Privacy Policy
Privacy Policy
This Privacy Policy describes how Pack Grid LLC, a Virginia limited liability company doing business as Pack Grid("Pack Grid," "we," "us," or "our"), handles information through pack-grid.com, the Pack Grid application, and related services.
Scope and our role
This Policy applies to information we handle about website visitors, account holders, customer personnel, support contacts, and authorized integration users. It does not govern a third party's independent practices, including Amazon, Shopify, Clerk, Stripe, PostHog, SellerCloud, or QZ Tray.
For account, billing, security, and direct business relationship information, Pack Grid generally determines why and how the information is processed. For operational data a customer submits or connects for its organization, Pack Grid generally processes that data on the customer's instructions to provide the service. The customer is responsible for its own notices, permissions, and lawful use of that data.
Information we collect
Depending on how the service is used, we may collect:
- Account and identity information: name, business email, authentication identifiers, organization name, role, permissions, and account status.
- Billing information: selected plan, subscription status, transaction identifiers, billing contact details, and limited payment metadata. Stripe processes payment-card details; Pack Grid does not receive full card numbers through Stripe Checkout.
- Operational and customer-provided data: products, SKUs, ASINs, FNSKUs, UPCs, inventory, costs, warehouse locations, ship-from and destination information, shipment contents, labels, packing records, printing settings, user-created views, and workflow events.
- Authorized integration data: Amazon Selling Partner API and related reporting data, SellerCloud catalog and inventory data, integration credentials or tokens in protected form, and sync status or error information.
- Amazon direct-to-consumer fulfillment data:when Amazon authorizes Pack Grid for the Direct-to-Consumer Shipping Restricted role and a selling partner enables the feature, Amazon order identifiers, recipient names, delivery addresses, permitted contact details, delivery instructions, order items, shipping labels, carrier selections, and tracking information needed to fulfill the seller's merchant-fulfilled orders.
- Shopify order fulfillment data:when a merchant connects a Shopify store, order identifiers and numbers, order items and quantities, fulfillment status, the buyer's name and general destination (city, state or province, and country), shipping labels purchased through Shopify Shipping, and carrier and tracking information needed to fulfill the merchant's orders. We deliberately do not request, store, or display buyer email addresses, phone numbers, street addresses, or Shopify customer profiles; the full shipping address remains in Shopify and appears only on the shipping-label documents Shopify produces.
- Technical information: IP address, browser and device information, request and security logs, session identifiers, cookie data, timestamps, diagnostic information, and feature interactions.
- Communications: support requests, feedback, and other messages sent to us.
Sources of information
We receive information directly from users and customer administrators; automatically from browsers, devices, and service infrastructure; from Amazon, Shopify, or SellerCloud when a customer authorizes an integration; from Clerk for authentication and organization management; from Stripe for billing; and from service providers that help us operate and secure the service.
How we use information
We use information to:
- create accounts, authenticate users, and manage organizations;
- provide inventory, shipment, warehouse, analytics, reporting, integration, label, and printing functionality;
- retrieve eligible merchant-fulfilled Amazon orders; support picking and packing; obtain, generate, and print shipping labels; confirm fulfillment; and submit carrier and tracking information to Amazon;
- process subscriptions and administer billing;
- respond to support requests and send transactional, security, and service communications;
- protect accounts, prevent abuse, troubleshoot errors, monitor service reliability, and respond to security incidents;
- comply with law, enforce agreements, and protect Pack Grid, customers, users, and third parties; and
- improve functionality for the customer whose data is being processed, using that data only within the customer-authorized service scope.
Amazon Selling Partner API information
We process Amazon Services API information only for the connected selling partner, only after that selling partner authorizes Pack Grid, and only for the functionality the seller requests. Each seller's Amazon information is logically isolated by organization and available only to authenticated users whose organization role permits access.
If Amazon approves Pack Grid for the Direct-to-Consumer Shipping Restricted role, Pack Grid will receive the minimum Amazon customer PII needed to ship merchant-fulfilled orders: recipient name, delivery address, and any permitted contact details or delivery instructions. Pack Grid uses this information only to retrieve the authorized order, support pick-and-pack operations, obtain or generate a shipping label, print fulfillment documents, confirm shipment, and submit carrier and tracking information. Pack Grid does not use Amazon customer PII for advertising, profiling, unrelated analytics, product development, or general-purpose artificial-intelligence or machine-learning training.
Amazon information may be disclosed only to the connected selling partner's authorized users, Amazon, infrastructure subprocessors identified in this Policy, and a seller-selected shipping or printing provider when necessary to complete the requested fulfillment action. We do not sell Amazon seller or customer information, use one seller's data to benefit another seller, disclose it to another customer, or create cross-seller competitive intelligence or benchmarking about Amazon's business.
We apply the Amazon Selling Partner API Data Protection Policy to the receipt, storage, use, transfer, and deletion of Amazon information. Non-PII Amazon information is deleted within 18 months unless a longer period is required by law. Amazon customer PII is removed from active systems no later than seven days after order delivery; encrypted backup copies expire within 21 days, so no copy remains more than 30 days after delivery. We also honor earlier deletion instructions and any shorter deletion period Amazon requires. A documented legal hold may extend retention only where required by law.
A selling partner may revoke Pack Grid's authorization through Amazon at any time. Revocation stops future retrieval. Pack Grid then deletes retained Amazon customer PII under the schedule above, except for the minimum information required to complete an already-authorized fulfillment operation or comply with law.
Shopify order information
When a merchant installs the Pack Grid app on a Shopify store and links it to their organization, Pack Grid mirrors the store's orders so the merchant can view, pack, and ship them. We minimize the buyer information we handle to what fulfillment requires: the order's items and status, the buyer's name, and the general destination (city, state or province, and country). Pack Grid does not request the Shopify customer API scope and does not retrieve, store, or display buyer email addresses, phone numbers, street addresses, or customer profiles; the full shipping address stays in Shopify, which addresses label purchases from its own order records and prints the address on the label document. Buyer information is used only to display the merchant's orders, purchase and print shipping labels through Shopify Shipping, and submit fulfillment and tracking information back to Shopify — never for advertising, profiling, unrelated analytics, or model training.
Buyer name, destination details, shipping-label documents, and tracking references are removed from active systems no later than seven days after the order is cancelled or after we receive confirmation that it was delivered. Carriers do not always report a delivered scan; when no delivery confirmation reaches us, the same information is removed no later than 30 days after the order is fulfilled or closed. Encrypted backup copies expire within 21 days of deletion, so no copy remains more than 28 days after delivery or cancellation — or, when delivery is never confirmed, more than 51 days after fulfillment. Non-personal order records (order number, items, quantities, fulfillment status, and label-purchase outcome) are retained for the merchant's operational history. We honor Shopify's mandatory privacy webhooks: a buyer-initiated redaction request erases that buyer's order and label data, and uninstalling followed by Shopify's store-redaction request deletes the store's entire mirrored dataset. Access to buyer data inside Pack Grid is limited to the merchant's authorized users and is recorded in an audit log that itself contains no customer information.
How we disclose information
We may disclose information to:
- customer organization administrators and authorized members according to their roles;
- infrastructure and data service providers, including Convex and Vercel;
- authentication and organization-management providers, including Clerk;
- payment and subscription providers, including Stripe;
- product-analytics providers, including PostHog, which receives a pseudonymous Clerk user identifier, explicitly instrumented product and workflow events, and related browser, device, page, and network metadata;
- customer-authorized integrations, including Amazon, Shopify, and SellerCloud;
- local printing software selected by the customer, such as QZ Tray, when a user directs Pack Grid to print a document;
- professional advisers, auditors, insurers, and prospective parties to a financing, acquisition, reorganization, or sale; and
- government authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce our agreements.
Service providers may process information only to perform services for us and are subject to appropriate contractual confidentiality and security obligations. We do not disclose one customer's operational data to another customer.
Cookies and similar technologies
Pack Grid and its providers use cookies or similar storage for authentication, session security, Amazon OAuth protection, remembered station organization preferences, interface preferences, fraud prevention, and service operation. For first-party product analytics, PostHog uses cookies or local browser storage to maintain a pseudonymous identifier and, after sign-in, associate it with an opaque Clerk user identifier. PostHog tracks only explicitly instrumented product and workflow events and related browser, device, page, and network metadata. We do not use advertising cookies or trackers for cross-context behavioral advertising.
Because Pack Grid does not currently sell personal information, share it for cross-context behavioral advertising, or conduct cross-context behavioral advertising tracking, browser Do Not Track signals do not change our current practices. Where legally required, we treat recognized opt-out preference signals, including Global Privacy Control, as requests to opt out of applicable sale or sharing.
No sale or targeted advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or use personal information for targeted advertising as those terms are defined by applicable U.S. state privacy laws. We do not knowingly sell or share personal information of anyone under 16.
Retention and deletion
We retain account and operational information for the active customer relationship and afterward only as reasonably necessary to provide an export or deletion period, maintain security and audit records, resolve disputes, enforce agreements, and meet legal, tax, accounting, and contractual obligations. Billing records may be retained for legally required accounting and tax periods. Security and diagnostic logs are retained according to documented operational schedules and applicable contractual requirements. PostHog product-analytics events are retained for no more than 12 months after capture. Associated person profiles are retained while the account remains active. We initiate deletion of the profile and its associated events within 30 days after a verified deletion request or account closure.
Amazon and Shopify information are subject to the more specific limits described above. Amazon customer PII and Shopify buyer information are deleted from active systems and encrypted backups within the stated fulfillment schedules. Other information may be retained longer only where required by law, necessary to establish or defend legal claims, or otherwise permitted by the governing contractual requirements.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including role-based access, least-privilege controls, unique user identities, multi-factor authentication for production administration, encryption in transit and at rest, protected integration credentials, access and security logging, vulnerability management, restricted production access, encrypted geographically separate backups, service-provider review, and incident-response procedures. Amazon Restricted Data and shipping PII are not permitted in development, test, support-ticket, analytics, or application-log data. We prohibit sending customer names, street addresses, phone numbers, buyer email addresses, label contents, or raw SP-API responses containing PII to PostHog. No method of storage or transmission is completely secure.
If we determine that a security incident requires notice under applicable law or contract, we will provide notice to affected parties and authorities as required.
Your choices and privacy rights
Depending on where you live and subject to applicable exceptions, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; learn about its sources, purposes, and recipients; opt out of certain processing; appeal a denied request; and receive equal service without unlawful discrimination for exercising a privacy right.
Submit a request to hemal.m@pack-grid.com. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization or direct confirmation from the individual. To appeal a decision, reply to our response with "Privacy Appeal" in the subject line.
For customer-controlled operational data, we may direct a user to the customer organization that controls the account or assist that organization in responding. Organization administrators can also manage member access and connected integrations.
International processing
Pack Grid is based in the United States. Information may be processed in the United States and other locations where our providers operate. Where required, we use contractual or other lawful safeguards for international transfers.
Children
Pack Grid is a business service not directed to children or anyone under 18. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided information to the service.
Changes to this Policy
We may update this Policy to reflect changes in the service, law, or our practices. We will post the revised Policy with a new last-updated date and provide additional notice when a material change requires it.
Contact
Pack Grid LLC
Virginia, United States
Email: hemal.m@pack-grid.com
Contact us at that address for privacy questions, data requests, retention or deletion requests, or security concerns.