Privacy policy

This Policy explains what personal information ShippingRefunds.ai handles, why we need it, who receives it, and the choices available to account users and shipment recipients.

Effective July 29, 2026 Version 2026-07-29

We do not
Sell personal information or use advertising cookies
Credentials
Connected-service secrets are encrypted
Your controls
Access, correction, deletion, and consent requests

1. Scope and accountability

This Privacy Policy describes how the operator of ShippingRefunds.ai (“ShippingRefunds.ai,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through our websites, applications, claim-support services, and communications (collectively, the “Service”). It applies to account users, prospective customers, support contacts, and individuals whose information appears in shipment or claim records.

We follow applicable Canadian private-sector privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws where applicable. Our designated Privacy Officer is responsible for our privacy program, service-provider oversight, access requests, and complaints and may be reached using the details in Section 16.

2. Information we collect

Depending on how the Service is used, we may collect:

  • Account and business information: name, business name, email address, password hash, role, telephone number, business and ship-from address, workspace settings, and email-verification status.
  • Integration information: connected-service identifiers, customer or account numbers, authorization tokens, API credentials, connection status, import settings, and synchronization history. Sensitive integration credentials are stored in encrypted form.
  • Shipment, order, and recipient information: tracking and order numbers, service type, shipment dates, delivery estimates and events, postage and product values, contents descriptions, and recipient names, businesses, email addresses, telephone numbers, and delivery addresses.
  • Claim information: claim type and status, filing details, customer confirmations, supporting descriptions, Canada Post ticket or reference numbers, carrier responses, refund amounts, filing history, and claim-related emails.
  • Billing information: plan, trial and renewal dates, shipment-volume units, invoices, subscription status, Stripe customer and subscription identifiers, and limited payment-method details returned by Stripe. Stripe processes complete card details; we do not store complete payment-card numbers in our application database.
  • Support and communications: messages, attachments, feedback, delivery status, and information you provide when contacting us.
  • Technical and usage information: IP address, browser or device user agent, session and login timestamps, security records, feature activity, automation status, error details, and operational logs.
  • Prospect information: contact details, company, approximate shipment volume, current tools, and interests submitted through an information or signup form.

Please do not provide social insurance numbers, government identification, financial account credentials unrelated to supported integrations, or other information the Service does not request.

3. How we collect information

We collect personal information:

  • directly from you when you register, configure an account, choose a plan, or contact us;
  • from users and administrators within your organization;
  • from connected shipping tools and Canada Post at your direction;
  • from Stripe and other providers that support billing, email, hosting, and security;
  • from carrier tracking pages, APIs, files, invoices, and claim-related communications; and
  • automatically through essential cookies, session records, and application logs.

When we collect information directly from an individual, consent may be express or implied depending on the sensitivity of the information and the reasonable expectations of the individual. We may also process information without consent where applicable law permits or requires it.

4. How we use information

We use personal information for purposes a reasonable person would consider appropriate, including to:

  • create, authenticate, secure, and administer accounts and workspaces;
  • connect authorized carrier and shipping-tool accounts and import shipments;
  • monitor tracking, calculate timing, identify potential claims, and prevent duplicates;
  • prepare claim packages and, where separately authorized, submit claims as your agent;
  • track claim status, carrier correspondence, filing history, and reported recoveries;
  • provide AI-assisted reviews and explanations when enabled;
  • measure billable shipment volume, administer trials, process payments, and issue invoices;
  • send security, account, billing, claim, support, and other service communications;
  • respond to requests, troubleshoot, maintain, analyze, and improve the Service;
  • detect abuse, fraud, security threats, and violations of our Terms;
  • create aggregated or de-identified analytics that do not reasonably identify an individual; and
  • comply with law, enforce agreements, establish legal claims, and protect rights and safety.

We do not sell personal information. We do not use Customer Data for third-party targeted advertising, and we do not permit AI providers to use Customer Data for their own marketing. If we want to use personal information for a materially new purpose, we will provide notice and obtain consent where required.

5. Shipment recipient data

Our business customers provide personal information about their shipment recipients. For that information, the customer determines why shipments are created and connected to the Service, and ShippingRefunds.ai processes the information to provide the requested monitoring and claim workflow. Customers are responsible for having lawful authority to provide recipient information, giving any required notices, limiting their users’ access, and responding to recipient requests concerning the customer’s own records.

If you are a shipment recipient, contacting the business that shipped your package is usually the fastest way to exercise a privacy right. You may also contact our Privacy Officer. We will verify the request and, where appropriate, work with the relevant customer while protecting the privacy of others and confidential business information.

6. AI and automated processing

When enabled, selected shipment, tracking, claim, and workflow information may be sent to an AI service provider to classify supplied evidence, flag inconsistencies, summarize a case, or recommend an operational next step. Outputs are stored with the relevant workspace for audit and review. We instruct these features to use supplied evidence and not invent carrier events or claims.

