SyncShip

SyncShip Privacy Policy

How SyncShip handles information across its shipping platform, website, integrations, and support services

Effective Date: May 1st , 2026 | Last Updated: July 1st , 2026

This Policy covers information for which SyncShip decides the purpose and means of processing. When a merchant imports order, buyer, recipient, or shipment information and SyncShip processes it only to provide services to that merchant, the merchant generally remains responsible for the individual-facing privacy notice and instructions. Jurisdiction-specific terms appear near the end.

This Policy is designed for SyncShip's business-to-business shipping technology. It should be read together with the SyncShip Terms of Service, any order form, product-specific terms, and any Data Processing Addendum that applies to a customer's use of the Services.

1. About SyncShip and This Policy

SyncShip LLC is a New Jersey limited liability company. In this Policy, "SyncShip," "we," "us," and "our" refer to SyncShip LLC. We provide software that helps business customers connect ecommerce channels, manage orders, compare shipping services, create labels, coordinate fulfillment, track packages, manage returns, and use related integrations and application programming interfaces.

This Policy explains what personal information we collect, where it comes from, why we use it, when we disclose it, how long we keep it, and the choices that may be available to an individual. "Personal information" is used broadly in this Policy and includes information that identifies, relates to, describes, can reasonably be associated with, or can reasonably be linked to an individual or household, as defined by applicable law. Information that has been lawfully deidentified or aggregated so that it cannot reasonably be linked to an individual is not personal information for purposes of this Policy.

The Services are intended for commercial users who are at least 18 years old. Availability in a country does not mean that every feature, carrier, payment method, or integration is available there. Local disclosures or contractual terms may supplement this Policy.

A short operational summary

  1. SyncShip receives business-account information and the order, recipient, shipment, and product details needed to perform shipping and fulfillment functions.
  2. Customers choose which stores, marketplaces, carriers, warehouses, payment services, and applications to connect, and those connections exchange data according to the permissions selected by the customer.
  3. Independent payment providers process card, bank, wallet, and similar payment transactions. SyncShip uses transaction and ledger information to fund and administer the SyncShip Balance and label purchases.
  4. We disclose information to carriers, marketplaces, payment providers, cloud and security vendors, and other parties when needed to provide, protect, or administer the Services.
  5. We do not sell order-recipient data, shipment addresses, label information, SyncShip Balance records, or SMS consent data for third-party marketing.
  6. Individuals may have rights over their information. The correct request route depends on whether SyncShip or a business customer controls the data.

2. Scope and Privacy Roles

Where this Policy applies

This Policy applies to the SyncShip website, hosted platform, mobile or desktop experiences if offered, customer and developer portals, APIs, support channels, sales communications, events, and other products or services that display or link to this Policy. It covers account administrators, authorized users, prospective customers, business contacts, website visitors, developers, suppliers, carrier contacts, and individuals whose information SyncShip handles for its own business purposes.

This Policy does not govern employee or job-applicant records covered by a separate workforce notice, a third party's independent website or service, or personal information that SyncShip processes solely under a business customer's documented instructions where the applicable customer agreement or Data Processing Addendum governs that processing.

When SyncShip is the controller or business

SyncShip generally determines why and how information is processed for account creation, customer relationship management, billing, SyncShip Balance administration, fraud prevention, service security, website analytics, product improvement, legal compliance, and SyncShip's own communications. In those contexts, SyncShip acts as a controller, business, or similar responsible organization under applicable law.

When SyncShip is a processor or service provider

A customer may upload, import, generate, or transmit information about marketplace buyers, store customers, shipment recipients, return senders, and other downstream individuals. When SyncShip handles that information only to perform the customer's requested shipping, order-management, fulfillment, or integration functions, SyncShip generally acts for that customer as a processor or service provider. The customer decides whether it may collect and use the information, provides required notices, responds to individual rights requests, and gives SyncShip lawful instructions.

If you are a buyer, recipient, or other downstream individual, the merchant or organization that collected your information is normally the first place to direct a privacy request. If you contact SyncShip, we may identify or refer the request to the relevant customer, subject to security, confidentiality, and law.

3. Key Terms

Account. A registered SyncShip business account and its related users, settings, integrations, credentials, and records.

Connected Service. A carrier, marketplace, ecommerce store, payment service, warehouse system, application, API client, or other external service linked to SyncShip by or for a customer.

Customer. The business, organization, or commercial user that contracts with or creates an Account with SyncShip.

Customer Data. Information submitted to, generated in, or received through the Services on a Customer's behalf, including order, buyer, recipient, shipment, inventory, label, tracking, and integration information.

Downstream Individual. A buyer, consumer, recipient, sender, return contact, or other person whose information a Customer makes available through the Services.

Sensitive Personal Information. Personal information treated as sensitive under applicable law, which may include authentication credentials, government identifiers, precise location, financial account information, and certain protected characteristics or communications content.

Services. The SyncShip website, software platform, APIs, integrations, support, and related commercial services that link to this Policy.

SyncShip Balance. The Account ledger credit described in the Terms of Service that may be funded through supported payment methods and used only for postage-label transactions with carriers, including carrier corrections attributable to those labels.

4. Information We Collect

The information SyncShip receives depends on the Services used, the Account configuration, the permissions granted to Connected Services, the shipping transactions performed, and the individual's relationship with SyncShip or a Customer. We may collect the following categories.

Business identity and contact information

This may include a name, business name, job title, department, business address, shipping or return address, email address, telephone number, preferred language, time zone, and communications preferences. We may also collect information identifying an Account owner, administrator, authorized user, billing contact, technical contact, developer, warehouse contact, or supplier representative.

Account, credential, and security information

This may include usernames, password hashes, multifactor-authentication status, recovery information, role and permission settings, OAuth grants, access tokens, API keys, application identifiers, login timestamps, IP addresses, device and browser details, authentication events, security alerts, and records of changes made within an Account. Customers should not place passwords or secret keys in support tickets or free-text fields.

Business verification and compliance information

We may request or receive information needed to verify a business, authorized representative, carrier account, payment method, or shipping eligibility. Depending on risk, law, or a third-party program, this may include entity registration information, tax identifiers, beneficial-owner or control-person details, government-issued identification, address evidence, sanctions-screening results, carrier credentials, and verification status. SyncShip seeks to limit collection to what is reasonably required for the applicable purpose.

Order, buyer, recipient, and fulfillment information

When a Customer connects a sales channel or imports an order, SyncShip may receive order numbers, store or marketplace identifiers, buyer and recipient names, company names, delivery and return addresses, telephone numbers, email addresses, customer notes, gift indicators, requested delivery services, order status, and return information. Depending on the channel and permissions, we may also receive limited buyer-account or marketplace metadata. Customers must not import information that the Connected Service does not permit them to use.

Product, inventory, and customs information

This may include product title, SKU, quantity, price, weight, dimensions, image or listing reference, inventory location, country of origin, declared value, currency, Harmonized System or tariff code, item description, export classification, tax or importer identifier, and other information needed for shipping, customs, restricted-item review, or marketplace fulfillment.

