Skip to content

In DevelopmentComing soon

Privacy Policy

Last updated: April 27, 2026

1. Data Controller

Valerian Huber
Dahlienweg 11
83109 Großkarolinenfeld, Germany
Email: help@packmate.shop

2. Legal Basis

Personal data is processed on the basis of Art. 6 GDPR:

  • Art. 6(1)(b) GDPR — Performance of contract (app provision, packaging calculation, order processing)
  • Art. 6(1)(f) GDPR — Legitimate interest (server logs for security, error analysis, abuse prevention)

3. Data Collected

The following data is processed when you use PackMate:

  • Shopify store domain and store metadata
  • Product data: titles, dimensions, weight, fragility flags (stored as Shopify metafields and in our database)
  • Box configurations (sizes, weight limits, fill materials)
  • Order data for the orders you choose to calculate (line items, weights, recipient ZIP for tariff lookup) — never recipient names, addresses or payment information unless you explicitly create a shipping label
  • Pack-calculation history (saved cost, fill weight, box selection — used for the Pro analytics dashboard)
  • Server logs (IP address truncated, timestamp, user agent) for 30 days

4. Purpose of Processing

The data is processed exclusively for the provision of PackMate's functionality (packaging calculation, 3D pack visualization, shipping cost optimization, analytics, and DHL shipping label generation when you opt in).

5. Subprocessors

The following processors handle data on our behalf:

  • Hetzner Online GmbH (Germany) — VPS hosting + PostgreSQL database. All servers in EU.
  • Vercel Inc. (USA) — hosts our marketing website at packmate.shop only. No merchant data is sent to Vercel.
  • Shopify Inc. — the primary platform; relationship governed by Shopify's own Data Processing Addendum. PackMate receives data via Shopify's GraphQL Admin API under your install authorization.
  • DHL Paket GmbH (Germany) — only when you actively create a shipping label using your own DHL business account. We act as an integration; the carrier relationship is between you and DHL.

A Data Processing Agreement (DPA) per Art. 28 GDPR is available on request — email help@packmate.shop.

6. AI Integration

PackMate offers an MCP (Model Context Protocol) server for connection to AI assistants like Claude.ai, Claude Code or ChatGPT. We do not host AI inference. When you connect an AI assistant, the assistant runs on the AI provider's infrastructure (your account, your subscription) and calls PackMate tools as needed. PackMate is not a subprocessor for the AI provider; the AI assistant's data handling is governed by its own privacy policy.

7. Authentication

PackMate uses Shopify's built-in OAuth authentication and session tokens (JWT). No additional third-party authentication service is used. We never see or store Shopify merchant passwords.

8. Data Storage and Retention

Application data is stored on EU-based servers (Hetzner). Pack calculations and analytics data are retained per plan: 7 days (Free), 90 days (Basic), 365 days (Pro), 3 years (Premium). Custom plans negotiate individual retention windows. Product dimensions are stored both in our database and as Shopify metafields in your store.

Upon uninstallation of the app, all your data is automatically deleted after a 30-day grace period (per Shopify requirements). You can request immediate deletion at any time by emailing help@packmate.shop. Product dimension metafields remain in your Shopify store; remove them via the Shopify Admin if desired.

9. International Data Transfers

Our primary data infrastructure (servers, database) is in the EU. The marketing website is hosted via Vercel (USA), but no merchant data is processed there — only the public landing page. Where transfers occur (e.g., Shopify's own infrastructure), they are governed by EU Standard Contractual Clauses or equivalent safeguards.

10. Your Rights (GDPR Articles 15–22)

You have the right to:

  • Access your personal data (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Erasure / "right to be forgotten" (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Lodge a complaint with a supervisory authority (Art. 77) — for Germany: BayLDA, Promenade 18, 91522 Ansbach

To exercise any of these rights, contact help@packmate.shop. We respond within 30 days.

11. Cookies

PackMate uses only technically necessary cookies for session management and authentication via Shopify. The marketing website at packmate.shop does not currently use analytics cookies.

12. Changes to This Policy

Material changes will be communicated via the app dashboard and via email to your store contact. The "Last updated" date above tracks revisions.

13. Contact

Questions about this policy: help@packmate.shop