Naar inhoud springen

In ontwikkelingBinnenkort

This page is available in English and German only. Showing the English version.

Privacy Policy

Last updated: October 4, 2026

1. Data Controller

Valerian Huber
Dahlienweg 11
83109 Großkarolinenfeld, Germany
Email: support@packmate.shop

2. Legal Basis

Personal data is processed on the basis of Art. 6 GDPR:

  • Art. 6(1)(b) GDPR — Performance of contract (app provision, packaging calculation, order processing)
  • Art. 6(1)(f) GDPR — Legitimate interest (server logs for security, error analysis, abuse prevention)

3. Data Collected

The following data is processed when you use PackMate:

  • Shopify store domain and store metadata
  • Product data: titles, dimensions, weight, fragility flags (stored as Shopify metafields and in our database)
  • Box configurations (sizes, weight limits, fill materials)
  • Order data for the orders you choose to calculate (line items, weights, recipient ZIP for tariff lookup) — never recipient names, addresses or payment information unless you explicitly create a shipping label
  • Pack-calculation history (saved cost, fill weight, box selection — used for the analytics dashboard)
  • Server access logs (IP address, timestamp, requested address, user agent) for 7 days — to fend off attacks and to find errors

4. Purpose of Processing

The data is processed exclusively for the provision of PackMate's functionality (packaging calculation, 3D pack visualization, shipping cost optimization, analytics, and DHL shipping label generation when you opt in).

5. Subprocessors

The following processors handle data on our behalf:

  • Hostinger International Ltd. (Cyprus) — server hosting and PostgreSQL database in the Frankfurt am Main data centre, including self-hosted error and visit measurement (GlitchTip, Umami).
  • Hetzner Online GmbH (Germany) — storage for the daily backup of database and uploads in Falkenstein. Backups are encrypted before they leave our server.
  • Resend (Plus Five Five, Inc.) (USA) — delivery of emails to you as a merchant, such as deadline reminders; sent via AWS SES in the EU. Basis: EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Vercel Inc. (USA) — hosts our marketing website at packmate.shop only. No merchant data is sent to Vercel.
  • Shopify Inc. — the primary platform; relationship governed by Shopify's own Data Processing Addendum. PackMate receives data via Shopify's GraphQL Admin API under your install authorization.
  • DHL Paket GmbH (Germany) — only when you actively create a shipping label using your own DHL business account. We act as an integration; the carrier relationship is between you and DHL.

The current list with purpose, location and date is at packmate.shop/legal/sub-processors.

A Data Processing Agreement (DPA) per Art. 28 GDPR is available on request — email support@packmate.shop.

6. AI Integration

PackMate offers an MCP (Model Context Protocol) server for connection to AI assistants like Claude.ai, Claude Code or ChatGPT. We do not host AI inference. When you connect an AI assistant, the assistant runs on the AI provider's infrastructure (your account, your subscription) and calls PackMate tools as needed. PackMate is not a subprocessor for the AI provider; the AI assistant's data handling is governed by its own privacy policy.

7. Authentication

PackMate uses Shopify's built-in OAuth authentication and session tokens (JWT). No additional third-party authentication service is used. We never see or store Shopify merchant passwords.

8. Data Storage and Retention

Application data is stored on servers in Germany (Hostinger, Frankfurt am Main). How long each kind is kept:

  • Pack calculations and analytics: per plan 7 days (Free), 90 days (Basic), 365 days (Pro) or 3 years (Business); they are deleted afterwards. Custom plans negotiate their own windows.
  • Recipient data in shipping labels (name, address): anonymised 90 days after creation.
  • Log of writing API calls: 400 days.
  • Product dimensions: in our database and as Shopify metafields in your store.
  • Pack plan on the order: PackMate stores two metafields per order in your store (number of packages, carton and contents per package). They are removed again 45 days after the calculation; you can switch this off in the app and remove all fields at once.

After uninstalling: API keys are revoked immediately. About 48 hours later Shopify asks us to delete your shop's data, and we then remove it completely from our database. You can request earlier deletion at any time by emailing support@packmate.shop. Metafields that are still in your Shopify store at that point (product dimensions, pack plan) stay there; after uninstalling we no longer have access to them. Remove them in the app beforehand or via the Shopify Admin afterwards.

Backups: We back up the database daily. Backups on the server are deleted after 14 days. In addition, an encrypted copy is kept at Hetzner in Falkenstein; it is deleted after 35 days. Backups are used for restoring only. Deleted data may therefore still be contained in backups for up to 35 days.

9. International Data Transfers

Our primary data infrastructure (servers, database) is in the EU. The marketing website is hosted via Vercel (USA), but no merchant data is processed there — only the public landing page. Emails to you are sent via Resend (USA, EU-US Data Privacy Framework and Standard Contractual Clauses). Where transfers occur (e.g., Shopify's own infrastructure), they are governed by EU Standard Contractual Clauses or equivalent safeguards.

10. Your Rights (GDPR Articles 15–22)

You have the right to:

  • Access your personal data (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Erasure / "right to be forgotten" (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Lodge a complaint with a supervisory authority (Art. 77) — for Germany: BayLDA, Promenade 18, 91522 Ansbach

To exercise any of these rights, contact support@packmate.shop. We respond within 30 days.

11. Cookies and Audience Measurement

PackMate uses only technically necessary cookies for session management and authentication via Shopify. The marketing website at packmate.shop sets no analytics cookies.

For audience measurement of the marketing website we use Vercel Web Analytics (Vercel Inc., USA, EU-US Data Privacy Framework). It sets no cookies and stores nothing on your device; it records page views, referrer, device type and country, and the visitor identifier is a daily rotating hash that cannot be traced back to your IP address. There is no cross-device or cross-site tracking. The legal basis is our legitimate interest (Art. 6 (1) (f) GDPR) in knowing which pages are read; no consent is required. You can object here — the setting applies to this device and browser:

In addition we use Umami, a self-hosted instance run by the operator (Alpin-Code) at analytics.alpin-code.de. Umami likewise sets no cookies and stores nothing on your device; it records page views, referrer, device type and country. The legal basis is again our legitimate interest (Art. 6 (1) (f) GDPR). The objection below applies to both services — only the objection itself is kept as a flag in your browser so that it still applies on your next visit.

12. Changes to This Policy

Material changes will be communicated via the app dashboard and via email to your store contact. The "Last updated" date above tracks revisions.

13. Contact

Questions about this policy: support@packmate.shop