Shipment, label, tracking, claim, and return information

This may include origin and destination details, package attributes, selected carrier and service, quoted and charged rates, label and tracking identifiers, manifests, scans, delivery events, signatures where provided by a carrier, proof-of-delivery records, adjustment reasons, returns, voids, refund requests, claims, loss or damage documentation, insurance or protection details, and related communications.

Payment and SyncShip Balance information

Independent payment providers may collect card, ACH, PayPal, Apple Pay, Google Pay, or other payment credentials. SyncShip may receive the billing name and address, payment method type, last digits of an account, token or transaction reference, authorization and settlement status, funding amount, decline or reversal reason, chargeback information, and risk signals. SyncShip also maintains Balance funding, debit, credit, reconciliation, refund, adjustment, and negative-balance records.

When a hosted or tokenized payment flow is used, the payment provider is intended to receive the complete card or bank credential rather than SyncShip. SyncShip does not need a card security code or online-banking password to operate the Balance. The exact information visible to SyncShip depends on the payment method, provider, fraud controls, and applicable law.

Support, sales, and communications information

We may keep emails, chat transcripts, support tickets, call notes or recordings when notice is provided, survey responses, meeting records, feedback, feature requests, complaint details, marketing choices, and documents or screenshots supplied to diagnose a problem. Support communications may contain Account, order, label, device, or integration information relevant to the request.

Device, website, and usage information

When someone visits or uses the Services, we may collect IP address, approximate location derived from IP, device type, operating system, browser type, language, referring and exit pages, URLs, page and feature activity, button clicks, session timestamps, error and performance data, cookie and similar identifiers, and application or API request logs. We do not require precise GPS location for ordinary label creation, but a future location-dependent feature would request any consent or device permission required by law.

API, application, and integration telemetry

For developers and integrated systems, we may collect application names, callback domains, scopes, token issuance and revocation events, endpoint requests, response codes, rate-limit events, payload metadata, webhook delivery records, error traces, and security indicators. Payload content may be processed when needed to complete a request, troubleshoot, investigate misuse, or meet legal obligations.

Derived information

We may derive information such as configuration preferences, likely support needs, usage trends, address quality indicators, shipment-risk signals, fraud or abuse indicators, and suggested workflow settings. Derived information is treated as personal information when it can reasonably be linked to an individual.

Information we do not ask Customers to provide

The Services are not designed to store protected health information, full payment-card authentication data, biometric templates, criminal-history files, or information about religion, political views, sexual life, or medical status. Shipping contents and free-text fields can indirectly reveal sensitive facts. Customers should use neutral descriptions where lawful and should not provide sensitive information unless it is strictly necessary for a requested shipment, legally permitted, and supported by the applicable feature.

5. Where Information Comes From

SyncShip may receive personal information from the following sources:

  1. Directly from an individual or Customer. Information is supplied during registration, verification, billing, shipping, support, surveys, sales discussions, or other interactions.
  2. Authorized users and administrators. An Account owner or administrator may create users, assign roles, supply business contacts, and manage settings for other people in the organization.
  3. Connected stores and marketplaces. At a Customer's direction, ecommerce and marketplace services may send order, buyer, product, inventory, fulfillment, and status information through APIs, webhooks, files, or other connection methods.
  4. Carriers, postal operators, customs intermediaries, and protection providers. These parties may return rates, account validation, labels, scans, delivery events, adjustments, claims, refunds, customs events, and compliance information.
  5. Payment and financial service providers. Processors, banks, wallet providers, and fraud services may send transaction status, tokenized payment details, verification results, disputes, reversals, and risk signals.
  6. Applications, developers, warehouses, and fulfillment partners. A Customer may authorize another provider to send information to or retrieve information from SyncShip.
  7. Automatically from technology. Servers, browsers, devices, cookies, SDKs, logs, and security tools generate technical and usage information when the Services are accessed.
  8. Public and commercial sources. Where lawful, we may use business registries, sanctions lists, address-validation data, professional contact sources, and fraud-prevention data to verify information or protect the Services.

6. How We Use Information

SyncShip uses personal information only for purposes that are reasonably connected to the Services, our business relationship, a legal requirement, or another purpose disclosed when information is collected. Specific uses include the following.

  1. Create and administer Accounts. Register organizations and users, verify authority, configure roles, authenticate access, maintain settings, and provide notices.
  2. Connect systems and synchronize commerce data. Authorize and maintain Connected Services, receive orders and inventory updates, transmit status information, process webhooks, and keep requested integrations functioning.
  3. Provide shipping and fulfillment functions. Compare eligible rates, create and void labels, produce customs documents, route orders, coordinate warehouse activity, obtain tracking, support returns, and present shipment history.
  4. Process payments and maintain the Balance. Initiate authorized funding, confirm payment, credit or debit the Balance, pay for labels, apply carrier adjustments, process eligible refunds, reconcile transactions, and collect amounts due.
  5. Support Customers and users. Respond to inquiries, investigate errors, restore access, troubleshoot integrations, provide training, and document outcomes.
  6. Protect the Services and participants. Detect suspicious access, fraud, account takeover, prohibited shipments, abusive automation, payment risk, sanctions exposure, security incidents, and violations of law or contract.
  7. Operate, measure, and improve SyncShip. Monitor reliability, capacity, performance, adoption, and workflow outcomes; debug errors; test changes; develop features; and improve usability.
  8. Communicate. Send transaction, label, tracking, security, billing, legal, support, product, and service messages, and send marketing where permitted.
  9. Comply and enforce. Meet tax, accounting, postal, carrier, customs, sanctions, legal-process, recordkeeping, and regulatory duties; establish or defend claims; and enforce agreements.
  10. Carry out a requested or consented purpose. Use information in another way when the individual or Customer has directed the processing or supplied legally effective consent.

7. How We Disclose Information

SyncShip does not disclose personal information indiscriminately. We disclose the information needed for a defined operational, legal, security, or customer-directed purpose, subject to applicable contracts and law.

  1. Carriers, postal operators, and shipping-program providers. We provide sender, recipient, package, customs, account, and transaction information needed to quote, purchase, tender, track, adjust, return, protect, or claim a shipment.
  2. Marketplaces and ecommerce channels. We exchange order, inventory, shipment, tracking, cancellation, and fulfillment information according to the Customer's connection settings and the channel's rules.
  3. Payment, banking, and fraud providers. We provide billing, identity, transaction, device, and risk information needed to authorize payments, fund the Balance, prevent fraud, handle disputes, and reconcile transactions.
  4. Cloud, infrastructure, security, and business vendors. Providers may host data, deliver communications, monitor security, support customers, validate addresses, analyze performance, manage authentication, or perform other services for SyncShip.
  5. Customer-selected applications and fulfillment partners. We disclose information to a developer, warehouse, 3PL, consultant, or other party when a Customer authorizes that party or gives it Account credentials or API access.
  6. Account administrators and authorized users. People with Account permissions may view and manage information available to their assigned role. Customers are responsible for granting and reviewing access.
  7. Professional advisers and insurers. Lawyers, accountants, auditors, consultants, insurers, and similar professionals may receive information under duties of confidentiality when needed for advice, claims, audits, financing, or risk management.
  8. Government, courts, and lawful requestors. We may provide information when reasonably necessary to comply with law, legal process, regulatory or customs requirements, or a valid governmental request, or to protect rights, safety, security, or the integrity of the Services.
  9. Corporate transactions. Information may be reviewed or transferred in connection with a financing, reorganization, acquisition, merger, sale of assets, insolvency, or similar transaction, subject to appropriate confidentiality and any notice required by law.
  10. With direction or consent. We may disclose information for another purpose when the individual or Customer has instructed us to do so or provided valid consent.

