Loading
QA_SHIP // LEGAL
Last updated: 10 July 2026
This Privacy Policy explains how QAShip ("we", "us") collects, uses, shares, and protects personal data when you use the QAShip test case management platform at qaship.com (the "Service"). It should be read alongside our Terms of Service.
Where you use the Service as a member of an organisation's workspace, that organisation controls the content of its workspace, and we process workspace content on its behalf. This policy covers the personal data we handle as a controller, such as your account information and usage data.
Account information — when you register we collect your name, email address, and a password (stored only in hashed form). If you sign in with Google or Microsoft, we receive your name, email address, and profile picture from that provider. If you register a passkey, we store the public key credential needed to verify sign-ins; your biometric data never leaves your device.
Content you provide — test cases, test runs, results, notes, comments, attachments, organisation and project names, and any other content you or your team submit to the Service.
Usage and technical data — log data such as IP address, browser type, device information, pages visited, and actions taken in the Service (for example, an audit trail of who created or updated a record), collected when you use the Service.
Communications — messages you send us, such as support requests or feature requests.
We use personal data to: (a) provide, maintain, and secure the Service, including authentication and session management; (b) operate collaboration features, such as showing your name and avatar to members of your organisation and recording who created or changed records; (c) send transactional emails such as verification, password reset, and invitation emails; (d) provide optional AI-assisted features when you use them; (e) monitor, troubleshoot, and improve the Service; (f) enforce our Terms of Service and protect against misuse; and (g) comply with legal obligations.
We do not sell your personal data, and we do not use your workspace content to train AI models.
Where the UK or EU General Data Protection Regulation applies, we process personal data on the following bases: performance of a contract (providing the Service you signed up for); our legitimate interests (securing and improving the Service, preventing abuse), balanced against your rights; your consent, where we ask for it; and compliance with legal obligations.
We share personal data only as needed to run the Service: with infrastructure and hosting providers that store our databases and run the application; with our email delivery provider to send transactional emails; with AI service providers to process the prompts and context you submit when you use AI features; and with identity providers (Google, Microsoft) when you choose to sign in with them.
If you connect a third-party integration such as Jira, we exchange the data needed to provide that integration (for example, creating an issue from a test result) with that service under its own terms and privacy policy.
We may also disclose personal data where required by law, to protect our rights or the safety of users, or as part of a merger, acquisition, or sale of assets (in which case this policy will continue to apply to your data until you are notified otherwise).
The Service is collaborative. Your name, email address, avatar, and activity within a workspace (such as tests you create, results you record, and audit log entries) are visible to other members and administrators of that organisation. Organisation administrators manage membership of their workspace and can remove members.
We use cookies that are strictly necessary to operate the Service, primarily to keep you signed in and to secure your session. We do not use advertising or cross-site tracking cookies. You can block cookies in your browser settings, but the Service will not function without the essential ones.
We keep personal data for as long as your account is active or as needed to provide the Service. When you delete your account, or when an organisation deletes its workspace or data, we delete the associated personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce agreements. Backups are retained on a rolling basis and are overwritten in the normal course of operations.
We take appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, role-based access controls, and isolation of each organisation's data. No system is completely secure, so we cannot guarantee absolute security; please use a strong, unique password or a passkey.
Our service providers may process data outside the country in which you live, including outside the UK and the European Economic Area. Where they do, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses to protect your data.
Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; receive a copy of your data in a portable format; object to or restrict certain processing; and withdraw consent where processing is based on consent. You can exercise many of these directly in the Service — your account settings let you update your details and delete your account, and the export tools let you download your data.
To make any other request, contact us using the details below. If you are in the UK or EU, you also have the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office).
The Service is not directed at children and may not be used by anyone under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children; if you believe a child has provided us with personal data, please contact us and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before they take effect. The "Last updated" date at the top of this page indicates when it was last revised.
If you have questions about this Privacy Policy or how we handle your data, contact us at support@qaship.com.
See also our Terms of Service.