← Back to ShipWave

Privacy Policy

Last updated: July 21, 2026

1. Introduction

ShipWave is developed, owned, and operated by Levy Electric, Inc. ("we," "our," or "us"), and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our shipping management application, including our Shopify app integration.

2. Information We Collect

2.1 Information from Shopify Stores

When you connect your Shopify store to ShipWave, we access the following information based on the permissions you grant:

  • Order Information: Order details, shipping addresses, customer names, product information, and order status
  • Product Information: Product titles, SKUs, weights, and dimensions for shipping calculations
  • Fulfillment Information: Fulfillment status and tracking information
  • Location Information: Store locations and inventory levels for warehouse management
  • Shipping Information: Shipping zones and rates configured in your store
  • Fraud and Risk Information: Shopify risk indicators, payment and fulfillment context, customer email, phone, billing and shipping address details, checkout identifiers, order history signals, and fraud-review evidence needed for merchant-configured fraud rules
  • Storefront Event Information: Web Pixel or theme-app telemetry such as page, product, cart, checkout, and completed-checkout events, device/session identifiers, IP-derived signals, browser metadata, and event timestamps used for fraud velocity and bot-surge detection

2.2 Account Information

We collect information you provide when creating an account, including your email address, name, and business information.

2.3 Usage Information

We automatically collect information about how you interact with our service, including log data, device information, and analytics.

2.4 Marketplace Information (Amazon, eBay, Walmart)

If you connect a marketplace account (such as Amazon, eBay, or Walmart) to ShipWave, we access order information from that marketplace through its official API, including buyer names, shipping addresses, contact details, order contents, and order status. This information is used solely to fulfill the buyer's order — generating shipping labels, shipping the product, providing order support, and meeting tax and accounting obligations. We never use marketplace buyer information for marketing, advertising, or any secondary purpose, and we never sell it.

3. How We Use Your Information

We use the collected information to:

  • Provide shipping label generation and rate comparison services
  • Sync orders from your Shopify store for fulfillment processing
  • Sync and fulfill orders from connected marketplaces (Amazon, eBay, Walmart)
  • Calculate shipping rates based on package dimensions and destinations
  • Generate shipping labels and update fulfillment tracking in your store
  • Manage warehouse inventory and automation rules
  • Evaluate fraud rules, publish deterministic checkout validation blocks, place risky orders on fulfillment hold for merchant review, run identity challenges, and retain fraud evidence
  • Measure storefront, cart, checkout, session, and device velocity for bot-surge and repeated-attempt detection
  • Improve and optimize our services
  • Communicate with you about your account and our services
  • Comply with legal obligations

4. Information Sharing

We may share your information with:

  • Shipping Carriers: USPS, UPS, FedEx, DHL, and other carriers to generate shipping labels and track packages
  • Payment Processors: For processing payments for shipping labels
  • Service Providers: Third-party services that help us operate our platform (hosting, analytics)
  • Merchant-Enabled Fraud Providers: Optional identity, phone, IP, email, or device reputation providers only when you enable those providers for fraud review or customer verification
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information to third parties.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption of access tokens using AES-256-GCM
  • Encryption of merchant-owned provider credentials before storage
  • HMAC hashing of emails, phones, addresses, IPs, device identifiers, session identifiers, and user-agent values where raw values are not required for fraud velocity counters
  • HTTPS encryption for all data transmission
  • Secure cloud infrastructure with regular security audits
  • Access controls and authentication requirements

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. When you disconnect your Shopify store or delete your account, we will delete your associated data within 30 days, except where we are required to retain it for legal, tax, accounting, dispute, fraud-evidence, or merchant-configured retention purposes.

Buyer personally identifiable information from connected marketplaces (such as Amazon) is retained only as long as necessary to fulfill the order and is purged within 30 days of order fulfillment, except where retention is required for tax, accounting, or other legal obligations.

Fraud Suite retention windows are configurable by the merchant. Fraud decisions, provider payloads, storefront session events, velocity counters, traffic rollups, and related evidence are deleted or minimized according to those settings and any legal retention obligations. Provider raw payloads are minimized separately from normalized fraud facts so merchants can reduce sensitive retention without losing audit history.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Disconnect your Shopify store at any time
  • Export your data
  • Opt out of marketing communications

8. Shopify App Users

If you install our Shopify app, you authorize us to access your store data as described above. You can revoke this access at any time by uninstalling the app from your Shopify admin. Upon uninstallation, we will cease accessing your store data and delete stored information according to our retention policy.

If you enable Fraud Suite, ShipWave uses Shopify order, customer, checkout, storefront event, payment-risk, fulfillment, and product data to evaluate your configured fraud rules and enforcement settings. You can disable Fraud Suite, storefront telemetry, checkout blocking, fulfillment holds, provider enrichment, or individual rules from the ShipWave admin.

Shopify privacy and GDPR webhooks for customer data requests, customer redaction, and shop redaction include Fraud Suite records such as decisions, evidence, provider results, linked session/pre-checkout events, velocity counters, and rollup markers.

9. Amazon Information

Where you connect an Amazon selling account, ShipWave handles Amazon order and buyer information in accordance with the Amazon Services API Acceptable Use Policy and Data Protection Policy. Amazon buyer personally identifiable information is encrypted in transit (TLS) and at rest (AES-256), access is restricted to authorized personnel on a need-to-know basis, it is used only to fulfill the buyer's order, it is never shared except with the shipping carrier required to deliver that order, and it is purged within 30 days of order fulfillment unless retention is legally required.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Email: support@shipwave.app
Company: Levy Electric, Inc.
Address: 653 E 14th Street, Unit 1C
New York, NY 10009