, rate-limit records, webhook records, and failed notification records may be retained for shorter operational periods according to our active configuration.
Account, purchase, license, entitlement, accounting, dispute, fraud-prevention, and legal records may need to be retained for longer periods.
Information associated with a discontinued Shipflash feature may also remain in historical records, backups, database migrations, or legally required records until it is deleted, anonymized, overwritten according to retention processes, or no longer reasonably required.
When information is no longer needed, we will delete, anonymize, or otherwise dispose of it according to our applicable processes and legal obligations.
Security
We use reasonable technical and organizational measures designed to protect personal information.
Depending on the system, these measures may include access controls, restricted server credentials, database permissions, row-level security, webhook-signature verification, encryption of supported sensitive information, rate limiting, abuse prevention, audit records, dependency monitoring, and administrative-access restrictions.
No system, network, transmission method, or storage mechanism can be guaranteed to be completely secure.
You are responsible for protecting your email account, GitHub account, devices, passwords, recovery methods, and credentials under your control.
Personal-Data Incidents
If a personal-data protection failure occurs, we will investigate and take reasonable measures to contain, remediate, and recover from the incident.
We will notify affected individuals, regulators, or other authorities when required by applicable law.
Where Indonesian personal-data protection law applies and its notification requirements are triggered, we will provide the required written notification within the period prescribed by applicable law, including the applicable 3 × 24 hour notification period.
Required notifications may include information regarding the affected personal information, when and how the incident occurred, and measures taken to address and recover from the incident.
International Data Transfers
Shipflash and its service providers may process personal information in Indonesia or other countries where the relevant providers maintain infrastructure, personnel, or subprocessors.
Those countries may have data-protection laws that differ from those in your jurisdiction.
Where applicable law imposes conditions on an international transfer of personal information, we will use a transfer basis or safeguard recognized by that law where required.
Third-party providers may also perform international transfers according to their respective infrastructure, agreements, privacy practices, and legal obligations.
Your Rights and Choices
Depending on your location and applicable law, you may have rights relating to your personal information, including rights to obtain information regarding processing, request access, correct inaccurate information, request deletion or destruction of eligible information, withdraw consent where processing relies on consent, object to or restrict certain processing, obtain eligible information in portable form, object to certain automated decisions, unsubscribe from optional marketing communications, or submit a complaint to an appropriate authority.
To make a privacy request, contact support@mail.shipflash.dev or use the Shipflash contact page.
We may need to verify your identity and authority before fulfilling a request.
Some information may continue to be retained where necessary or permitted for licensing, product access, payment records, tax obligations, security, fraud prevention, dispute resolution, legal claims, or other legal obligations.
Marketing and Communications
You may unsubscribe from optional marketing communications using the instructions provided in the communication or by contacting us.
Even after you unsubscribe from optional marketing, we may continue to send necessary transactional, authentication, purchase, billing, repository-access, security, or support communications.
Children
Shipflash is intended for individuals who are legally able to enter into a binding agreement.
Shipflash is not directed to children, and we do not knowingly collect children's personal information in circumstances where applicable law requires authorization that has not been obtained.
If you believe a child has provided personal information to Shipflash without appropriate authorization, contact support@mail.shipflash.dev.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in Shipflash, providers, processing activities, security practices, or applicable law.
The updated version will be published with a revised “Last updated” date.
Where applicable law requires additional notice or consent for a material change, we will provide it as required.