Privacy policy
Last updated:
What we collect, why, who helps us run the service, and how to have it deleted. In plain words, because you should be able to read it.
Who we are
ShipTiffin runs Tiffin servers (“boxes”) for customers: one server per customer, with a dashboard at dashboard.shiptiffin.com and apps at addresses under shiptiffin.app or the customer’s own domains. In this policy “ShipTiffin”, “we” and “us” mean the operator of this service, and “you” means anyone who uses it or visits this website.
Questions about privacy go to hello@shiptiffin.com. A person reads that inbox.
What we collect
Your account
Your email address and your name, so you can sign in and we can reach you about your box. If you sign in with a passkey, your device keeps the private key; we store only the public key and a counter.
How your box is used
Measurements of the box and its projects: CPU, memory, disk and network use, how many requests each app serves and how fast, whether services are healthy. We use them to run the service, plan capacity and, once pricing exists, to bill you.
Logs
Your box keeps logs: what its own services print, what your apps print, and a line for each request that reaches an app (time, method, the path without its query string, status, duration, and the visitor’s IP address and browser). It also keeps short traces of slow or failing requests, and a record of mail your apps send. Sign-in tokens and keys are masked before a line is stored. These logs stay on your box. We read them only to keep the service running, to answer a question you ask us, or to look into abuse.
Data in your apps
Everything your apps store (database rows, files, KV keys, the accounts of people who sign in to your apps) lives on your box. Mail your apps send goes out through the mail provider you connect to your box, under your agreement with them. You decide what goes there. For that data we act on your behalf: we don’t look at it, use it or share it, except to keep the service running, when you ask us to help, to investigate abuse of the service, or when the law requires it.
When you write to us
What you send us, and our replies.
This website
shiptiffin.com runs on a Tiffin box. It counts visits the way every Tiffin box does: without cookies or scripts, from the request itself. A visitor is a hash of the IP address and browser with a salt that changes daily and is deleted after 48 hours; the IP address and browser are not stored with the count. Browsers that send Global Privacy Control are not counted.
Sign in with Google
You can sign in to your ShipTiffin account and dashboard with Google. ShipTiffin also provides a shared “Sign in with Google” for apps hosted on ShipTiffin. When you choose it, or an app’s owner turns it on and you choose it there, Google’s screen names ShipTiffin, and Google shares your name, email address and profile picture. We ask for nothing else: no access to your Gmail, Drive, Calendar, contacts or any other Google data.
This information is used only to sign you in: to find your ShipTiffin account, or to create or find your account in that app and show your name and picture there. Signing in to the dashboard with Google only works for an email address that already has access to that box. It goes to the box that runs the app and is stored with the app’s user accounts, which that app’s owner looks after under their own privacy policy. Our terms require owners who use this sign-in to follow Google’s rules for this data, below.
ShipTiffin’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell Google user data.
- We do not use it for advertising, and we do not share it with advertisers or data brokers.
- We do not use it to train AI or machine learning models, ours or anyone else’s.
- We pass it to no one except the app you are signing in to, the providers below that host the service, or when the law requires it.
- No person at ShipTiffin reads it unless you ask us to, it is needed for security or to investigate abuse, or the law requires it.
You can remove ShipTiffin’s access at any time in your Google Account, under third-party apps and services. To delete the data itself, ask the app’s owner, or see your choices.
How we use it
- To run your box and the dashboard, and to sign you in.
- To keep the service secure: spotting abuse, scanners and break-in attempts.
- To tell you about your box: problems, planned maintenance, and changes to these policies.
- To answer you when you write to us.
- To bill you, once pricing exists.
What we never do
- Sell your data, or the data of the people who use your apps.
- Show ads, or put advertising or cross-site tracking scripts on our pages or yours.
- Use your data, or your apps’ data, to train AI models.
Who helps us run it
A few companies process data for us to provide the service. They get only what their part needs.
| Provider | What it does for us |
|---|---|
| Hetzner | The servers your box and this website run on, in Hetzner’s data centres. |
| SendGrid (Twilio) | Delivers the email ShipTiffin itself sends: account and sign-in emails, notices about your box. Mail your apps send goes through the mail provider you connect, not through us. |
| Cloudflare | DNS for shiptiffin.com and shiptiffin.app, and forwarding of mail sent to our shiptiffin.com addresses to our inbox. Traffic to your box does not pass through its proxy. |
| Only if you choose Sign in with Google, as described above. |
HTTPS certificates come from Let’s Encrypt; like every public certificate, they publish the domain names they cover. If you connect GitHub to deploy your code, GitHub shares the repositories you choose with your box. When we add a payment provider, we will list it here first.
How long we keep it
- Your account: while it is open.
- App and request logs: 30 days. Measurements of the box: 30 days. Request traces: 3 days.
- Mail your apps send through your mail provider: the full message for 7 days, a log entry for 30 days.
- Visit counts: 365 days by default (you can change it per project). They hold no IP addresses and no cookies; the daily salt behind them is deleted after 48 hours.
- Data in your apps: until you delete it, or until your box is closed.
- Deleted databases and buckets: kept for 7 days in case you change your mind, then gone.
- Backup copies kept off the box: 30 days, each.
- When your box is closed, we delete the server and its disks, and with them everything on it. Backup copies kept off the box expire within 30 days after that. Export anything you want to keep first.
- Email you send us: as long as we need it to help you, and no longer than we have to.
Your choices
You can see, correct, export or delete your data. Most of it you can handle yourself in the dashboard: projects export to a file, and deleting a project deletes its data. For anything else, including deleting your account and everything we hold about you, email hello@shiptiffin.com from the address on your account. We reply within 30 days, usually much sooner.
If you are someone who uses an app hosted on ShipTiffin, the app’s owner decides what happens to your data in it. Ask them first; if you can’t reach them, write to us and we will pass your request on.
Depending on where you live, you may have further rights under data protection law, including to complain to your local data protection authority. We will help you use them.
Security
Every box is its own server, so one customer’s apps never share a machine with another’s. Traffic is HTTPS only. Databases and other services are not reachable from the internet. Secrets are encrypted on the box, API keys are stored only as hashes, and the dashboard signs people in with one-time links or passkeys rather than passwords. Rate limits and automatic bans guard against scanners and brute-force attempts.
No system is perfectly secure. If we learn of a breach that affects your data, we will tell you promptly. If you find a security problem, please write to hello@shiptiffin.com.
Children
ShipTiffin is a tool for building and running software, not a service for children. You must be at least 16 to open an account. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
When we change this policy, we update the date at the top. If a change matters, for example a new provider or a new use of your data, we email account holders before it takes effect. We will never start using Google user data in a new way without asking you first.
Contact
Email hello@shiptiffin.com about anything in this policy. Our terms of service cover the rest of how ShipTiffin works.