Privacy Policy
Last updated 3 September 2026
How ShipSherpa collects, uses and protects personal data, and the terms on which it processes customer data.
These terms bind everyone who uses ShipSherpa, in any role.
Last updated 3 September 2026
How ShipSherpa collects, uses and protects personal data, and the terms on which it processes customer data.
These terms bind everyone who uses ShipSherpa, in any role.
Part 1
Ship Sherpa Limited is the data controller for the personal data described in this policy. That means we decide why and how it is used.
For anything to do with your personal data, including the requests described in section 1.8, contact us at support@shipsherpa.co.uk. Put "Privacy" in the subject line and we will route it to the right person. We accept requests by any other channel too, including support chat and post, but email reaches us fastest.
This policy applies to everyone whose data passes through ShipSherpa:
If you are a recipient, we hold your details because the sender gave them to us so we could deliver to you. You have the same rights over that data as anyone else, set out in section 1.8.
We need a lawful basis under UK data protection law for each thing we do with your data. These are ours.
| What we use it for | Our legal basis |
|---|---|
| Pricing, booking, collecting and delivering, and supporting you while we do it | Performance of our contract with you |
| Delivering to a recipient whose details the sender gave us | Our legitimate interest in carrying out the delivery the sender asked for |
| Taking payment, refunds and chargebacks | Performance of our contract, and legal obligation for the records we must keep |
| Invoices, VAT and accounting records | Legal obligation |
| Live tracking and location history, for dispatch, safety, proof and disputes | Performance of our contract, and our legitimate interest in proving what happened to a parcel |
| Checking that drivers are entitled and insured to drive | Legal obligation, and our legitimate interest in the safety of customers and the public |
| Assessing a business account application | Our legitimate interest in managing commercial risk. This is our own check, not one the law requires of us |
| Preventing fraud, securing accounts, and keeping audit records | Our legitimate interest in protecting customers, drivers and the platform |
| Defending or bringing legal claims | Our legitimate interest in establishing, exercising or defending claims |
| Marketing emails and texts | Your consent, which you can withdraw at any time |
| Analytics and other optional cookies | Your consent, given through our cookie banner |
Messages about a booking you have made are not marketing. We send those whatever your marketing preference, because you need them to receive your delivery. Turning off marketing never stops them.
Where we rely on legitimate interests, we have considered whether our reasons outweigh your rights, and you can ask us to explain that assessment.
We do not make decisions about you by automated means alone where those decisions have a legal or similarly significant effect. Applications, rejections, account suspensions and privacy requests are all decided by a person.
Software supports those people rather than replacing them. Our pricing engine works out quotes and whether we can serve a route, and when a reviewer writes feedback on a driver application we use a Google service to help put it into plainer English. The reviewer decides the outcome and writes the reason; nothing is added to it.
During driver onboarding we ask for a photograph of the driver's face. A member of our team compares it with the photograph on their identity document. That comparison is the check, so the photograph is kept with the rest of the driver's verification records, for the period in section 1.7, as evidence that it was carried out.
We do not sell personal data. We share it only where it is needed to run the service or where the law requires it.
We may add or change providers as the service develops. Ask us at any time for the current list.
These are the periods we work to. We keep data for longer only where an open dispute, an insurance claim or a legal obligation requires it, and we record why whenever we do.
Closing an account is not the same as erasing your data. Closing it ends your access and stops us using your details to operate; the records above stay for the periods listed. If you want your personal data erased, ask us under section 1.8 and we will tell you what we can and cannot remove.
You can ask us to:
Not every right applies to every piece of data. Where we have to keep something, we will say which data, why, and for how long.
Marketing is different. You can tell us to stop sending marketing at any time and we will, without exception and without needing a reason. Use the unsubscribe link in any marketing message or change the setting in your account.
To make a request, email support@shipsherpa.co.uk. We may ask you to confirm your identity first, so that we do not hand your data to someone else. We will respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you if we need to.
A request to erase your data is reviewed by an authorised member of our team before anything is deleted. Sending the request does not delete anything by itself, and we will write to you with the outcome, including anything we have to keep and why.
Some of our providers process data outside the United Kingdom. Where that happens we rely on UK adequacy regulations, or on the UK International Data Transfer Agreement or Addendum, together with an assessment of the transfer. Ask us if you want to know which applies to a particular provider.
We set cookies that are necessary to sign you in, keep your session secure and complete a booking. Anything beyond that, including analytics, is set only if you accept it. You can change your choice at any time through the cookie settings control on our site. Our Cookie Policy has the detail.
If you are unhappy with how we have handled your data, tell us first at support@shipsherpa.co.uk so we can put it right.
You can also complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to come to us first, though it is usually quicker.
We update this policy as the service changes. The date it was last updated is shown at the top. If we start using your data in a way this policy does not already cover, we will tell you before we begin, by email or in the app.
Part 2
This Part applies where the customer is the Controller of personal data that ShipSherpa processes on its behalf. It does not apply where ShipSherpa acts as an independent Controller.
This DPA forms part of the agreement between:
ShipSherpa may act as independent Controller for fraud prevention, payment compliance, legal defence and platform integrity functions.
Processing includes:
ShipSherpa shall process personal data only on documented instructions unless required by law.
Measures include:
Approved subprocessors may include:
ShipSherpa will provide reasonable assistance with data subject requests.
ShipSherpa will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer-controlled data.
On termination, Customer personal data will be deleted or returned unless retention is required by law or claims defence obligations.
Restricted transfers require UK lawful transfer safeguards.
Reasonable audit support is available subject to confidentiality and security safeguards.