Service providers and processors may use information only for the contracted services, legal compliance, security, or other purposes permitted by their agreements and applicable law. Independent third parties, such as a carrier, marketplace, payment provider, or Customer-selected application, may also process information under their own privacy terms when acting for their own purposes.

8. Connected Services and Customer-Directed Exchanges

A Customer chooses whether to connect a store, marketplace, carrier account, warehouse, payment service, developer application, or other external system. The connection may use OAuth, API keys, credentials, webhooks, files, or another authorization method. SyncShip receives and sends information within the scopes authorized by the Customer and supported by the third party.

The Customer should review each Connected Service's requested permissions and privacy terms. Disconnecting a service generally stops new exchanges but does not automatically erase information already received, records required for completed transactions, or information retained independently by the third party. Revoking a connection may prevent order synchronization, tracking updates, label creation, refunds, or other functions.

If a Customer authorizes an application or developer to access its Account, that party's collection and use may be governed by its own privacy notice. SyncShip is not responsible for an independent party's practices, but may limit or revoke technical access when we reasonably believe it threatens security, violates law, or does not comply with SyncShip's developer requirements.

9. Marketplace Buyers, Recipients, and Customer Responsibilities

Customers determine which order and recipient information enters SyncShip and how it will be used in their commerce and fulfillment operations. Each Customer is responsible for having an appropriate legal basis, providing its own privacy notices, honoring marketplace and carrier rules, limiting user access, and giving SyncShip only lawful instructions.

Recipient information may be used to create a label, validate an address, arrange a delivery or return, provide tracking, respond to a delivery issue, meet customs or carrier requirements, prevent fraud, and retain transaction records. SyncShip does not use Customer-provided recipient address lists to market unrelated SyncShip services directly to recipients unless SyncShip has a separate lawful relationship and provides any required notice.

A Customer must not combine or repurpose marketplace data in a way prohibited by the marketplace's developer or data-protection rules. Where source-specific rules impose stricter use, disclosure, deletion, or retention limits, those rules may restrict what SyncShip and the Customer may do with the data.

10. Carrier, Postal, Customs, and Protection Data

A label or shipment request necessarily sends information to a carrier, postal operator, authorized postage provider, customs participant, broker, or protection provider. Those entities may need names, addresses, contact details, package attributes, customs descriptions, values, classification codes, account information, and payment or claim details. They may return tracking scans, delivery events, surcharges, inspections, customs outcomes, signatures, returns, refunds, or claims information.

A carrier or postal operator may act as an independent controller for transportation, network security, regulatory reporting, customs, claims, fraud prevention, and its own legal obligations. Its privacy notice and shipping terms apply to those activities. SyncShip does not control every downstream use required by a carrier or governmental authority.

Certain USPS or authorized-postage programs may present a Privacy Act statement, customer registration notice, or other program disclosure during enrollment or label purchase. Any statement required by that program supplements this Policy. SyncShip will not claim that it is a postal operator merely because the Services transmit data to or receive data from USPS or another carrier.

11. Payments and the SyncShip Balance

SyncShip uses payment gateways, processors, banks, wallet providers, and risk services to handle supported payment methods. Their privacy notices apply to information they collect for payment authorization, identity verification, settlement, disputes, and compliance. SyncShip may send them Account, billing, device, transaction, and fraud-prevention information and receive the results described in this Policy.

After an eligible funding transaction is confirmed, SyncShip credits the Customer's Balance ledger. The Balance is restricted to postage-label transactions with carriers, including corrections attributable to those labels; it is not a general-purpose payment account, cannot be transferred to another user, and is not available for routine withdrawal. We use Balance records to authorize label purchases, apply refunds and carrier adjustments, investigate payment reversals, prevent abuse, reconcile accounts, and satisfy financial and legal recordkeeping duties.

SyncShip does not sell payment credentials or Balance information for advertising. Payment information may be disclosed to processors, financial institutions, carriers, fraud services, professional advisers, or authorities for the transaction, security, accounting, collections, dispute, or legal purpose for which it is needed.

12. APIs, Applications, and Developer Access

Customers and approved developers may use SyncShip APIs to transmit orders, retrieve rates, create labels, receive tracking events, manage webhooks, and perform other documented functions. API access can expose Customer Data, including personal information, according to the credential's scopes and the user's Account permissions. Customers must protect credentials, use least-privilege access, and promptly revoke access that is no longer required.

SyncShip may log API requests, credential events, network information, payload metadata, and limited payload content for delivery, support, security, rate limiting, fraud prevention, debugging, billing, and compliance. We may retain security and transaction logs after a credential is revoked when needed to investigate misuse, document transactions, or satisfy legal and third-party program requirements.

A developer that obtains personal information through a Customer's authorization must publish and follow an accurate privacy notice, collect only what its application needs, use data only for authorized purposes, protect credentials and data, honor deletion and revocation requirements, and comply with applicable source platform rules. SyncShip may review or suspend an application to protect Customers, Downstream Individuals, Connected Services, and the integrity of the platform.

13. Cookies and Similar Technologies

SyncShip and providers acting for us may use cookies, local or session storage, pixels, tags, scripts, SDKs, server logs, conversion APIs, and comparable technologies on the website or within the Services. These tools can recognize a browser or device, preserve a session, measure use, remember settings, diagnose errors, protect access, and evaluate communications or marketing. A cookie is a small browser-stored file; other technologies may collect similar identifiers or event information without placing a traditional cookie.

Technology categories

  1. Strictly necessary. Supports login, security, load balancing, fraud protection, consent settings, shopping or payment flow, and other functions required to provide a requested service. These technologies generally cannot be disabled through our preference tool.
  2. Functional. Remembers language, region, display, workflow, or other choices that make the Services easier to use.
  3. Analytics and performance. Measures visits, feature use, errors, response time, navigation, and campaign effectiveness so we can understand and improve the Services.
  4. Advertising and measurement. May help SyncShip measure campaigns, limit repeated ads, build audiences, or show more relevant business advertising on other services. These technologies are used only where enabled and permitted.

Examples of information collected

These technologies may collect a cookie or device identifier, IP address, approximate region, browser and device characteristics, referring URL, pages or screens viewed, actions taken, session duration, campaign or click identifier, and whether an email or feature was engaged. Where session-replay or interaction analytics is used, we configure it to support product and usability analysis and seek to mask sensitive form fields; users should not enter secrets into unapproved fields.

