Twinshipper

Privacy policy

Version 2026-09-08-draft

If you want your details removed from our data, you do not need to read any of this — use the removal form. It asks only for the email address concerned.

Who this covers

This policy explains what Twinshipper does with personal information. It covers two very different groups of people, and it is worth being clear about which one you are.

The first is our customers: the freight brokerages who hold accounts, and the people at them who sign in and run searches. The second is the much larger group of people whose work contact details appear in our results — transportation managers, supply chain leads, owners of shipping companies — who never signed up for anything. Both are addressed below, and the section about the second group is the one most people come here to read.

Information about you, if you hold an account

When you create an account we collect your name, work email address, and the name of your organisation. If you subscribe or buy credits, our payment processor collects your billing details; we receive a record of the transaction and the last four digits of the card, and we never see or store the full card number.

As you use the service we record what you searched for, when, and what it cost in credits. That usage record is how billing works, and it is the same ledger the product shows you on your billing page. We also keep a log of your acceptance of our terms, stamped with the version you were shown.

We use this to run your account, bill you, support you, and tell you about changes to the service. We do not sell information about our own customers.

Business contact information about other people

The core of the product is a database of business contact information that we assemble from publicly available and commercially available sources, rather than from the people themselves. It covers people in their professional capacity: their employer, their job title, a work email address, sometimes a work phone number, and a link to a public professional profile.

It does not intentionally include home addresses, personal email addresses, personal phone numbers, or any information about someone's private life. If you believe a record contains any of that, tell us and we will remove it.

We make this information available to our customers for their own business-to-business sales and marketing. Our customers are contractually prohibited from reselling or republishing it, and they are responsible for complying with the marketing and data-protection rules that apply to them when they make contact.

If you have found this page because you received an email and want to know how your details were obtained, or you want them removed, the section on your rights below tells you how. The removal form needs nothing from you but the email address concerned.

What happens to the company you paste in

A search starts with the website of a company you already work with. That URL, and what we read from the public pages of that website, is the seed for the search.

We treat that seed as yours. It is stored against your organisation's account and is visible to the people on your account. It is not shown to other customers, it is not used to build a picture of who your customers are, and it is not shared with any brokerage.

What we do reuse is the general, non-identifying result of analysing a public website — for example, that a given domain belongs to a plastics extruder with facilities in two states. That cache is what makes the service fast and cheap to run, and it is derived from public pages anyone can read. The fact that you were the one who looked is not part of it.

Cookies and analytics

We use strictly necessary cookies to keep you signed in and to protect the service from abuse. These cannot be switched off without breaking sign-in.

We use Google Analytics 4 to understand how people find and move through our public website — which pages they land on, which marketing channel brought them, and whether they went on to sign up. This sets cookies in your browser and sends Google a record of the pages you viewed along with a generated identifier. Google does not receive your name or your email address from us.

We do not run advertising cookies or third-party tracking pixels on the site today. If that changes, this section changes with it, and it changes before the pixel goes live rather than after.

Who else handles this data

We use a small number of service providers, each handling only what its function requires. Our database and authentication are provided by Supabase; the application runs on Railway. Payments are processed by Stripe. Background jobs are orchestrated by Inngest. Rate limiting uses Upstash.

To find and check business information we use Exa for discovery and Abstract API for email and company verification. Website analytics are provided by Google.

Each of these is engaged to process data on our instructions rather than for its own purposes. We do not sell or rent information about our own account holders to anyone.

How long we keep things

We keep your account information for as long as your account is open. After an account is closed we keep what we need in order to meet our tax, accounting and dispute-handling obligations, and delete the rest.

Search results and usage records are retained while your account is open, because they are the record of what you were billed for.

Where someone has asked to be removed from our contact data, we keep a minimal record of the request itself so that the same record does not reappear the next time we refresh our sources. Keeping that suppression entry is what makes a removal durable rather than temporary.

Your rights, and how to use them

Depending on where you live, you may have the right to ask what personal information we hold about you, to have it corrected, to have it deleted, to object to our processing of it, and to receive a copy of it.

If your details appear in our contact data, the fastest route is the removal form at twinshipper.com/privacy/request. It asks only for the email address concerned. Acting on it removes the record from our database and from our customers' accounts, and adds a suppression entry so that it is not re-added.

For anything else, or if you hold an account with us, email hello@twinshipper.com. We will respond within the time the applicable law allows, and we will not charge you or require you to create an account in order to exercise a right.

If you are in the UK or the EU and are unhappy with how we have handled a request, you can complain to your national data protection authority.

Security

Access to customer data is restricted at the database level, so one organisation's searches and results are not reachable from another organisation's account. Traffic to the service is encrypted in transit, and access to production systems is limited to those who need it.

No system is perfectly secure, and we would rather say so than imply otherwise. If you believe you have found a vulnerability, email hello@twinshipper.com and we will work with you on it.

Children

Twinshipper is a business tool sold to companies. It is not directed at children, and we do not knowingly collect information about anyone under 16.

Changes, and how to reach us

If we change this policy we will update the version shown at the top of this page. Where a change materially affects our customers, or people whose details are in our data, we will do more than quietly edit the page.

Questions, requests and complaints all go to hello@twinshipper.com.