TOKONEY Limited trading as Shipio · Company No. 12245258 · Last updated: 24 March 2026
This privacy policy explains how TOKONEY Limited, trading as Shipio ("we", "us", "our", "Shipio"), collects, uses, stores and shares personal data when you visit our website at www.shipio.app, use the Shipio platform, or otherwise interact with us.
This policy applies to: Supplier users — individuals who create accounts and use the Shipio platform on behalf of a supplier organisation; End customers — individuals whose personal data is processed through the platform as part of a supplier's quoting, booking, invoicing or payment workflows; and Website visitors — individuals who visit www.shipio.app.
If you are a supplier using the Shipio platform, our Supplier Platform Terms (including Schedule 1 — Data Processing Terms) also apply and explain Shipio's role as a data processor on your behalf.
This privacy policy explains how we collect, use, store and share personal data across our website and platform. It applies to supplier users, end customers, and website visitors. References to "Shipio", "we", "us" and "our" mean TOKONEY Limited trading as Shipio.
We are the controller for personal data we collect and process for our own business purposes, including managing supplier accounts, authenticating users, operating and improving the platform, running analytics, sending service communications, recording terms acceptance, and managing payments and compliance.
When a supplier uses the platform to create quotes, manage bookings, generate invoices and process payments for end customers, we process personal data on that supplier's behalf as its processor. The supplier determines what end-customer data is uploaded and how it is used within the platform. If you are an end customer and have questions about how your data is handled, you should contact the supplier you are dealing with directly in the first instance.
Supplier users
End customers
End-customer data is usually provided to us by the supplier you are dealing with, including where that supplier uploads information into the platform, sends it through an integration, or causes it to be processed through configured workflows. This typically includes:
Website visitors
Where we act as controller, we process personal data for the following purposes:
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating and managing supplier accounts and authenticating users | Performance of contract (Article 6(1)(b)) |
| Processing platform fees and managing payment integrations | Performance of contract |
| Sending service communications (quote notifications, invoice emails, payment confirmations, booking updates) | Performance of contract |
| Recording terms acceptance and maintaining audit trails | Legitimate interests (platform governance and dispute resolution) |
| Operating, securing and improving the platform | Legitimate interests (service improvement and security) |
| Aggregated, de-identified or anonymised analytics, benchmarking and product improvement | Legitimate interests (service improvement) |
| Developing machine-assisted features using aggregated, de-identified or anonymised data | Legitimate interests (product development) |
| Responding to support requests and communications | Legitimate interests (customer service) |
| Preventing fraud, enforcing our terms, and complying with legal obligations | Legal obligation / Legitimate interests (fraud prevention and compliance) |
| Website and product analytics | Legitimate interests, or consent where required |
We do not use identifiable Supplier Data or Customer Data to train third-party AI models.
As a processor
When processing end-customer data on behalf of suppliers, we act on the supplier's instructions as defined by their use of the platform and configured workflows. This may include generating quotes, creating bookings, producing invoices, sending payment requests and supporting payment flows. The supplier is responsible for having a lawful basis for this processing.
We share personal data only where necessary to operate the platform and provide our services. We do not sell personal data.
We may share personal data with the following categories of recipients:
A current list of our main service providers and subprocessors is available on request.
Partner suppliers
Where a supplier uses the platform to request pricing or services from a partner supplier, relevant shipment data such as inventory, addresses, packing details and customs information may be shared with that partner supplier through the platform. End-customer identity is not shared by default.
Legal and regulatory disclosures
We may disclose personal data where required by law, regulation, legal process or enforceable government request, or where necessary to protect the rights, property or safety of Shipio, our users or others.
Our service providers may operate in multiple jurisdictions. Where personal data is transferred outside the United Kingdom or European Economic Area, we will ensure that appropriate safeguards are in place as required by applicable data protection law, including approved standard contractual clauses or reliance on an adequacy decision where available.
| Data type | Retention period |
|---|---|
| Supplier account data | Duration of the account plus 90 days (reactivation window) |
| Quotes, invoices and payment records | Duration of the account plus 7 years (legal and accounting purposes) |
| Attachments (uploaded documents) | Duration of the account plus 2 years after termination |
| Terms acceptance records | Retained for audit and dispute resolution purposes |
| Website and product analytics data | Retained in accordance with our providers' standard retention settings or internal retention policies |
| Support communications | Duration of the account plus 2 years |
When retention periods expire, we will delete or anonymise personal data unless further retention is required by law or reasonably necessary to establish, exercise or defend legal claims.
Shipio platform (app)
We use cookies and similar technologies for platform functionality, security, session management and limited analytics. We use PostHog for product analytics within the platform to help us understand how the platform is used and improve the product.
Shipio website (www.shipio.app)
We use cookies and similar technologies on our website for site functionality, security and limited analytics to understand website usage and improve our services. We do not currently use cookies for advertising or cross-site behavioural tracking.
Where consent is required for cookies or similar technologies, we will obtain it through an appropriate consent mechanism. You can also manage cookies through your browser settings, although disabling certain cookies may affect site or platform functionality.
Under UK data protection law, you have the following rights in relation to your personal data:
Right to object
Where we process your personal data on the basis of legitimate interests, you have the right to object to that processing. You can do this by contacting us using the details in section 13.
Automated decision-making
We use AI-assisted processing to help suppliers extract information from documents, interpret quote requests and prepare draft workflow outputs. At present, these outputs are subject to supplier review and approval before they are acted on. If we introduce any feature that involves solely automated decision-making about individuals with legal or similarly significant effects, we will update this privacy policy and provide any additional information and safeguards required by applicable data protection law.
If you are an end customer
Your data is usually processed by Shipio on behalf of the supplier you are dealing with. To exercise your rights, please contact that supplier directly in the first instance. If you need further assistance, you can contact us and we will help direct your request where appropriate.
If you are a supplier user or website visitor
You can contact us directly using the details in section 13 below. We will respond to valid requests within one month, or notify you if we need an extension.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, role-based permissions, database security controls, and regular security reviews of our infrastructure and third-party providers.
The Shipio platform is a B2B service for business users. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected personal data from a child, we will delete it promptly.
We may update this policy from time to time. If we make material changes, we will notify supplier users by email or in-product notice where appropriate. The updated policy will be published at https://www.shipio.app/privacy with the revised date shown above.
For any questions about this privacy policy, to exercise your data protection rights, or to request our current subprocessor list, please contact us at:
Email: privacy@shipio.app
Post: TOKONEY Limited, 85 Great Portland Street, London W1W 7LT, UK
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.