PackSnap Data Protection Terms
Version: v1
Effective date: July 16, 2026
Last updated: July 16, 2026
These Data Protection Terms (the "Data Terms") form part of the agreement between Hof Coral, an individual operating the PackSnap service under the PackSnap name ("PackSnap"), and the organization using the PackSnap Services ("Customer"). They apply when PackSnap processes Customer Personal Data on the Customer's behalf.
These Data Terms supplement the PackSnap Terms of Service or another written agreement that incorporates them (the "Agreement"). Capitalized terms not defined here have the meaning given in the Agreement.
By accepting these Data Terms for a Customer, you represent that you have authority to bind that Customer.
1. Definitions
For these Data Terms:
- "Applicable Data Protection Law" means privacy, data protection, and data-security law that applies to PackSnap's processing of Customer Personal Data under the Agreement.
- "CCPA" means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.
- "Customer Personal Data" means Personal Data contained in Customer Data that PackSnap processes on the Customer's behalf to provide the Services.
- "Data Subject" means an identified or identifiable person to whom Personal Data relates, or a "consumer" under the CCPA.
- "GDPR" means Regulation (EU) 2016/679, and "UK GDPR" means the GDPR as incorporated into United Kingdom law.
- "Personal Data" means information defined as personal data, personal information, or a similar protected category under Applicable Data Protection Law.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by PackSnap. It does not include an unsuccessful attempt that does not compromise Customer Personal Data.
- "process," "processing," "controller," "processor," "business," "service provider," "sell," and "share" have the meanings given by Applicable Data Protection Law.
- "Subprocessor" means a third party appointed by or for PackSnap to process Customer Personal Data in connection with the Services.
2. Roles and scope
2.1 Customer as controller or business
The Customer determines the purposes and means of processing Customer Personal Data and acts as the controller or business. The Customer instructs PackSnap to process Customer Personal Data to provide, secure, maintain, and support the Services as described in the Agreement and Annex I.
2.2 PackSnap as processor or service provider
PackSnap acts as the Customer's processor and, where the CCPA applies, as its service provider or contractor. PackSnap will process Customer Personal Data only:
- on the Customer's documented instructions, including the Agreement and use of Service features;
- to provide, secure, maintain, and support the Services;
- as otherwise permitted by Applicable Data Protection Law; or
- as required by law, in which case PackSnap will notify the Customer before processing unless the law prohibits notice.
2.3 PackSnap-controlled information
These Data Terms do not apply to personal information for which PackSnap independently determines the purposes and means of processing, such as PackSnap's own account administration, billing, fraud prevention, security, legal compliance, and business-contact records. The PackSnap Privacy Policy applies to that processing.
2.4 Customer instructions
The Agreement, these Data Terms, the Customer's configuration and use of the Services, and written support requests are the Customer's documented instructions. Additional instructions must be consistent with the Agreement and may be subject to reasonable fees if they require work outside the Services.
If PackSnap reasonably believes an instruction violates Applicable Data Protection Law, PackSnap will notify the Customer and may suspend the affected processing until the parties resolve the issue.
3. Customer obligations
The Customer represents and warrants that:
- it has complied and will comply with Applicable Data Protection Law;
- it has all rights, notices, consents, authorizations, and lawful bases required to collect Customer Personal Data and provide it to PackSnap for the processing described here;
- its instructions are lawful and do not cause PackSnap to violate Applicable Data Protection Law;
- it will collect and provide only Customer Personal Data reasonably necessary for the Services;
- it is authorized to use any marketplace export, order record, buyer information, photograph, or other data it submits;
- it will respond to Data Subjects and regulators concerning its processing and provide PackSnap with timely instructions when assistance is needed; and
- it will not submit regulated or highly sensitive data that the Services are not designed to process.
Unless PackSnap expressly agrees in writing, the Customer must not submit Social Security or national identification numbers, payment-card numbers, account passwords, protected health information, biometric identifiers, precise geolocation, information about children, or special-category or criminal-offense data.
The Customer is responsible for configuring roles, limiting user and device access, removing former personnel and lost devices, and using available deletion and retention controls.
