FMC Licensed NVOCC · OTI Bonded Carrier  |  Used Automobile Export Specialists to West Africa  |  Regulated by the U.S. Federal Maritime Commission
VShip Logo
VSHIP CO
International Ocean Freight

VShip Documents Upload App

Privacy Policy

Last updated: June 9, 2026

This Privacy Policy explains how VShip (“VShip,” “we,” “us,” or “our”) uses personal data about you in connection with the VShip Document Upload application (the “App”), a tool for capturing, uploading, assembling, and transmitting export and shipping documents.

1. Specific provisions

Data controller. The entity responsible for your personal information under this policy is VShip, 3636 33rd Street, Astoria, NY 11106, United States. Our contact details are in Section 11.

Personal information. In this policy, “personal information” means any information relating to an identified or identifiable individual, including information that would constitute “personal data” under the General Data Protection Regulation (GDPR) or other applicable data protection and privacy laws. The scope is broad and covers information in any form.

This policy applies to the App. A more specific notice — such as your device’s camera or photo-library permission prompt — governs the activity it describes where it conflicts with this policy.

2. Protecting your personal data

VShip is based in the United States, and our servers and hosting infrastructure (Microsoft Azure) are located there. If you access the App from outside the United States, your personal information will be transferred to and processed in the United States. We protect it as described in this policy, including the transfer safeguards in Section 5.

3. Personal data we collect and how we use it

The table below sets out the categories of personal data we collect, what each includes, where it comes from, why we use it, and our legal basis. For each purpose we use only the data needed for it.

Category What it includes Source Purpose Legal basis
Account and contact data Full name, company name, email address, phone number You, at registration or contact Create and manage your account; authenticate you; respond to requests; send service and security messages Performance of our agreement; our legitimate interest in supporting and securing the service
Submission data The documents you upload (e.g., car titles, bills of sale, export powers of attorney) and any booking number you provide You, via the submission feature Receive, process, convert, assemble, store, and deliver your documents to the recipients you designate Performance of our agreement
Camera and photo-library content Photographs and document images you capture or select Your device, with your permission Assemble and deliver the images as part of your submission, and for no other purpose Your consent (withdrawable in device settings); performance of our agreement
Usage and device data Device identifiers, app/browser type, IP address, access times, diagnostic data; security logs Collected automatically when you use the App Keep the App secure; troubleshoot; detect and prevent misuse or fraud; analyze usage to improve reliability Our legitimate interest in a secure, functioning service; legal obligation where applicable

Personal data of other people in your documents. The documents you upload frequently contain personal information about other people — for example, the names, addresses, signatures, and sometimes identification numbers of buyers, sellers, or signatories. You are responsible for ensuring you have the right to share that information with us. We process it only to provide the App’s document-handling features and for no independent purpose. We do not request payment-card or financial-account information and ask that you not upload it.

We also use personal data to comply with legal obligations and to respond to lawful requests, using whatever data the obligation requires (legal basis: legal obligation). We do not sell your personal data, use it for cross-context behavioral advertising, or use uploaded document content to build advertising or unrelated profiles. These uses correspond to the business purposes enumerated under the CCPA/CPRA (Cal. Civ. Code § 1798.140(e)).

4. Sharing of personal data

We share personal information only where it is relevant and necessary to perform the activities described in this policy:

Your personal information will not be disclosed to anyone outside VShip except as described above or as permitted or required under applicable law, and, where necessary, subject to written assurances that the recipient will protect the data with adequate security measures.

5. Transfer and protection of your personal data

Where a transfer of personal data from the EEA, UK, or Switzerland is restricted under applicable law, we rely on the European Commission’s Standard Contractual Clauses (the “SCCs”), and for the UK the UK International Data Transfer Addendum (and Swiss equivalents). We apply the SCC module appropriate to each transfer — the controller-to-controller module (Module One) for transfers to an independent controller, and the controller-to-processor module (Module Two) for transfers to a service provider acting on our behalf. The applicable SCCs, as published by the European Commission and in force from time to time, are incorporated into this Privacy Policy by reference and form part of our data-transfer arrangements, with supplementary measures where appropriate. You may request a copy using the contact details in Section 11.

