Plain-Language Summary
We collect only what we need to serve you, we never sell your personal information, and we honor every privacy right granted to you under U.S. federal and state law. This policy tells you exactly what data we collect, why we collect it, and how you can control it.
Introduction
Welcome to PackTist ("PackTist," "we," "us," or "our"). We are committed to protecting your personal information and your right to privacy under applicable United States federal and state laws. This Privacy Policy governs all personal information we collect through our website packtist.com, our platform, related applications, and any other services we offer (collectively, the "Services").
By accessing or using PackTist, you acknowledge that you have read, understood, and agree to the data practices described in this Privacy Policy. If you do not agree with the terms of this policy, please discontinue use of our Services.
This Privacy Policy has been prepared to comply with applicable U.S. federal laws — including the Federal Trade Commission Act (FTC Act, 15 U.S.C. § 45), the CAN-SPAM Act of 2003 (15 U.S.C. § 7701 et seq.), the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.), and the Electronic Communications Privacy Act (ECPA, 18 U.S.C. § 2510 et seq.) — as well as comprehensive state privacy laws including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), and the New York SHIELD Act.
Governing Jurisdiction
This Privacy Policy is governed exclusively by the laws of the United States of America and applicable U.S. state laws. All user rights, obligations, and remedies described herein are those established under U.S. federal and state law. Disputes relating to this policy shall be resolved under U.S. jurisdiction.
Who We Are
PackTist is a premium custom packaging platform that connects brands with world-class packaging solutions. We provide an end-to-end digital platform for ordering, managing, and customizing packaging — from rigid boxes and mailer boxes to luxury retail packaging — with full-color print, specialty finishes, and dedicated account management.
For purposes of U.S. state privacy laws, PackTist is a "business" as defined under CCPA/CPRA and a "controller" as defined under the VCDPA, CPA, CTDPA, UCPA, and TDPSA. We determine the purposes and means by which personal information is collected and processed through our Services.
- Company: PackTist — a trading name of IMT Solutions LLC
- Website: packtist.com
- Privacy Contact: support@packtist.com
- Mailing Address: PackTist Privacy Team — United States (full address available upon request)
Information We Collect
We collect personal information in several ways: directly from you when you interact with our Services, automatically when you visit our website, and occasionally from trusted third parties. The categories below align with CCPA/CPRA definitions of personal information.
3.1 Information You Provide Directly
- Identifiers: Full name, email address, mailing/billing/shipping address, phone number, company name, username, and account password (stored using one-way bcrypt hashing — never readable by our staff).
- Commercial Information: Order history, product selections, quantities, custom specifications, pricing, payment status, artwork file uploads, and quote request details.
- Financial Information: We do not store your full payment card number, CVV, or PIN. All payment transactions are processed exclusively by PCI-DSS Level 1 certified processors (Stripe, PayPal). We retain only limited payment metadata: last four digits of a card, card type, billing zip, payment status, and transaction reference IDs.
- Communications Content: Emails, live chat messages, support ticket content, and any other correspondence you send us.
- User-Generated Content: Logos, artwork files, brand assets, and design templates you upload for packaging customization.
- Professional or Employment Information: Job title, company role, company size, or industry — provided during registration or quote requests.
- Survey and Feedback Responses: Voluntary responses to satisfaction surveys, testimonials, or product reviews.
- Job Application Information: Resumes, cover letters, work history, and contact details submitted by employment applicants.
3.2 Information Collected Automatically
- Internet or Network Activity: IP address, browser type and version, operating system, device type and identifiers, referring URL, pages visited, time on page, links clicked, and navigation paths.
- Geolocation Data: City- and country-level location inferred from your IP address. We do not collect precise GPS-level location without your explicit consent.
- Log Files: Server-generated logs recording access timestamps, HTTP request types, response codes, and error events — used for security and debugging.
- Cookie and Tracking Data: Data stored by cookies, web beacons, pixel tags, and local storage. See Section 7 for full details.
3.3 Information from Third Parties
- Social Login Providers: If you register using Google or Facebook, we receive your name, email, and profile picture from that provider, subject to your settings with them.
