Legal · Last updated 2026-06-01

Sub-processors

ShipGenius relies on a short list of vendors to host, store, transmit, and process customer data on our behalf. Each one is contractually bound to confidentiality and security terms at least as strict as our commitments to you in our Privacy Policy. We review each vendor's SOC 2 (or equivalent) report annually.

VendorPurposeData accessedLocationPolicy
Supabase, Inc.Managed PostgreSQL database, object storage for uploaded filesAll customer business data at rest — shipments, invoices, contracts, audit logs, encrypted carrier credentialsUnited StatesPrivacy policy
Vercel, Inc.Hosting for the ShipGenius web applicationRequest metadata (IP, user-agent, route), session cookies, rendered HTML responses. No raw business content at rest.United States (global edge network)Privacy policy
Railway CorporationHosting for the ShipGenius API and worker servicesIn-memory request and job payloads during processing; container logsUnited StatesPrivacy policy
Doppler, Inc.Secrets manager for application credentials and master encryption keysShipGenius operational secrets. No customer business data.United StatesPrivacy policy
Anthropic, PBC (Enterprise plan)LLM inference for the Genie chat, monthly executive narrative, and contract-parsing pipelinePrompt context only at the moment of inference. Zero retention by default; no training on customer data, per Anthropic Enterprise terms.United StatesPrivacy policy
Postmark (ActiveCampaign, LLC)Transactional email delivery (magic-link sign-in, monthly summary, alerts)Recipient email address and the body of the transactional message being sentUnited StatesPrivacy policy
Microsoft Corporation (Microsoft 365)Inbound email handling for shipgenius.ai mailboxesEmail sent to ShipGenius support, privacy, security, and legal addressesUnited StatesPrivacy policy
GoDaddy.com, LLCDNS and domain registration for shipgenius.aiDNS configuration. No customer business data.United StatesPrivacy policy
Functional Software, Inc. (Sentry)Application error monitoringError stack traces with PII redacted before transmission; request metadataUnited StatesPrivacy policy
Axiom, Inc.Application log aggregationStructured logs with PII redacted at write time. 90-day retention.United StatesPrivacy policy
PostHog, Inc.Product analytics and feature flagsAggregate page-view and feature-use events; pseudonymous user identifier. No raw business content.United StatesPrivacy policy
FedEx CorporationCarrier rate and invoice APIs (called only when you have authorized a FedEx connection)Your FedEx account number and the shipment data needed to fetch published rates and invoicesUnited StatesPrivacy policy
United Parcel Service of America, Inc.Carrier rate and invoice APIs (called only when you have authorized a UPS connection)Your UPS account number and the shipment data needed to fetch published rates and invoicesUnited StatesPrivacy policy

When this page changes

We will update this page before any new sub-processor begins processing customer data on our behalf. To be notified when this page changes, email privacy@shipgenius.ai with the subject "Sub-processor notifications" and we will add you to the notifications list. We will give at least 30 days' notice before a new sub-processor takes effect, except in cases where a shorter notice period is required by an urgent security need.

If you object to a proposed new sub-processor on reasonable grounds, write to the same address and we will work with you to find an accommodation — including, where appropriate, allowing you to close your account on a prorated basis with no penalty.

Carriers are not sub-processors of our service

When you connect a carrier to ShipGenius, we make API calls to that carrier on your behalf using credentials you provide. The carrier is your service provider — not ours — and is acting on your authorization. We include FedEx and UPS in the table above for transparency about every party that receives your data via ShipGenius, even though the contractual relationship for those calls is between you and the carrier.