6. Security measures

We use commercially reasonable technical and organizational measures, including encryption in transit (TLS 1.2 or higher), role-based access controls, password-complexity requirements, and security logging and monitoring, and we evaluate these measures on an ongoing basis. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

7. Personal data retention

We keep personal information only as long as necessary for the purposes described in this policy, then delete or anonymize it, unless we are required or entitled under applicable law to retain it longer.

Category Retention
Account information Duration of the account relationship, plus up to 24 months after closure
Uploaded documents and files [OPEN — confirm with VShip] Retained to provide and deliver the service; deleted or anonymized within [X days/months] after delivery or when no longer needed for processing, support, or a legal requirement
Usage data and server logs Up to 24 months for security, troubleshooting, and improvement

We may retain personal data longer where required by law, to establish or defend legal claims, or where residual copies persist in routine encrypted backups (which are not restored except for security, disaster recovery, or legal compliance).

8. Your data protection rights

Device permissions. You can enable or disable camera and photo-library access at any time in your device settings. Disabling them may limit certain features.

EEA / UK / Switzerland (GDPR). Subject to the conditions and exceptions in applicable law, you have the right to request access to your personal information; request rectification of inaccurate or incomplete information; request erasure; object to or request restriction of processing; request portability of information you provided to us, in a structured, commonly used, machine-readable format; withdraw consent at any time (without affecting processing already carried out); and lodge a complaint with your local supervisory authority. We respond within 30 days or as the law requires.

These rights are subject to exemptions and may not all be available depending on where you are based — for example, where other law requires us to retain the data. We evaluate each request carefully and explain our reasons where we cannot act.

9. California privacy rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA/CPRA”).

Categories of personal information we collect

In the preceding 12 months, we have collected the following statutory categories of personal information (Cal. Civ. Code § 1798.140(v)(1)). We do not collect categories that are not listed below.

Statutory category (Cal. Civ. Code § 1798.140(v)(1)) Examples collected by VShip
(A) Identifiers Full name, email address, phone number, company name, device identifiers, IP address
(B) Customer records (§ 1798.80(e)) Name, phone number, company name
(H) Sensory / visual information Photographs and document images you upload through the camera or photo library

Sensitive personal information. We do not request sensitive personal information. However, a document you upload may itself contain an identification number (for example, a driver’s license number shown on a vehicle title). Where that occurs, we collect that information only as an incidental part of the document and use it solely to provide the service you request — not to infer characteristics about you. Consistent with Cal. Civ. Code § 1798.140(ae), we use such information only for purposes permitted under the CCPA/CPRA, and you may exercise the right to limit its use and disclosure as described below.

Sources, purposes, and disclosures

We collect personal information directly from you (account registration, submissions, and communications), automatically from your device when you use the App, and from your device camera or photo library when you grant permission. We use each category for the business purposes in Section 3.

Categories disclosed for a business purpose. In the preceding 12 months, we disclosed the following categories of personal information to service providers and contractors for the business purposes described in Section 3: identifiers and customer-records information (to our cloud hosting/storage and email-delivery providers and our documentation team); and sensory/visual information — the documents and images you upload (to our cloud hosting/storage provider and our documentation team). These disclosures are made under contracts that meet CCPA/CPRA requirements. We do not sell or share personal information (as “sell” and “share” are defined under the CCPA/CPRA), and we have not sold or shared personal information in the preceding 12 months.

Your rights and how to exercise them

California residents have the right to know, access, and obtain a copy of the personal information we hold; to request correction of inaccurate information; to request deletion; to limit the use and disclosure of sensitive personal information; to opt out of any future sale or sharing; and not to receive discriminatory treatment for exercising these rights.

Submit a request using the methods in Section 11. We will verify your identity using information associated with your account. You may make a verifiable request up to twice in a 12-month period, and we will respond within 45 days (extendable by up to another 45 days with notice). An authorized agent may submit a request on your behalf with proof of authorization.

Because we may retain some personal information for longer than 12 months, you may also request access to personal information we collected about you before the 12-month period preceding your request (going back to January 1, 2022). When you submit a request to know, you may specify a date range or ask for all personal information we hold about you.

10. Age requirement

The App is a business tool intended only for users 18 or older, and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it and close any associated account.

11. Contact us and changes to this policy

We may update this policy from time to time. We will post the updated version, revise the “Last updated” date, and — for material changes — notify you by email or a prominent in-app notice before the change takes effect.

If you have questions about this policy, wish to exercise your rights, or want a copy of our data-transfer mechanisms, contact us: