Your code deserves
a clear boundary.
ShipVRA is operated by PastePile Labs LLC, a Georgia limited liability company. PastePile Labs LLC is the data controller for the personal information processed to provide ShipVRA.
What a scan stores
ShipVRA stores the submitted public URL, scan timestamps, rule outcomes, sanitized findings, and purchase records. Raw response bodies and cookie values are not retained as scan evidence.
A private browser session controls access to scans, purchased reports and connected repository results. The session cookie is HttpOnly, uses SameSite=Lax and is restricted to HTTPS in production. It expires after 90 days. Session credentials are stored as hashes.
Repository access
When you connect GitHub, your access token is encrypted at rest. Deep Inspect reads bounded source files at a recorded commit and retains sanitized findings. It does not execute repository code.
Disconnecting removes the stored GitHub token. You can also revoke the app in GitHub settings. Purchase processing is handled by Stripe; ShipVRA does not store card details.
Workspace recovery
You can create a recovery code from your workspace. The code is shown once, and only its hash is stored. Keep the code in a password manager: anyone holding it can restore access to your workspace.
Restoring a workspace consumes the code, issues a new one and signs out previous device sessions. Creating a replacement code invalidates the previous code. Without a saved recovery code, clearing or losing your session can make the workspace inaccessible.
Export your evidence
Workspace export provides structured JSON containing your scans, findings, source results, repair records, verification records and order summaries. It excludes session and recovery credentials, GitHub access tokens and internal signing secrets.
Exports have record and payload limits. The downloaded file states those limits and marks categories where records were omitted. Evidence is sanitized again before export.
Retention and erasure
PastePile Labs LLC retains workspace, application, scan, inspection, report and related customer data while your workspace remains active and as reasonably necessary to provide the service. When you request workspace deletion, eligible customer workspace data is removed from active ShipVRA systems within 30 days.
Deleted information may remain in encrypted backups for up to 30 additional days before normal backup expiration or rotation. Payment, order, refund, dispute, accounting, fraud-prevention, security and related audit records may be retained for up to 7 years when reasonably necessary for financial records, tax records, legal obligations, accounting, fraud and abuse prevention, security investigations and dispute resolution.
Third-party providers
ShipVRA uses third-party providers to run the service. These may include Stripe (payment processing), GitHub (repository access), Vercel (application hosting), Supabase (database) and a transactional email provider. Data retained by these providers is subject to their own policies.
Deleting your workspace with ShipVRA does not by itself delete data these providers hold independently, and ShipVRA does not claim third-party deletion unless it actually initiated or verified that deletion.
Support and contact
For questions about this policy, exports, deletion or a data request, contact support@shipvra.com. Written correspondence may be sent to:
PastePile Labs LLC
8735 Dunwoody Place Ste N
Atlanta, GA 30350
USA
Certifications
ShipVRA has not been independently certified against SOC 2, HIPAA, PCI DSS, GDPR or CCPA and does not represent that it has been. This policy describes actual processing, not a certification.