Privacy Policy
1. Introduction
Bullship, LLC d/b/a ShipU (“ShipU,” “we,” “us,” or “our”) provides cloud-based software for university and campus mailrooms. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our websites, use our applications and kiosks, or otherwise interact with us (collectively, the “Services”).
Our two roles. We handle personal information in two distinct capacities:
- As a business (controller) for information about our University customers, their staff, website visitors, and prospects — this Policy applies fully.
- As a service provider (processor) for information about a University’s end customers (for example, student and staff mailbox holders and shipping customers) that Universities submit to the platform (“End Customer Data”). We process End Customer Data only on the University’s instructions to provide the Services. The University is responsible for its own privacy practices; if you are an end customer of an institution that uses ShipU, please direct privacy inquiries to that institution. Where you contact us directly, we will assist or refer your request to the relevant institution.
2. Information We Collect
2.1 Information you provide:
- Account and business information: business name, address, contact details, staff names, emails, phone numbers, and roles.
- Payment information: processed by our payment processor, Stripe. We store only payment tokens and identifiers — never full card numbers.
- End Customer Data submitted by Universities: end customer names, contact details, delivery addresses, mailbox and package records, package and mail photographs, notification preferences, and USPS Form 1583 information and related identity documentation where a University uses those features.
- Communications: support requests, feedback, and correspondence.
2.2 Information collected automatically:
- Usage and device data: IP address, browser and device type, operating system, pages viewed, actions taken, and timestamps.
- Cookies and similar technologies: used for authentication and session management (strictly necessary), preferences, and analytics. You can control cookies through your browser settings; disabling strictly necessary cookies may break the Services.
- Product analytics: we use analytics tools (such as PostHog) to understand feature usage, and error monitoring (such as Sentry) to detect and fix defects.
2.3 Information from third parties: identity information from Google if you sign in with Google; payment and payout status from Stripe; shipment tracking events from carriers and shipping API providers.
3. How We Use Information
We use personal information to:
- Provide, operate, secure, and maintain the Services;
- Process payments, subscriptions, and prepaid wallet transactions;
- Create shipping labels and track shipments through carriers;
- Send transactional communications (receipts, package notifications, account and billing emails) on our own behalf and, at Universities’ direction, on their behalf;
- Provide customer support;
- Monitor, detect, and prevent fraud, abuse, and security incidents;
- Analyze usage to improve the Services and develop new features;
- Comply with legal obligations and enforce our Terms of Service;
- With your consent or at your direction, for other purposes disclosed at the time of collection.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. How We Disclose Information
We disclose personal information only as follows:
- Service providers (subprocessors): vendors that host and support the Services under contractual confidentiality and data-protection obligations, including cloud hosting and infrastructure (Vercel, Supabase), payment processing (Stripe), shipping services (EasyPost and carriers), email delivery (Resend), SMS delivery (Twilio), background job processing (Inngest), error monitoring (Sentry), analytics (PostHog), and bot protection (Cloudflare).
- Carriers and shipping providers: shipment details (names, addresses, package data) necessary to purchase labels and move packages.
- Universities: End Customer Data is visible to the University that manages the relevant customer relationship.
- Legal and safety: when required by law, subpoena, or court order; to protect the rights, safety, or property of ShipU, our customers, or the public; or in connection with investigating fraud or security issues.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy’s protections.
We do not otherwise share, sell, or rent personal information to third parties.
5. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls with tenant isolation enforced at the database layer, webhook and API authentication, rate limiting, audit logging, and continuous error and security monitoring. Payment card data is handled exclusively by Stripe (PCI DSS Level 1); ShipU systems never store cardholder data.
No method of transmission or storage is completely secure. If we become aware of a breach of security affecting your personal information, we will notify affected customers and regulators without undue delay, consistent with applicable law, and will provide information about the nature of the breach and the measures taken in response.
6. Data Retention and Deletion
We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations (including USPS CMRA record-keeping and tax requirements), to resolve disputes, and to enforce agreements. Our retention practices are governed by our internal Data Retention and Disposal Policy; representative periods include customer account records (duration of the relationship plus two years), financial records (duration of the relationship plus seven years), and temporary files such as report exports (thirty days).
You may request deletion of your personal information by emailing the contact in Section 12 with verification of account ownership. We honor verified requests within thirty (30) days except where retention is legally required, and we delete or anonymize Customer Data following account termination after a thirty (30) day export window.
7. Your Privacy Rights
Depending on your state or country of residence, you may have the right to:
- Know/access the categories and specific pieces of personal information we have collected about you;
- Correct inaccurate personal information;
- Delete personal information, subject to legal exceptions;
- Portability — receive a copy of your personal information in a usable format;
- Opt out of sale, sharing, or targeted advertising (we do not sell or share personal information as defined by the CCPA/CPRA);
- Non-discrimination for exercising your rights.
California residents (CCPA/CPRA): In the preceding 12 months we collected the categories of personal information described in Section 2 (identifiers, commercial information, internet activity, geolocation inferred from IP, and professional information) from the sources and for the purposes described above. We do not sell or share personal information, and we do not use or disclose sensitive personal information other than to provide the Services. We honor opt-out preference signals such as Global Privacy Control where applicable.
To exercise any right, contact us using Section 12. We will verify your identity and respond within the timeframe required by law (generally 45 days for California requests, extendable once). You may use an authorized agent with written permission. If we deny a request, you may appeal by replying to our response.
If your personal information was submitted to ShipU by an institution using our platform, we may refer your request to that institution or ask it to assist, as required by our role as a service provider.
8. International Data Transfers
The Services are hosted in the United States. If you access the Services from outside the U.S., you consent to the transfer, processing, and storage of your information in the U.S., which may have different data-protection laws than your jurisdiction. Where required, we rely on appropriate safeguards for cross-border transfers.
9. Children’s Privacy
The Services are business tools not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 for purposes of any sale or sharing, which we do not engage in). If you believe a child has provided us personal information, contact us and we will delete it.
10. Third-Party Links and Services
The Services may link to third-party websites and services (including carrier sites and Stripe-hosted pages). Their privacy practices are governed by their own policies, which we encourage you to review.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last Updated” date and, for material changes, notify account holders by email or in-product notification before the changes take effect.
12. Contact Us
For privacy questions or to exercise your rights:
Bullship, LLC d/b/a ShipU
Email: hello@shipu.co