Your controls

Where a cookie preference tool is displayed, it can be used to accept, reject, or change non-essential technology choices. Browser and device settings may also block or delete cookies, limit advertising identifiers, or restrict tracking. Disabling a required technology may prevent login, preference storage, payment confirmation, or another requested function. Choices may need to be repeated after cookies are cleared, a different browser or device is used, or an anonymous session is started.

SyncShip distinguishes Global Privacy Control and other legally recognized opt-out preference signals from a general browser 'Do Not Track' setting. Where applicable law requires and the signal can be associated with the browser, device, or known profile, we treat a valid opt-out preference signal as a request to opt out of sale, sharing, or targeted advertising for the applicable context. Because there is no uniform legal standard for ordinary Do Not Track signals, the Services may not respond to those signals unless law requires otherwise.

14. Sale, Sharing, and Targeted Advertising

SyncShip does not sell personal information for monetary payment. We also do not sell or disclose Customer-provided order-recipient data, shipment addresses, customs information, label data, Balance information, payment credentials, or SMS opt-in records to third parties for their independent marketing.

If SyncShip enables advertising or cross-service measurement technologies, online identifiers, approximate location, and website activity may be made available to analytics or advertising providers. Some U.S. state laws may call this a 'sale,' 'sharing,' or processing for targeted advertising even when no money is paid for the information. An individual may use the available cookie controls, a recognized opt-out preference signal, or the request method in this Policy to exercise an applicable opt-out right.

This advertising disclosure concerns website and marketing activity, not the operational disclosures needed to connect stores, buy labels, route shipments, process payments, prevent fraud, or provide Customer-requested services. SyncShip does not knowingly sell or share personal information of anyone under 16.

15. Service Messages, Marketing, and SMS

We may send Account, authentication, security, transaction, label, tracking, billing, support, legal, and service-change messages that are reasonably necessary to administer the relationship. These operational messages are not marketing, and an Account may not be able to opt out of them while the relevant service or transaction remains active.

Where permitted, we may send product news, invitations, educational material, promotions, or other business marketing. A recipient can unsubscribe through the link in an email or contact us. An unsubscribe request may take a reasonable time to apply across systems and does not stop transactional or legally required messages.

If a user asks to receive SMS or similar messages, message and data charges may apply. Instructions in the message, including replying STOP where supported, can be used to withdraw from optional messages. Mobile numbers, SMS consent, and opt-in records are not sold or shared with unaffiliated third parties for their own marketing. Communications providers may process them only to deliver, secure, or administer the messaging service.

16. Automation, Fraud Models, and AI-Enabled Tools

The Services use customer-configured rules and automated processing to synchronize orders, validate fields, select configured workflows, route requests, detect errors, apply permissions, prevent abuse, and flag transactions that may need review. A Customer remains responsible for the rules it configures and should review material outputs before acting on them.

SyncShip may use machine-learning or AI-enabled tools for fraud detection, security monitoring, support suggestions, document or data extraction, address and shipment quality checks, forecasting, and product improvement. We seek to minimize the personal information supplied to such tools and use providers under contractual, confidentiality, and security restrictions appropriate to the function.

SyncShip does not use Customer-provided recipient or order data to train a publicly available general-purpose AI model. We do not intend to make a decision based solely on automated processing that produces legal or similarly significant effects about an individual. If a covered use is introduced, SyncShip will provide the notice, explanation, human review, objection, or appeal rights required by applicable law.

Automated security or risk processing may delay a payment, label, connection, or Account action while verification occurs. A Customer can contact support to ask for review, subject to measures needed to protect fraud-detection methods and other users.

17. Deidentified, Aggregated, and Statistical Information

SyncShip may transform information into statistics or other data that is not reasonably capable of being linked to an individual. We may use such information to measure carrier or feature performance, understand shipping trends, plan capacity, benchmark workflows, detect abuse, improve products, and prepare business reports. We maintain deidentified information in deidentified form and do not attempt to reidentify it except to test whether deidentification safeguards remain effective or as otherwise permitted by law.

Aggregated or deidentified information may be disclosed to Customers, carriers, partners, advisers, or the public when the disclosure does not reasonably identify an individual. Source-specific marketplace, carrier, or contract restrictions continue to apply even when applicable privacy law would otherwise treat the data as non-personal.

18. Data Retention

We retain personal information for the shortest period reasonably necessary for the purpose for which it was collected, taking account of the Account relationship, transaction lifecycle, Customer instructions, carrier and marketplace rules, legal and accounting obligations, limitation periods, disputes, security needs, and backup schedules. The applicable period therefore varies by record and context.

  1. Account and user records. Generally retained while the Account is active and for a reasonable period afterward for reactivation, audit, billing, security, dispute, and legal purposes.
  2. Order, recipient, label, shipment, customs, and tracking records. Retained as needed to complete fulfillment, obtain tracking, process returns, refunds, claims, and carrier adjustments, support the Customer, meet source-platform rules, and satisfy tax, postal, customs, and legal duties.
  3. Payment and Balance records. Retained for reconciliation, fraud and chargeback review, collections, financial reporting, tax, audit, and legal recordkeeping. Financial records may be kept for a longer statutory period even after an Account closes.
  4. Support and communications. Retained for issue resolution, quality, training, security, claims, and relationship history, with duration based on sensitivity and operational need.
  5. Security, authentication, and API logs. Retained for a period appropriate to investigate incidents, enforce limits, detect patterns, defend the Services, and meet contractual or legal requirements.
  6. Cookies and advertising identifiers. Retained according to the technology's configured lifecycle, the consent or preference tool, provider settings, and applicable law.
  7. Verification and compliance records. Retained only for the verification, risk, sanctions, carrier-program, tax, legal, or audit period that requires them, with access restricted according to sensitivity.

When deletion is appropriate, information may be deleted, anonymized, or isolated from ordinary use. Deletion from active systems may not immediately remove copies from disaster-recovery backups; those copies are protected, not restored for ordinary business use, and removed or overwritten through the backup cycle. We may preserve information subject to a legal hold, fraud investigation, unresolved transaction, carrier adjustment, or other lawful exception.

19. Security

SyncShip uses administrative, technical, and physical measures designed to protect personal information against unauthorized access, acquisition, alteration, disclosure, loss, or destruction. Depending on the system and risk, these measures may include encryption in transit, protected storage, role-based access, multifactor authentication, network and application controls, logging, monitoring, vulnerability management, incident response, backups, vendor review, confidentiality obligations, and personnel training.

No online service, transmission, or storage method can be guaranteed completely secure. Customers contribute to security by using unique credentials, enabling available multifactor authentication, limiting roles, protecting API keys and Connected Service tokens, reviewing users, securing their own devices and networks, and promptly reporting suspected compromise to info@sync-ship.com.

If SyncShip confirms a security incident involving personal information, we will investigate, contain, remediate, and provide notifications to Customers, individuals, regulators, or other parties when and as required by law or contract. To protect users, we may temporarily reset credentials, suspend connections, restrict transactions, or require additional verification.

