This Privacy Policy explains how IKIGAI Ventures BV, trading as SHIP (“SHIP,” “we,” “us”), handles personal data when you visit letsship.ai, contact us, create an account, or use the SHIP platform.
IKIGAI Ventures BV is established in the Netherlands and registered with the Dutch Chamber of Commerce under KVK 87875438. Our VAT ID is NL864433815B01.
1. Scope and our role
SHIP is a B2B software-delivery platform for engineering teams.
We act as a controller when we decide why and how to process data for our website, demo and waitlist requests, accounts, organization administration, service security, and direct support.
We generally act as a processorwhen a customer uses SHIP to process its issues, repositories, source code, prompts, mission records, agent outputs, and proof artifacts. The customer controls that data and its instructions. The customer's privacy notice and its agreement with us, including any data processing addendum, apply to that processing. If you ask us about data we process only for a customer, we may direct your request to that customer.
2. Data we handle
Depending on how you interact with SHIP, we may handle:
- Website and security data: IP address, browser and device information, request timestamps, pages requested, and security or anti-abuse signals.
- Demo, waitlist, and communications data: name, business email, team size, message, request source, and communications sent to us.
- Account and organization data: email, display name, avatar, password hash or external identity, organization, role, invitations, login history, and authentication sessions.
- Integration and project data: connected Linear workspace and GitHub repository identifiers, project settings, provider selection, and encrypted credentials or tokens.
- Customer Content:issues, comments, repository content, source code, pull requests, CI information, prompts, mission records, agent inputs and outputs, and other material submitted or generated at a customer's direction.
- Proof and observability data: session logs, screenshots, videos, test traces, audit events, model and harness information, token usage, cost data, timings, and operational diagnostics.
- Support and legal data: requests, correspondence, verification information, and records needed to resolve an inquiry or comply with law.
We do not intentionally collect special-category or sensitive personal data, children's data, health records, financial-account data, education records, or biometric identifiers. Customers must not submit that data unless we have expressly agreed in writing that the use case is supported.
3. How we receive data
We receive data:
- directly from you or your organization;
- from administrators who invite you to an organization;
- from customer-directed integrations such as Linear and GitHub;
- from customer-selected AI providers;
- automatically when the website and service operate; and
- from service providers that help us secure and operate SHIP.
4. Why we use data and our legal bases
We use personal data to:
- provide the website, accounts, integrations, and SHIP service;
- execute customer-directed software-delivery workflows;
- authenticate users and administer organizations, projects, and permissions;
- secure the service, prevent abuse, investigate incidents, and protect customer environments;
- provide mission history, proof, cost reporting, and operational support;
- respond to demo requests, waitlist signups, support messages, and privacy requests;
- improve reliability and understand service performance; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Where EU or UK data-protection law requires a legal basis, we rely on:
- contract or steps before entering a contract to provide requested accounts and services;
- legitimate interests in operating a B2B service, responding to business inquiries, securing SHIP, preventing fraud, and improving reliability, where those interests are not overridden by individual rights;
- consent for optional communications or processing where consent is required, which can be withdrawn; and
- legal obligations where we must keep or disclose information.
When we process Customer Content as a processor, the customer determines the applicable legal basis.
5. AI and automated processing
SHIP uses AI models to perform customer-directed software-delivery tasks such as planning, coding, review, and testing. These workflows may generate incorrect, incomplete, or unexpected results and require appropriate human review.
SHIP does not use these workflows to make decisions about individuals that produce legal or similarly significant effects. If that changes, we will assess the use and update this Policy before deployment.
We do not use Customer Content to train our own general-purpose AI models. A customer-selected AI provider handles data under the customer's configuration and its own terms. Customers should review those settings and terms.
6. When we disclose data
We disclose data only as needed for the purposes described above:
- Cloudflare provides hosting, storage, networking, security, sandbox, and Turnstile services.
- Anthropic provides inference for SHIP-selected orchestration.
- Customer-directed integrations include Linear, GitHub, and customer-selected Anthropic, OpenAI, or OpenRouter-backed model providers. The customer directs these connections.
- Professional advisers and authorities may receive data where reasonably necessary for advice, compliance, security, a transaction, or legal claims.
- A successor may receive data as part of a merger, financing, reorganization, or sale, subject to appropriate safeguards.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
7. International processing
SHIP is established in the Netherlands, and our providers and customer-directed integrations may process data in other countries, including the United States. Where required, we use recognized safeguards such as adequacy decisions or approved contractual protections. Contact legal@letsship.ai for information about safeguards relevant to your data.
8. Retention
We keep data only while it is reasonably needed for the purposes described in this Policy, the customer agreement, security, dispute resolution, and legal obligations.
- Authentication sessions normally expire after 30 days.
- Many transient mission, provenance, and operational records normally expire after about 30 days.
- Account, organization, project, integration, support, and legal records are generally kept for the customer relationship and a reasonable period afterward.
- Session logs and proof artifacts may be kept longer to provide audit and verification history. Some proof links are designed to remain available for up to five years unless a shorter agreed period or deletion request applies.
We are implementing a unified termination-deletion schedule across all service stores. Until that work is complete, do not rely on this Policy as a promise that every copy of Customer Content is deleted within a fixed number of days. Customer-specific deletion commitments apply only when stated in an executed agreement and supported by the service configuration.
We may retain limited information longer when required by law, needed for security or legal claims, or preserved in restricted backup or archival systems until their normal deletion cycle.
9. Security
We use technical and organizational measures designed to protect data. These include project-scoped access, isolated execution environments, encrypted connector credentials, short-lived task credentials, access controls, and audit records.
No service can guarantee absolute security. Customers remain responsible for configuring their integrations, provider accounts, repository permissions, approval controls, and users appropriately. Report a suspected security issue to legal@letsship.ai.
11. Your rights
Depending on where you live and the context, you may have rights to:
- access personal data;
- correct inaccurate or incomplete data;
- delete data;
- restrict or object to processing;
- receive portable data;
- withdraw consent without affecting earlier lawful processing; and
- complain to a data-protection authority.
Send requests to legal@letsship.ai. We may verify your identity and authority before acting. Rights are not absolute and may be limited by law, another person's rights, or our role as a processor.
If you are in the Netherlands, you may complain to the Autoriteit Persoonsgegevens. You may also contact the authority in the country where you live or work.
12. Children
SHIP is a business service and is not directed to children. You must be at least 18 years old and authorized to act for a business to create an account. Contact us if you believe a child has provided data to SHIP.
13. Changes
We may update this Policy as SHIP changes. We will revise the date above and provide additional notice when a change materially affects how we use personal data or where law requires it.
14. Contact
IKIGAI Ventures BV, trading as SHIPEstablished in the Netherlands
KVK: 87875438
VAT ID: NL864433815B01
Email: legal@letsship.ai