Privacy Policy
Last Updated: August 25, 2026
1. Information We Collect
We collect the following information:
- Account Information: Email address and name when you create an account
- Search & Usage Data: Keywords, niches, and stores you search or view
- Payment Information: Processed securely by Stripe (we do not store credit card details)
- Usage Analytics: Pseudonymous usage data such as pages visited, product actions, and conversion steps to help us improve the service (Google Analytics)
- Ad Measurement: Page views and conversion steps used to measure and improve advertising on Meta (Meta Pixel)
- Signup Attribution: Referring domain, landing page path, and campaign tags associated with your account signup
- Chrome Extension Data: If you install our optional Chrome extension, the store pages you ask it to analyse and the listings you choose to import — see the Chrome Extension section below
2. How We Use Your Information
We use your information to:
- Provide dropshipping intelligence and search services
- Process payments and manage your account
- Send service updates and important notifications
- Improve our product and user experience
- Measure advertising performance and reach relevant audiences
- Comply with legal obligations
3. Third-Party Services
We use the following third-party services:
- Supabase: Database and authentication
- Stripe: Payment processing
- Resend: Transactional email delivery
- Google Analytics: Product usage analytics, loaded by default; you may opt out (see Cookies below)
- Meta Pixel: Advertising measurement on Facebook and Instagram, loaded by default; you may opt out (see Cookies below)
- Sentry: Error and performance monitoring used to keep the service reliable. We do not use Sentry Session Replay
- Data & scraping providers: Used to gather public store and product signals
Each service has its own privacy policy governing how they handle data.
4. Chrome Extension
Our Chrome extension is optional and free. It creates a panel only on a Shopify store homepage, a Shopify product page, or an AliExpress product page. On every other page — including cart, checkout, account, search, collection and blog pages — it displays nothing and makes no request.
On our own site it displays nothing either. It does one thing there: it lets a Connect button on whatshipping.com open the Shopify setup guide, so you do not have to go and find a Shopify store to start from. It reads nothing from our pages and sends us nothing on its own.
What the extension sends to WHAT Shipping:
- Store address: when the panel opens on a Shopify store, so we can return research we already hold on it. This request does not include your account details
- Product page address: when you open a Shopify product page, so we can return that product's ranking. This request includes your session cookie so we can tell whether your plan unlocks the more detailed figures. We do not keep a record of the pages you visit
- Public catalogue summary: for a Shopify store that is not yet in our research index, and only when you are signed in, the extension reads that store's own publicly published product data in your browser and sends us a summary of it — the store address, product handles, titles, prices and image addresses — so the store can be added to our index. This is public storefront information about a merchant, contains no personal data, and is never sent for a store we already cover
- Listings you choose to import: when you press Import, the product listing on screen, including from an AliExpress page, so we can build the draft in your own store
- Shopify credentials you choose to connect: the Client ID and secret shown on Shopify's own developer pages when you click Connect my store. Secrets are encrypted at rest and are never written to logs
- Anonymous usage counts: which panel screens and buttons get used, recorded as daily totals. These carry no account identifier, no cookie and no page address
The extension does not:
- Record or transmit your browsing history
- Read pages other than the three types listed above
- Send your data to anyone other than WHAT Shipping
- Build a full store report unless you press the button that does so
Why Chrome says "Website content" and "Web history"
Chrome shows those labels because the extension has to recognise a Shopify or AliExpress product page on whatever store you open. Shopify stores live on custom domains, so the extension cannot be limited to a list of known sites. That is not a request for your Chrome history — this extension does not use the history permission.
- Website content: we read the public product page you already have open so we can show the verdict, or copy the listing you asked to import. Cart, checkout, account, search, collection and blog pages are never read
- Web history: we do not collect, store, or transmit it. Chrome shows this disclosure whenever an extension can run on more than one site. We never save a list of sites you visited
Our use of information received from the Chrome Web Store complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Removing the extension stops all of the above; data already held in your account remains covered by the rest of this policy, including your deletion rights.
5. Data Retention
- Account Data: Until you request account deletion
- Search History: Retained while your account is active
- Signup Attribution: Retained with your account unless you opt out of analytics cookies before attribution is attached
- Payment Records: 7 years (legal requirement)
- Extension Usage Counts: Kept indefinitely as daily totals. They contain no account identifier, so they cannot be traced back to you or deleted individually
- Public Catalogue Data: Merchant storefront information added to our research index is retained as part of that index. It is public business data, not personal data
6. Your Rights
You have the right to:
- Access your personal data
- Request data deletion
- Export your data
- Opt out of marketing emails
- Opt out of analytics and advertising cookies at any time
- Update your information
7. Data Security
We implement industry-standard security measures including:
- Encrypted data transmission (HTTPS/TLS)
- Secure database with row-level security
- Regular security reviews
- Limited employee access to data
8. Cookies
We use essential cookies for:
- Authentication and session management
- Remembering your preferences
Referral cookie (action-based): if you arrive via a partner's referral link and choose to claim the referral discount, we set a single first-party cookie recording the referral code for up to 30 days. It is used only to apply your discount and credit the partner who referred you; it is never set without your action and is not used for advertising or cross-site tracking. If you create an account, or explicitly accept an offer while signed in, the referral is attached to that account so the discount and partner attribution continue across devices. Attribution is set once, cannot overwrite an existing referral, and is unavailable after your first paid subscription.
Analytics and advertising cookies (on by default): we use Google Analytics and the Meta Pixel to understand how the product is used and to measure advertising. Google Analytics may set first-party _ga cookies. The Meta Pixel may set cookies such as _fbp / _fbc and process page views and conversion events. These tools load for visitors by default.
How to opt out: use Cookie preferences in the site footer or your dashboard settings to choose "Opt out". We store that choice as ws_analytics=denied for up to 12 months, stop loading Google Analytics and the Meta Pixel, and clear related cookies where possible. You can turn analytics back on from the same preferences control.
Signup attribution cookie: unless you have opted out, we may set a short-lived first-party cookie containing only the external referring domain, landing path, and standard campaign tags. If you create an account within seven days, that context is attached to the account once to help us understand which acquisition channels work. Opting out clears any attribution that has not yet been attached.
We do not sell your personal data. Opting out of analytics cookies does not affect essential account cookies or your ability to use the service.
9. GDPR Compliance
For users in the European Union, we comply with GDPR requirements including:
- Contract performance for accounts, billing, and service delivery
- Analytics and advertising measurement with an easy opt-out (see Cookies)
- Legitimate interests for security, fraud prevention, and error monitoring
- Right to data portability
- Right to be forgotten
- Right to opt out of analytics and advertising cookies without affecting essential service
- Data breach notification within 72 hours
10. CCPA Compliance
For California residents, we comply with CCPA requirements:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we do not sell data)
- Right to non-discrimination for exercising privacy rights
11. Children's Privacy
Our service is not intended for users under 18 years of age. We do not knowingly collect information from children.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by email or through our service.
13. Contact Us
For privacy-related questions or requests:
Tagan Labs LLC, 30 N Gould St, STE R, Sheridan, Wyoming 82801, USA
Email: legal@whatshipping.com
