Legal

Privacy Policy

Effective date: September 6, 2026

1. Who we are and what this Policy covers

PackOS, Inc. ("PackOS", "we", "us") makes shipping software for businesses. This Privacy Policy explains what information we handle and why.

It covers this website at www.packospro.com, PackOS Checkout, PackOS Labels, and the PackOS Enterprise early-access pages.

PackOS is built for businesses and the people who work in them. It is not directed at individuals under 18, and we do not knowingly collect personal information from them.

2. Our two roles

We handle information in two different roles, and your rights differ depending on which one applies.

For visitors to this website, account holders, people who fill in our forms, and people who book a demo, PackOS decides why and how the information is used. In privacy law we are the controller, or the business, for that information.

For a merchant's own customer data inside PackOS Checkout and PackOS Labels, PackOS acts on the merchant's instructions. In privacy law we are the processor, or the service provider, for that data, and the merchant is the controller. If you are a shopper or a shipment recipient and want to know how your data is used, start with the merchant you bought from and their privacy policy. We will help that merchant answer you.

3. Information we collect

3.1 Information you give us

  • Account details: name, email address, company name, and a password, which is stored as a hash and never in plain text.
  • Contact form: name, email address, company, the reason you chose, and your message.
  • Enterprise early-access form: name, email address, company, and the platform you use.
  • Newsletter: your email address, stored only after you confirm it.
  • Shipping rate calculator: the package and address details you type, and the email address the result is sent to.
  • Demo bookings: the details you give the scheduler, including your name, email address and the time you pick.
  • Support messages you send us, and feedback or feature requests you choose to share.

3.2 Information we collect automatically

  • Usage data from Google Analytics 4: page views and events such as clicks on our calls to action.
  • Device and browser information, such as browser type and operating system.
  • Your IP address, and the coarse location, at city or region level, derived from it.
  • Log data such as timestamps, pages requested and errors.
  • The cookies and advertising technologies listed in section 6, including the Meta Pixel.
  • Your network address, used for a short window as the key of a rate-limit counter on our forms and APIs. We also refuse any request body over 32 KB.

3.3 Information from your store platform

When a merchant installs PackOS Checkout, we receive the data the app needs to quote a rate: order line items, product dimensions and weights, the merchant's box library, and the shopper's shipping destination at checkout. We process it for the merchant, under section 2.

3.4 Information needed to buy a label

To produce a label and tracking in PackOS Labels we handle recipient names, addresses, phone numbers and email addresses, and package weights and dimensions.

3.5 Payment information

A third-party payment processor handles card details. PackOS never receives or stores your card number. We keep a ledger of the amounts you added to your balance, the labels you bought and the labels you voided.

4. How we use information

  • To provide, operate and secure the Services, and to authenticate you.
  • To produce rates, box recommendations, labels and tracking.
  • To bill PackOS Checkout through Shopify.
  • To run the prepaid balance ledger and to reconcile carrier adjustments.
  • To reply to your contact, early-access, demo and support messages.
  • To send the newsletter, and only after you confirm your subscription.
  • To understand how the site and the products are used, and to improve them.
  • To measure our advertising and to build audiences, as described in section 6.4.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To meet legal obligations and to enforce our Terms of Service.

We do not sell personal information for money. We do share limited information with Meta Platforms through the Meta Pixel for advertising measurement and audience building, which California law treats as "sharing" for cross-context behavioral advertising. Section 6.4 says exactly what is shared, and section 10 is how you opt out.

5. How we share information

We share information with vendors who help us run the Services. We name them by category, with the examples in use today, because a vendor can change:

  • Hosting and infrastructure, such as Vercel, Amazon Web Services and Railway.
  • Email delivery, such as Resend.
  • Analytics, such as Google Analytics.
  • Advertising measurement, such as Meta Platforms.
  • Scheduling, such as Cal.com, and the calendar and video service it books into, such as Google Calendar and Google Meet.
  • The store platform you connect, such as Shopify.
  • Carriers and a shipping intermediary.
  • A payment processor.
  • Rate-limit storage, such as Upstash.

Carriers and the shipping intermediary receive recipient and package details because a label cannot be produced without them.

We also share information within your own organization, according to the roles and permissions you configure.

We disclose information where the law requires it, or where we believe in good faith that disclosure is needed to comply with a legal obligation or court order, to protect our rights or property, to investigate wrongdoing connected to the Services, or to protect anyone's safety.

If PackOS is part of a merger, acquisition, asset sale or bankruptcy, information may transfer as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.

We share information in any other case only with your consent.

6. Cookies and similar technologies

6.1 Essential cookies

The PackOS Labels application at app.packospro.com sets a session cookie so you stay signed in. Turning it off makes the application unusable.

6.2 Analytics cookies

Google Analytics 4 sets cookies to count visits and events. You can block them in your browser settings, or install the Google Analytics opt-out browser add-on.

6.3 Referral and campaign cookies

When you arrive with a referral code in the address, we set a first-party cookie named packos_ref that holds that code for 30 days. Campaign values from a link, the UTM parameters, are stored the same way and for the same period, in a cookie named packos_utm. Both cookies are readable by app.packospro.com, so a referral survives the move from this website to the application. They carry a code and campaign labels, not your name.

6.4 Advertising: the Meta Pixel

This website uses the Meta Pixel for advertising measurement and audience building. It loads only when it is configured for the site, and never while a developer is running the site locally.

