Privacy Policy
Effective May 1, 2026. This policy explains what data we collect, why we collect it, and what choices you have.
1. Data we collect
Account data
When you sign up we collect your email, a hashed password (or your OAuth provider identifier), your display name, your account currency, and the company / billing details you choose to add.
Shipment data
To purchase a label we need the sender and recipient names, postal addresses, package weight and dimensions, declared contents, and the chosen service. We pass the minimum necessary subset of this data to the relevant carrier or carrier aggregator.
Payment and balance data
For card top-ups, payment processing is handled by our card processor; we receive metadata (last four digits, brand, country) but do not store full card numbers. For crypto top-ups, we record the destination address, the on-chain transaction hash, and the credited amount.
API and dashboard activity
We log API requests (timestamp, route, status, request id, and a truncated summary), webhook delivery attempts, and security-relevant events such as logins and password changes.
2. How we use it
- To operate the Service — authenticate you, draft and buy labels, route webhooks, and reconcile your balance.
- To prevent fraud and abuse, including reviewing risk-flagged activity and enforcing our Acceptable Use Policy.
- To meet legal obligations, including tax and recordkeeping requirements and lawful requests from authorities.
- To improve the Service — diagnose bugs, measure feature usage in aggregate, and inform product decisions.
3. Sharing
We share data with: (a) the carriers (or carrier aggregators) needed to fulfill your shipment; (b) the payment and crypto-confirmation providers needed to credit your balance; (c) infrastructure sub-processors (hosting, error monitoring, transactional email); and (d) authorities where legally required. We do not sell your personal data and we do not share it with advertisers.
4. Retention
We retain account, shipment, and balance records for as long as your account is active and afterwards for as long as necessary to comply with tax, accounting, and dispute-resolution obligations. Logs of API and security activity are retained on a rolling window appropriate to their purpose.
5. Your choices
You can update your account details from the in-app settings. To request export or deletion of your personal data, email billy@goatlabels.io. We may need to retain certain records (for example, completed shipments and balance transactions) to comply with our legal obligations even after an account is closed.
6. Security
We protect data in transit with TLS, store secrets and credentials using industry-standard secret management, and apply least-privilege access controls. No system is perfectly secure; report suspected vulnerabilities to billy@goatlabels.io.
7. International transfers
GoatLabels operates from the United States. By using the Service you understand that your data may be processed in the United States and in any country where our sub-processors operate, subject to appropriate safeguards.
8. Children
The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact billy@goatlabels.io and we will delete it.
9. Changes
We may update this policy. Material changes will be announced via in-app notice or email at least 14 days before they take effect.
10. Contact
Privacy questions or requests: billy@goatlabels.io.
