*Last updated : January 8, 2024
ShipHero LLC is committed to protecting your privacy. This privacy statement describes the collection, use, and disclosure of your personal information when you utilize ShipHero LLC offerings and products. By using ShipHero LLC Services, you agree to the collection and use of information in accordance with this Privacy Policy.
Personal data regulations regarding the relationship between the customer as the Data Controller and SHIPHERO LLC as the Data Processor
Terms for Privacy & Data with SHIPHERO LLC, is effective from May 4, 2018
Personal data regulations regarding the relationship between the customer as the Data Controller and SHIPHERO LLC as the Data Processor
1. The subscription that the customer has with SHIPHERO LLC is a platform for enabling shipping processes for the customer and as a natural part of this, SHIPHERO LLC processes various personal data on the customer’s behalf.
During the Subscription Term, we will provide you access to use the Subscription Service as described in this Agreement.
This section concerns the relationship between the Data Controller (customer) and the Data Processor (SHIPHERO LLC), in connection with the personal data regulations.
2 Processed personal data.
2.1 The Data Processor, as part of the subscription, has access, on behalf of the Data Controller, to process:
Name and address of the persons receiving the consignments.
Information about the individual type of item sent and the value/price of the item.
3. The purpose and scope of the personal data processing.
3.1 As a natural part of the Data Processor’s status as the provider of subscription-based solutions for handling the Data Controller’s freight processes, the Data Processor stores the information, and similarly the Data Controller exchanges information with relevant third parties in the form of freight companies that the Data Controller uses, and possibly customs authorities (if the consignments are cross-border).
3.2 The purpose of the personal data processing is to manage the Data Controller’s freight processes.
3.3 It is emphasized that the Data Processor may only process personal data to the extent necessary for the operation of the Data Controller’s SHIPHERO subscription with the Data Processor, and/or if the Data Processor is required by law to process the data otherwise.
3.4 It is emphasized that the freight companies to which personal data is disclosed as part of this agreement are the Data Controller’s (the customer’s) Data Processors, not SHIPHERO LLC’ Data Processors. – SHIPHERO LLC has only an intermediary function in this regard.
4. The Data Processor’s obligations
4.1. The Data Processor may only process the personal data in question in accordance with the instructions of the Data Controller, i.e. the instructions contained in the SHIPHERO solution under which the Data Processor shall manage freight processes for the Data Controller.
4.2. The Data Processor is required to comply with the currently-applicable personal data legislation and shall notify the Data Controller immediately if an instruction from the Data Controller is, in the Data Processor’s opinion, contrary to the General Data Protection Regulation.
4.3. The Data Processor shall use appropriate technical and organisational security measures to ensure that personal data is not destroyed, lost, degraded or disclosed to unauthorised bodies, misused or otherwise processed in breach of personal data legislation, whereby the Data Processor shall implement the measures necessary pursuant to article 32 of the General Data Protection Regulation.
4.4. The Data Processor is obliged to inform the Data Controller without undue delay of any data breach. In this regard, the Data Processor shall inform the Data Controller of:
• The nature of the data breach
• If possible, the type and number of affected data subjects, as well as the type of personal data concerned and the number of records of personal data concerned.The measures that the Data Processor has taken or proposes should be taken to deal with the data breach, including, where appropriate, measures to limit its potential adverse effects.
• The probable consequences of the data breach.
4.5. The Data Processor shall, at the Data Controller’s request, provide the Data Controller with sufficient information to ensure that the Data Processor has taken the necessary technical and organisational security measures.
4.6. The Data Processor shall provide all the information necessary to demonstrate that the Data Processor complies with the General Data Protection Regulation’s article 28, whereby the Data Processor shall allow and contribute to audits, including inspections carried out by the Data Controller or another auditor authorised by the Data Controller. It is emphasised that inspections/audits in every respect take place at the Data Controller’s expense.
4.7. The Data Processor shall secure/ensure that the persons who are authorised by the Data Processor to process personal data have committed themselves to confidentiality or are bound by an appropriate statutory professional secrecy obligation.
4.8. If a data subject asks the Data Processor (usually such requests will be made to the Data Controller) for access to and insight into that person’s personal data, the Data Processor shall immediately forward the request to the Data Controller.
