PackDash
Privacy Policy
Effective Date: September 11, 2026
This Privacy Policy explains how PackDash processes information when Shopify merchants install or use the PackDash app, browser extension, recording workflow, video access pages, and related services.
PackDash is provided by Kineteck. Privacy questions can be sent to trustdashapp@gmail.com.
1. Information We Process
PackDash processes the minimum information needed to support packing verification, recording storage, secure video access, fulfillment status tracking, merchant settings, and security auditing.
- Merchant and store information: Shopify shop domain, app installation/session data, Shopify access tokens, staff user identifiers, staff names and email addresses when provided by Shopify authentication, app enabled status, audio recording settings, and Google Drive connection settings.
- Order and fulfillment information: Shopify order IDs, order names/numbers, order creation or update timestamps, fulfillment status, fulfillment order IDs and statuses, PackDash fulfillment tracking status, and fulfillment event metadata.
- Customer information: customer first and last name when used for fulfillment display, and customer email address when needed to issue and verify secure packing video access. PackDash does not access customer postal addresses, phone numbers, payment card data, or order totals in the audited implementation.
- Product information: first line item title and image for fulfillment display, product IDs from the order for recommendations, and public storefront product details such as product title, handle, image, price, options, variants, and availability for the recommendation cards shown near the customer video page.
- Recording and video access information: packing video files, recording duration, upload status, Google Drive file IDs and file metadata, generated tokenized access URLs, secure video token records and hashes where applicable, token previews, one-time passcode hashes and timing data, customer verification status, and video access audit events.
- Automatically collected technical data: IP address, user agent, request timing, access result, failure reason, browser extension identifiers used to target the active merchant browser session, and operational diagnostic logs.
2. How We Use Information
PackDash uses information to:
- show merchants recent Shopify orders and recording status;
- detect authorized fulfillment progress events;
- open the packing recording workflow for the correct order;
- record and upload packing verification videos;
- store recordings in the merchant-connected Google Drive account;
- create secure customer video access links and one-time codes;
- let authenticated merchants view or delete recordings;
- write PackDash-owned Shopify order metafields;
- provide video access analytics to the merchant;
- perform security checks, rate limiting, audit logging, and deletion workflows.
PackDash does not use the audited data flows for advertising, sale of personal data, unrelated profiling, or unrelated marketing.
3. Shopify Data
PackDash authenticates with Shopify OAuth and requests the scopes configured for the app: write products, write metaobjects, write metaobject definitions, read orders, write orders, read fulfillments, write fulfillments, read customers, and write merchant-managed fulfillment orders.
Some configured scopes support Shopify app configuration or template definitions. In the audited workflow, PackDash does not actively write product or metaobject records as part of packing verification.
In the current implementation, PackDash reads order IDs, order numbers, order timestamps, fulfillment status, fulfillment orders, customer names and emails, first line item title and image, order currency, order product IDs, and the shop primary domain where those fields are needed for the app workflow.
PackDash writes PackDash-owned Shopify order metafields for fulfillment tracking status, the secure recording video URL, and the PackDash packing video ID. When recordings or retained data are deleted, PackDash attempts to clear those app-owned order metafields.
4. Chrome Extension
The PackDash Fulfillment Detector Chrome Extension runs on Shopify Admin pages at admin.shopify.com and is used to connect Shopify fulfillment activity with the PackDash packing verification workflow. The production extension is configured to communicate with the PackDash production backend at https://packdash-production-21a3.up.railway.app, or another merchant-configured PackDash HTTPS app URL.
The extension detects relevant Shopify Admin order and fulfillment activity, including order-page fulfillment actions and visible fulfillment status transitions to in progress. To do this, it may inspect Shopify Admin page URLs, rendered order-page status text, and Shopify Admin fulfillment-related fetch or XMLHttpRequest activity. The information used for PackDash includes the Shopify shop/domain context, order ID, order number where available, fulfillment order or fulfillment ID, fulfillment/tracking status, Shopify status, workflow source, detected time, page/workflow context, and actor details when supplied by the PackDash server.
The extension stores configuration and state in the browser, including the PackDash app URL, last known shop, extension instance ID, target token, and the latest fulfillment event for the active recording session. These values let PackDash target the correct active browser session and open the correct recording workflow.
