SHIP FAST

Legal

Privacy policy

Ship Fast (https://ship-fast.ai, "we", "us") · Effective date:

1. Who is responsible

The data controller for personal data processed through this service, unless stated otherwise, is

SHIPFAST PRIVATE LIMITED
Represented by Surya Remanan

Company registration number: CIN U62012KL2026PTC104011

Privacy and data-protection requests: hello@ship-fast.ai

Activities described in this notice include processing connected to India. Depending on your location, other laws may apply in addition.

2. Summary

Ship Fast is an AI-assisted product for generating website projects from text prompts. We process account data, the content you submit (including prompts and generated files), technical identifiers needed to run and protect the service, and limited analytics. Some processing is carried out by vendors (for example cloud hosting, authentication, payments, and AI inference) strictly to provide the product.

3. What we collect

3.1 Account and authentication

If you sign in, we use Clerk Authentication and may process your Clerk user ID, email address, and profile details provided by your identity provider (such as Google or GitHub) when you choose those options.

3.2 Projects, prompts, and generated output

We store the prompts and other instructions you submit and the generated project files needed to show previews, exports, deployments, and session history. This content is tied to your session and, when you are signed in, to your account.

3.3 Usage, security, and abuse prevention

We process IP addresses, request metadata, timestamps, and similar technical data for rate limiting, fraud prevention, reliability, and automated safety checks on user-submitted text (including logging that a request was blocked, with technical identifiers such as IP and account where available, without retaining the blocked text in security logs by design).

For session-level abuse prevention, we store a SHA-256 hash of your IP address, protected with a cryptographic 32-byte salt. We automatically remove this IP hash after 90 days. This processing is based on our legitimate interests in securing the service and preventing fraud and abuse.

3.4 Analytics

We use Plausible Analytics configured for first-party collection via this site's endpoint. Plausible is designed to minimise personal data; please see Plausible's documentation for details.

3.5 Session replay

On the production site we use LogRocket to record a replay of your session — the pages you visit, and how you move through and interact with the interface — so we can diagnose faults and support requests. Requests are served through our own domain rather than LogRocket's servers directly.

Recording is configured so that the values you type are masked, and the bodies of network requests and responses are not captured, which means your prompts, generated content, payment details, and authentication tokens are not recorded. Where you are signed in, we associate the replay with your account identifier, name, and email address so a session can be matched to a support request. Session replay does not run on local, staging, or preview environments.

3.6 Partner attribution and partner programme

With your consent, we use Dub to attribute visits from partner referral links. Dub may set a dub_id marketing cookie for up to 30 days and process a referral click identifier, referring page, landing page, and limited browser or device information. We do not load Dub's browser analytics until you allow marketing cookies.

If you create or use an account after a referral, we apply first-source attribution: the earliest eligible native referral or Dub partner referral is associated with your account. We may send Dub a stable account identifier and limited profile information, such as your name and email address, to record the referred signup and provide the partner portal.

For enrolled partners, Dub supports referral reporting, commissions and payouts. For eligible subscription purchases and refunds, we send transaction identifiers, amount, currency, status, and payment processor type. Payout and tax information you submit directly to Dub is governed by Dub's privacy notice.

3.7 Payments

Paid features are processed through Stripe and Razorpay. We do not receive your full payment card number on our servers; payment data is handled by the payment provider. We receive status information (for example subscription state, invoices, refunds, or credit purchases) through our billing integrations and may store it in Convex associated with your account. Eligible partner-attributed subscription events are also reported to Dub as described above.

3.8 Optional operations notifications

If we configure an operations webhook (for example Slack), certain events in production may posttruncated prompt text and user or billing metadata to that system for monitoring. This is disabled in development by default and only applies when such an integration is enabled.

3.9 AI and media providers

To generate sites and imagery we may send portions of your prompt and derived instructionsto model and infrastructure providers (such as Groq, Runpod where configured, and stock providers such as Pexels or Unsplash for image search). Those providers act as further processors and have their own terms and privacy notices.

3.10 GitHub integration

If you connect GitHub, tokens or credentials required for repository actions are handled according to that integration; do not paste secrets into prompts.

4. Why we use data (purposes)

  • To provide Ship Fast, including creating and displaying your projects and processing exports.
  • To authenticate you and manage your account, quotas, and entitlements.
  • To process payments and prevent abuse of billing or promotional programmes.
  • With consent, to attribute partner referrals; and to administer partner enrollment, reporting, commissions, refunds, and payouts.
  • To secure the service, enforce acceptable use (including automated content rules), and investigate incidents.
  • To understand aggregate product usage and improve stability and performance.
  • To comply with legal obligations and respond to lawful requests.

Where GDPR-style rules apply, we rely on the following bases as appropriate:

  • Contract — providing the service you request.
  • Legitimate interests — security, abuse prevention, product improvement, and proportionate analytics, balanced against your rights.
  • Legal obligation — where the law requires processing or retention.
  • Consent — where we expressly ask for it (for example Dub marketing cookies and optional communications), which you may withdraw.

6. Recipients and subprocessors

We share data with categories of recipients including:

  • Clerk (Authentication services)
  • Convex (Database and backend services for billing data)
  • Stripe and Razorpay (payments)
  • Dub (consent-based partner attribution and partner programme administration)
  • Plausible Analytics
  • LogRocket (session replay for diagnostics and support)
  • AI, GPU, or inference providers (for example Groq, Runpod) and stock imagery APIs (for example Pexels, Unsplash)
  • Infrastructure and deployment providers that host ship-fast.ai and related services
  • Professional advisers or authorities where required by law

7. International transfers

We and our vendors may process data in Switzerland, the EEA, the United Kingdom, the United States, India, and other countries where service providers operate. Where required, we implement appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) and can provide more information on request.

8. Retention

We keep personal data only as long as needed for the purposes above, including any legal, accounting, or reporting requirements. Session and project data are kept until you delete them or your account, or until we delete them under our data lifecycle rules. Technical logs may be kept for a shorter operational period.

Session IP hashes used for security and abuse prevention are automatically cleared after 90 days.

The Dub browser attribution cookie lasts for up to 30 days unless you withdraw consent sooner. Account-level attribution and partner transaction records may be kept while your account or partner relationship remains active and afterward where needed for accounting, fraud prevention, disputes, or legal obligations. Withdrawing marketing consent clears the Dub cookie from this browser and stops future Dub browser tracking; it does not automatically erase records already required for those purposes.

9. Your rights

Subject to applicable law, you may have the right to:

  • Access, correct, or delete your personal data
  • Restrict or object to certain processing
  • Data portability where technically feasible
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact hello@ship-fast.ai. We may need to verify your identity before fulfilling a request.

10. Security

We implement technical and organisational measures appropriate to the risk, including access controls and encryption in transit where supported by our providers. No method of transmission over the Internet is completely secure.

11. Children

Ship Fast is not directed at children under the age where parental consent is required in their jurisdiction. We do not knowingly collect personal information from children. Our acceptable-use rules prohibit sexual content involving minors and related abuses; violations may be blocked and logged.

12. Changes

We may update this notice. The effective date at the top will change when we do. For material changes we will provide notice as required by law or through the product.

13. Contact

Questions about this policy: hello@ship-fast.ai

Public site: https://ship-fast.ai/