Skip to main content

Security, Privacy & Compliance

This page describes security practices, infrastructure and providers used to process shipping data. Contact our team for supporting documents needed for your review.

Compliance Status

We document every certification honestly: what we hold today, what's in progress, and what's not applicable.

Described practices

PCI-DSS

Card fields use Stripe Elements. PCI compliance remains a shared responsibility; using Stripe does not automatically certify our platform.

Described practices

PIPEDA

Canadian privacy law, fully applicable.

Described practices

GDPR

GDPR-compatible practices (data export, right to erasure, DPA available).

Report not published

SOC 2 Type II

Not certified. No SOC 2 report for our platform is currently published.

Report not published

Annual Penetration Test

No independent penetration test report is currently published. Contact us for the status of any engagement.

For evaluation

ISO 27001

Evaluated based on enterprise customer demand.

Security Practices

Encryption in Transit

Public pages use HTTPS and publish an HSTS header to request encrypted connections from supporting browsers.

Encryption at Rest

Supabase documents AES-256 disk encryption for its infrastructure. This is a provider control, not native encryption of every Postgres field. Review specific requirements with our team.

Authentication & Access

Authentication uses Supabase Auth. Role checks and RLS policies protect access. Ask for scope and exception details for your assessment.

Multi-Factor Authentication

TOTP MFA available for all admin accounts. Customer-facing rollout in progress.

Rate Limiting

50+ API routes protected by Upstash Redis-backed rate limiting. Per-IP + per-user limits, standards-compliant Retry-After headers.

Monitoring & Alerts

Errors tracked via Sentry. Application logs in Vercel Observability. Alerts configured for error spikes and payment failures.

Audit Trails

Structured logs record instrumented administrative operations. Confirm their coverage and retention against your organization’s requirements.

Payment Idempotency

Payment flows use idempotency and duplicate controls. Their presence is not a guarantee that a payment error cannot occur.

BOLA Protection

Private-resource access uses ownership or role checks appropriate to the workflow. These controls form part of the defence against unauthorized access.

Input Validation

Input validation and field allowlists restrict changes accepted by the relevant workflows. Specific controls depend on the route.

Signed Webhooks

Easyship, SendGrid, and Stripe webhooks verified via HMAC signature with constant-time comparison (timingSafeEqual).

Bidirectional EDI 214

Standards-compliant X12 EDI 214 generation + parsing for enterprise partners. Native support for carrier shipment status feeds.

Infrastructure & Data Residency

Database

Supabase Postgres hosted in AWS ca-central-1 in Canada. Backup and restoration arrangements should be confirmed as part of your security review.

Compute

Next.js application hosted on Vercel. The verified deployment uses functions in the US iad1 region and a global CDN.

Storage

Supabase Storage (S3-backed). Label PDFs, invoices, brand assets. RLS-gated access.

Availability

Availability depends on the application and its providers. This page publishes neither historical uptime measurements nor a contractual service-level commitment; contact us to discuss your requirements.

Sub-Processors

Every third-party entity that processes customer data. Updated at least 30 days before any new sub-processor is added. To be notified of changes by email, contact privacy@shipsmarter.ca.

Provider reports and certifications apply to their own services and scope. They do not certify our platform.

VendorPurposeDataRegionDocumentation
Supabase Database, authentication, file storageUser profiles, shipments, invoices, label PDFsAWS · ca-central-1 (Canada)View provider documentation
Vercel Hosting, serverless functions, CDNCode, data processed by functions and request logsFunctions: iad1 (USA) · Global CDNView provider documentation
Stripe Card payments, wallets, payment authorizationsCard data (never touched by us: handled by Stripe Elements)GlobalView provider documentation
PayPal Alternative paymentsPayPal order IDs, amountsGlobalView provider documentation
NOWPayments Cryptocurrency paymentsWallet addresses, transaction IDsEUView provider documentation
SendGrid Transactional emails (confirmations, invoices, tracking)Email addresses, outbound email contentUSView provider documentation
Postmark Inbound email reception (support tickets)Received support emailsUSView provider documentation
Anthropic Claude API for AI features (advisor, HS classification, vision)AI prompts and responses; retention depends on provider terms and the features usedUSView provider documentation
Upstash Rate limiting (Redis)IP addresses, user IDs (short TTL)AWS us-east-1View provider documentation
Sentry Error tracking & observabilityStack traces (PII scrubbed before send)US / EUView provider documentation
Easyship Carrier aggregator (rates, labels, tracking)Shipment details, addresses, customs declarationsSingapore HQView provider documentation

Data Handling

Data We Collect

Profile information (name, email, phone, address), shipment details (origin, destination, contents, customs declarations), payment data (via Stripe, never stored on our side), admin activity logs.

Retention

Active data retained for the lifetime of the account. After account deletion: profile and shipments removed within 30 days, invoices retained 7 years for Canadian tax compliance (CRA).

Right to Erasure

You can request account deletion at any time from Settings or by emailing privacy@shipsmarter.ca. We respond within 30 days per PIPEDA and GDPR.

Data Portability

Full data export available in CSV/JSON from your dashboard at Settings → Data. Includes profile, shipments, invoices, and tracking logs.

No Sale, No Ad Sharing

Your data is never sold, never shared for advertising. Period. No third-party marketing or analytics integration receives personal data.

Incident Response

In the event of a data breach or significant security incident, we commit to:

  • Notify affected customers by email within 72 hours of incident confirmation
  • Notify the relevant authorities (Office of the Privacy Commissioner of Canada) per PIPEDA
  • Publish a detailed post-mortem on this page within 14 days of resolution
  • Provide a dedicated support channel for affected customers

Incident history: This page is not a comprehensive incident register. Ask our team for the information needed for your security review.

Responsible Vulnerability Disclosure

We welcome reports from security researchers. If you discover a vulnerability, contact security@shipsmarter.ca with:

  • A detailed description of the vulnerability
  • Reproduction steps
  • Potential impact
  • Your contact for follow-up

We commit to acknowledging receipt within 2 business days, actively investigating, and coordinating public disclosure with you. We commit to not pursuing legal action against researchers acting in good faith.

Data Processing Agreement (DPA)

For customers subject to GDPR, PIPEDA, or contractual compliance requirements, we provide a standard DPA on request. Email privacy@shipsmarter.ca with your company name and the context of the request.

This page is updated regularly. Last updated:

Privacy choices

Essential cookies keep ShipSmarter working. If you accept, we also measure site usage and how our Meta ads (Facebook, Instagram) perform.

Privacy policy