Legal
Privacy Policy
What we collect, why, and the choices you have. SHIPTRACE is designed to hold as little personal data as possible.
Last updated 11 September 2026
1. Who we are
This website is operated by the SHIPTRACE team (“SHIPTRACE”, “we”, “us”), which is the data controller for personal data processed through it. You can reach us by a direct message to @shiptrace_ on X or the correction form.
2. What we collect
- Account data if you create an account: email address, a username you choose, a display name, and an optional bio. Passwords are handled by our authentication provider and are never visible to us.
- Contributions: evidence submissions, correction requests, votes, and watchlists. Evidence and corrections are public and attributed to your username by design.
- Moderation records: decisions, reasons and timestamps attached to a moderator's account, kept permanently as part of the audit history.
- Technical data: IP address, browser type and request logs collected by our hosting provider for security and reliability, retained for a limited period.
- Cookies: a session cookie needed to keep you signed in. We do not use advertising cookies. See section 7.
We never ask for wallet addresses, private keys, holdings, or payment details.
3. Why we process it
- To run the service: sign you in, show your watchlist, publish your submissions, and let moderators review them (performance of our terms with you).
- To keep the record trustworthy: attributing submissions and preserving moderation history (our legitimate interest in accuracy and accountability).
- To keep the service secure and prevent abuse, including rate limiting and spam protection (legitimate interest).
- To answer your requests, including correction and dispute requests (legitimate interest and legal obligations).
4. What is public
Your username, display name, bio, badges, accepted-evidence count, and every evidence submission, correction request and vote count are public. Your watchlist is private unless you make it public. Your email address is never shown publicly.
Because SHIPTRACE is an audit record, accepted submissions and moderation decisions are retained even if you later delete your account; they are then shown under an anonymised name.
5. Who we share data with
- Vercel hosts the website and processes request logs.
- Supabase stores account and application data and provides authentication.
- GitHub is queried for public repository metadata about tracked projects, not about you.
These providers process data on our instructions. We do not sell personal data and do not share it with advertisers. We may disclose data when required by law.
6. International transfers
Our providers may process data outside your country, including in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards offered by those providers.
8. Retention
- Account data: for as long as your account exists, then deleted within 30 days of a deletion request.
- Public contributions and moderation records: retained as part of the audit history, anonymised after account deletion.
- Server logs: typically 30 days.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a supervisory authority. To exercise these rights, contact us by a direct message to @shiptrace_ on X or the correction form. We may need to verify your identity first.
10. Children
SHIPTRACE is not directed at children under 16 and we do not knowingly collect their data.
11. Changes
We will post any changes on this page and update the date at the top. Material changes will be announced on the site.
See also the Privacy Policy, the Terms of Use and the Methodology.