- Advertising and Analytics Platforms: We may receive aggregate or pseudonymous data from Google Ads and Meta to measure ad effectiveness. This data is not used to build individual profiles for sale.
- Business Data Enrichment: We may supplement business-account profiles with publicly available company data (industry, company size) from professional sources.
3.4 CCPA/CPRA Personal Information Categories
| CCPA Category | Examples Collected | Business Purpose | Sold or Shared? |
|---|---|---|---|
| Identifiers | Name, email, IP address, account ID | Account management, order processing | No |
| Customer Records (Cal. Civ. Code § 1798.80) | Name, address, payment metadata | Billing, fulfillment | No |
| Commercial Information | Order history, product preferences | Fulfillment, personalization | No |
| Internet / Network Activity | Browsing behavior, pages visited | Analytics, site improvement | No |
| Geolocation Data | City/country (IP-derived) | Localized content, shipping estimates | No |
| Professional Information | Job title, company name | Account setup, B2B services | No |
| Inferences | Preferences derived from usage patterns | Personalization, recommendations | No |
Sensitive Personal Information — CPRA Notice
PackTist does not intentionally collect "sensitive personal information" as defined under CPRA § 1798.140(ae) — including Social Security numbers, driver's license or state ID numbers, financial account numbers with access credentials, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, health information, or data concerning sex life or sexual orientation. If you believe you have inadvertently submitted such data, contact support@packtist.com immediately.
How We Use Your Information
We use personal information only for legitimate business purposes consistent with the context in which it was collected, as permitted by the FTC Act and applicable state laws. We do not use your data for any purpose that would constitute an unfair or deceptive trade practice under Section 5 of the FTC Act.
4.1 Providing and Operating the Services
- Creating, maintaining, and securing your user account and customer portal.
- Processing and fulfilling your packaging orders, custom quote requests, and reorder instructions.
- Sending transactional communications: order confirmations, production updates, shipping notifications, and delivery tracking.
- Enabling design file uploads, artwork previews, and version management within your account.
- Providing live chat support, resolving customer service tickets, and responding to inquiries.
- Improving the functionality, usability, and performance of the PackTist platform.
4.2 Billing and Financial Administration
- Processing payments and generating invoices, receipts, and credit memos.
- Managing refunds, disputes, and chargebacks in accordance with our Returns Policy.
- Verifying billing information and detecting and preventing fraudulent transactions.
- Maintaining financial records as required under federal tax law (IRS record retention obligations, 26 U.S.C.).
4.3 Marketing and Communications
- Sending promotional emails, product announcements, and newsletters — only to users who have opted in, or to existing customers under the CAN-SPAM Act's existing business relationship exemption.
- Serving targeted or retargeted advertisements on third-party platforms (Google, Meta) where you have not exercised an opt-out.
- Personalizing on-site content, recommendations, and promotions based on your interaction history.
- Measuring marketing campaign performance through analytics and attribution tools.
Opt Out of Marketing at Any Time
Every promotional email we send contains a clear, one-click "Unsubscribe" link. We process opt-out requests within 10 business days as required by the CAN-SPAM Act. You may also opt out by emailing support@packtist.com. Unsubscribing from marketing does not affect transactional emails related to your active orders or account.
4.4 Analytics and Platform Improvement
- Analyzing how users navigate our platform to identify usability issues and improve features.
- Conducting internal research and development to create new products and services.
- Generating aggregated, de-identified analytics that cannot reasonably be used to identify individuals.
4.5 Legal Compliance and Safety
- Complying with applicable U.S. federal and state laws, regulations, and binding court or government orders.
- Responding to lawful requests from U.S. government authorities, courts, or law enforcement agencies, consistent with ECPA requirements.
- Establishing, exercising, or defending legal claims against or by PackTist.
- Enforcing our Terms of Service, acceptable use policies, and other agreements.
- Detecting, investigating, and preventing fraud, security incidents, and other unlawful activity.
