Legal

Privacy Policy

Effective July 30, 2026. This policy explains what data we collect, why we collect it, and what choices you have.

1. Data we collect

Account data

When you sign up we collect your email, a hashed password (or your OAuth provider identifier), your display name, your account currency, and the company / billing details you choose to add.

Shipment data

To purchase a label we need the sender and recipient names, postal addresses, package weight and dimensions, declared contents, and the chosen service. We pass the minimum necessary subset of this data to the relevant carrier or carrier aggregator.

Payment and balance data

For card top-ups, payment processing is handled by our card processor; we receive metadata (last four digits, brand, country) but do not store full card numbers. For crypto top-ups, we record the destination address, the on-chain transaction hash, and the credited amount.

API and dashboard activity

We log API requests (timestamp, route, status, request id, and a truncated summary), webhook delivery attempts, and security-relevant events such as logins and password changes.

Cookies and advertising measurement

When you visit our marketing site we set first-party cookies to measure which advertising campaigns bring visitors to us: gl_id, a randomly generated visitor identifier (2 years); gl_clids, the advertising click identifiers present in the URL you arrived on (90 days); and gl_attr_ft and gl_attr_lt, which record the first and most recent campaign that referred you (2 years and 90 days respectively). We set these on our own domain and use them for attribution measurement only — not to advertise to you on other sites.

2. How we use it

  • To operate the Service — authenticate you, draft and buy labels, route webhooks, and reconcile your balance.
  • To prevent fraud and abuse, including reviewing risk-flagged activity and enforcing our Acceptable Use Policy.
  • To meet legal obligations, including tax and recordkeeping requirements and lawful requests from authorities.
  • To improve the Service — diagnose bugs, measure feature usage in aggregate, and inform product decisions.

3. Sharing

We share data with: (a) the carriers (or carrier aggregators) needed to fulfill your shipment; (b) the payment and crypto-confirmation providers needed to credit your balance; (c) infrastructure sub-processors (hosting, error monitoring, transactional email); (d) advertising platforms, where we report conversion events (such as a completed signup or account top-up) so we can measure which advertising campaigns are effective; and (e) authorities where legally required. We do not sell your personal data.

4. Retention

We retain account, shipment, and balance records for as long as your account is active and afterwards for as long as necessary to comply with tax, accounting, and dispute-resolution obligations. Logs of API and security activity are retained on a rolling window appropriate to their purpose.

5. Your choices

You can update your account details from the in-app settings. To request export or deletion of your personal data, email billy@goatlabels.io. We may need to retain certain records (for example, completed shipments and balance transactions) to comply with our legal obligations even after an account is closed.

We do not set advertising-measurement cookies for visitors in the European Union, the European Economic Area, or the United Kingdom. If your browser sends a Global Privacy Control signal, we honor it and skip those cookies.

6. Security

We protect data in transit with TLS, store secrets and credentials using industry-standard secret management, and apply least-privilege access controls. No system is perfectly secure; report suspected vulnerabilities to billy@goatlabels.io.

7. International transfers

GoatLabels operates from the United States. By using the Service you understand that your data may be processed in the United States and in any country where our sub-processors operate, subject to appropriate safeguards.

8. Children

The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact billy@goatlabels.io and we will delete it.

9. Changes

We may update this policy. Material changes will be announced via in-app notice or email at least 14 days before they take effect.

10. Contact

Privacy questions or requests: billy@goatlabels.io.