PACKPROOF

Privacy Policy

Effective: [LAUNCH DATE] · Controller: [PACKPROOF LEGAL ENTITY] · Contact: support@packproof.example

This policy explains how PackProof collects, uses, shares, protects and deletes information. Replace every bracketed field and obtain legal review before launch.

Information we collect

Account and sign-in information

When you use Google sign-in, we receive the identifiers and basic profile fields authorized by you, such as display name, email address and profile image. We do not receive your Google password. Facebook and TikTok sign-in are not enabled in the initial Android release.

Transaction information

We collect the item description, agreed price, condition, identifiers, certificate or serial information, transaction terms, participant confirmations, shipping carrier, tracking number and transaction status that users submit.

Evidence and user content

We store photographs, videos, documents, reports, return-passport records, messages submitted through concern forms and associated metadata. Evidence metadata may include capture and upload time, file size, content type, uploader role, camera-read shipping barcode, cryptographic fingerprints, app/build identifiers, device model and operating-system version, network connection type, and motion-sensor statistics sampled during capture. These signals support integrity review but do not prove that a transaction or item is genuine. Do not upload government IDs, payment-card data, private communications or unrelated people.

Optional location

Before a capture, you may choose to include precise location. When enabled, coordinates, accuracy, altitude when available and capture time are placed in the private evidence manifest visible to transaction participants. Location is off by default and is not required to use PackProof.

Technical information

We receive device and app-integrity signals, diagnostic logs, a privacy-preserving cryptographic value derived from the network subnet used to request an upload, and notification tokens. We do not retain the raw ingress IP address in the evidence manifest. Paid subscriptions and RevenueCat billing are not enabled in the initial Android release.

How we use information

When we share information

Transaction content is shared with the other participant in that transaction. We also use service providers including Google Firebase, Google sign-in, Google Play distribution services and Expo. Providers process information under their own terms and our service arrangements. We may disclose information when legally required, to protect users or the service, or as part of a corporate transaction with appropriate notice and safeguards. We do not sell personal information for money or use transaction evidence for targeted advertising.

Retention and deletion

We retain account and transaction information while needed to provide PackProof, maintain security, satisfy the retention period shown in the product, or comply with legal obligations. Users can schedule deletion in Account settings or at our web deletion page. A seven-day cancellation period applies. After that period, the profile and the user’s uploaded evidence are deleted. Shared transaction timelines may retain redacted, non-profile action records so the remaining participant’s history is not silently rewritten. We may retain limited fraud-prevention, legal-hold or security records when lawfully necessary.

Your choices and rights

You can export your account data, control notifications, report or block another participant and request deletion. Depending on location, you may have rights to access, correct, delete, restrict or object to processing and to appeal a privacy decision. Contact support@packproof.example with “Privacy Request” in the subject.

Security

PackProof uses authenticated access controls, server-authoritative workflow changes, private storage rules, app attestation, encryption in transit, provider-managed encryption at rest, Android Keystore encryption for queued offline evidence, upload limits, audit records and cryptographic file and manifest fingerprints. Evidence waiting for connectivity is encrypted inside the app’s private storage; uninstalling the app, clearing its data or losing the device may make that local queue unrecoverable. No system can guarantee absolute security. Protect your device and linked accounts and report suspected compromise promptly.

Children

PackProof is not directed to children under 18 and high-value private transactions should be conducted only by adults legally capable of entering the transaction.

International use

Information may be processed in the United States and other places where our providers operate. [ADD ENTITY-SPECIFIC TRANSFER MECHANISM AND REGIONAL DISCLOSURES BEFORE INTERNATIONAL LAUNCH.]

Changes

We will post material changes here and, where required, notify users in the app. Continued use after the effective date is subject to the updated policy.