Sharing & Disclosure of Your Information
We do not sell, rent, or trade your personal information to third parties for their own marketing or business purposes. We disclose personal information only in the limited circumstances described below, consistent with FTC guidance and applicable state law.
5.1 Service Providers
We engage third-party service providers that process personal information solely on our behalf and under our instruction. These providers are contractually prohibited from using your data for any independent purpose and must maintain security standards consistent with this policy. They include:
- Cloud Hosting and Infrastructure: Vercel (hosting, U.S. data centers), Neon (PostgreSQL database), Cloudinary (image/file storage)
- Payment Processing: Stripe and/or PayPal — PCI-DSS Level 1 certified processors
- Email Delivery: Resend — for transactional and promotional email delivery
- Customer Support / Live Chat: Tawk.to — for in-platform chat support
- Analytics: Google Analytics (IP anonymization enabled), Plausible Analytics
- Shipping and Logistics: DHL, FedEx, UPS, and other carriers for order fulfillment and delivery tracking
- CRM and Sales Tools: Internal tools used by our account management and sales teams
5.2 Business Transfers
If PackTist undergoes a merger, acquisition, asset sale, reorganization, or bankruptcy, personal information may be transferred as part of that transaction. We will provide affected users with at least 30 days' prior notice via email and a prominent website notice before personal information becomes subject to a materially different privacy policy, and will offer an opportunity to opt out where required by applicable state law.
5.3 Legal Process and Law Enforcement
We may disclose personal information in response to lawful legal process — including valid subpoenas, court orders, or government agency demands — provided those requests satisfy applicable legal standards (including ECPA requirements for electronic communications). Where permitted by law, we will notify you before disclosing your information. We may also share information to protect the rights, property, or safety of PackTist, our users, or the public.
5.4 With Your Consent
We will share your personal information with third parties in any circumstance not described above only when you have given us clear, affirmative, informed consent to do so.
We Do Not Sell Personal Information
PackTist does not "sell" personal information as that term is defined under the CCPA/CPRA (Cal. Civ. Code § 1798.140(ad)), the VCDPA (Va. Code § 59.1-575), the CPA (C.R.S. § 6-1-1303), or any other applicable U.S. state privacy law. See Section 6 for your right to opt out of the sharing of data for targeted advertising purposes.
Do Not Sell or Share My Personal Information
Under the California Privacy Rights Act (CPRA) and comparable state privacy laws, you have the right to opt out of the "sale" of your personal information and of "sharing" for purposes of cross-context behavioral advertising — even where no money changes hands.
PackTist does not sell personal information. However, we use advertising pixels and remarketing tags operated by Google and Meta, which may constitute "sharing" for cross-context behavioral advertising under California's legal definition. Residents of California, Colorado, Connecticut, Virginia, Texas, and other states with opt-out rights may exercise those rights as follows:
- Click the "Do Not Sell or Share My Personal Information" link in the footer of our website — this activates your opt-out immediately.
- Use your browser's Global Privacy Control (GPC) signal — we recognize and honor GPC signals as valid opt-out requests under California (CPRA) and Colorado (CPA) law.
- Email support@packtist.com with subject line: "Do Not Sell or Share Request."
- Opt out of Google interest-based advertising at adssettings.google.com.
- Opt out of Meta advertising at facebook.com/adpreferences.
We will process opt-out requests within 15 business days. We will not discriminate against you in any way — including by denying services, charging different prices, or reducing service quality — because you exercised this right.
Cookies & Tracking Technologies
We use cookies, web beacons, pixel tags, local storage, and similar technologies to operate our Services, analyze usage, and — where you have not opted out — support advertising campaigns. You have meaningful control over non-essential tracking technologies.
7.1 What Are Cookies?
Cookies are small text files placed on your browser or device when you visit a website. They allow sites to recognize your device, maintain session state, remember preferences, and measure activity. Some are strictly necessary for the site to function; others are optional and used for analytics or advertising.
