Privacy

Last updated 31 August 2026.

Shipbay is one page per person. This notice explains what we hold, why we hold it, and how to get it back or get rid of it. It covers shipbay.dev and every page served from it.

Shipbay is run by one person, not a company. For anything in this notice — including any request below — message @georgevichbiz on X.

What we collect

When you create an account

  • Your handle — the address your page lives at.
  • Your email address, so we can reach you about your account.
  • Your password, stored only as a bcrypt hash. We cannot read it, and we cannot tell you what it is.
  • The dates the account was created and last changed.

When you sign in with X

  • Your X account id and username.
  • Your confirmed email address, when X provides one. If it does not, we ask you for one.

We do not receive your X password, and we cannot post as you. If you signed up with an email address and later sign in with X using the same confirmed address, we treat them as the same person and link the two.

When you pay

Payments are handled by Dodo Payments, who act as the seller of record. Your card details go to them and never reach our servers. From that transaction we keep only which plan you chose, whether it is active, and when it was paid.

What you put on your page

Your name, your one-line description, your projects and your links. This is the part of Shipbay meant to be read, and anyone with your link can see it. Do not put anything there you would not hand to a stranger.

When someone subscribes to a newsletter

A page can carry an email box. If a visitor fills it in, we store that address and the date, and show both to the person whose page it is. They can download the list at any time.

That list belongs to the page owner, not to us. We hold it on their behalf and do nothing else with it — we do not mail it, sell it, or use it to reach anybody. If you subscribed to someone's page and want off the list, ask them; if that fails, message @georgevichbiz on X and we will remove you.

Cookies

We set no advertising or analytics cookies. The only cookies Shipbay uses are the ones that make signing in work:

  • A session cookie that keeps you signed in for 30 days. It is httpOnly, so scripts on the page cannot read it, and it is signed so it cannot be forged.
  • Three short-lived cookies during X sign-in, holding the request state and the proof that the request came from us. They last ten minutes.
  • A 15-minute cookie holding a verified X identity, if you need to pick a handle before your account exists.

Visits to a page

When someone opens a Shipbay page, or follows one of its links, we record that it happened, which site referred them, and the country their request came from. The country is worked out by our hosting provider at the edge and handed to us as a two-letter code — we do not look at or store the visitor’s IP address ourselves, and we set no cookie on visitors. These counts are shown to the person whose page it is, and to nobody else.

Server logs

Our servers record requests, including IP addresses and timestamps, so we can keep the service working and spot abuse.

Stopping abuse

Sign-in attempts, sign-ups and password reset requests are counted so that no one address can flood them. What we store is a one-way digest of the address — and, for password resets, of the email address it was asked for — never the address itself. A digest cannot be turned back into what made it, is useless anywhere but here, and is deleted automatically when its counting window closes, a few minutes later.

What we do not do

  • We do not sell your data, and we do not share it for advertising.
  • We run no analytics or tracking scripts.
  • We do not profile you or make automated decisions about you.
  • There is no feed, so nothing you do is ranked or scored.

Why we are allowed to hold it

If you are in the UK or the EU, our lawful bases under the GDPR are:

  • Performing our contract with you — your account, your page, and your payment. Without these we cannot provide the service you asked for.
  • Our legitimate interests — keeping the service available, secure, and free of abuse.
  • Our legal obligations — keeping records of sales for tax and accounting.

Who else handles it

We use a small number of companies to run Shipbay. They may only act on our instructions:

  • MongoDB Atlas, which stores accounts and pages.
  • Vercel, which runs the site, holds server logs, and counts page views for us.
  • Dodo Payments, which takes payments and issues receipts.
  • Resend, which delivers the few emails we send — a password reset, or a notice that your password changed.
  • X, but only if you choose to sign in with it.

Where these companies move data outside the UK or EEA, that transfer relies on the safeguards in their own terms, such as standard contractual clauses.

How long we keep it

  • Your account and page: until you delete them, or until the account has been closed for 12 months.
  • Records of payments: as long as tax law requires, usually six years.
  • Server logs: a short period set by our hosting provider, measured in days, after which they are deleted automatically.

What you can ask for

Whatever your location, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop using it. If you are in the UK or EU these are rights under the GDPR, and you can also complain to your data protection authority — in the UK, the Information Commissioner’s Office.

Message @georgevichbiz on X. We will answer within 30 days. We may ask you to confirm you control the account first.

Children

Shipbay is not for people under 16. We do not knowingly hold their data, and we delete any account we find belongs to one.

Changes

If we change this notice we will update the date at the top. If the change matters — new data, a new reason for holding it — we will email you before it takes effect.

Privacy — Shipbay