20. International Processing and Transfers

SyncShip is established in the United States, and personal information may be processed in the United States. Cloud, support, security, payment, carrier, marketplace, and other providers may process information in the countries where they operate. A cross-border shipment also requires information to reach carriers, customs participants, and authorities in origin, transit, and destination jurisdictions.

Where applicable law restricts international transfers, SyncShip uses a recognized transfer mechanism or other lawful basis appropriate to the relationship. Depending on the jurisdiction and transfer, this may include an adequacy determination, standard contractual clauses approved by the European Commission, the UK International Data Transfer Agreement or UK Addendum, contractual and technical safeguards, consent where lawfully available, or a statutory exception for a necessary transaction or legal claim.

SyncShip does not claim participation in the EU-U.S. Data Privacy Framework or its UK or Swiss extensions unless SyncShip appears as an active participant on the official program list and updates this Policy. An applicable Data Processing Addendum may provide additional transfer terms and a method to request information about the safeguards used for Customer Data.

Foreign courts, regulators, law-enforcement agencies, customs authorities, or national-security bodies may have lawful access to information processed in their jurisdiction. SyncShip evaluates requests under the applicable legal process and discloses only the information reasonably required, subject to lawful restrictions.

21. Privacy Choices and Individual Rights

Depending on residence, relationship, and applicable law, an individual may have rights to confirm processing, obtain access, receive a copy, correct inaccurate information, delete information, restrict or object to processing, receive portable data, withdraw consent, opt out of targeted advertising or sale, limit certain uses of sensitive information, obtain information about automated processing, or appeal a denied request. Rights are subject to legal definitions, exceptions, verification, and the role in which SyncShip holds the data.

Account controls

Authorized users may be able to review or update profile, contact, role, integration, notification, and other Account information directly in the Services. An Account administrator may control information for other users. Some transaction, security, or legal records cannot be changed through the Account and may need to be retained.

Marketing and tracking choices

Marketing email can be declined through its unsubscribe link. Optional SMS can be stopped through the provided instruction. Non-essential cookies can be managed through the available preference tool or browser settings. A valid Global Privacy Control or other recognized opt-out signal will be handled as described in the Cookies section. These choices do not stop service messages or transaction disclosures needed to fulfill a request.

Consent withdrawal

Where processing is based on consent, the individual may withdraw that consent for future processing. Withdrawal does not make earlier lawful processing invalid and may prevent a requested optional feature, connection, communication, or service from continuing.

22. Submitting, Verifying, and Appealing a Privacy Request

How to submit

A request may be sent to info@sync-ship.com with the subject line 'Privacy Request' or mailed to the address in the Contact section. The request should identify the individual, the right being exercised, the country or U.S. state of residence, the email address or Account involved, and enough context for SyncShip to locate the relevant records. Do not email a password, full payment credential, or unnecessary identification document.

Customer-controlled information

If the request concerns order, buyer, recipient, or shipment information processed for a Customer, the requester should normally contact that Customer. SyncShip may refer the requester to the Customer or ask the Customer for instructions. We will assist covered Customers with verified requests as required by the Customer agreement, Data Processing Addendum, and applicable law.

Identity and authority verification

We verify a request using information reasonably matched to our records, such as Account access, email confirmation, transaction details, business affiliation, or other appropriate evidence. The verification method depends on the sensitivity of the information and the risk of unauthorized disclosure or deletion. If we cannot verify identity or authority with reasonable confidence, we may ask for additional information or decline the request to protect the individual and other parties.

Authorized agents

Where law permits an authorized agent, the agent must provide evidence of authority and information sufficient to verify the request. We may also contact the individual directly to confirm the authorization unless a valid power of attorney or another legal exception applies. SyncShip may reject an agent request that cannot be authenticated.

Response, exceptions, and appeals

SyncShip will respond within the period required by applicable law and will provide notice if a lawful extension is needed. A request may be limited or denied when an exception applies, including security, fraud prevention, legal privilege, another person's privacy, transaction completion, accounting or tax obligations, carrier or customs records, legal claims, or an inability to verify the requester. When required, we will explain a denial and provide instructions to appeal. An appeal should be sent with the subject 'Privacy Rights Appeal' within the period stated in our response.

SyncShip will not unlawfully discriminate against an individual for exercising a privacy right. A different experience may result when information is necessary for a requested service, when a feature depends on valid consent, or when law allows a reasonably related price or service difference.

23. Children and Age Restrictions

SyncShip provides business services and does not direct the Services to children. A person must be at least 18 years old to create or control an Account. We do not knowingly collect personal information directly from a child through child-directed activity, and we do not knowingly sell or share personal information of anyone under 16.

A Customer's order data could incidentally identify a minor recipient. In that context, SyncShip processes the information to fulfill the Customer's shipping instructions and not to profile or market to the child. If a parent or guardian believes a child submitted personal information directly to SyncShip without appropriate authorization, the parent or guardian may contact us so we can investigate and take action required by law.

24. Third-Party Sites, Embedded Content, and Social Features

The website or Services may link to a carrier, marketplace, payment provider, social network, video, support tool, or other third-party service. An embedded control or social feature may allow the third party to collect IP address, device information, page activity, and any information the user chooses to send. A third party's privacy notice governs its independent collection and use. A link or integration does not mean SyncShip controls or endorses all of that party's privacy practices.

Users should review third-party notices before supplying information or enabling a connection. SyncShip's privacy choices do not automatically change settings maintained by another company, and disconnecting a third-party service does not require that company to delete information it lawfully retained for its own purposes.

25. Changes to This Policy

We may revise this Policy to reflect changes in the Services, data practices, vendors, integrations, law, or business operations. The revised version will show a new Last Updated date and will be posted through the website or Services. If a change materially affects how we use personal information, we will provide any additional notice or consent required by applicable law, which may include an Account notice, email, website banner, or notice at the point of collection.

A policy revision does not retroactively make an incompatible use lawful. We encourage Customers to review this Policy periodically and to keep their Account contact information current so they can receive important notices.

26. Contact SyncShip

Questions, complaints, privacy requests, consent withdrawals, and appeals concerning this Policy may be directed to:

SyncShip LLCAttention: Privacy360 Florence AveHillside, NJ 07205United States

Email: info@sync-ship.com

Website: sync-ship.com

Please use 'Privacy Request' for an initial rights request and 'Privacy Rights Appeal' for an appeal. If the inquiry concerns a merchant order or delivery, include the merchant name and order or tracking reference, but do not include a password or complete payment credential.

JURISDICTION-SPECIFIC ADDENDA. The following provisions supplement the main Policy. They apply only when the identified law covers the individual and SyncShip's processing. If an addendum conflicts with the main Policy, the addendum controls for that jurisdiction to the extent of the conflict.

27. California Privacy Notice

This section serves as a California Notice at Collection and privacy disclosure for California residents where the California Consumer Privacy Act, as amended, applies. Terms such as personal information, sensitive personal information, sell, share, business purpose, service provider, and consumer have the meanings assigned by California law. The categories below describe information collected during the preceding 12 months and information SyncShip reasonably expects to collect while this notice remains current.

Categories, sources, purposes, recipients, and retention

Identifiers and contact information

Examples. Examples include name, business or household address, email, telephone number, username, Account identifier, IP address, marketplace or carrier identifier, and tracking or label identifier.