7.2 Cookie Categories
| Category | Purpose | Duration | Can You Opt Out? |
|---|---|---|---|
| Strictly Necessary | Authentication, session management, security CSRF tokens, load balancing | Session / up to 30 days | No — required for basic functionality |
| Functional / Preference | Remembering language, currency, and display preferences | Up to 1 year | Yes — via cookie preferences |
| Analytics / Performance | Google Analytics (with IP anonymization), Plausible — measuring traffic and behavior to improve the site | Up to 2 years | Yes — via cookie preferences or GA opt-out add-on |
| Advertising / Targeting | Google Ads pixel, Meta Pixel — conversion tracking and retargeted advertising campaigns | Up to 90 days | Yes — via GPC, Do Not Sell opt-out, or platform-level settings |
| Third-Party (Live Chat) | Tawk.to — chat session identification and persistence | Session / up to 6 months | Yes — by disabling the chat widget |
7.3 Your Cookie Controls
- Cookie Preference Center: Our site provides a preference panel where you can accept or reject optional cookie categories at any time.
- Browser Settings: You can configure your browser (Chrome, Firefox, Safari, Edge) to block or delete cookies. Blocking essential cookies may impair site functionality.
- Global Privacy Control (GPC): We recognize GPC signals as valid opt-outs for cross-context behavioral advertising under California and Colorado law.
- Google Analytics Opt-Out: Install Google's opt-out browser add-on.
- Digital Advertising Alliance (DAA): Opt out of interest-based advertising at optout.aboutads.info.
- Network Advertising Initiative (NAI): Opt out of targeted ads from NAI member companies at optout.networkadvertising.org.
Email Communications & CAN-SPAM Compliance
All commercial email communications we send are governed by the federal CAN-SPAM Act of 2003 (15 U.S.C. § 7701 et seq.) and its implementing regulations (16 C.F.R. Part 316). We fully comply with all CAN-SPAM requirements:
- Accurate Header Information: The "From," "To," "Reply-To," and routing information in all our emails accurately identifies PackTist as the sender. We do not use deceptive addresses or domains.
- Non-Deceptive Subject Lines: Subject lines accurately reflect the content of the email and do not use misleading or false language.
- Advertising Identification: Commercial emails are clearly identified as advertisements where required by law.
- Physical Postal Address: Every commercial email we send includes our valid physical mailing address, as required by 15 U.S.C. § 7704(a)(5).
- Clear Opt-Out Mechanism: Every promotional email contains a clearly visible, functioning unsubscribe link or opt-out mechanism.
- Prompt Opt-Out Processing: We process all opt-out requests within 10 business days as required by 15 U.S.C. § 7704(a)(4). We do not charge fees or require unnecessary information to process an opt-out.
- No Post-Opt-Out Commercial Emails: Once you opt out, we do not send you commercial emails and do not sell or transfer your email address to another party for their commercial email use after opt-out.
- No Third-Party Violations: We do not authorize third parties to send commercial emails on our behalf in violation of the CAN-SPAM Act.
Transactional Emails Are Always Delivered
Opting out of marketing emails does not affect transactional or relationship communications required to fulfill your orders or maintain your account — including order confirmations, shipping updates, invoice receipts, password resets, and security alerts. These are not "commercial electronic mail messages" under CAN-SPAM and will continue to be sent as needed.
Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods reflect applicable U.S. federal and state records retention requirements.
| Data Type | Retention Period | Legal or Business Basis |
|---|---|---|
| Account Information | Duration of account + 2 years after closure | Contractual obligation; state consumer protection law |
| Order Records and Invoices | 7 years | IRS tax record retention (26 U.S.C. § 6001); federal accounting rules |
| Payment Metadata | 7 years | IRS requirements; PCI-DSS compliance obligations |
| Unfulfilled Quote Requests | 18 months | Legitimate business interest; sales follow-up |
| Customer Support Records | 3 years from resolution | Dispute resolution; applicable statutes of limitation |
| Artwork and Design Files | Active account + 90 days after closure | Reorder facilitation; deleted promptly upon verified request |
| Marketing Opt-In Records | 3 years from last engagement or unsubscribe | CAN-SPAM compliance; consent record-keeping |
| Analytics and Log Data | 14 months active; anonymized thereafter; raw logs deleted at 26 months | Security monitoring; platform improvement |
| Job Application Data | 1 year if not hired; 3 years if hired | EEOC record-keeping regulations (29 C.F.R. § 1602); HR compliance |
When personal information is no longer required, we securely delete or irreversibly anonymize it so that it cannot reasonably be linked to any individual. You may request earlier deletion at any time, subject to our legal obligations to retain certain records (see Section 10).