AI output does not itself expand filing authority or make Canada Post’s decision. Core eligibility rules, required customer confirmations, and plan permissions remain separate controls. You may contact us for information about an AI-assisted result. We may use human review when a task needs attention or when required for support, safety, or quality.

7. When we disclose information

We may disclose personal information only as reasonably necessary to:

  • Service providers: vendors that provide hosting, databases, security, email delivery and routing, payment processing, technical support, automation, and AI processing. Core providers may include Railway, Cloudflare, Stripe, and OpenAI.
  • Connected services and carriers: Canada Post and a shipping tool when you connect an account, request data, or authorize a claim workflow.
  • Your organization: authorized workspace owners, administrators, and members according to their access.
  • Legal and safety recipients: courts, regulators, law enforcement, or other parties when we reasonably believe disclosure is required or permitted by law, needed to protect rights or safety, or necessary to investigate fraud or abuse.
  • Business transaction parties: advisers, financiers, and a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and continued lawful handling.

Service providers may use personal information only to perform contracted services or as otherwise permitted by law. We remain accountable for personal information transferred to a service provider for processing under our control.

8. Processing outside your province or Canada

We and our service providers may process or store information in Canada, the United States, and other jurisdictions where they operate. Information in another jurisdiction may be subject to that jurisdiction’s laws and lawful access by courts, law enforcement, or national-security authorities. We assess providers, limit their permitted use, and use contractual, organizational, and technical measures intended to provide protection comparable to our obligations under applicable Canadian privacy law.

Contact our Privacy Officer if you would like more information about relevant service providers or processing locations.

9. Cookies and device storage

We use essential cookies to keep users signed in, protect gated or administrative areas, preserve authorized workspace context, and support security. These cookies are necessary for requested Service functionality. Some interface preferences and onboarding state may be stored temporarily in browser session storage and normally disappear when that browser session ends.

We do not currently use third-party advertising cookies or behavioural-advertising pixels. Blocking essential cookies may prevent login or other authenticated features. If we introduce non-essential analytics or advertising technologies, we will update this Policy and provide consent controls where required.

10. Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including while an account is active and afterward where needed for claim history, billing and tax records, dispute resolution, security, backup integrity, legal compliance, and enforcement. Retention depends on the record’s purpose, sensitivity, legal requirements, carrier claim timelines, and whether it is subject to a request or dispute.

When information is no longer required, we delete, anonymize, or securely dispose of it. Deletion from encrypted backups and provider systems may occur on a delayed cycle. We may retain aggregated or de-identified information that no longer reasonably identifies an individual. Disconnecting an integration stops new authorized imports but does not by itself delete shipment and claim history already in the workspace.

11. Security safeguards

We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information. Measures include access controls, hashed passwords, secure session cookies, encryption in transit, authenticated encryption for supported integration credentials, restricted administrative access, logging, provider controls, and data backup and recovery practices.

No system is completely secure. You are responsible for strong account credentials, limiting workspace access, and protecting connected-service credentials. If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and regulators as required by applicable law and keep required breach records.

12. Your privacy choices and rights

Subject to applicable law and appropriate identity verification, you may ask us to:

  • explain whether we hold personal information about you and how it has been used or disclosed;
  • provide access to personal information under our control;
  • correct incomplete or inaccurate personal information;
  • withdraw consent to future collection, use, or disclosure where consent is the basis;
  • delete information that is no longer required, subject to legal and operational exceptions;
  • disconnect an integration or disable optional automatic filing; or
  • challenge our compliance with this Policy.

We may need information to verify your identity and authority. Access can be limited where required or permitted by law, including to protect another person’s privacy, confidential commercial information, legal privilege, security, or an investigation. Withdrawing consent does not affect earlier lawful processing and may prevent us from providing features that depend on that information. We will respond within the timelines required by applicable law and explain any refusal.

13. Email communications

We send transactional messages needed to operate the Service, such as verification, security, trial, billing, plan, claim, filing, and support messages. You cannot opt out of essential service messages while keeping the affected feature or account active. Where we send commercial electronic messages, we will rely on a lawful form of consent or an applicable exemption, identify the sender, and provide a working unsubscribe method as required by Canada’s Anti-Spam Legislation. An unsubscribe does not stop required transactional messages.

14. Children

The Service is for businesses and is not directed to children or minors. We do not knowingly create accounts for individuals below the age of majority. If you believe a child has provided personal information to us outside an ordinary shipment-recipient record, contact our Privacy Officer so we can investigate and take appropriate action.

15. Changes to this Policy

We may update this Policy as our Service, providers, or legal obligations change. We will post the updated version and effective date. If a change materially affects how we use or disclose personal information, we will provide additional notice and obtain consent where required by law.

16. Privacy questions and complaints

Send privacy questions, access or correction requests, deletion requests, and complaints to:
Privacy Officer, ShippingRefunds.ai
Email: [email protected]
Subject line: Privacy Request

Please provide enough detail for us to understand the request, but do not send passwords or sensitive integration credentials by email. We will investigate complaints and explain our response. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia, as applicable.