4.9. The Data Processor shall assist the Data Controller with appropriate technical and organisational tools to enable the Data Controller to fulfil the Data Controller’s obligations to respond to requests for the exercise of the rights of the data subjects as specified in chapter III of the General Data Protection Regulation.
5. Specifically about the transfer of information to sub-data processors or third parties
5.1 As a natural part of the SHIPHERO solution, the Data Processor is entitled to disclose personal data to the Data Controller’s other data processors (freight companies), and the Data Processor is also entitled to exchange personal data with the customs authorities.
5.2 In all other cases the Data Processor may only disclose or transfer personal data to third parties or sub-processors with the prior agreement with the Data Controller. However, the Data Processor may disclose or transfer personal data without the Data Controller’s instructions, if permitted by law.
5.3 If the Data Processor hands over personal data to another data processor (sub-processor), the Data Processor is obliged to conclude a sub-processor agreement with the sub-processor, whereby the Data Processor’s sub-processor is subject to at least the same conditions as stated in this section 9.
5.4 The Data Processor shall notify the Data Controller if the Data Processor has plans to extend the circle of sub-processors and/or to replace existing sub-processors with others.
5.5 The Data Processor must not transfer personal data to third countries that the EU Commission has not assessed as safe third countries.
5.6 If the information is transferred to foreign sub-processors, it must be stated in the data processing agreement, cf. 9.5.3 that sub-processors shall comply with the EU’s General Data Protection Regulation and any other current personal data law in force. Sub-processors in EU countries with specific regulatory requirements regarding data processing must also comply with these requirements.
6. Duration of data processing
6.1 The processing of personal data pursuant to this agreement continues until such time as the SHIPHERO subscription concluded between the parties ceases.
6.2 However, in the event of the termination of a subscription, the Data Processor is bound by this agreement for as long as the Data Processor has access to personal data originating from the Data Controller.
6.3 In the event of termination of a SHIPHERO subscription, the Data Processor is required to delete any backups and other copies of the personal data.
7. Access Controls
7.1 SHIPHERO will maintain appropriate access controls to protect the Nonpublic Information throughout the term of the Agreement and at all times while SHIPHERO and SHIPHERO Parties have access to or possession of the Client’s Nonpublic Information.
7.2 Client will be solely responsible for implementing and maintaining access controls on its own systems to which SHIPHERO may be granted access in accordance with the provision of services.
8. Authorized Persons
8.1 SHIPHERO will limit access to the Client’s Nonpublic Information to those individuals who have a business need to access the Client’s Nonpublic Information in connection with the services provided to Client (“Authorized Persons”).
For the purposes of this Privacy Policy:
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Agreement) refers to ShipHero LLC, Inc..
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the
Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
Information For Us Residents
We collect Personal Data from US residents and comply with the consumer privacy laws of California, Colorado, Connecticut, Utah, and Virginia (“US Privacy Laws”). This Detailed US Privacy Notice applies to US residents (“users,” “you,” or “your”).
For the purposes of this Detailed US Privacy Notice, “Personal Data” means information that is linked or reasonably linkable to a particular individual or household. However, the following categories of information are not Personal Data:
Publicly available information;
Deidentified or aggregated data; To or
Information otherwise excluded from the scope of US Privacy Laws.
This Privacy Notice provides the following information to US residents:
Categories of Personal Data we collect;
Purposes for which we use Personal Data;
Categories of Personal Data we disclose to third parties;
Categories of third parties to which we disclose Personal Data; and
How US residents can exercise their rights under US Privacy Laws:
The rights to access, correct, or delete Personal Data;
The right to obtain a portable copy of Personal Data;
The right to limit the use of sensitive Personal Data in certain circumstances;
The rights to opt out of targeted advertising, sales of Personal Data, or profiling; and
The right to appeal our decisions about your requests.
Categories Of Non Sensitive Personal Data
The table below outlines the non-sensitive categories of Personal Data ShipHero LLC collects about US residents and whether and how they are disclosed to third parties.
We collect Non-Sensitive Personal Data from the following sources:
Directly from our users
Inferences from your activity using our services
From our affiliates (“affiliates” are businesses that share common ownership with ShipHero LLC)
From our business partners (“business partners” are companies that we have a pre-existing commercial relationship with)
Categories of Personal Data:
Identifiers
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories of Personal Data:
Internet/Electronic Activity
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories Of Sensitive Personal Data
We do not Process any categories of Sensitive Personal Data
Use Of Personal Data
We use Personal Data for the purposes described above. Personal Data may also be used or disclosed as otherwise permitted or required by applicable law.