Your Privacy Rights
Depending on your state of residence, you may have the following rights regarding your personal information. We honor these rights for all U.S. users to the extent required by applicable law. We will not discriminate against you for exercising any privacy right.
Right to Know
Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our business purposes, and the third parties with whom we share it.
Right to Delete
Request deletion of personal information we hold about you, subject to statutory exceptions (e.g., completing your transaction, fraud prevention, legal obligations).
Right to Correct
Request correction of inaccurate personal information. Available under CPRA, VCDPA, CPA, CTDPA, UCPA, and TDPSA.
Right to Portability
Request a copy of your personal information in a portable, readily usable format (where technically feasible) so you can transfer it to another provider.
Right to Opt Out
Opt out of the sale or sharing of personal information and of targeted advertising. We honor Global Privacy Control (GPC) browser signals as valid opt-out requests.
Right to Non-Discrimination
We will not deny you goods or services, charge different prices, or provide a lesser level of service because you exercised any privacy right under applicable law.
Right to Opt Out of Profiling
Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. Available under VCDPA, CPA, CTDPA, UCPA, and TDPSA.
Right to Appeal
If we decline your rights request, you may appeal our decision. We will review appeals and respond within the timeframes mandated by your state's law.
How to Submit a Request
- Email: support@packtist.com — Subject: "Privacy Rights Request"
- Account Portal: Log in and navigate to Account → Privacy & Data to manage your information directly.
We will acknowledge receipt within 10 business days and fulfill your request within 45 calendar days (extendable by an additional 45 days for complex requests, with written notice of the extension and reason). We will verify your identity before processing any request. We will not require you to create an account solely to submit a rights request. Authorized agents may submit requests on your behalf with a written authorization signed by you.
California Residents — CCPA / CPRA
This section applies to residents of the State of California and supplements Section 10. It is provided pursuant to the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), codified at California Civil Code § 1798.100 et seq., and regulations adopted by the California Privacy Protection Agency (CPPA).
11.1 Your CCPA/CPRA Rights
- Right to Know (Cal. Civ. Code § 1798.110): Request disclosure of categories and specific pieces of personal information collected, categories of sources, business or commercial purposes, and categories of third parties — covering the preceding 12-month period. You may make up to two such requests per 12-month period at no charge.
- Right to Delete (§ 1798.105): Request deletion of personal information, subject to statutory exceptions.
- Right to Correct (§ 1798.106): Request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing (§ 1798.120): Direct us to stop selling or sharing your personal information, including for cross-context behavioral advertising. Exercise via our "Do Not Sell or Share" link in the site footer or by contacting us.
- Right to Limit Use of Sensitive Personal Information (§ 1798.121): To the extent we process sensitive personal information, you may limit our use to authorized purposes. (We do not intentionally collect sensitive personal information — see Section 3.)
- Right to Non-Discrimination (§ 1798.125): We will not deny services, charge different prices, or reduce service quality because you exercised any CCPA/CPRA right.
11.2 Shine the Light — Cal. Civ. Code § 1798.83
California residents may request a list of categories of personal information shared with third parties for their direct marketing purposes during the prior calendar year. PackTist does not share personal information with third parties for their own direct marketing purposes. You may still submit a Shine the Light inquiry to support@packtist.com — Subject: "California Shine the Light."
11.3 Financial Incentives Notice
PackTist does not currently offer financial incentives, price differences, or service differences in exchange for the collection, retention, or sale of personal information. Any future program will comply with CPRA § 1798.125(b) disclosure requirements and be offered only with your prior opt-in consent.
