Privacy Policy
Effective date: 1 January 2026
PackageIQ ("we", "us", "our") is committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights regarding it. It applies to all users of packageiq.io and related services.
PackageIQ is currently operated on a pre-incorporation basis while our registered legal entity is formed in Bosnia and Herzegovina. Our registered company name, address, and company number will be published here once incorporation is complete; until then, direct any data protection query to the contact in Section 9.
1. Information we collect
Account data
When you create an account we collect your display name, email address, and a hashed password. If you sign in via Google OAuth we receive the name and email address your Google account makes available.
Usage data
We collect information about how you use the service: pages visited, packaging analyses submitted, report types selected, and feature interactions. This data is used solely to improve the product and is not sold to third parties.
Product and packaging data
When you run an analysis you submit product descriptions, packaging specifications, market context, and optionally a packaging photograph. This content is processed by AI models to generate your report and is stored so you can retrieve the report later. It is not used to train AI models or shared with other customers.
Payment data
Payment processing is handled by Stripe (token pack purchases) and Paddle (subscription tier purchases). Paddle acts as our Merchant of Record for tier purchases: it collects your card and billing details directly and is responsible for its own tax/VAT compliance on those transactions. We do not store card numbers or full payment details ourselves. We retain transaction records (amount, date, status, and the relevant Stripe payment intent ID or Paddle transaction ID) to support receipts and refund requests.
Technical data
Standard server logs record IP addresses, browser type, and request timestamps. These are retained for up to 30 days for security and debugging purposes.
2. How we use your information
- To deliver and operate the PackageIQ service (necessary to perform our contract with you)
- To generate packaging analysis reports using AI providers (OpenAI, Anthropic) (necessary to perform our contract with you)
- To process payments and issue receipts (necessary to perform our contract with you; legal obligation for tax and accounting records)
- To send transactional emails (account confirmation, report ready notifications) (necessary to perform our contract with you)
- To detect and prevent fraud or abuse (our legitimate interest in keeping the service secure)
- To comply with legal obligations (legal obligation)
We do not send marketing emails without your explicit opt-in (based on your consent, which you may withdraw at any time - see Section 5).
3. AI providers and third-party services
Generating reports and running the service requires sharing data with the following processors:
- OpenAI (report generation, image generation) - governed by OpenAI's data processing agreement; located in the United States
- Anthropic (report generation) - governed by Anthropic's data processing agreement; located in the United States
- Stripe (token pack payment processing) - governed by Stripe's privacy policy; located in the United States
- Paddle (subscription tier payment processing, acting as Merchant of Record) - governed by Paddle's privacy policy; located in the United Kingdom
- Supabase (our primary application database - accounts, sessions, payment records - and knowledge base retrieval via pgvector) - data processed within the EU
We have data processing agreements in place with each provider. Where a provider processes data outside the EU/EEA/UK, that transfer is protected by Standard Contractual Clauses or an equivalent safeguard under the provider's data processing agreement. None of these providers use your submitted data to train their public models under their current API terms.
4. Data retention
- Account data - retained while your account is active and for 90 days after deletion
- Analysis reports - retained for 24 months; you may delete individual reports at any time from your account
- Payment records - retained for 7 years to meet accounting and tax obligations
- Server logs - retained for 30 days
5. Your rights (GDPR)
If you are based in the European Economic Area, UK, or Switzerland you have the following rights:
- Access - request a copy of the personal data we hold about you
- Rectification - correct inaccurate data
- Erasure - request deletion of your account and associated data (subject to legal retention obligations)
- Portability - receive your data in a machine-readable format
- Objection - object to processing based on legitimate interest
- Restriction - request that we limit processing while a dispute is resolved
- Withdraw consent - where processing relies on your consent (for example, marketing emails), withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, email us at iq.package@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority, or with the supervisory authority of the country where we are established, if you believe our processing of your personal data infringes the GDPR.
We are not currently required to appoint a Data Protection Officer under Article 37 GDPR. Data protection queries can be directed to the contact in Section 9.
6. Cookies and local storage
We use browser localStorage to persist your theme preference and selected language. We do not use advertising or tracking cookies. If we introduce cookies in future we will update this policy and request consent where required.
7. Security
Passwords are stored as bcrypt hashes - we never store plaintext passwords. All traffic is encrypted in transit via HTTPS/TLS. Access to production databases is restricted by IP allowlisting and requires multi-factor authentication.
8. Changes to this policy
We may update this policy to reflect changes in the service or applicable law. Material changes will be notified by email to registered users at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance of the revised policy.
9. Contact
Questions about this policy or requests to exercise your data rights:
We have not yet appointed a formal Article 27 EU representative; this section will be updated with those details once our legal entity is incorporated. Until then, EU/UK/Swiss data subjects can direct any GDPR-related query to the email address above.