Privacy

Privacy policy

How Ship It! Software Limited handles information when you use Parquet Viewer.

Last updated: September 5, 2026

This Privacy Policy describes how Ship It! Software Limited ("Company", "we", "us") collects, uses, discloses, and protects information when you visit or use Parquet Viewer. It is incorporated into our Terms of Service.

Optional account

You do not need to sign in to use this site or any of its file tools. If you choose Log in or sign up, your browser redirects to Loam Data's sign-in and consent pages, provided using Supabase Auth. After you approve access, this site's server exchanges a one-time authorization code for your account subject and, when available, your email address and display name. We use those details only to create and display the optional identity session on this site.

The server immediately discards the Loam access token, refresh token, and ID token after it retrieves your identity. It encrypts the bounded identity details and expiry in an HttpOnly, SameSite=Lax cookie that lasts for up to one hour and is scoped only to this site's origin. A separate encrypted transient cookie holds OAuth state and the PKCE verifier for up to ten minutes while login is in progress. Neither cookie uses a parent domain, and authentication details are not placed in local storage, session storage, Product analytics, or operational telemetry. CSV Viewer and Parquet Viewer cannot read each other's identity cookies.

You can continue anonymously, decline the Loam consent request, or log out at any time. Logging out clears this site's identity cookie and does not sign you out of Loam Data or another microsite.

Your Parquet data

Opening a selected file reads it into memory in the current tab. Filtering, sorting, schema inspection, and CSV generation also happen locally. Those viewing and conversion actions do not send a selected filename, schema, column name, cell value, or generated CSV to an analysis service.

The tool keeps the active dataset in browser memory until you open another file, close the viewer, close the tab, or the browser releases that memory.

Analyze with SQL works differently. For each analysis, this site's server uses a Loam service-account key to create one ordinary private leased Namespace. The service-account key stays on the server and is never sent to your browser.

Loam returns a reveal-once analysis token that is valid only for that exact Namespace. The page holds the token only in memory and sends it explicitly with analysis requests. It is not placed in a cookie, local storage, session storage, a URL, or a log, and it is lost when the page reloads or closes.

You can add multiple Parquet files to the analysis. Your browser uploads each file directly to Loam Data object storage using a time-limited signed upload, and Loam creates one ordinary table per file. SQL can query or join those tables. Loam receives the uploaded file contents, table names, and SQL statements needed to perform the analysis and return its results.

The private Namespace lease expires after 24 hours by default and never more than seven days after creation. Activity does not extend this fixed expiry. Expiry revokes access and schedules physical cleanup. We do not use file contents to train an AI model.

Personal data we collect

Loading a page, policy, favicon, or public sample makes a normal request to the hosting service. Its infrastructure can process standard request details such as time, requested path, IP address, and browser information for delivery, reliability, and security. Public sample files are site assets, so requesting one also tells the server which sample path was requested.

The utility also reports a small allowlisted set of operational outcomes, such as whether parsing, export, or SQL analysis succeeded, together with fixed upper-bound size and duration buckets and a coarse error category. Operational telemetry never contains analysis tokens, signed upload URLs, required upload headers, SQL text, row data, local file names, or table names. It also excludes schemas, column names, cell values, free-form error text, user identifiers, persistent browser identifiers, login state, account subjects, email addresses, and display names.

How we use personal data

We use ordinary request data to deliver and secure the site, prevent misuse, diagnose failures, and understand operational reliability. We do not sell personal data.

Product analytics measurement

We use PostHog to count canonical page views and coarse operational outcomes so we can understand use and reliability. The browser sends each bounded event to this site, which forwards it to PostHog. If this deployment has a public Loam Data Product Analytics Source configured, the browser also sends the same bounded event directly to Loam Data for a controlled delivery comparison. Without a configured source ID, no direct Loam Product analytics request is made. Each event contains a canonical path, fixed site and browser context, validated outcome fields or coarse numeric buckets, and a random in-memory session identifier that resets on reload and is not stored in a cookie or local storage.

Product analytics creates no cookie or persistent visitor profile. Event fields exclude query strings, referrers, IP addresses, analysis tokens, signed upload URLs, required upload headers, SQL, local file names, table names, file contents, schemas, column names, rows, cell values, and free-form errors. Selected file contents stay in the browser for local viewing and conversion; they reach Loam Data only when you separately start Analyze with SQL as described above. When direct Loam delivery is enabled, a normal request can still expose ordinary request data such as an IP address and browser information to Loam Data for delivery, security, and rate limiting. PostHog is configured to discard IP data and not create person profiles from forwarded events.

Cookies and Product analytics

Parquet Viewer does not set a Product analytics cookie, store a Product analytics identifier in local storage, or run advertising trackers. Its allowlisted operational events are sent without a user or persistent browser identifier and contain only enums and fixed numeric buckets. Hosting infrastructure may use necessary request data to deliver and protect the site. When direct Loam Product analytics is enabled, Loam Data may process the ordinary request data described above. If these practices change, we will update this policy before the new collection begins.

Service providers

We use hosting and content-delivery providers to serve pages and public sample files. They may process ordinary request data on our behalf under their own security and data-protection obligations. Local viewing and conversion do not send selected Parquet contents to them. Analyze with SQL uses Loam Data object storage and analysis infrastructure. When direct Loam Product analytics is enabled, Loam also processes the limited events described above. Optional Optional login or signup uses Loam Data's authentication and consent service, provided using Supabase Auth, to process the login request and the bounded account details described above.

Retention and security

Browser-local Parquet data is not retained by us. Each SQL analysis Namespace is private and kept only until the fixed lease expiry described above, followed by asynchronous physical cleanup. Hosting providers may retain ordinary request data and the allowlisted operational events in logs for limited periods needed for security and reliability. The optional identity cookie lasts for up to one hour, and the in-progress login cookie lasts for up to ten minutes. We use reasonable safeguards, but no website or transmission method is completely secure.

Your choices and rights

You can use the site without selecting a file and without logging in. You can decline consent or log out to clear this site's identity session. Browser settings can restrict cookies and other storage. Depending on where you live, you may have rights to ask about, correct, or delete personal data we hold. Ordinary request logs may not always be attributable to you.

Policy changes

We may update this policy when the utility or its data practices change. The date above shows the latest revision. Material changes will be described here before they take effect where practical.