Privacy Policy
We are committed to transparency about how ShipInADay handles your account data, project briefs, messages, and payments.
Your project stays yours
ShipInADay builds MVPs for founders. We do not sell your project briefs, messages, or personal data. We use your information only to deliver the development service you requested.
1. Introduction
ShipInADay ("we," "us," or "our") is operated by Peak Collective LLC dba Ship in a Day, a company organized under the laws of the State of Missouri, United States.
This Privacy Policy describes the information we collect when you visit www.shipinaday.com, submit a project request, use your customer dashboard, or communicate with our team.
We may update this Privacy Policy from time to time. Material changes will be posted with a revised "Last updated" date. Continued use after the effective date constitutes acceptance of the updated policy.
2. Data We Collect
We collect information you provide and metadata generated during use of the service:
- Account information: name, email, and authentication details when you sign in via Google, GitHub, or email/password.
- Project information: app ideas, feature requirements, tier selections, custom quotes, timeline preferences, and status updates.
- Messages: questions and replies in your project thread between you and our team.
- Billing information: processed by Stripe. We do not store full credit card numbers on our servers.
- Technical metadata: IP addresses, browser user-agent strings, and request timestamps in server logs for security and operations.
We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will delete it.
3. How We Use Your Data
- Review project requests and deliver contracted development work.
- Send transactional emails about status, quotes, and payments.
- Operate the customer dashboard, messaging, and preview environments.
- Process payments and manage project lifecycle.
- Respond to support requests and prevent fraud or abuse.
We process personal data on the following legal bases:
- Contract: to perform our agreement with you.
- Legitimate interests: to operate, secure, and improve the service.
- Legal obligations: where required by applicable law.
- Consent: where required, such as optional marketing communications.
4. Project Data & Deliverables
Your project brief and messages are used solely to scope, build, and hand off your MVP. Delivered source code, repositories, and deployment artifacts are transferred to you upon completion according to your tier or custom agreement.
We may retain anonymized portfolio references only with your explicit permission. We do not publish your app idea or proprietary details without consent.
5. Data Retention & Deletion
- Active projects: retained while your account and project remain active.
- Completed projects: account and project records retained up to 3 years after project completion or account closure, unless a longer period is required by law.
- Support messages: retained for the duration of your support window plus 1 year.
- Server security logs: retained up to 90 days.
- Billing records: Stripe maintains payment records per its retention policies.
To request account or data deletion, contact [email protected].
6. Third-Party Services
We share limited data with service providers that help us operate ShipInADay:
- Stripe — payments and checkout
- Resend — transactional email
- Google / GitHub — optional OAuth sign-in
- Cloudflare — DNS, CDN, and R2 delivery archives
- OVH — application hosting and PostgreSQL database infrastructure
We are based in Springfield, Greene County, Missouri, United States. If you access the service from outside the U.S., your information may be transferred to and processed in the U.S. and other countries where our service providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our vendors.
8. Data Security
- HTTPS encryption for data in transit.
- Authentication required on customer and admin API routes.
- Role-based access so customers only see their own projects.
- Stripe-hosted checkout for payment card handling.
If we become aware of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.
9. Your Privacy Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate account information.
- Request deletion of your account and associated project data.
- Request restriction or portability of your data where applicable.
- Object to certain processing based on legitimate interests.
Submit requests to [email protected]. We will verify your identity and respond within 30 days where GDPR applies, or 45 days where CCPA/CPRA applies.
California residents: we do not sell or share personal information for cross-context behavioral advertising. You may request access to, deletion of, or correction of personal information as described above.
EEA/UK residents: you may lodge a complaint with your local supervisory authority if you believe our processing violates applicable law.
10. Contact Us
Questions about this Privacy Policy? Contact: