Operated by Sognora
SafeRates Privacy Policy
Effective August 16, 2026
What SafeRates processes
Wix sends SafeRates a signed shipping-rate request when a shopper reaches checkout. That request can include the delivery country, state, city, postal code and street, together with cart quantities and product weights. SafeRates reads only the country, state, city and postal code needed for rating. It does not persist the street address.
SafeRates stores a short operational record for each request: destination country and postal code, shipment weight, whether a default weight was used, rating source, checkout outcome, number of options and response time. It also stores the merchant settings entered in the app: US ship-from ZIP, package dimensions, default weight and backup rate. The Wix app instance ID and OAuth refresh token are stored so the installed app can authenticate and operate.
What SafeRates does not store
SafeRates does not store shopper names, email addresses, phone numbers, street addresses, payment details, order contents or product names. It does not ask merchants for carrier-account passwords or tokens. An email address is not collected by the current SafeRates settings screen.
How the data is used and shared
SafeRates sends the ship-from postal code, destination country/state/city/postal code, package dimensions and weight to Shippo, Inc. to request live USPS estimates. It does not send a shopper name, email, phone number or street address to Shippo. SafeRates limits the checkout response to supported USPS services and does not use UPS rates.
The service is hosted on Fly.io and its database is provided through Supabase. These vendors process data only to host and operate SafeRates. Sognora does not sell checkout or merchant data, use it for advertising, or build shopper profiles.
Retention and deletion
Settings and quote history are used while the app is installed. When Wix delivers an app-removal event, SafeRates removes the stored settings and quote history and clears its Wix refresh token. A minimal removal record may remain to prevent further use and resolve operational records. To request access, correction or deletion, email shin@sognoragroup.com. We verify that the requester is authorised for the Wix site before acting.
Security and international processing
Inbound Wix rate requests are verified with Wix's RS256 signature, and dashboard sessions are verified with HMAC-SHA256. Data is encrypted in transit and isolated to the SafeRates database schema. Sognora operates from South Korea; infrastructure and rating providers may process data in other countries, including the United States.
Changes and contact
Material changes appear on this page with a new effective date. Privacy, security and deletion questions go to shin@sognoragroup.com.