Disclosing Personal Data
We share Personal Data with the following categories of third parties:
Processors: We use processors to securely handle Personal Data on our behalf and only on our instructions. These companies may not use your Personal Data for their own purposes.
Our Business Partners: We may disclose relevant personal data to our business partners to provide you with exclusive offers for products and services that may interest you.
See the table above for more details about how different categories of Personal Data are disclosed.
We do not sell Personal Data to anyone.
Exercising Your Personal Data Rights
US residents have the following rights under US Privacy Laws:
The rights to access, correct, or delete Personal Data;
The right to obtain a portable copy of Personal Data;
The right to limit the use of Sensitive Personal Data in certain circumstances;
The rights to opt out of targeted advertising, sales of personal data, or profiling;
The right not to receive discriminatory treatment for exercising your privacy rights; and
The right to appeal our decisions about your requests if you disagree with them.
If you are a US resident, you can submit a request to exercise your personal data rights under US Privacy Laws by sending us an email to dataprivacy@shiphero.com. ShipHero LLC also processes opt-out requests sent by Universal Opt-Out Mechanisms (also referred to as “Opt-Out Preference Signals”) frictionlessly in compliance with US Privacy law. You can send an Opt-Out Preference Signal for our business to process frictionlessly by visiting our website using a device or browser that broadcasts commonly used and recognized Opt-Out Preference Signals. We will apply the Opt-Out Preference Signals we receive to the browser or device that sent the signal, as well as any user profiles associated with that browser or device.
To protect your privacy, we may need to authenticate your identity before we respond to your rights request. We will verify your identity by sending an email to your email address on file to obtain a confirmation response. We may ask you for additional information as part of this process, including your account number. If you do not complete the verification process, we may be unable to process your request. Any information you provide to authenticate your identity will only be used to process your rights request and not for any other purpose. Please be aware that we do not accept or process rights requests submitted through other means.
We will respond to your rights request within 45 days, though in certain cases, we may inform you that we will need up to another 45 days to act on your request. If we suspect fraudulent or malicious activity on or from your account, we will delay taking action on your request until we can appropriately verify your identity and the request as authentic. Also note that each of the rights are subject to certain exceptions.
We reserve the right to decline to process, or charge a reasonable fee for, requests from a US resident that are manifestly unfounded, excessive, or repetitive.
Notice Of Right To Limit The Use Of Sensitive Personal Information
You have the right to limit some uses of Sensitive Personal Data. In general, you may direct companies not to use Sensitive Personal Data except as necessary to provide goods or services you have requested or other exempt purposes. However, ShipHero LLC does not Process any Sensitive Data.
Children’s Data
We do not knowingly collect or use the Personal Information of children under 16. If you believe that we have collected the Personal Information of a child under 16, please contact us at dataprivacy@shiphero.com.
Children’s Data
We do not knowingly collect or use the Personal Information of children under 16. If you believe that we have collected the Personal Information of a child under 16, please contact us at dataprivacy@shiphero.com.
Authorized Agent Requests
You may designate an authorized agent to make a rights request on your behalf. Your authorized agent may submit such a request by following the same method described above in the section titled Exercising Your Personal Data Rights. We may require verification of your authorized agent’s authority in addition to the information we require for verification of your identity.
Contact Us
If you have any questions or concerns regarding this Detailed US Privacy Notice, contact us at dataprivacy@shiphero.com.
Last updated: December 04, 2023
Privacy Information For California Employees, Contractors, And Applicants
We collect Personal Data from US residents and comply with the consumer privacy laws of California, Colorado, Connecticut, Utah, and Virginia (“US Privacy Laws”). This Detailed US Privacy Notice applies to US residents (“users,” “you,” or “your”).
For the purposes of this Detailed US Privacy Notice, “Personal Data” means information that is linked or reasonably linkable to a particular individual or household. However, the following categories of information are not Personal Data:
Publicly available information;
Deidentified or aggregated data; To or
Information otherwise excluded from the scope of US Privacy Laws.
