Data Security Policy
How we protect consumer and client marketing data
Last Updated: June 1, 2026
ShipUp implements comprehensive technical, administrative, and physical safeguards to protect all personal and business data processed through our digital marketing operations.
1. Technical Safeguards
- Encryption: All data encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
- Secure Servers: Marketing solutions data hosted on secure, ISO 27001-aligned cloud infrastructure
- Access Controls: Role-based access control (RBAC) with multi-factor authentication for all internal agency systems
- Firewall Protection: Enterprise-grade web application firewalls and intrusion detection systems
- Regular Backups: Automated encrypted backups with point-in-time recovery capability
- Vulnerability Scanning: Regular automated vulnerability scans and campaign asset penetration testing
2. Administrative Safeguards
- Designated Data Protection Officer (DPO) overseeing all digital campaign processing activities
- Employee background checks and comprehensive corporate confidentiality agreements
- Annual security awareness training for all staff with access to client or consumer personal data
- Need-to-know data access policies limiting exposure to sensitive account information
- Vendor risk assessments for all third-party data and advertising technology processors
- Data Processing Agreements (DPAs) with all technology and automation partners
3. Physical Safeguards
- Secured corporate office facilities with restricted access controls
- Clear desk and clear screen policies for all agency employees handling sensitive data
- Secure shredding and disposal of physical documents containing corporate or personal information
4. Data Minimization
We practice data minimization — collecting only the data necessary for specific, disclosed digital marketing purposes. Consumer data shared with business partners is strictly limited to what is required to fulfill campaign objectives, as explicitly outlined in client service agreements.
5. Client & Consumer Data Handling
- Transmitted securely only to the specific client or integrated platform whose campaign the consumer interacted with
- Never sold to unrelated external third parties or data brokers
- Stored only for the specific duration necessary to fulfill strategic marketing objectives
- Subject to consumer data rights requests (access, deletion, correction) at any time
6. Third-Party Platform Security
All third-party advertising platforms (Meta, Google, TikTok, DSP networks, analytics tools) used in our marketing operations are regularly evaluated for security compliance. We rely exclusively on industry-standard platforms built with their own robust enterprise security frameworks and globally recognized certifications.
7. Security Incident Response
See our Data Breach Response Policy for complete incident response procedures and notification timelines.
8. Contact Our Security Team
Security inquiries: security@shipup.co.in
To report a vulnerability:
security@shipup.co.in — Subject: "Vulnerability Report"