Privacy Policy
Last updated: April 23, 2026
1. Introduction
PackVault ("we," "us," or "our") operates the website packvault.us (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our Platform, create an account, buy or sell products, or otherwise interact with our services.
By using PackVault, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Platform.
2. Information We Collect
2.1 Information You Provide Directly
When you register for an account, list products for sale, make a purchase, or contact us, we may collect:
- Account Information: Name, email address, username, and password (stored in hashed form — we never store your password in plain text).
- Seller Information: Store name, store description, and payout information. Bank account details for seller payouts are collected and stored by our payment partner QorPay — PackVault never stores, accesses, or processes your bank account numbers, routing numbers, or other financial account details.
- Shipping Information: Full name, street address, city, state, ZIP code, and country provided during checkout for order fulfillment.
- Transaction Information: Order details, purchase history, listing information, prices, and quantities.
- Communications: Messages sent through our buyer-seller messaging system, support tickets, and any other correspondence with us.
- Listing Content: Product descriptions, seller notes, and photos uploaded to listings.
2.2 Information Collected Automatically
When you visit or use the Platform, we may automatically collect:
- Device Information: Browser type, operating system, device type, and screen resolution.
- Usage Data: Pages visited, time spent on pages, links clicked, and search queries.
- IP Address: Used for security purposes including rate limiting, fraud prevention, and approximate geolocation.
- Cookies: We use essential cookies to maintain your session and authentication state. We do not use third-party advertising or tracking cookies.
2.3 Information We Do NOT Collect
PackVault does not collect or store:
- Credit card numbers, debit card numbers, or CVV codes — all payment card information is processed directly by QorPay and never touches our servers.
- Bank account numbers or routing numbers — payout details are tokenized and stored by QorPay.
- Social Security numbers or government-issued ID numbers.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Account Management: To create and manage your account, verify your identity, and authenticate your access.
- Order Processing: To process purchases, facilitate shipping, calculate fees, and manage payouts to sellers.
- Communication: To send order confirmations, shipping notifications, verification emails, and respond to support requests.
- Platform Operations: To display product listings, price history, and seller ratings.
- Security: To detect and prevent fraud, unauthorized access, and other illegal activities. This includes rate limiting, monitoring for suspicious activity, and reviewing seller applications.
- Improvement: To analyze usage patterns, diagnose technical issues, and improve our Platform.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
We do not sell your personal information to third parties. We do not use your data for targeted advertising. We do not share your information with data brokers.
4. How We Share Your Information
We may share your information only in the following circumstances:
4.1 With Service Providers
We share information with third-party service providers who perform services on our behalf:
- QorPay (QorCommerce): Payment processing and seller payout services. QorPay receives payment card information directly from you through their secure iframe — this data does not pass through PackVault's servers. QorPay also stores seller bank account tokens for payout purposes.
- Resend: Email delivery service used to send verification emails, order confirmations, and other transactional communications. Resend receives your email address to deliver these messages.
- Railway: Cloud hosting provider for our backend services and database.
- Vercel: Cloud hosting provider for our frontend website.
4.2 With Other Users
Certain information is shared between buyers and sellers to facilitate transactions:
- Sellers can see the buyer's shipping name and address for orders they need to fulfill, the buyer's username, and any messages sent through our messaging system.
- Buyers can see the seller's store name, ratings, sales count, and any messages sent through our messaging system.
- Seller email addresses, phone numbers, and payout information are never shared with buyers. Buyer email addresses are never shared with sellers.
4.3 For Legal Reasons
We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to:
- Comply with a legal obligation, subpoena, or court order.
- Protect and defend the rights or property of PackVault.
- Prevent or investigate possible wrongdoing in connection with the Platform.
- Protect the personal safety of users of the Platform or the public.
4.4 Business Transfers
If PackVault is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS).
- Password Security: Passwords are hashed using bcrypt before storage. We never store passwords in plain text.
- Payment Security: Payment card data is handled entirely by QorPay's PCI-compliant systems through secure iframes. Card data never touches our servers.
- Access Controls: Administrative access to our systems is protected by multi-layer authentication.
- Security Headers: Our Platform employs security headers including Content-Type-Options, Frame-Options, Referrer-Policy, and XSS-Protection.
- Rate Limiting: API endpoints are rate-limited to prevent abuse and brute-force attacks.
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying affected users in the event of a data breach in accordance with applicable law.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
- Account Data: Retained for as long as your account is active. You may delete your account at any time through your account settings.
- Transaction Records: Retained for a minimum of 7 years to comply with tax and accounting obligations.
- Support Tickets: Retained for 3 years after resolution for quality assurance and dispute resolution purposes.
- Deleted Listings: Soft-deleted listings are permanently removed after 30 days.
- Email Verification Tokens: Automatically expire and are deleted after 24 hours.
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
7.1 All Users
- Access: You can view your personal information through your account settings.
- Correction: You can update your name, email, and other account details through your account settings.
- Deletion: You can delete your account at any time through your account settings. This will permanently remove your profile, listings, and associated data. Transaction records may be retained as required by law.
- Data Portability: You may request a copy of your personal data by contacting us.
- Communication Preferences: You can manage your email preferences. Transactional emails (order confirmations, security alerts) cannot be opted out of while your account is active.
7.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose about you.
- Request deletion of your personal information.
- Opt out of the sale or sharing of your personal information. Note: PackVault does not sell or share your personal information for cross-context behavioral advertising.
- Non-discrimination for exercising your privacy rights.
7.3 Residents of Other US States with Privacy Laws
If you reside in a state with a comprehensive privacy law (including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Indiana, Kentucky, Rhode Island, and others), you may have similar rights to access, correct, delete, and port your data, as well as opt out of certain processing activities. To exercise these rights, please contact us using the information below.
8. Cookies and Tracking
PackVault uses only essential cookies necessary for the operation of the Platform:
- Authentication Token: Stored in your browser's local storage to keep you logged in. This is cleared when you log out.
- Session Data: Temporary data stored during checkout (such as shipping address) that is cleared after your session.
We do not use third-party advertising cookies, social media tracking pixels, or cross-site tracking technologies. We do not serve ads on our Platform. We do not track you across other websites.
9. Children's Privacy
PackVault is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13 without verification of parental consent, we will take steps to remove that information from our servers.
Users between the ages of 13 and 18 may use PackVault only with the involvement and consent of a parent or guardian.
10. Third-Party Links
Our Platform may contain links to third-party websites or services that are not owned or controlled by PackVault. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policy of every site you visit.
11. International Users
PackVault is operated in the United States and our services are primarily directed to users within the United States. If you access our Platform from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located. By using our Platform, you consent to the transfer of your information to the United States.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top. For significant changes, we may also send you a notification via email.
Your continued use of the Platform after any changes to this Privacy Policy constitutes your acceptance of those changes. We encourage you to review this Privacy Policy periodically for any updates.
13. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your data is handled, you can contact us:
- Email: support@packvault.us
- Support Page: packvault.us/support
We will respond to all privacy-related requests within 30 days, or sooner as required by applicable law.
14. Limitation of Liability
To the maximum extent permitted by applicable law, PackVault shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits or revenues, whether incurred directly or indirectly, or any loss of data, use, goodwill, or other intangible losses, resulting from your access to or use of or inability to access or use the Platform, any conduct or content of any third party on the Platform, or unauthorized access, use, or alteration of your transmissions or content.