Legal

Privacy policy

Effective 28 July 2026. This policy explains how PackLock processes data when a merchant installs or uses the Shopify app.

Data we process

PackLock reads store identity and contact details, order IDs and numbers, physical line-item titles, variants, SKUs and quantities, order notes, fulfilment-order and location details, and native fulfilment Holds. It stores Pack Check Ticks, timestamps, the surface used, Guard events, settings, plan state, and monthly guarded-order counts.

PackLock does not request or display shopper names, shipping addresses, billing details, or payment information.

Why we process it

We process this data to identify Guardable Fulfilment Orders, place and release Shopify Holds, provide Pack Checks, reconcile missed or edited fulfilment orders, enforce plan limits, provide support, prevent abuse, and meet legal obligations.

Processors and international transfers

PackLock uses Shopify to provide the commerce platform and Cloudflare Workers and D1 to run and store app data. These providers may process data in countries outside the merchant's country under their applicable transfer safeguards.

Retention and deletion

Completed Pack Checks, resolved fulfilment records, Guard events, and usage records are kept for up to 365 days. Support requests are kept for up to 180 days, customer data-request exports for up to 30 days, pseudonymous redaction-suppression hashes for up to 90 days, webhook deduplication records for seven days, and completed background jobs for two days. Open Pack Checks are retained while they still require action. A Shopify customers/redact request immediately deletes PackLock data linked to the supplied order IDs. Uninstall marks the shop uninstalled and removes PackLock's access token. Shopify's mandatory shop/redact webhook deletes the remaining operational shop data, normally about 48 hours later; a minimal shop-domain redaction marker is retained until reinstall solely to prevent in-flight work from recreating deleted records. Shopify order tags remain in the merchant's store until the merchant removes them.

Station Link security

A Station Link is a signed credential. Anyone with it can see order numbers, item data, quantities, and order notes and can complete Pack Checks. Merchants should limit access to packing devices and regenerate the link if it is exposed.

Your choices and rights

Merchants can Pause new Holds, disable Completion Markers, regenerate the Station Link, release all active Holds, uninstall PackLock, and request access, correction, or deletion where applicable. Shopper privacy requests are routed through Shopify; PackLock does not store direct shopper identity fields.

Contact

Email andrew@b4sed.dev for privacy requests. Include the .myshopify.com store domain so we can identify the installation.