Privacy
Sensitive claim materials are handled as controlled inputs.
Effective date: July 28, 2026
Last updated: July 28, 2026
1. Who we are
PactPack is operated by [Legal entity name to be added before launch].
Contact email: hello@pactpack.com.
Mailing address: [Business mailing address to be added before launch]
Replace the legal entity name and mailing address placeholders before launch.
2. What we collect
Account data
Name, business email address, password hash or authentication metadata, referral code, account preferences, legal-assent records, and session/security logs tied to account access.
Intake and job data
Company and contact fields, ZIP code, property address, claim reference, carrier name, scope notes, estimate PDFs, roof photos, measurement files, generated supplement outputs, revision history, QA notes, and support correspondence.
Payment and billing data
Checkout and billing records needed to confirm payment status, prevent fraud, respond to support issues, and meet accounting obligations. Stripe processes payment-card details; PactPack does not store full card numbers.
Device and usage data
IP address, browser or device metadata, page-level usage analytics, authentication events, and application logs used for security, reliability, and product improvement.
3. How we use data
- Create and secure accounts, authenticate users, and preserve session continuity.
- Run ZIP-based coverage screening and determine whether a jurisdiction is accepted, limited, or unsupported.
- Prepare, review, revise, deliver, and support supplement packs based on the materials submitted.
- Process billing, reconcile job status, prevent abuse or fraud, and maintain audit trails.
- Measure product performance, investigate issues, and improve workflow quality through essential first-party telemetry plus any separate optional analytics cookies a visitor explicitly enables where required.
4. Third-party services / processors
Stripe
Payment processing and transaction support.
ScIDE Analytics
Essential first-party product and website telemetry used for security, reliability, workflow verification, and product improvement, plus synthetic verification during setup.
Vercel
Hosting, delivery infrastructure, logs, and deployment operations.
Supabase
Authentication, database, storage, and related application infrastructure when configured for the deployment.
5. Retention
Account records
Kept while the account is active and generally up to 24 months after the last meaningful activity, unless a longer period is required for security, dispute handling, or law.
Draft jobs that never become paid orders
Generally deleted or anonymized within 90 days after inactivity unless needed to investigate abuse or support requests.
Completed jobs, uploads, generated outputs, and revision history
Generally retained for 24 months after delivery so customers can access records, request revisions inside scope, or resolve disputes.
Support records
Generally retained for 24 months after the related request closes.
Billing and payout records
Generally retained for 7 years where needed for tax, accounting, fraud-prevention, and audit obligations.
Analytics records
Generally retained for up to 13 months unless a shorter period applies in a configured tool or law requires less.
6. Your rights
- • Access a copy of account and job information we hold about you.
- • Request correction of incomplete or inaccurate information.
- • Request deletion of account data, uploads, and generated outputs, subject to records we must keep for security, fraud prevention, accounting, or legal obligations.
- • Request export of submitted and generated job records in a portable format where reasonably available.
To submit a request, email hello@pactpack.com with the subject line Privacy Request or use the in-app support path when available.
We aim to acknowledge verified requests within 5 business days and respond within 30 days unless law allows or requires a different period.
7. Cookies and analytics
Essential cookies support authentication, security, checkout or intake continuity, and PactPack's first-party ScIDE telemetry. Separate optional analytics or marketing cookies, if introduced later, remain off until consent is recorded where required.
The cookie banner and preference center control only non-essential cookies. They do not block first-party ScIDE telemetry that keeps the service measurable, secure, and testable.
Manage cookie choices on the Cookies page. See the Terms of Service for service-boundary rules that govern uploads and generated outputs.