The extension communicates with PackDash backend endpoints to maintain a targeted server-sent events connection, correlate a Shopify Admin fulfillment action with the correct order and fulfillment order, request the recording workflow after an eligible in-progress transition, check whether a recording already exists, and delete an existing recording when the server provides a valid delete token. PackDash uses extension routing identifiers, recording intent records, upload intent IDs, upload tokens, and short-lived signed delete tokens for these workflows.
When recording is triggered, the extension opens the PackDash HTTPS recording page for the relevant order. That page captures camera video, and microphone audio only according to the merchant's audio recording setting, through the browser's media permission flow. The resulting WebM recording, recording duration, Shopify shop, order identifiers, fulfillment identifier when available, extension instance ID, upload intent ID, and upload token are transmitted to the PackDash backend. PackDash then stores recording metadata and uploads the recording file to the merchant-connected Google Drive account as described in the Recordings and Media, Data Storage, and Google Drive sections.
PackDash uses extension data only to provide and operate the PackDash fulfillment, packing verification, recording, upload, duplicate-recording protection, deletion, audit, and security workflows. Extension-related recording intents and trigger audit records are retained and deleted according to the retention practices described below.
5. Recordings and Media
PackDash records video from the merchant browser's camera on the standalone recording page. Audio is recorded only when the merchant's PackDash audio recording setting is enabled. The current default for a shop with no saved setting is audio enabled.
The recording page is opened from an authorized fulfillment workflow or the merchant's PackDash record button with a short-lived upload authorization tied to the shop, order, and active extension session. The page may auto-start after browser permission is granted, and the merchant can stop the recording manually. The resulting WebM file is uploaded to PackDash and then to the connected Google Drive account.
Packing videos may show products, package contents, shipping labels, screens, papers, people, voices, or other information visible or audible to the recording device. Merchants should avoid capturing information that is not needed for packing verification.
6. Data Storage
PackDash stores application metadata in PostgreSQL through Prisma. Stored records include Shopify sessions, fulfillment records, Drive settings, upload records, packing video metadata, video access tokens, merchant bypass tokens, video access events, recording intents, extension trigger audits, processed fulfillment event IDs, and merchant app settings.
The actual packing video file is uploaded to the merchant-connected Google Drive account. PackDash stores Drive file IDs and related metadata so it can stream, delete, and manage the recording. PackDash also stores generated tokenized PackDash access URLs in upload records and Shopify order metafields so the current customer and merchant video-link workflow continues to work.
7. Google Drive
Google Drive integration is optional, but the current upload workflow requires a connected Google Drive account before a recording can be saved successfully. Merchants connect Google Drive through Google's OAuth flow using the Drive file permission scope.
PackDash stores Google OAuth access tokens, refresh tokens, token expiry, the connected Drive email address, and optional folder ID or folder URL settings. Recordings are uploaded to the selected folder when configured, otherwise to the connected account's Drive root.
After upload, PackDash creates secure PackDash video access records and stores the PackDash tokenized video access URL. New uploads are not intentionally made public in Google Drive; PackDash streams playback through its own OTP-protected or merchant-authenticated endpoint using the merchant's connected Drive authorization. PackDash also includes a maintenance action that can remove public Drive permissions from older uploaded files.
Disconnecting Google Drive removes PackDash's stored Drive access credentials but does not itself delete historical Drive files or revoke permissions on files that already exist. Existing recordings should be deleted through PackDash recording deletion or retention workflows while Drive access is connected.
8. Data Retention
PackDash's default customer/order-related retention period is 90 days. This is controlled by the DATA_RETENTION_DAYS environment variable and is constrained in code to values from 30 to 365 days.
Expired or consumed temporary records, including recording intents, merchant bypass tokens, and expired online sessions, are deleted after the temporary retention period. The default is 7 days, controlled by TEMPORARY_RECORD_RETENTION_DAYS and constrained in code to values from 1 to 30 days.
Secure video access tokens currently expire after 30 days by default through VIDEO_ACCESS_TOKEN_TTL_DAYS. Expired token rows are deleted by the retention cleanup job. Video session cookies used for playback last 15 minutes, and merchant bypass tokens expire after 45 seconds.
The retention cleanup can run from a command-line script, a secured HTTP endpoint protected by RETENTION_JOB_SECRET, or the in-process daily scheduler when enabled in production or explicitly enabled by RETENTION_SCHEDULER_ENABLED. The cleanup job is batched and uses a PostgreSQL advisory lock to avoid overlapping deletion runs.
