Privacy policy
PackedBy records which member of your warehouse team packed which order.
Last updated 31 August 2026
The short version. PackedBy does not read, request, or store your customers' names, email addresses, postal addresses, phone numbers, or payment details. It stores order numbers, timestamps, and whatever name you assign each packer: a first name, a full name, initials or a nickname, entirely your choice. Nothing is sold, shared, or sent to any third party.
Who we are
PackedBy is operated by Jem Cas Pty Ltd (ACN 624 836 773), Australia. Questions about this policy, or about data we hold, go to support@packedby.app.
This policy covers the PackedBy app installed from the Shopify App Store and the packing
station page it provides at packedby.app.
What the app stores
For each shop that installs PackedBy:
- Your myshopify.com domain, time zone, plan, and install date.
- An access token issued by Shopify, encrypted at rest.
- Your settings, and the names and colors of your packers exactly as you type them. You decide what each packer is called: a first name, a full name, initials or a nickname. Nothing is imported from anywhere.
- Your location names as they appear in Shopify.
- For orders: the order number (for example
#1001), Shopify's internal order ID, when it was placed, whether it is paid, cancelled or fulfilled, and how many items require shipping. - For each pack: which packer, which order, and when, plus whether the tag reached Shopify, and whether it was later undone.
What the app does not store
The app never requests or retains:
- Customer names, email addresses, shipping or billing addresses, or phone numbers.
- Payment details, card numbers, or transaction amounts.
- Product names, SKUs, variants, or prices. The app counts items; it does not read them.
- Order notes, discount codes, or customer-supplied text of any kind.
This is a deliberate design constraint rather than a policy promise. The app asks Shopify only for the fields listed in the section above, so the data is not held anywhere to be lost, sold, or requested.
Permissions, and why each one is needed
- read_orders: to build the list of orders still waiting to be packed, and to answer "who packed this one?" when you search an order number.
- write_orders: to add a
packed-by-nametag to an order once someone packs it, and to remove that tag if the pack is undone. Tagging can be switched off in Settings, in which case the app never writes to your store at all. - read_merchant_managed_fulfillment_orders: to tell which of your locations an order is assigned to, so a device at one warehouse does not show another warehouse's queue.
- read_locations: to show your locations by name rather than by ID.
Your staff's names
The names you assign your packers are the only personal information the app holds. They are visible only to people who can reach your manager page or your Pack Station link, and they appear in your exported CSV.
Because you choose the label rather than the app importing it, you decide how identifying it is. Initials or nicknames work exactly as well as full names for everything the app does, and a shop that prefers to hold no identifying information about its staff can run the app that way without losing anything.
You can rename a packer at any time, and the new name applies to their past packs as well as their future ones, because it is the same person. Tags already written to orders in Shopify are left as they were. Choosing "Hide forever" in Settings removes that packer and their records permanently.
Where the data lives
PackedBy runs on Cloudflare Workers, and stores data in Cloudflare D1. Cloudflare is our only sub-processor. We use no analytics service, no advertising network, no error-tracking service, and no third-party scripts. The app makes outbound requests to Shopify and to nothing else.
How long it is kept
- While the app is installed, your pack history is kept so that reporting and exports remain complete. Nothing is deleted or rewritten in the ordinary course of use; an undone pack is marked as undone rather than removed.
- When you uninstall, the access token is destroyed immediately and the app can no longer reach your store.
- Shopify sends a deletion request 48 hours after uninstall. On receiving it, every record belonging to your shop is permanently deleted.
- You can export your full pack history to CSV at any time before uninstalling.
Customer data requests
Shopify requires apps to respond to requests from your customers about data an app holds on them. Because PackedBy holds no customer data at all, there is nothing to return and nothing to erase. We answer these requests accordingly.
Security
- Access tokens are encrypted at rest with AES-GCM.
- All traffic is over HTTPS.
- Every webhook from Shopify is signature-verified before it is acted on.
- Your Pack Station link contains an unguessable key. Anyone holding that link can record packs for your shop, so treat it as a password. You can regenerate it in Settings, which immediately invalidates the old one.
Your rights
Depending on where you are, you may have rights to access, correct, export, or delete the information described here. The export and delete paths above are available to you directly in the app. For anything else, write to support@packedby.app and we will respond within 30 days.
Changes
If this policy changes in a way that affects what is collected or who it is shared with, the date at the top will change and merchants will be notified in the app before the change takes effect.