We use a small number of external services ("sub-processors") to run ShipSprint. Each one receives only the data listed here, only to provide its function.
Railway (hosting & database) — runs the application and stores all workspace data. Uploaded images are stored in Railway object storage (Singapore region).
Razorpay (payments, India) — processes card/UPI subscription payments. Receives plan, seat count and organization id. Card details never touch our servers.
PhonePe (payments, India) — processes checkout payments. Receives order id and amount only.
Brevo / Resend / SMTP (email delivery) — deliver transactional and notification email. Receive recipient address, subject and message body.
Google & Microsoft (optional sign-in) — when you choose "Sign in with Google/Microsoft", the provider shares your email and profile name with us.
GitHub (optional integration) — if your workspace enables it, GitHub sends us branch/commit/PR metadata you generate. We send nothing to GitHub.
AI assistants (optional, customer-initiated) — if you connect Claude or ChatGPT via MCP, the assistant reads workspace data under your own OAuth grant, which you can revoke in your profile at any time.
We will update this page before adding or replacing any sub-processor.