Submit a California Rights Request
Email support@packtist.com with subject "CCPA/CPRA Request" or use the Privacy Rights portal in your account settings. We respond within 45 days. For appeal of a denied request, contact us at the same address — Subject: "CCPA Appeal." Unresolved complaints may be directed to the California Privacy Protection Agency (CPPA) at cppa.ca.gov or the California Attorney General at oag.ca.gov.
Other State Privacy Rights
Several U.S. states have enacted comprehensive consumer privacy laws that grant residents specific data rights. PackTist honors all applicable state privacy laws. If you reside in one of the following states, your rights under that state's law are recognized and honored:
Virginia — VCDPA
Rights to access, correct, delete, and portability; opt out of targeted advertising, profiling, and sale. Appeal rights: respond within 60 days of denial. Va. Code Ann. § 59.1-571 et seq.
Colorado — CPA
Rights to access, correct, delete, portability; opt out of targeted advertising, profiling, and sale. GPC signals honored as valid opt-outs. C.R.S. § 6-1-1301 et seq.
Connecticut — CTDPA
Rights to access, correct, delete, portability; opt out of targeted advertising, profiling, and sale. Appeals: 45 days. Conn. Gen. Stat. § 42-515 et seq.
Utah — UCPA
Rights to access, delete, and portability; opt out of targeted advertising and sale. Utah Code § 13-61-101 et seq., effective December 31, 2023.
Texas — TDPSA
Rights to access, correct, delete, portability; opt out of targeted advertising, profiling, and sale. Effective July 1, 2024. Bus. & Com. Code § 541.001 et seq.
Florida — FDBR
Rights to access, correct, delete, portability; opt out of targeted advertising, profiling, and sale. Applicable to controllers meeting the Florida threshold. Fla. Stat. § 501.701 et seq.
New York — SHIELD Act
Requires reasonable data security safeguards for any entity handling private information of New York residents. We maintain SHIELD-compliant security practices. N.Y. Gen. Bus. Law § 899-aa et seq.
All Other States
We actively monitor evolving state privacy legislation and update our practices as new laws take effect. Contact support@packtist.com to exercise rights regardless of your state of residence.
To exercise rights under any applicable state law, email support@packtist.com and state your state of residence and the specific right you wish to exercise. We apply the most protective standard applicable to your request.
Children's Privacy — COPPA Compliance
PackTist is a commercial platform intended exclusively for adults. Our Services are not directed to children under the age of 13, and we do not knowingly collect, use, or disclose personal information from children under 13, in full compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501–6506, and implementing regulations at 16 C.F.R. Part 312.
We do not knowingly collect personal information from users under the age of 18. You must be at least 18 years old to create a PackTist account, place orders, or use our Services. We do not verify age at registration but rely on users' agreement to our Terms of Service confirming they meet this age requirement.
If you are a parent or legal guardian and believe your child under 13 has provided us with personal information without your verifiable parental consent, please contact us immediately:
- Email: support@packtist.com — Subject: "COPPA — Child Data Concern"
- We will promptly delete the child's information, notify you upon completion, and take steps to prevent future collection.
- We will respond within 5 business days.
We do not condition any service or feature on a child providing more personal information than is reasonably necessary to participate. If we discover that we have inadvertently collected personal information from a child under 13, we will delete it immediately and, where required, report the incident to the Federal Trade Commission.
FTC COPPA Enforcement
The Federal Trade Commission enforces COPPA. If you believe a website or online service has violated COPPA, you may file a complaint with the FTC at reportfraud.ftc.gov or ftc.gov/coppa.
Security of Your Information
We implement and maintain a comprehensive, written information security program designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction. Our security practices are consistent with the FTC's reasonable security standards, the New York SHIELD Act's data security requirements, and applicable state data security statutes.
Technical Safeguards:
- All data in transit encrypted using TLS 1.2 or higher (HTTPS) across all pages and API endpoints — no unencrypted HTTP allowed.
- Data at rest encrypted using AES-256 on all production databases and file storage systems.
- Passwords hashed using bcrypt (industry-standard, non-reversible) and are never stored in recoverable form.
