Legal · Last updated 2026-06-01
Sub-processors
ShipGenius relies on a short list of vendors to host, store, transmit, and process customer data on our behalf. Each one is contractually bound to confidentiality and security terms at least as strict as our commitments to you in our Privacy Policy. We review each vendor's SOC 2 (or equivalent) report annually.
| Vendor | Purpose | Data accessed | Location | Policy |
|---|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database, object storage for uploaded files | All customer business data at rest — shipments, invoices, contracts, audit logs, encrypted carrier credentials | United States | Privacy policy |
| Vercel, Inc. | Hosting for the ShipGenius web application | Request metadata (IP, user-agent, route), session cookies, rendered HTML responses. No raw business content at rest. | United States (global edge network) | Privacy policy |
| Railway Corporation | Hosting for the ShipGenius API and worker services | In-memory request and job payloads during processing; container logs | United States | Privacy policy |
| Doppler, Inc. | Secrets manager for application credentials and master encryption keys | ShipGenius operational secrets. No customer business data. | United States | Privacy policy |
| Anthropic, PBC (Enterprise plan) | LLM inference for the Genie chat, monthly executive narrative, and contract-parsing pipeline | Prompt context only at the moment of inference. Zero retention by default; no training on customer data, per Anthropic Enterprise terms. | United States | Privacy policy |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery (magic-link sign-in, monthly summary, alerts) | Recipient email address and the body of the transactional message being sent | United States | Privacy policy |
| Microsoft Corporation (Microsoft 365) | Inbound email handling for shipgenius.ai mailboxes | Email sent to ShipGenius support, privacy, security, and legal addresses | United States | Privacy policy |
| GoDaddy.com, LLC | DNS and domain registration for shipgenius.ai | DNS configuration. No customer business data. | United States | Privacy policy |
| Functional Software, Inc. (Sentry) | Application error monitoring | Error stack traces with PII redacted before transmission; request metadata | United States | Privacy policy |
| Axiom, Inc. | Application log aggregation | Structured logs with PII redacted at write time. 90-day retention. | United States | Privacy policy |
| PostHog, Inc. | Product analytics and feature flags | Aggregate page-view and feature-use events; pseudonymous user identifier. No raw business content. | United States | Privacy policy |
| FedEx Corporation | Carrier rate and invoice APIs (called only when you have authorized a FedEx connection) | Your FedEx account number and the shipment data needed to fetch published rates and invoices | United States | Privacy policy |
| United Parcel Service of America, Inc. | Carrier rate and invoice APIs (called only when you have authorized a UPS connection) | Your UPS account number and the shipment data needed to fetch published rates and invoices | United States | Privacy policy |
When this page changes
We will update this page before any new sub-processor begins processing customer data on our behalf. To be notified when this page changes, email privacy@shipgenius.ai with the subject "Sub-processor notifications" and we will add you to the notifications list. We will give at least 30 days' notice before a new sub-processor takes effect, except in cases where a shorter notice period is required by an urgent security need.
If you object to a proposed new sub-processor on reasonable grounds, write to the same address and we will work with you to find an accommodation — including, where appropriate, allowing you to close your account on a prorated basis with no penalty.
Carriers are not sub-processors of our service
When you connect a carrier to ShipGenius, we make API calls to that carrier on your behalf using credentials you provide. The carrier is your service provider — not ours — and is acting on your authorization. We include FedEx and UPS in the table above for transparency about every party that receives your data via ShipGenius, even though the contractual relationship for those calls is between you and the carrier.