Privacy

Sensitive claim materials are handled as controlled inputs.

Effective date: July 28, 2026

Last updated: July 28, 2026

1. Who we are

PactPack is operated by [Legal entity name to be added before launch].

Contact email: hello@pactpack.com.

Mailing address: [Business mailing address to be added before launch]

Replace the legal entity name and mailing address placeholders before launch.

2. What we collect

Account data

Name, business email address, password hash or authentication metadata, referral code, account preferences, legal-assent records, and session/security logs tied to account access.

Intake and job data

Company and contact fields, ZIP code, property address, claim reference, carrier name, scope notes, estimate PDFs, roof photos, measurement files, generated supplement outputs, revision history, QA notes, and support correspondence.

Payment and billing data

Checkout and billing records needed to confirm payment status, prevent fraud, respond to support issues, and meet accounting obligations. Stripe processes payment-card details; PactPack does not store full card numbers.

Device and usage data

IP address, browser or device metadata, page-level usage analytics, authentication events, and application logs used for security, reliability, and product improvement.

3. How we use data

  • Create and secure accounts, authenticate users, and preserve session continuity.
  • Run ZIP-based coverage screening and determine whether a jurisdiction is accepted, limited, or unsupported.
  • Prepare, review, revise, deliver, and support supplement packs based on the materials submitted.
  • Process billing, reconcile job status, prevent abuse or fraud, and maintain audit trails.
  • Measure product performance, investigate issues, and improve workflow quality through essential first-party telemetry plus any separate optional analytics cookies a visitor explicitly enables where required.

4. Third-party services / processors

Stripe

Payment processing and transaction support.

ScIDE Analytics

Essential first-party product and website telemetry used for security, reliability, workflow verification, and product improvement, plus synthetic verification during setup.

Vercel

Hosting, delivery infrastructure, logs, and deployment operations.

Supabase

Authentication, database, storage, and related application infrastructure when configured for the deployment.

5. Retention

Account records

Kept while the account is active and generally up to 24 months after the last meaningful activity, unless a longer period is required for security, dispute handling, or law.

Draft jobs that never become paid orders

Generally deleted or anonymized within 90 days after inactivity unless needed to investigate abuse or support requests.

Completed jobs, uploads, generated outputs, and revision history

Generally retained for 24 months after delivery so customers can access records, request revisions inside scope, or resolve disputes.

Support records

Generally retained for 24 months after the related request closes.

Billing and payout records

Generally retained for 7 years where needed for tax, accounting, fraud-prevention, and audit obligations.

Analytics records

Generally retained for up to 13 months unless a shorter period applies in a configured tool or law requires less.

6. Your rights

  • Access a copy of account and job information we hold about you.
  • Request correction of incomplete or inaccurate information.
  • Request deletion of account data, uploads, and generated outputs, subject to records we must keep for security, fraud prevention, accounting, or legal obligations.
  • Request export of submitted and generated job records in a portable format where reasonably available.

To submit a request, email hello@pactpack.com with the subject line Privacy Request or use the in-app support path when available.

We aim to acknowledge verified requests within 5 business days and respond within 30 days unless law allows or requires a different period.

7. Cookies and analytics

Essential cookies support authentication, security, checkout or intake continuity, and PactPack's first-party ScIDE telemetry. Separate optional analytics or marketing cookies, if introduced later, remain off until consent is recorded where required.

The cookie banner and preference center control only non-essential cookies. They do not block first-party ScIDE telemetry that keeps the service measurable, secure, and testable.

Manage cookie choices on the Cookies page. See the Terms of Service for service-boundary rules that govern uploads and generated outputs.

8. Children

PactPack is not directed to children under 13 and is intended for business users handling job-by-job claim-support workflows.

9. Security

We use administrative, technical, and organizational controls designed to protect account credentials, uploads, generated outputs, and payment-state records. No system is perfectly secure, so customers should also limit uploads to materials needed for the job and protect their own account credentials.

10. Changes to this policy

We may update this policy as the product, vendors, or legal requirements change. Material updates will be posted here with a revised last-updated date and, where appropriate, surfaced in-product.

11. Effective date / Last updated

Effective date: July 28, 2026. Last updated: July 28, 2026.