Sources. Sources include the individual, Customer administrators, Connected Services, carriers, payment providers, applications, public or commercial verification sources, and automatic technology.

Purposes. Purposes include Account administration, shipping, order synchronization, support, communications, security, verification, fraud prevention, legal compliance, and marketing where permitted.

Disclosures. Recipients may include carriers, marketplaces, payment and fraud providers, cloud and business vendors, Customer-authorized parties, advisers, transaction participants, and authorities.

Retention. Retention is based on the Account and transaction lifecycle, carrier and marketplace rules, security needs, legal obligations, disputes, and backup cycles.

Customer records and business relationship information

Examples. Examples include billing and business contact details, signature or acceptance records, Account role, customer-service history, and verification information. Government identifiers are collected only when a verification, carrier, payment, tax, or legal requirement makes them necessary.

Sources. Sources include the individual, the Customer, verification providers, payment services, carriers, public registries, and professional or commercial sources.

Purposes. Purposes include onboarding, verification, billing, support, contract administration, risk management, dispute handling, and legal compliance.

Disclosures. Recipients may include verification, payment, fraud, cloud, security, support, accounting and professional providers, carriers, and authorities where required.

Retention. Retention follows the business relationship and any longer verification, accounting, tax, sanctions, dispute, or legal period that applies.

Commercial and transaction information

Examples. Examples include subscription, payment, Balance, label, shipment, refund, adjustment, return, claim, order, and service-use history.

Sources. Sources include the individual, Customers, marketplaces, carriers, payment providers, warehouses, applications, and SyncShip systems.

Purposes. Purposes include providing the Services, processing and reconciling transactions, support, analytics, forecasting, security, collections, accounting, and compliance.

Disclosures. Recipients may include carriers, marketplaces, payment providers, cloud and operational vendors, Customer-selected partners, advisers, and authorities.

Retention. Retention is tied to transaction completion and the periods needed for adjustments, refunds, claims, fraud, accounting, tax, audit, contract, and legal obligations.

Internet, device, and electronic activity

Examples. Examples include browser and device data, IP address, cookie or device identifiers, login and API events, pages or features used, interactions, error logs, and advertising or campaign activity.

Sources. Sources include browsers, devices, servers, cookies, SDKs, analytics, security tools, communications, and advertising or measurement providers.

Purposes. Purposes include providing and securing the Services, authentication, fraud prevention, troubleshooting, analytics, product improvement, communications measurement, and advertising where enabled.

Disclosures. Recipients may include hosting, security, support, analytics, communications, and advertising or measurement providers.

Retention. Retention follows security and operational needs, log schedules, cookie lifecycles, consent choices, provider settings, and legal requirements.

Approximate geolocation

Examples. Examples include city, region, or country inferred from an IP address. Precise GPS location is not required for ordinary label creation and would be collected only for a feature that needs it and with any required permission.

Sources. Sources include devices, network information, security services, and location features enabled by the user.

Purposes. Purposes include security, fraud prevention, localization, service availability, analytics, and a location-dependent feature requested by the user.

Disclosures. Recipients may include cloud, security, analytics, fraud, and feature providers.

Retention. Retention follows the underlying log, security, cookie, feature, and legal schedule.

Professional and organizational information

Examples. Examples include employer, business name, title, role, department, authority, Account permissions, warehouse location, and professional contact details.

Sources. Sources include the individual, Customer administrators, business directories, Connected Services, and verification sources.

Purposes. Purposes include Account and relationship management, authentication, authorization, sales, support, security, and compliance.

Disclosures. Recipients may include vendors that support account operations, communications, sales, security, and verification, plus Customer-authorized users.

Retention. Retention generally follows the Account and business relationship, with longer retention where needed for security, contracts, claims, or law.

Inferences and risk indicators

Examples. Examples include likely preferences, workflow suggestions, address-quality indicators, support needs, shipment-risk signals, and fraud or account-security indicators.

Sources. Sources include the categories above and outputs of analytics, security, and rules-based or automated tools.

Purposes. Purposes include personalization, workflow improvement, support, security, fraud detection, quality control, and product development.

Disclosures. Recipients may include cloud, analytics, security, fraud, support, and Customer-authorized operational providers.

Retention. Retention is based on the usefulness and sensitivity of the indicator, the underlying transaction or security need, and legal requirements.

Sensitive personal information

Examples. Examples may include Account credentials, government identifiers used for verification, payment account information handled by payment providers, precise location if a user enables a qualifying feature, and the content of communications sent to support. Shipment text may incidentally reveal sensitive facts.

Sources. Sources include the individual, Customer, payment and verification providers, Connected Services, devices, and support communications.

Purposes. Purposes are limited to authentication, payment, verification, security, fraud prevention, requested support, shipping, legal compliance, and other purposes California law permits without a right to limit.

Disclosures. Recipients are limited to providers and parties necessary for those purposes, such as payment, verification, security, support, carrier, legal, and governmental recipients.

Retention. Retention is limited according to sensitivity and the verification, transaction, support, security, or legal period that requires the information.

Sale, sharing, and advertising status

SyncShip does not sell personal information for money. If advertising or cross-service measurement tools are enabled, SyncShip may share identifiers, internet or device activity, approximate location, and related inferences with advertising or analytics providers in a manner California law treats as sharing for cross-context behavioral advertising. SyncShip does not sell or share Customer-provided order-recipient data, shipping addresses, label or customs data, payment credentials, Balance information, or SMS consent data for that purpose. California residents may opt out through available cookie settings, a recognized opt-out preference signal, or a Privacy Request.

California rights

  1. Know the categories of personal information collected, sources, purposes, retention criteria, categories sold or shared, and categories of recipients.
  2. Request access to applicable specific pieces of personal information, subject to verification and legal exceptions.
  3. Request correction of inaccurate personal information and deletion of personal information, subject to exceptions.
  4. Opt out of sale or sharing and cross-context behavioral advertising where those activities occur.
  5. Limit use and disclosure of sensitive personal information when the information is used outside purposes California law permits without a limitation right.
  6. Receive equal service and pricing without unlawful retaliation for exercising a California privacy right.

Requests are submitted and verified under Section 22. A California resident may use an authorized agent as described there. We may deny or limit a request when California law permits, and we will explain the decision and any available next step. We do not use sensitive personal information to infer characteristics or for another purpose that presently triggers the right to limit. If that changes, we will provide an appropriate method to limit use.

Minors, financial incentives, and direct marketing

SyncShip has no actual knowledge that it sells or shares personal information of anyone under 16. We do not currently offer a financial incentive or price difference in exchange for personal information. If we introduce such a program, we will provide its material terms and obtain any required opt-in before enrollment.

California Civil Code Section 1798.83 may allow certain California residents to ask whether defined categories of personal information were disclosed to outside parties for those parties' direct-marketing activities. SyncShip does not disclose order-recipient information or other covered personal information to unaffiliated third parties for their own direct marketing without an applicable choice. A request may be sent with the subject 'California Direct Marketing Request.'