- Access to production systems requires multi-factor authentication (MFA) and is restricted to authorized personnel only.
- Payment processing handled exclusively by PCI-DSS Level 1 certified third-party processors. PackTist never receives or stores full card numbers.
- Automated vulnerability scanning, dependency auditing, and timely security patch management applied on a regular basis.
- Network segmentation, access logging, and intrusion detection systems deployed across our cloud infrastructure.
Organizational Safeguards:
- Role-based access control (RBAC) ensuring employees access only the minimum personal information necessary for their role (principle of least privilege).
- Regular security and data protection training for all staff with access to personal information.
- Data security provisions in all contracts with third-party service providers handling personal information.
- A written incident response plan that is regularly reviewed and tested.
- Annual security assessments and periodic penetration testing of production systems.
Data Breach Notification — State Law Compliance
In the event of a security breach involving your personal information, we will notify affected residents in accordance with all applicable state data breach notification laws — including California (Cal. Civ. Code § 1798.82), New York (SHIELD Act / Gen. Bus. Law § 899-aa), Texas (Bus. & Com. Code § 521.053), Florida (Fla. Stat. § 501.171), and all other applicable state statutes. Most states require notification without unreasonable delay and within 30–60 days of discovery. Notification will describe what happened, what categories of data were involved, steps we are taking, and recommended protective actions for you. We will also notify the FTC and applicable state regulators as required by law.
While we take every reasonable precaution, no electronic system is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials. Contact us immediately at support@packtist.com if you suspect any unauthorized activity on your account.
Third-Party Websites & Links
Our website and Services may contain links to third-party websites, plug-ins, and applications. Clicking those links may allow third parties to collect or share data about you. PackTist does not control these external websites, is not responsible for their content or privacy practices, and this Privacy Policy does not apply to them.
We encourage you to review the privacy policy of every third-party website you visit. The FTC may have jurisdiction over deceptive data practices by U.S.-based operators — concerns about specific third parties can be reported to the FTC at reportfraud.ftc.gov. Notable third-party integrations you may encounter on our platform include:
- Tawk.to — live chat widget. Their privacy policy governs data collected during chat sessions.
- Google Analytics — subject to Google's Privacy Policy. We use IP anonymization and data processing terms.
- Stripe / PayPal — subject to their own PCI-DSS-compliant privacy policies and security standards.
- Google Ads / Meta Pixel — advertising measurement subject to Google's and Meta's privacy policies and your ad preferences settings.
- Social Media Platforms — interactions with social media features are governed by those platforms' terms and privacy policies.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our data practices, the Services we offer, or applicable U.S. federal and state law. The revised policy will be posted to this page with an updated "Last Revised" date at the top of the document.
For material changes — those that significantly affect how we collect, use, or share personal information, or that affect your rights — we will provide prior notice by:
- Sending an email notice to the address associated with your account at least 30 days before the change takes effect;
- Displaying a prominent notice banner on our website homepage and within your account dashboard;
- For California residents, providing the disclosures required by CPRA § 1798.130(a)(7) regarding any new uses of previously collected personal information.
Your continued use of our Services after the effective date of any revised policy constitutes your acceptance of the changes, to the extent permitted by applicable law. If you disagree with a material change, you may close your account and request deletion of your personal information before the effective date by contacting support@packtist.com.
Prior versions of this Privacy Policy are archived and available upon request by emailing support@packtist.com.
Contact Us
For any questions, concerns, or formal requests regarding this Privacy Policy or our data practices, please contact our Privacy Team. We respond to general inquiries within 5 business days and to formal rights requests within the timeframes required by applicable law.
Reach Our Privacy Team
We're here to help with any privacy question, rights request, or data concern.
Filing a Complaint with a U.S. Regulator
If you believe we have violated your privacy rights and we have not adequately resolved your concern, you may file a complaint with the Federal Trade Commission (FTC) at reportfraud.ftc.gov. California residents may contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov or the California Attorney General at oag.ca.gov. All other state residents may contact their respective state Attorney General's office for privacy-related complaints.