Privacy Policy

Effective July 21, 2026

This policy explains how PackLedger collects, uses, stores, and deletes information when merchants use the PackLedger Shopify app and related support services.

Information we process

The CSV-first release does not request Shopify product or order API access and does not ingest Shopify customer data through the Admin API.

The fixed Shopify parser skips customer identity columns, and generic mapping blocks recognized customer identity headers before preview or import. That includes customer IDs or account identifiers, company, city or location, names, email, phone, and street or address fields. Plain Name remains available only for product-title and SKU-name mappings. Merchants must not map identity-bearing values from ambiguous, mislabeled, or nonstandard headers into operational fields.

How we use information

We use information only to provide, secure, support, and improve PackLedger; calculate packaging EPR estimates; create merchant- requested exports and evidence packs; maintain an audit trail; and comply with legal obligations. We do not sell personal information or use merchant data for advertising.

Service providers

PackLedger is delivered through Shopify. Production application hosting and persistent file storage use Render, and application data is stored in Neon Postgres. These providers process data only to deliver their contracted infrastructure services and are subject to their own security and privacy terms.

Retention and deletion

Raw CSV upload bytes can contain any columns supplied by the merchant. They are stored temporarily for column mapping, deleted after commit or cancel, and abandoned uploads are purged within 24 hours. Normalized order records may retain an optional merchant-provided postal code for jurisdiction mapping. The normalized schema is designed for operational order and destination data and has no dedicated fields for customer names, email addresses, phone numbers, street addresses, or Shopify customer IDs. Import errors retain only allowlisted fields and messages, not raw row values.

We keep merchant data while the app is installed and as needed to provide the service. An uninstall stops app access. Shopify's mandatory customers/redact and shop/redact webhooks are authenticated before processing. Normalized PackLedger records have no dedicated Shopify customer-ID field, so they cannot be reliably matched by Shopify customer ID. PackLedger also has no dedicated Shopify customer-ID field for temporary raw CSV uploads. A customer data request therefore records the current temporary-upload count and that matching limitation. Customer compliance requests are recorded without retaining the webhook's customer or order identifiers. Customer redaction purges all temporary raw CSV uploads for the shop. A verified shop redaction request deletes the shop organization and its associated application records. Infrastructure backups may remain for a limited period under provider backup and disaster-recovery cycles before they are overwritten.

Security and access

We use Shopify authentication, encrypted network connections, access controls, audit logging, and managed infrastructure. No internet service can guarantee absolute security. Merchants should limit CSV uploads to the fields PackLedger documents and avoid including customer identity fields.

Your choices and rights

Merchants can correct or remove data in the app, uninstall the app, or ask us for access, correction, export, or deletion assistance. Depending on where you live, applicable law may provide additional privacy rights. We may verify the requester's identity and authority before acting on a request.

Changes and contact

We may update this policy as PackLedger changes. The effective date above identifies the current version. Questions or privacy requests can be sent to support@packledger.app.