28. Nevada Residents

Nevada law may give a covered consumer the right to submit a verified request directing an operator not to sell specified covered information for monetary consideration to a person that will license or sell it to another person. SyncShip does not engage in that type of sale. A Nevada resident may nevertheless send a request to info@sync-ship.com with the subject 'Nevada Privacy Request' and include the email address associated with the interaction, Nevada residency, and enough information for verification. We will respond within the period required by Nevada law and may request additional information to authenticate the request.

29. Residents of Other U.S. States

Comprehensive state privacy laws may apply to residents of Colorado, Connecticut, Delaware, Indiana, and Iowa. They may also apply in Kentucky, Maryland, Minnesota, Montana, and Nebraska, while comparable requirements exist in New Hampshire, New Jersey, and Oregon. Rhode Island, Tennessee, Texas, Utah, Virginia, and other states have also adopted similar laws. Coverage and rights differ by state, often depend on legal thresholds, and generally concern individuals acting in a personal or household context. This section applies only to the extent the relevant state law covers SyncShip and the information at issue.

State-law rights

  1. Confirm and access. Confirm whether SyncShip processes personal data and access covered data.
  2. Correct. Correct inaccuracies, taking account of the nature and purpose of the information.
  3. Delete. Delete personal data provided by or obtained about the consumer, subject to exceptions.
  4. Portability. Receive covered data in a portable and readily usable format when technically feasible.
  5. Opt out. Opt out of targeted advertising, sale, or qualifying profiling that produces a legal or similarly significant effect, where the resident's state provides that right.
  6. Consent and sensitive data. Withdraw consent or exercise state-specific choices concerning sensitive data when applicable.
  7. Non-discrimination. Exercise a covered right without unlawful discriminatory treatment.

SyncShip does not sell personal data for monetary payment. Website advertising or cross-service measurement may be treated as targeted advertising or a sale under a broad state definition. A resident can opt out using available cookie settings, a recognized universal opt-out mechanism, or a Privacy Request. Operational disclosures to carriers, marketplaces, processors, and Customer-selected services are not targeted advertising.

Requests, agents, and appeals

A state request is submitted under Section 22. We may authenticate residency, identity, Account relationship, and agent authority using commercially reasonable methods. A consumer generally may make the number of free requests provided by the applicable law. SyncShip will respond within the statutory period and may take a lawful extension after notice. If a covered request is denied, residents of states providing an appeal right may appeal by emailing info@sync-ship.com with the subject 'Privacy Rights Appeal.' Our appeal response will explain the result and, where required, how to contact the appropriate state attorney general.

Sensitive data and significant decisions

SyncShip processes sensitive information only when reasonably necessary for authentication, payment, business verification, fraud prevention, a requested shipment or support function, or legal compliance. We do not process personal data for qualifying profiling that makes a solely automated legal or similarly significant decision about an individual. If either practice changes, we will implement the consent, assessment, opt-out, or appeal mechanism required by the applicable state.

30. European Economic Area, Switzerland, and United Kingdom

This section applies when the EU General Data Protection Regulation, UK GDPR, Swiss Federal Act on Data Protection, or related national law governs SyncShip's processing. 'Personal data,' 'controller,' 'processor,' and 'data subject' carry the meanings assigned by the applicable law.

Controller and processor roles

SyncShip LLC is the controller for Account administration, billing and Balance records, security, website operations, relationship management, marketing, and other purposes SyncShip determines. For order, recipient, and shipment data processed only under a Customer's instructions, the Customer is ordinarily the controller and SyncShip is its processor. Processor terms, subprocessors, assistance, deletion, audits, and international transfer provisions may be addressed in a Data Processing Addendum.

Lawful bases

  1. Contract and requested pre-contract steps. We use Account, transaction, integration, payment-status, shipping, support, and related information to provide the Services, administer the Account, and perform actions requested before or during the commercial relationship.
  2. Legitimate interests. We use information to secure and improve the Services, prevent fraud and prohibited use, maintain business records, provide B2B support and relevant communications, analyze performance, manage vendors, establish or defend legal claims, and operate a reliable commercial platform. We assess whether those interests are overridden by an individual's rights and expectations.
  3. Legal obligation. We process information when needed for tax, accounting, sanctions, customs, carrier or postal requirements, lawful governmental requests, security or breach obligations, and other duties imposed by law.
  4. Consent. We rely on consent for optional marketing, non-essential cookies, a voluntary location or communications feature, or another activity where consent is the appropriate basis. Consent can be withdrawn for future processing.
  5. Vital interests or public interest. In unusual circumstances, information may be processed to protect someone's life or safety or to perform a task in the public interest when applicable law provides that basis.

Providing information is generally voluntary, but Account, transaction, recipient, package, payment, and verification information may be contractually or operationally necessary. Without it, SyncShip may be unable to create an Account, connect a service, purchase a label, complete a shipment, provide support, or meet a legal obligation.

Data subject rights

  1. Access personal data and obtain information about its processing.
  2. Correct inaccurate or incomplete personal data.
  3. Request erasure where a lawful retention ground does not apply.
  4. Restrict processing in circumstances provided by law.
  5. Object to processing based on legitimate interests and object at any time to direct marketing.
  6. Receive data supplied to SyncShip in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies.
  7. Withdraw consent without affecting processing that was lawful before withdrawal.
  8. Not be subject to a decision based solely on automated processing that has a legal or similarly significant effect, except where law permits and safeguards are provided.
  9. Complain to the data-protection authority for the place of residence, work, or alleged infringement.

The right to object to direct marketing is unconditional. Other rights may be limited by contract, legal obligation, legal claims, public interest, another person's rights, or another statutory exception. Requests are made under Section 22. If SyncShip is a processor, the request should be directed to the relevant Customer controller.

International transfers

Personal data may be processed in the United States and other countries that may not have been recognized as providing equivalent protection. Where required, SyncShip relies on an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. We may apply supplemental contractual, access, encryption, or security measures based on the transfer and risk. A Customer may request additional information through the privacy contact.

Retention, DPO, and representatives

Retention follows Section 18 and is limited by purpose, legal duty, Customer instruction, and transaction need. SyncShip's privacy contact coordinates GDPR and UK GDPR matters. If applicable law requires SyncShip to appoint a data protection officer or an EU, UK, or Swiss representative, the relevant contact information will be provided in an applicable supplemental notice, Data Processing Addendum, or Service interface.

EEA residents may identify their national supervisory authority through the European Data Protection Board. UK residents may contact the Information Commissioner's Office. Swiss residents may contact the Federal Data Protection and Information Commissioner. We ask individuals to contact SyncShip first so we have an opportunity to address the concern.

EEA authorities: European Data Protection Board member authorities

United Kingdom: Information Commissioner's Office

Switzerland: Federal Data Protection and Information Commissioner

31. Canada

This section applies when the Personal Information Protection and Electronic Documents Act or substantially similar provincial law governs SyncShip's commercial handling of personal information. SyncShip is accountable for personal information under its control and identifies purposes at or before collection, limits collection to what is reasonably necessary, and uses, discloses, retains, safeguards, and provides access to information in accordance with applicable Canadian requirements.

Consent and service necessity

Consent may be express or implied depending on sensitivity, reasonable expectations, and the circumstances. Some processing is permitted without consent by law. An individual may withdraw consent for future processing, subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent SyncShip or a Customer from providing a requested integration, shipment, support function, or communication.

Canadian rights

  1. Ask whether SyncShip holds personal information about the individual and obtain information about its use and disclosure.
  2. Access personal information, subject to lawful exceptions protecting another person, legal privilege, security, confidential commercial information, or other protected interests.
  3. Challenge accuracy and completeness and request an appropriate correction or notation of a dispute.
  4. Withdraw consent where consent is the basis, and challenge SyncShip's compliance with applicable Canadian privacy requirements.

Requests are made under Section 22. We may verify identity and ask for enough detail to locate the information. We will respond within the period required by the applicable federal or provincial law and will explain any lawful refusal. Access will be provided at minimal or no cost unless law permits a reasonable charge disclosed in advance.

Cross-border processing

Canadian personal information may be processed in the United States and in other countries where cloud, payment, carrier, marketplace, support, security, or Customer-selected providers operate. It may be accessible to courts, regulators, and law-enforcement authorities under the law of those places. SyncShip uses contractual and security measures appropriate to the role and sensitivity and remains responsible for information under its control as required by Canadian law.

Commercial electronic messages and complaints

Marketing electronic messages are sent with consent or another basis permitted by Canada's Anti-Spam Legislation and include an unsubscribe method. Unsubscribing does not stop messages needed for an Account, transaction, security, legal notice, or requested support. An unresolved complaint may be directed to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator after contacting SyncShip.

Federal regulator: Office of the Privacy Commissioner of Canada

32. Australia

This section applies to the extent the Privacy Act 1988 (Cth) and Australian Privacy Principles cover SyncShip's handling of personal information. The main Policy explains the kinds of information collected, how it is collected and held, the purposes for use and disclosure, and how an individual may seek access, correction, or make a complaint.

Consequences if information is not provided

If required information is not provided, SyncShip may be unable to establish or secure an Account, verify a business or payment, connect a store or carrier, quote or purchase a label, create customs documents, process a Balance transaction, investigate a claim, respond to support, or comply with law. Optional marketing and non-essential cookies can generally be declined without preventing core service use, although features may be less personalized.

Overseas recipients

Australian personal information is likely to be disclosed to recipients in the United States, where SyncShip and primary infrastructure may operate. Depending on the Customer's selected carriers, marketplaces, payment services, applications, support arrangements, and shipment destinations, recipients may also be located in Canada, the United Kingdom, the European Economic Area, New Zealand, Australia, and origin, transit, or destination countries. Because a Customer can select global third parties and shipping routes, it is not always practicable to identify every country in advance.

Where the Australian Privacy Principles require it, SyncShip takes steps reasonable in the circumstances to address an overseas recipient's handling of personal information. A carrier, marketplace, payment provider, or other party may be an independent organization with its own obligations and privacy notice.

Access, correction, and complaints

  1. Request access to personal information SyncShip holds about the individual.
  2. Ask SyncShip to correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
  3. Complain about an alleged breach of the Australian Privacy Principles or an applicable privacy code.

A request or complaint is submitted under Section 22 with enough detail for investigation. We may verify identity, protect another person's information, and rely on a lawful refusal ground. We will respond within a reasonable period, give written reasons where required, and generally do not charge for a correction or complaint. If a permitted access charge is appropriate, it will be reasonable and communicated in advance.

We will investigate a privacy complaint, may request additional information, and will communicate the outcome. If the individual remains dissatisfied, the individual may complain to the Office of the Australian Information Commissioner.

Australian regulator: Office of the Australian Information Commissioner

33. New Zealand

Where New Zealand's Privacy Act 2020 applies, SyncShip handles personal information consistently with the applicable information privacy principles, including purpose limitation, reasonable security, retention only as long as required for a lawful purpose, and controls on disclosure and overseas transfer.

An individual may request access to readily retrievable personal information and ask for correction. If SyncShip does not make a requested correction, the individual may ask us to attach a statement describing the requested correction where the law requires. We may verify identity and may withhold information on a ground permitted by law, in which case we will provide the required explanation and complaint information.

New Zealand information may be sent to the United States and to other countries involved in cloud services, payments, integrations, carriers, or the selected shipping route. SyncShip uses a lawful basis and safeguards appropriate to the disclosure. An unresolved concern may be submitted to the Office of the Privacy Commissioner of New Zealand.

New Zealand regulator: Office of the Privacy Commissioner

34. United Arab Emirates, Saudi Arabia, and Mexico

United Arab Emirates

If the UAE Personal Data Protection Law or a free-zone privacy regime applies, an individual may have rights to information about processing, access, correction, deletion, restriction or objection, portability, and review of certain automated processing, subject to the applicable regime and exceptions. SyncShip processes UAE personal data for the purposes in this Policy and uses a lawful cross-border mechanism or exception when required.

The federal UAE regime, the Dubai International Financial Centre, and the Abu Dhabi Global Market have different rules and regulators. The applicable notice, contract, or Customer location determines the regime. A UAE request may be submitted under Section 22, and SyncShip will identify any relevant regulator or local process when responding if the law requires it.

Saudi Arabia

Where Saudi Arabia's Personal Data Protection Law applies, a data subject may have rights to be informed, access personal data, obtain it in a clear format, request correction, completion or updating, and request destruction when a lawful retention ground does not apply. Consent may be withdrawn where consent is the basis and law permits withdrawal. SyncShip will use a lawful transfer basis and safeguards for transfers outside the Kingdom, including approved contractual measures when required.

Some shipment, customs, payment, security, or legal records may need to be retained or disclosed under Saudi law or to complete a requested cross-border shipment. Requests may be submitted under Section 22. The Saudi Data and AI Authority or another competent authority may supervise the applicable processing.

Mexico

Where Mexican private-sector data-protection law applies, this Policy is intended to operate as an integral privacy notice describing the responsible entity, information processed, purposes, transfers, choices, and contact method. A data subject may exercise rights of access, rectification, cancellation, and opposition (ARCO rights), request limitation of use or disclosure, or revoke consent where legally available.

A Mexican request should identify the right, the information concerned, evidence reasonably sufficient to verify identity or representation, and a method to receive the response. SyncShip may retain or process information where a contract, shipment, legal duty, claim, security need, or another statutory exception applies.

35. Other Countries and Mandatory Local Rights

Customers and users in other countries may have privacy rights under local law. The main Policy applies together with any non-waivable local requirements. If local law gives an individual a right or imposes a shorter response period, stricter consent standard, data-localization rule, or additional transfer safeguard that cannot lawfully be displaced, SyncShip will apply that requirement to the covered processing.

A request from another country may be submitted under Section 22. The requester should identify the country and the right relied on. SyncShip may ask the relevant Customer, carrier, marketplace, payment provider, or local adviser for information needed to determine the applicable role, law, and response.

END OF PRIVACY POLICY