Privacy Policy

Last updated: July 31, 2026

← Back to Home

1. Introduction

At Shipbly B.V. ("Shipbly," "we," "our," or "us"), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mail forwarding, package forwarding, and local agent services.

This policy is designed to comply with the General Data Protection Regulation (GDPR) and Dutch data protection laws. By using our services, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Personal Information

We collect personal information that you provide directly to us, including:

  • Name, email address, phone number
  • Billing and shipping addresses
  • Payment information (processed securely through Stripe)
  • Identity verification documents when required
  • Communication preferences and language settings

2.2 Package and Order Information

  • Package details, contents, and values
  • Retailer information and order confirmations
  • Shipping preferences and instructions
  • Photos of packages for documentation purposes
  • Tracking numbers and delivery confirmations

2.3 Usage Information

  • IP address, browser type, and device information
  • Pages visited, time spent on our platform
  • Login times and frequency of use
  • Feature usage and preferences

3. How We Use Your Information

3.1 Service Delivery

  • Process and fulfill your package forwarding requests
  • Coordinate local agent services and bookings
  • Generate shipping labels and customs declarations
  • Provide customer support and service updates

3.2 Business Operations

  • Process payments and manage subscriptions
  • Send service notifications and updates
  • Verify identity and prevent fraud
  • Comply with legal and regulatory requirements
  • Improve our services and user experience

4. Legal Basis for Processing

GDPR Compliance

We process your personal data based on the following legal grounds under GDPR:

Contract Performance (Art. 6(1)(b) GDPR)

Processing necessary to perform our service contract with you, including package handling and delivery.

Legitimate Interests (Art. 6(1)(f) GDPR)

Fraud prevention, service improvement, and business operations that don't override your privacy rights.

Legal Compliance (Art. 6(1)(c) GDPR)

Meeting customs, tax, and regulatory requirements for international shipping.

Consent (Art. 6(1)(a) GDPR)

Marketing communications and optional features (which you can withdraw at any time).

5. Information Sharing and Disclosure

5.1 Service Providers

We share information with trusted third parties who help us provide our services:

  • Stripe: Payment processing (PCI DSS compliant)
  • Shipping Carriers: PostNL, DHL, UPS, FedEx for package delivery
  • Invoice Ninja: Billing and invoice management
  • Cloud Storage: Secure file storage for package photos and documents

5.2 Legal Requirements

We may disclose information when required by law or to:

  • Comply with customs and tax authorities
  • Respond to legal process or government requests
  • Protect our rights, property, or safety
  • Prevent fraud or investigate security issues

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction, subject to appropriate safeguards.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and employee training
  • Secure data centers and backup procedures
  • Incident response and breach notification procedures

7. Data Retention

Retention Periods: We keep your data only as long as necessary for the purposes outlined in this policy.

Account Information: Until account deletion + 1 year for legal compliance

Package Records: 7 years for customs and tax requirements

Payment Data: As required by financial regulations (typically 7 years)

Marketing Data: Until consent is withdrawn or 3 years of inactivity

Security Logs: 2 years for fraud prevention and investigation

8. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA) for service delivery purposes. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent data protection
  • Binding Corporate Rules for multinational service providers
  • Specific consent for transfers where required

9. Your Privacy Rights

Under GDPR, you have the following rights:

Access & Portability

  • • Request copies of your data
  • • Receive data in a portable format

Correction & Deletion

  • • Correct inaccurate information
  • • Request deletion of your data

Processing Limits

  • • Restrict certain processing
  • • Object to processing

Consent & Complaints

  • • Withdraw consent anytime
  • • Lodge complaints with authorities

To exercise your rights, contact us at privacy@shipbly.io. We will respond within 30 days and may require identity verification to protect your data.

10. Cookies and Tracking

We use cookies and similar technologies to improve your experience, analyze usage, and provide personalized content:

Essential Cookies

Required for platform functionality, authentication, and security. Cannot be disabled.

Analytics Cookies

Help us understand how you use our platform to improve services. Can be disabled in settings.

Preference Cookies

Remember your settings like language and currency preferences.

11. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will delete it immediately. Parents or guardians who believe we may have collected information from a child should contact us.

12. Updates to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. We will notify you of any material changes by email or through prominent notices on our platform. The "Last updated" date at the top indicates when the policy was last revised. Your continued use after changes indicates acceptance of the updated policy.

13. Contact Information

For questions about this Privacy Policy or to exercise your rights, please contact us:

Data Protection Officer: privacy@shipbly.io

General Privacy Questions: hello@shipbly.io

Postal Address: Shipbly B.V., Jan van Eijckplein 2, 4703GV Roosendaal, The Netherlands

EU Representative: Available through our platform or privacy@shipbly.io

Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
If you're not satisfied with our response, you can lodge a complaint at autoriteitpersoonsgegevens.nl

By using Shipbly services, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Last updated: July 31, 2026 | Version 1.0 | GDPR Compliant