When deleting old video data, PackDash attempts to delete Google Drive files before deleting the corresponding database metadata. If Drive deletion fails, PackDash retains the database metadata for a later retry and revokes affected video access where applicable.
9. Data Deletion and Privacy Requests
Merchants can delete a recording from PackDash. The shared delete logic deletes the matching Google Drive file, attempts to remove the PackDash recording video URL and packing video ID metafields from the Shopify order, and deletes the related PackDash video and upload records. Historical video access audit rows may remain until the retention cleanup removes them, unless a customer or shop redaction flow removes them earlier.
PackDash handles Shopify compliance webhooks using Shopify webhook authentication:
- customers/data_request: PackDash identifies matching stored PackDash records by customer email and requested order IDs and logs a count summary for operator review and manual follow-up.
- customers/redact: PackDash deletes matching customer/order protected data that can be identified from Shopify-provided order IDs, stored customer emails, and related PackDash video/order metadata. It also attempts to delete related Drive videos and PackDash-owned Shopify metafields.
- shop/redact: PackDash purges shop-level protected data, sessions, settings, order/video/audit records, and Drive videos where possible.
- app/uninstalled: PackDash immediately starts the same shop protected data purge when the app is uninstalled.
If Google Drive deletion cannot complete because Drive access fails, PackDash may retain the minimum metadata needed to retry deletion while preventing continued access to the affected video.
10. Security
PackDash uses Shopify's app authentication and webhook authentication framework for embedded admin access and Shopify webhook requests. Production app URLs configured in the app use HTTPS.
Secure video links use random tokens. PackDash stores token hashes for token records where applicable, stores generated tokenized access URLs where needed for the current video-link workflow, uses hashed one-time passcodes, limits repeated failed token and stream attempts, and verifies order email before issuing video playback access to customers. PackDash does not intentionally log raw video access tokens, tokenized video URLs, Google refresh tokens, OAuth secrets, or OTP values.
Video playback requires either customer OTP verification or an authenticated merchant bypass flow. Playback sessions are signed, bound to the user agent, sent through an HttpOnly Secure SameSite=Lax cookie or a temporary session query value, and expire after 15 minutes. Extension delete tokens are HMAC-signed, expire after 5 minutes, and bind the shop and order ID into the signature.
PackDash stores service credentials in environment variables. The database connection logger avoids printing database passwords. The codebase does not include a separate certification claim, third-party error tracking provider, or application-level encryption-at-rest implementation beyond the security controls provided by the hosting, database, Shopify, Google, and email providers.
11. Third-Party Services
PackDash uses these service providers in the audited implementation:
- Shopify: app installation, authentication, Admin API access, fulfillment/order workflows, webhooks, and order metafields.
- PostgreSQL database provider: application metadata storage through Prisma. The exact database host and region are configured through DATABASE_URL.
- Railway or configured application hosting provider:production hosting for the PackDash web application as reflected in the app configuration. Hosting logs may contain operational information such as shop domains, order IDs, request details, and error messages.
- Google APIs and Google Drive: OAuth connection, Drive account email lookup, recording uploads, file metadata, file streaming, permission management, and file deletion.
- Resend: delivery of one-time passcode emails for customer packing video access. PackDash sends the recipient email address, OTP content, order number where available, sender address, and email body to Resend for this purpose.
- Merchant storefront JSON endpoints: product recommendation and best-selling product lookups for the customer's video page. These requests use product IDs and public storefront product data, not customer identity.
13. Merchant Responsibilities
Merchants are responsible for using PackDash in a way that is lawful for their store, employees, customers, and fulfillment locations. Merchants should provide appropriate notices to staff and customers if packing videos may capture people, voices, labels, customer details, or other personal information.
Merchants control whether PackDash is enabled, whether audio recording is enabled, which Google account is connected, which Drive folder is used, and when recordings are manually deleted.
14. Your Rights and Requests
Privacy rights vary by location. Depending on applicable law, a merchant, customer, or authorized representative may request access, deletion, correction, or restriction of personal information processed by PackDash.
Shopify customer privacy requests should be submitted through the relevant Shopify merchant or Shopify privacy flow where applicable, so the request can reach PackDash through Shopify's compliance webhooks. Direct PackDash privacy requests can be sent to trustdashapp@gmail.com.
15. Changes to This Policy
PackDash may update this Privacy Policy as the app, legal requirements, or service providers change. The Effective Date above indicates when this version became effective.
16. Contact Us
Email: trustdashapp@gmail.com
App: PackDash
Company: Kineteck