The pixel sets Meta's own cookies, named _fbp and _fbc, and reports to Meta Platforms:

  • A page view when a page loads, and one more each time you move to another page on the site.
  • Schedule, when you book a time in the demo scheduler.
  • Lead, when you submit the Enterprise early-access form, when you confirm a newsletter subscription, and when you submit the shipping rate calculator.
  • Contact, when you submit the contact form.
  • InitiateCheckout, when you follow our link to the PackOS Checkout listing on the Shopify App Store.

Six moments on the site produce those four event names. Together with the page view, that is the whole list. No parameters are sent with them: we send Meta a standard event name and nothing more, so no email address, name or form content goes to Meta from this site. Meta still receives what any request to it carries: your IP address, the address of the page you are on, and its own cookies.

We also turn the pixel's automatic configuration off, which stops it reading values out of form fields on the page and stops it logging button clicks by itself.

California law treats this as "sharing" of personal information for cross-context behavioral advertising. You can stop it in three ways: use the opt-out button in section 10, which keeps your choice in a cookie named packos_ads_optout on that browser for one year; turn on Global Privacy Control in a browser that supports it, which we honour without any further step; or change your own ad settings with Meta.

7. How long we keep information

  • Account data: for the life of the account and 90 days after it closes.
  • Balance and label ledger records: for as long as applicable tax and accounting law requires.
  • Shopper data processed for PackOS Checkout: only as long as needed to return rates and to honour the merchant's redaction requests.
  • Leads and support mail: up to 3 years.
  • Newsletter subscriptions: until you unsubscribe.
  • Analytics: in aggregate, without an identifier attached to you.
  • Rate-limit counters: minutes to hours.

You can ask us to delete data earlier at privacy@packospro.com, subject to the records we must keep by law.

8. Security

  • Data is encrypted in transit with TLS.
  • Our data stores are encrypted at rest.
  • Passwords are stored as hashes, never in plain text.
  • Access to your data inside PackOS is role-based and limited to the people who need it.
  • Sign-in attempts are rate limited.
  • We review our security periodically and keep an incident response process.

No method of transmission or storage is perfect, and we cannot promise absolute security. If a breach affects your information, we will notify you as the law requires.

9. Your rights and choices

  • Access: ask for a copy of the personal information we hold about you.
  • Correction: correct information that is wrong, in the product or by writing to us.
  • Deletion: ask us to delete your account and its data, subject to records we must keep.
  • Portability: ask for an export in a machine-readable format.
  • Restriction: ask us to restrict processing in the circumstances the law allows.
  • Unsubscribe: leave the newsletter from the link in any issue, or by writing to us.

Write to privacy@packospro.com to exercise any of these. We respond to verified requests within 30 days.

If you are a merchant's customer, send your request to that merchant. They are the controller of that data, and we will help them answer you.

10. California residents

If you live in California, the CCPA as amended by the CPRA gives you specific rights. The clearest one to act on is here: use this button to opt out of the sharing described in section 6.4.

The choice is kept in a cookie on this browser, so make it again in another browser or after clearing cookies. We also honour Global Privacy Control: a browser that sends that signal is opted out here without clicking anything.

The categories of personal information we have collected in the last 12 months are the ones listed in section 3: identifiers such as your name, email address and IP address; commercial information such as your plan, your balance ledger and the shipments you created; internet activity such as page views and events; coarse geolocation derived from your IP address; and professional information such as your company and role. Section 3 says where each category comes from, section 4 says why we use it, and section 5 says who receives it.

We do not sell personal information for money.

We do share personal information for cross-context behavioral advertising through the Meta Pixel, as described in section 6.4. Identifiers and internet activity are the categories shared, and Meta Platforms is the recipient. The button above, Global Privacy Control, and Meta's own ad settings each stop it.

You also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising any of these rights.

An authorized agent may make a request for you if they give us written proof that you authorized them, and we may ask you to confirm it directly.

Send California requests to privacy@packospro.com.

11. Shopify merchants and their customers

PackOS Checkout is installed from the Shopify App Store, and Shopify requires apps to answer three mandatory webhooks. We honour all three: the customer data request webhook, the customer redaction webhook and the shop redaction webhook.

When Shopify sends one, we return or delete the shopper data we hold for that request within the time Shopify requires. A merchant who uninstalls PackOS Checkout triggers shop redaction, and the shop's data is deleted on that signal.

12. International transfers

PackOS is operated in the United States, and information is processed there. If you use the Services from outside the United States, your information is transferred to the United States and to the countries where our vendors operate.

Where the law requires a safeguard for that transfer, we put one in place, such as the Standard Contractual Clauses.

13. Business customer responsibilities

If you use PackOS for a business, you are responsible for:

  • Telling your team members about this Policy and how their information is used.
  • Configuring roles and permissions in your PackOS account appropriately.
  • Having a lawful basis for the personal data you put through the Services, and telling the people it belongs to what happens to it.
  • Telling us at privacy@packospro.com as soon as you suspect unauthorized access to your account.

14. Changes to this Policy

We may update this Policy as our practices, our vendors or the law change. For a material change we will give at least 14 days' notice by email to your account address, or by a notice in the Services, before it takes effect.

Using the Services after a change takes effect means you accept the updated Policy.

15. Contact

PackOS Privacy Team, PackOS, Inc.

Privacy: privacy@packospro.com

Support: support@packospro.com

Legal: legal@packospro.com

[Postal address]

Website: www.packospro.com

We aim to answer privacy questions within 5 business days, and formal requests within the 30 days section 9 gives.


Last updated: September 6, 2026