ShipHQ / privacy
Privacy policy
Effective 27 September 2026 · Website section updated 30 September 2026
Who operates ShipHQ
ShipHQ is operated by Rıdvan Uyan. For privacy requests, contact ridvan.uyn@gmail.com.
Information we use
- Account: an account identifier, optional name and email from Apple or Google sign-in, and support messages you send.
- Your HQ: office name and layout, avatar, progress, rewards, achievements, preferences and activity needed to run your game.
- Connected metrics: app identifiers and names, revenue, subscription counts, user activity, country-level aggregates, metric history and source sync status. The available fields depend on the services you connect.
- Connection credentials: authorization tokens or API credentials required to read the sources you authorize. Provider credentials are encrypted on our backend.
- App usage: which screens and actions you use in the app (for example opening the membership screen, choosing a plan, completing setup), the paywall variant shown, an app-instance identifier and your ShipHQ account identifier. We do not intentionally include connected business metrics, app names, provider credentials or customer records in product-analytics events.
- Diagnostics: service request and error information used to operate, secure and troubleshoot the service.
Why we process it
We use this information to provide the service you request, synchronize your metrics, save progress, support your account and protect against misuse. Where applicable, processing relies on providing our service, legitimate interests in security and operation, legal obligations, or your consent for optional features.
Connected services
Connections are optional. ShipHQ reads the metrics you authorize; it does not change your connected app’s pricing or run marketing campaigns for you. Disconnecting removes the saved connection credentials. Previously synchronized history may remain until you delete your ShipHQ account. You can also revoke access directly at the provider.
Product analytics in the app
ShipHQ uses Mixpanel and Google Analytics for Firebase to understand app usage, improve onboarding and features, and measure membership-screen experiments. We record interactions such as opening the app or membership screen, selecting a plan, completing setup, and purchase or restore outcomes. Event details can include the selected plan, billing period, offering variant and number of app slots in use.
Analytics providers process app-instance or device identifiers and technical app and device information. Events can be associated with your ShipHQ account identifier, including a guest account identifier. We do not intentionally include your connected business revenue, subscriber totals, app names, provider credentials or customer records in product-analytics events. We disable Mixpanel IP-based geolocation and Firebase advertising storage and personalization signals. Product analytics is separate from the optional Google Analytics connection used to display your own apps’ metrics.
For provider information, see Mixpanel privacy information and Firebase privacy and security information. You can contact us about access, objection or deletion requests as described below; signing out alone does not erase previously collected analytics records.
RevenueCat: connected metrics and ShipHQ purchases
If you connect your RevenueCat project, ShipHQ reads authorized project and app details and available aggregate metrics, such as recurring revenue, revenue history, active subscribers, new customers and trials. We use these to display your business performance, track progress and provide reports. Connection credentials are encrypted on our backend. Disconnecting removes saved connection credentials; previously synchronized history may remain until account deletion, as described below.
Separately, ShipHQ uses RevenueCat to manage purchases of ShipHQ memberships. RevenueCat processes a ShipHQ account or anonymous purchase identifier, product identifiers, transaction or receipt information, and subscription and entitlement status to validate purchases, restore access and keep premium access up to date. Apple handles App Store payment; ShipHQ does not receive your payment-card details. See RevenueCat privacy information. Deleting your ShipHQ account does not cancel an Apple subscription.
AI reports
When you choose to generate a room report, ShipHQ sends relevant aggregate app metrics and, where enabled, your private learning history to OpenAI. App names and provider credentials are excluded from that report payload. The screen explains the transfer before generation. We request that generated responses are not stored for later retrieval; OpenAI’s own service and security retention policies still apply.
Your private learning journal is account-specific. Contribution to collective founder trends is optional and off by default. The current shared context uses coarse, grouped growth trends, not other founders’ private journals. Turning contribution off removes your active contribution; already generated aggregate reports cannot be recalled.
Public profiles and sharing
Town visibility, app names, revenue and other profile fields follow Profile → Privacy. Check the visitor preview before enabling public visibility. Share cards and office videos include only the fields selected for that export. You choose the destination in the device’s share sheet. Information you publish to another service is then subject to that service’s policies.
Service providers and transfers
Supabase provides authentication, database and backend storage. Apple and Google provide optional sign-in. OpenAI processes requested AI reports. Mixpanel and Google (Firebase) process product analytics. RevenueCat manages ShipHQ subscription purchases and, when connected by you, supplies business metrics. Google Analytics and other authorized sources provide connected metrics. Providers may process data outside your country under their applicable safeguards and policies. We do not sell personal data or use it for cross-app advertising.
Storage, retention and deletion
We retain active account data and metric history while needed to provide your account. You can request correction, access or deletion by contacting us. Profile → Delete account removes your account and its connected credentials, office progress, metric history and private AI memory from active application tables. Backups and security logs may persist according to provider retention and legal requirements. We do not promise immediate removal from all backups.
Deleting ShipHQ does not delete your RevenueCat, Google or other provider accounts. It does not cancel an Apple subscription. See account deletion instructions.
Your choices and rights
You may use guest mode, disconnect sources, change visibility, decline collective contributions and delete your account. Depending on your location, you may have rights to access, correct, export, erase or restrict processing, object to processing, withdraw consent or complain to your local data protection authority. Contact us to exercise these rights; we may need to verify account ownership.
Website and children
This website does not add advertising cookies or third-party analytics scripts. The video on the home page is loaded from YouTube in privacy-enhanced mode (youtube-nocookie.com) only after you press play; from then on, YouTube’s privacy policy applies to that playback. Hosting providers may process technical request logs. ShipHQ is intended for app builders and business users, not children under 13. Contact us if you believe a child has provided personal information.
Changes
We will update this page when our practices change and provide additional notice in the app when appropriate.