This Privacy Notice provides the following information to US residents:
Categories of Personal Data we collect;
Purposes for which we use Personal Data;
Categories of Personal Data we disclose to third parties;
Categories of third parties to which we disclose Personal Data; and
How US residents can exercise their rights under US Privacy Laws:
The rights to access, correct, or delete Personal Data;
The right to obtain a portable copy of Personal Data;
The right to limit the use of sensitive Personal Data in certain circumstances;
The rights to opt out of targeted advertising, sales of Personal Data, or profiling; and
The right to appeal our decisions about your requests.
Categories Of Non Sensitive Personal Data
The table below outlines the non-sensitive categories of Personal Data ShipHero LLC collects about US residents and whether and how they are disclosed to third parties.
We collect Non-Sensitive Personal Data from the following sources:
Directly from our users
Inferences from your activity using our services
From our affiliates (“affiliates” are businesses that share common ownership with ShipHero LLC)
From our business partners (“business partners” are companies that we have a pre-existing commercial relationship with)
Categories of Personal Data:
Identifiers
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories of Personal Data:
Professional Information
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories of Personal Data:
Educational Information
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories Of Sensitive Personal Information
The table below outlines the categories of Sensitive Personal Information ShipHero LLC collects about Employees, Contractors, and Applicants and whether they are disclosed to third parties.
We collect Sensitive Personal Information from the following sources:
Directly from our Employees, Contractors, and Applicants
Categories of Sensitive Personal Information:
Government ID Information
Examples
Purpose(s) for Collection
Targeted Advertising
Sale
Other Disclosures
Retention Period
Categories Of Sensitive Personal Information
The table below outlines the categories of Sensitive Personal Information ShipHero LLC collects about Employees, Contractors, and Applicants and whether they are disclosed to third parties.
We collect Sensitive Personal Information from the following sources:
Directly from our Employees, Contractors, and Applicants
Categories Of Sensitive Personal Data
We do not Process any categories of Sensitive Personal Data
Use Of Personal Data
We use Personal Data for the purposes described above. Personal Data may also be used or disclosed as otherwise permitted or required by applicable law.
Disclosing Personal Data
We share Personal Data with the following categories of third parties:
Processors: We use processors to securely handle Personal Data on our behalf and only on our instructions. These companies may not use your Personal Data for their own purposes.
Our Business Partners: We may disclose relevant personal data to our business partners to provide you with exclusive offers for products and services that may interest you.
See the table above for more details about how different categories of Personal Data are disclosed.
We do not sell Personal Data to anyone.
Exercising Your Personal Data Rights
US residents have the following rights under US Privacy Laws:
The rights to access, correct, or delete Personal Data;
The right to obtain a portable copy of Personal Data;
The right to limit the use of Sensitive Personal Data in certain circumstances;
The rights to opt out of targeted advertising, sales of personal data, or profiling;
The right not to receive discriminatory treatment for exercising your privacy rights; and
The right to appeal our decisions about your requests if you disagree with them.
If you are a US resident, you can submit a request to exercise your personal data rights under US Privacy Laws by sending us an email to dataprivacy@shiphero.com. ShipHero LLC also processes opt-out requests sent by Universal Opt-Out Mechanisms (also referred to as “Opt-Out Preference Signals”) frictionlessly in compliance with US Privacy law. You can send an Opt-Out Preference Signal for our business to process frictionlessly by visiting our website using a device or browser that broadcasts commonly used and recognized Opt-Out Preference Signals. We will apply the Opt-Out Preference Signals we receive to the browser or device that sent the signal, as well as any user profiles associated with that browser or device.
To protect your privacy, we may need to authenticate your identity before we respond to your rights request. We will verify your identity by sending an email to your email address on file to obtain a confirmation response. We may ask you for additional information as part of this process, including your account number. If you do not complete the verification process, we may be unable to process your request. Any information you provide to authenticate your identity will only be used to process your rights request and not for any other purpose. Please be aware that we do not accept or process rights requests submitted through other means.
We will respond to your rights request within 45 days, though in certain cases, we may inform you that we will need up to another 45 days to act on your request. If we suspect fraudulent or malicious activity on or from your account, we will delay taking action on your request until we can appropriately verify your identity and the request as authentic. Also note that each of the rights are subject to certain exceptions.
