ShipWink
Sign In Get Started →
← Home
Trust & Safety

Security

Our commitment to protecting your data and transactions

On this page
Our CommitmentData Encryption Payment SecurityAuthentication InfrastructureCarrier API Security Responsible DisclosureData Breach Response
ShipWink takes the security of your data and transactions seriously. Here is an overview of the measures we use to protect you.

🔒 Our Commitment

Security is built into our platform architecture from the ground up. We follow industry best practices for data protection, access control, and incident response.

🔐 TLS 1.2+ Encryption
💳 PCI DSS via Stripe
🛡️ GDPR Compliant
🔑 Secure Auth

🔐 Data Encryption

  • In transit: All data between your browser and ShipWink is encrypted via TLS 1.2+ (HTTPS) on all endpoints.
  • At rest: Sensitive data is encrypted at rest using AES-256.
  • API keys: All carrier and payment credentials are stored encrypted and never exposed to frontend clients.

💳 Payment Security

ShipWink does not store your credit card or bank details. All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider — the highest certification available.

Wallet top-up transactions are processed entirely within Stripe's secure environment. ShipWink never touches raw card data.

🔑 Authentication

  • Password hashing using industry-standard bcrypt
  • Email verification required for new accounts
  • Session tokens with automatic expiry
  • Two-factor authentication (2FA) — coming in upcoming release

🏗️ Infrastructure

  • Servers hosted on hardened cloud infrastructure
  • Automated daily backups
  • Production system access restricted by role
  • Dependencies monitored for known vulnerabilities

📡 Carrier API Security

All communication with carrier APIs (EasyPost, USPS, UPS, FedEx, DHL) is made server-side using encrypted API keys. These keys are never exposed in client-side code or browser network requests.

🐛 Responsible Disclosure

If you discover a security vulnerability, please report it to hello@shipwink.com with the subject: "Security Disclosure".

We ask for reasonable time to investigate before public disclosure. We do not pursue legal action against good-faith security researchers.

🚨 Data Breach Response

In the event of a data breach, ShipWink will:

  • Notify affected users within 72 hours of becoming aware (per GDPR Article 33)
  • Send details to the email on your account: nature of breach, data affected, and remediation steps
  • Notify relevant data protection authorities as required by law
ShipWink

Smarter shipping for eCommerce sellers. Wholesale carrier rates, one dashboard.

hello@shipwink.com
Product+
Get Started Sign In Pricing
Legal+
Privacy Policy Terms of Service Refund Policy Acceptable Use Cookie Policy
Support+
Security Accessibility Help Center Track a Package Contact Support
© 2026 ShipWink. All rights reserved.
WCAG 2.1 AA GDPR CCPA SSL/TLS v1.0.13