4. Processing restrictions
PackSnap will not:
- sell Customer Personal Data;
- share Customer Personal Data for cross-context behavioral advertising;
- use Customer Personal Data for third-party advertising or data brokerage;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with the Customer or outside the specific purposes described in the Agreement and Annex I, except as permitted by Applicable Data Protection Law;
- use buyer Personal Data for unrelated marketing, profiling, or solicitation;
- attempt to re-identify information that has been properly de-identified; or
- combine Customer Personal Data with personal information received from another customer or collected from PackSnap's own interactions with a Data Subject, except where permitted by Applicable Data Protection Law and reasonably necessary to provide, secure, or improve the Services without identifying the Customer or Data Subject.
PackSnap may create and use information that has been aggregated, anonymized, or otherwise de-identified so that it cannot reasonably identify the Customer, a Data Subject, or any other individual, and cannot reasonably be linked back to Customer Personal Data. PackSnap may use that information to operate, secure, analyze, improve, and develop its products, services, and business. PackSnap will maintain it in de-identified form, will not attempt to re-identify it, will not disclose it in a form that identifies a Customer or individual, and will not create or use it where prohibited by Applicable Data Protection Law or applicable marketplace restrictions.
5. CCPA service-provider and contractor terms
To the extent the CCPA applies, the parties agree that:
- The Customer discloses Customer Personal Data to PackSnap only for the limited and specific business purposes described in Annex I.
- PackSnap will process Customer Personal Data only for those purposes and as otherwise permitted for a service provider or contractor by the CCPA.
- PackSnap will not sell or share Customer Personal Data.
- PackSnap will not retain, use, or disclose Customer Personal Data outside the direct business relationship with the Customer or for a commercial purpose other than the purposes specified in the Agreement, except as permitted by the CCPA.
- PackSnap will provide the same level of privacy protection required of service providers and contractors by the CCPA.
- PackSnap will notify the Customer if it determines it can no longer meet its obligations under the CCPA.
- The Customer may take reasonable and appropriate steps to help ensure PackSnap uses Customer Personal Data consistently with the Customer's CCPA obligations, subject to Section 13.
- Upon notice, the Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
- PackSnap will require each Subprocessor processing Customer Personal Data to be bound by written obligations that provide a level of protection appropriate to the processing and consistent with applicable service-provider or contractor requirements.
The specific business purposes are not a general reference to the Agreement; they are listed in Annex I under Nature and purpose of processing.
6. Confidentiality and personnel
PackSnap will ensure that personnel authorized to process Customer Personal Data:
- access it only as necessary for their responsibilities;
- are informed of its confidential nature;
- are bound by contractual, professional, or statutory confidentiality obligations; and
- receive security and privacy guidance appropriate to their role.
Customer Personal Data is Customer Confidential Information under the Agreement. Confidentiality obligations continue after personnel access and after termination of the Agreement.
7. Security measures
PackSnap will implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
The measures currently applicable to the Services are summarized in Annex II. PackSnap may update those measures as technology and risks change, provided an update does not materially reduce the overall protection of Customer Personal Data.
The Customer understands that security is a shared responsibility. The Customer must use the Services' access controls appropriately, secure its credentials and paired devices, train its personnel, and avoid submitting unnecessary or unsupported sensitive data.
8. Subprocessors
8.1 General authorization
The Customer gives PackSnap general written authorization to engage the Subprocessors listed in Annex III and to add or replace Subprocessors as reasonably necessary to provide the Services.
8.2 Subprocessor obligations
Before a Subprocessor processes Customer Personal Data, PackSnap will enter into a written agreement requiring the Subprocessor to protect that data with obligations appropriate to the services it provides. PackSnap remains responsible for the Subprocessor's performance of its data-protection obligations to the extent required by Applicable Data Protection Law.
8.3 Changes and objections
PackSnap may update its Subprocessor list from time to time. If a new Subprocessor materially changes the privacy or security risk of the Services, PackSnap will provide notice through the Services, by email, through an updated policy version, or by another reasonable method where required by law.
The Customer may object on reasonable data-protection grounds by emailing support@packsnap.io within 15 days after notice and describing the specific concern. The parties will work in good faith to address the concern. If no reasonable alternative is available, either party may terminate the affected portion of the Services. The Customer's sole remedy for an unresolved objection is termination of the affected Services and a prorated refund of prepaid fees for the unused terminated period.
9. Data Subject requests
Taking into account the nature of the processing, PackSnap will provide reasonable assistance for the Customer to respond to a verified request from a Data Subject to exercise rights under Applicable Data Protection Law.
If PackSnap receives a request relating to Customer Personal Data directly from a Data Subject, PackSnap will not independently fulfill the request unless authorized by the Customer or required by law. Where reasonably identifiable and legally permitted, PackSnap will direct the requester to the Customer or notify the Customer.
The Customer is responsible for determining whether a request is valid, verifying the requester, deciding how to respond, and providing instructions. PackSnap may charge reasonable fees for assistance that is unusually burdensome or outside standard Service functionality, unless law prohibits the charge.
10. Personal Data Breaches
PackSnap will notify the Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notification may be delivered to the Customer's account contact or another contact designated by the Customer.
As information becomes reasonably available, PackSnap will provide details needed for the Customer to understand the nature of the incident, including:
- the nature of the Personal Data Breach;
- the categories of affected Customer Personal Data and Data Subjects, where known;
- the likely consequences, where reasonably assessable;
- measures taken or proposed to contain, investigate, and remediate the incident; and
- a contact for follow-up.
PackSnap may provide information in phases as the investigation continues. A notification is not an admission of fault or liability.
PackSnap will take reasonable steps to contain and remediate a Personal Data Breach. The Customer is responsible for determining whether notice to Data Subjects, regulators, marketplaces, or others is legally required and for issuing those notices, except where law places the obligation directly on PackSnap.
Unsuccessful login attempts, blocked attacks, network scans, and similar events that do not compromise Customer Personal Data are not Personal Data Breaches under these Data Terms.
11. Assistance and regulatory cooperation
Taking into account the nature of processing and information available to PackSnap, PackSnap will provide reasonable assistance with the Customer's obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- data-protection impact assessments; and
- prior consultation with a regulator.
The Customer will reimburse reasonable costs for assistance that requires substantial work beyond normal Service functionality, unless the assistance is required because PackSnap breached these Data Terms.
If PackSnap receives a legally binding request from a public authority for Customer Personal Data, PackSnap will, unless prohibited by law:
- notify the Customer before disclosure;
- direct the authority to the Customer where appropriate;
- review the request for legal validity; and
- disclose only the information legally required.
12. Return and deletion
During the service term, the Customer may access, export, or delete certain Customer Data using available Service features. The Customer is responsible for exporting information it wishes to keep before closing its account or ending the Services.
Upon termination of the Agreement or the Customer's written request, PackSnap will delete or return Customer Personal Data within a commercially reasonable period, unless law requires retention or the Customer requests continued processing. PackSnap may retain limited records necessary for legal compliance, billing, fraud prevention, security, dispute resolution, or enforcement of the Agreement.
Customer Personal Data may remain temporarily in backups or disaster-recovery systems until overwritten through normal cycles. During that period, PackSnap will keep the data protected and will not use it for another purpose.
Deletion of a database record and deletion of an associated object, such as a proof image or import file, may occur as separate technical operations. PackSnap will use reasonable measures to complete both and to address identified orphaned objects safely without disrupting active Customer Data.
13. Information and audits
Upon reasonable written request, PackSnap will provide information reasonably necessary to demonstrate compliance with these Data Terms, such as relevant policy summaries, security descriptions, or responses to a reasonable questionnaire.
If that information is insufficient and Applicable Data Protection Law gives the Customer an audit right, the Customer may conduct an audit no more than once in any 12-month period, unless a confirmed Personal Data Breach or regulator requires more frequent review. An audit must:
- be scheduled with at least 30 days' notice where practicable;
- occur during normal business hours;
- avoid unreasonable disruption to PackSnap or other customers;
- protect PackSnap's and other customers' confidential information;
- be performed by the Customer or an independent auditor that is not a competitor and is bound by confidentiality; and
- be limited to systems and records relevant to Customer Personal Data.
The Customer bears its audit costs and PackSnap's reasonable support costs unless the audit identifies a material breach by PackSnap. PackSnap may satisfy an audit request through current independent reports or certifications when they reasonably address the request, but PackSnap does not represent that it currently holds any particular certification unless expressly stated in writing.
14. International transfers
The Customer authorizes PackSnap and its Subprocessors to process Customer Personal Data in the United States and other countries where they operate, subject to these Data Terms.
If the Customer's use of the Services requires a legally recognized transfer mechanism, the parties will cooperate in good faith to implement an appropriate mechanism before the restricted transfer. This may include applicable standard contractual clauses and legally required supplementary measures.
These Data Terms do not, by themselves, complete party-specific standard contractual clauses that require legal names, addresses, transfer roles, jurisdictions, or signatures. A Customer that requires those clauses must contact support@packsnap.io before submitting data subject to the transfer restriction.
15. GDPR and UK GDPR terms
To the extent the GDPR or UK GDPR applies to PackSnap's processing of Customer Personal Data:
- the subject matter, duration, nature, purpose, data types, and Data Subject categories are described in Annex I;
- PackSnap will process Customer Personal Data only on documented instructions, including with respect to international transfers, unless law requires otherwise;
- PackSnap will ensure authorized personnel are bound by confidentiality;
- PackSnap will implement appropriate security measures as required by Article 32;
- PackSnap will engage Subprocessors in accordance with Article 28;
- PackSnap will assist the Customer with Data Subject rights and obligations under Articles 32 through 36, taking into account the nature of processing and information available;
- PackSnap will delete or return Customer Personal Data at the end of the provision of Services, subject to legal retention; and
- PackSnap will make available information necessary to demonstrate compliance and permit audits as described in Section 13.
16. Liability and precedence
Each party's liability arising from these Data Terms is subject to the exclusions and limitations of liability in the Agreement, except to the extent Applicable Data Protection Law prohibits a limitation.
If these Data Terms conflict with the Agreement on the processing or protection of Customer Personal Data, these Data Terms control. If a separately executed data-processing agreement or transfer mechanism expressly supersedes these Data Terms, that signed document controls for its subject matter.
17. Duration and changes
These Data Terms remain effective for as long as PackSnap processes Customer Personal Data. Obligations that by their nature continue after termination, including confidentiality, security, deletion, and restrictions on use, remain effective while PackSnap retains Customer Personal Data.
PackSnap may update these Data Terms as the Services, providers, or law change. For a material change, PackSnap will provide notice and may require an authorized user to review and accept a new version. Changes will not materially reduce protection for Customer Personal Data during a committed paid term without a legal, security, or operational reason.
18. Contact
Questions, requests, security notices, or Subprocessor objections under these Data Terms may be sent to:
Hof Coral, operating under the PackSnap name
Email: support@packsnap.io
Website: https://packsnap.io
Annex I - Processing details
A. Subject matter
PackSnap processes Customer Personal Data to provide cloud-based operations software for live-selling and ecommerce teams, including show and order import, package organization, picking, scanning, pulling, packing, proof-image capture, gallery and report access, device and crew management, inventory workflows, support, and related security and administration.
B. Duration
Processing continues for the term of the Agreement and for the limited period afterward needed to return or delete data, complete backup cycles, comply with law, maintain security, and resolve disputes.
C. Nature and purpose of processing
The limited and specific business purposes are to:
- receive files and information the Customer chooses to upload or generate;
- validate, parse, normalize, organize, match, and store show, order, package, product, inventory, and shipping information;
- display Customer Data to authorized users and devices within the Customer's organization;
- authenticate and authorize users and devices;
- coordinate and record picking, scanning, pulling, packing, inventory, and fulfillment activity;
- create, upload, store, retrieve, display, share at the Customer's direction, and delete packing proof images;
- produce Customer-requested reports, galleries, operational metrics, and support records;
- host, back up, secure, monitor, troubleshoot, and maintain the Services;
- provide customer support and investigate errors, abuse, or security incidents; and
- comply with lawful Customer instructions and legal obligations.
Processing operations may include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission to authorized recipients, restriction, deletion, and destruction.
D. Categories of Data Subjects
- Customer owners, administrators, and platform users;
- Customer employees, contractors, operations personnel, and crew members;
- authorized users of paired operational devices;
- buyers, recipients, and marketplace users whose orders are fulfilled by the Customer;
- customer-support requesters and business contacts; and
- other individuals whose information the Customer lawfully includes in Customer Data.
E. Categories of Customer Personal Data
- names, usernames, business emails, profile images, roles, and organization affiliation;
- buyer usernames, recipient names, delivery addresses, and contact information included in authorized source data;
- marketplace, show, order, package, product, transaction, refund, cancellation, and fulfillment records;
- tracking numbers, package identifiers, shipping information, and status;
- product, barcode, SKU, inventory, location, quantity, price, and cost information where linked to a person or sole proprietor;
- proof photographs and related timestamps and metadata;
- crew-member names, device names, general device type, user agent, identifiers, pairing information, and last-seen time;
- scanning, pulling, packing, inventory, duration, performance, and audit activity;
- IP addresses, technical logs, errors, and security events; and
- communications and support records.
F. Sensitive data
The Services are not designed for special-category data, biometric identifiers, precise geolocation, government identifiers, payment-card numbers, account passwords, protected health information, or information about children. The Customer must not submit those categories unless PackSnap expressly agrees in writing.
A delivery address or an image may be subject to heightened protection in some jurisdictions. PackSnap processes it only for the operational purposes described in this Annex and does not use it to infer sensitive characteristics.
G. Frequency
Processing occurs when the Customer and its authorized users use the Services, including continuously for hosted records and periodically when users import files, access workflows, capture proof images, or request reports and support.
Annex II - Security measures
PackSnap maintains a risk-appropriate security program for the Services. Measures may include:
A. Access control and identity
- managed authentication for platform users;
- organization-scoped authorization and role-based permissions;
- separate device authentication using pairing codes, signed tokens, expiration controls, and revocable device signatures;
- least-privilege access for personnel and infrastructure roles; and
- removal or restriction of access when no longer required.
B. Data protection
- encryption in transit using industry-standard transport security;
- cloud-provider encryption at rest where supported by the managed service;
- logical separation of Customer organizations through application authorization and tenant identifiers;
- separate storage purposes for proof images, public media, and private imports; and
- time-limited signed upload or download URLs where appropriate.
C. Application and infrastructure security
- managed cloud infrastructure and restricted production network access;
- security groups, environment-specific configuration, and managed secrets or credentials;
- input validation, authenticated endpoints, authorization guards, and dependency management;
- logging and monitoring designed to identify errors, abuse, and security events; and
- controlled deployment and migration processes.
D. Availability and recovery
- managed database, object-storage, and infrastructure durability features;
- backups and recovery procedures appropriate to the Service and risk;
- retry and local queue behavior for interrupted proof-image uploads; and
- incident investigation, containment, remediation, and recovery practices.
E. Organizational measures
- confidentiality obligations for personnel and contractors with access;
- access limited to people with a business need;
- periodic review of security risks and service-provider access; and
- documented escalation and response for suspected security incidents.
These measures describe the current security posture at a general level and do not constitute a representation that PackSnap holds a particular security certification.
Annex III - Authorized Subprocessors
The Customer authorizes the following current Subprocessors and categories. A provider processes only the information relevant to the service it supplies.
| Subprocessor | Service | Processing location or scope |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, managed database, object storage, networking, caching, logs, backups, and infrastructure security | Primarily United States; AWS locations used by PackSnap |
| Clerk, Inc. | User authentication and identity management | Locations used by Clerk to provide its service |
| Stripe, Inc. | Subscription billing, payment processing, invoices, and payment-fraud controls | Locations used by Stripe to provide its service |
| Microsoft Corporation (Clarity) | Product analytics, interaction events, and session diagnostics where enabled | Locations used by Microsoft to provide Clarity |
PackSnap may also use limited professional, support, communication, monitoring, security, or product-data providers that receive only the minimum information necessary for their function. Material additions involving Customer Personal Data are governed by Section 8.
TikTok and Whatnot are trademarks of their respective owners. PackSnap is not affiliated with or endorsed by TikTok or Whatnot.