We reserve the right to decline to process, or charge a reasonable fee for, requests from a US resident that are manifestly unfounded, excessive, or repetitive.
Notice Of Right To Limit The Use Of Sensitive Personal Information
You have the right to limit some uses of Sensitive Personal Data. In general, you may direct companies not to use Sensitive Personal Data except as necessary to provide goods or services you have requested or other exempt purposes. However, ShipHero LLC does not Process any Sensitive Data.
Children’s Data
We do not knowingly collect or use the Personal Information of children under 16. If you believe that we have collected the Personal Information of a child under 16, please contact us at dataprivacy@shiphero.com.
Children’s Data
We do not knowingly collect or use the Personal Information of children under 16. If you believe that we have collected the Personal Information of a child under 16, please contact us at dataprivacy@shiphero.com.
Authorized Agent Requests
You may designate an authorized agent to make a rights request on your behalf. Your authorized agent may submit such a request by following the same method described above in the section titled Exercising Your Personal Data Rights. We may require verification of your authorized agent’s authority in addition to the information we require for verification of your identity.
Contact Us
If you have any questions or concerns regarding this Detailed US Privacy Notice, contact us at dataprivacy@shiphero.com.
Last updated: December 04, 2023
Last updated: December 04, 2023
This Privacy Policy (the “Policy”) applies to the processing of Personal Data, subject to all applicable privacy and data protection laws of Switzerland, the United Kingdom, the European Union and the European Economic Area (collectively, “Europe”), by ShipHero LLC and its subsidiaries and affiliates (“Company”, “we”, “our”, or “us”) through its website, products, and services (the “Services”). It describes how we collect, use, and disclose such Personal Data, your rights and choices with respect to your Personal Data, and how you can contact us if you have any questions or concerns.
Personal Data We Collect
We collect Personal Data from US residents and comply with the consumer privacy laws of California, Colorado, Connecticut, Utah, and Virginia (“US Privacy Laws”). This Detailed US Privacy Notice applies to US residents (“users,” “you,” or “your”).
For the purposes of this Detailed US Privacy Notice, “Personal Data” means information that is linked or reasonably linkable to a particular individual or household. However, the following categories of information are not Personal Data:
Publicly available information;
Deidentified or aggregated data; To or
Information otherwise excluded from the scope of US Privacy Laws.
This Privacy Notice provides the following information to US residents:
Categories of Personal Data we collect;
Purposes for which we use Personal Data;
Categories of Personal Data we disclose to third parties;
Categories of third parties to which we disclose Personal Data; and
How US residents can exercise their rights under US Privacy Laws:
The rights to access, correct, or delete Personal Data;
The right to obtain a portable copy of Personal Data;
The right to limit the use of sensitive Personal Data in certain circumstances;
The rights to opt out of targeted advertising, sales of Personal Data, or profiling; and
The right to appeal our decisions about your requests.
Categories Of Non Sensitive Personal Data
The table below outlines the non-sensitive categories of Personal Data ShipHero LLC collects about US residents and whether and how they are disclosed to third parties.
We collect Non-Sensitive Personal Data from the following sources:
Directly from our users
Inferences from your activity using our services
From our affiliates (“affiliates” are businesses that share common ownership with ShipHero LLC)
From our business partners (“business partners” are companies that we have a pre-existing commercial relationship with)
Categories Of Non Sensitive Personal Data
The table below outlines the non-sensitive categories of Personal Data ShipHero LLC collects about US residents and whether and how they are disclosed to third parties.
We collect Non-Sensitive Personal Data from the following sources:
Directly from our users
Inferences from your activity using our services
From our affiliates (“affiliates” are businesses that share common ownership with ShipHero LLC)
From our business partners (“business partners” are companies that we have a pre-existing commercial relationship with)
Our Contact Information
ShipHero LLC is the entity responsible for the processing of your Personal Data. If you have any questions or comments about this Policy, our privacy practices, or if you would like to exercise your rights with respect to your Personal Data, please contact us by email at dataprivacy@shiphero.com, or by mail at:
We collect Non-Sensitive Personal Data from the following sources:
ShipHero LLC
55 W RAILROAD AVE, BUILDING 4
Garnerville, New York 10923
USA