Privacy Notice
Document
PACK & KIN STUDIO — PRIVACY NOTICE
Version: 1.0 · Status: Approved · Approved: 2026-09-07 · Approved by: Dax Barron, Mail and More LLC
Approved by the operator for publication. A published version is immutable; a correction is issued as a new version rather than an edit.
1. Who this notice is for
This notice explains how Mail and More LLC, an Arizona limited liability company ("Pack & Kin," "we," "us") handles personal information about the people who hold accounts with us — a store's owner and staff, a dealer or sales representative, and a third-party developer.
It is not the notice a store's walk-in customer needs. If you bought something at, or rent a mailbox from, a store that runs on Pack & Kin Studio, your relationship is with that store, not with us. The store decides what it collects and why; we hold it on the store's behalf and act on the store's instructions. See Section 3 and Section 10.
Who we are. Pack & Kin and Pack & Kin Networks are trademarks of Mail and More LLC, an Arizona limited liability company, which trades under them and provides the Services as Pack & Kin Studio. Mail and More LLC is the entity responsible for the personal information described in this notice, and is who you contact under Section 18.
Scope of law. Pack & Kin operates in the United States only. This notice is written to the California Consumer Privacy Act as amended by the CPRA and the comparable laws of other U.S. states. We do not offer the Services to people in the European Economic Area, the United Kingdom or Switzerland, and nothing here should be read as a GDPR representation.
2. Our two roles, stated plainly
The single most important thing in this notice is which hat we are wearing, because it determines who you ask for what.
| Whose data | Our role | Governed by |
|---|---|---|
| You, as an account holder — a store owner, a member of store staff, a dealer, a developer | We are a business in our own right. We decide why and how it is used. | This notice |
| A store's own customers — the people who ship, rent boxes and buy at the counter | We are the store's service provider. The store decides; we process on its instructions. | The store's own privacy notice, plus Schedule E of the Platform Terms of Service |
A practical consequence. If you are a store's customer and you want your data, ask the store. We will not answer a request about a store's customer directly — we will refer you to the store, because the store is the one who can verify who you are. See Section 10.
3. What we deliberately do not collect
Stated first, because two common assumptions about a platform like this are wrong.
- We do not store card numbers, security codes, or magnetic-stripe data. Card details are tokenized by the payment processor. We hold a token, the card brand, and the last four digits — never a full card number, never a CVV, never track data.
- We do not store employee Social Security numbers or bank account details for payroll. Those are entered directly into the payroll provider's own onboarding and stay in that provider's environment. What we hold is an encrypted credential and aggregate labor cost.
- We do not store unmasked identification numbers from USPS Form 1583. We keep the type of identification presented and a masked number. The scanned form itself is a separate matter, and Section 5 covers it.
4. Information we collect about account holders
Identifiers and contact information — name, business name, email address, postal address, telephone number, and the account identifiers we issue.
Account and authentication data — your login credentials (passwords are stored hashed, never in readable form), multi-factor authentication settings, session and device information, and the roles and permissions assigned to you.
Commercial and billing information — your plan, the add-on packs you have activated, invoices, payment method tokens, wallet funding and balance history, and your transaction history with us.
Business and financial identity information for card processing. If you apply to be boarded for card processing, we collect what the processor's underwriting requires — which includes the owner's Social Security number and date of birth, the business tax identification number, and bank account and routing numbers. This is encrypted at rest, is masked wherever it is displayed, and is never returned in full to a browser. It is held in a form we can decrypt because it has to be transmitted to the processor.
Usage and technical data — pages and features used, API calls, IP address, browser and device information, and diagnostic logs. Our application logs are redacted on the way out: email addresses, telephone numbers and card-shaped digit sequences are masked by the logging layer, including inside error traces.
Communications — support requests, and correspondence with us.
Dealer and developer information — for dealers, the commission and performance data associated with your book of business; for developers, your integration's credentials and call history.
5. Information we process on behalf of a store
We hold this as the store's service provider, on the store's instructions, and this notice is not the notice that governs it. Described here so you know what is on the platform:
- Customer records — names, email addresses, telephone numbers and postal addresses.
- Shipment data — sender and recipient names and addresses, contents descriptions, declared values, customs declarations, and tracking history.
- Mailbox records — box holder identity, PS Form 1583 metadata, forwarding addresses, and mail and package activity.
- Documents — scanned Form 1583 filings, mail scans (including, where a store offers it, scans of opened contents), package arrival photographs, proof-of-delivery signatures, shipping labels, customs forms, receipts, and any document a store's staff uploads to a customer record.
- Point-of-sale history — sales, refunds, loyalty activity.
Sensitivity. Form 1583 scans and mail-content scans are the most sensitive material on the platform. They are held in private storage with no public route, reachable only through a signed, tenant-scoped path, and access is logged.
6. Where the information comes from
Directly from you; from your employer or the store that invited you; from a dealer who referred you; from your own use of the Services; from third parties you connect to your account (a carrier, a marketplace, an accounting system, a processor); and from service providers who return results to us, such as address verification and payment underwriting.
7. Why we use it
- To provide, operate, secure and support the Services.
- To authenticate you and enforce permissions.
- To bill you, collect payment, and manage your wallet.
- To buy transportation, place insurance, and process payments at your direction, which requires transmitting data to the relevant third party.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To communicate with you about your account, changes to the Services, and changes to our terms.
- To meet legal, tax, accounting and regulatory obligations, and to respond to lawful requests.
- To develop and improve the Services, subject to Section 8.
- To send you marketing about our own services, which you can opt out of at any time.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as "sell" and "share" are defined in the CCPA. We do not use or disclose sensitive personal information for any purpose that would require us to offer a right to limit.
8. Machine learning and artificial intelligence
The product uses machine learning for address parsing and correction, document and address scanning, commodity and HS-code classification, and fraud detection.
We do not train models on data that identifies you or a store's customers. We do not use personal information in a form that identifies, or is reasonably capable of being linked to, an identifiable person or a business to train, fine-tune or improve any model, and our AI and OCR providers are contractually prohibited from doing so.
We do train on de-identified and aggregated data. Data qualifies only where it cannot reasonably be used to infer information about, or be linked to, an identifiable individual, household or business — including by combination with other data we hold. Removing a name or an account number is not, by itself, enough: direct identifiers, free text written by or about a person, and precise recipient addresses are not treated as de-identified. We maintain technical safeguards against re-identification, commit publicly to keeping the data in that form, and impose the same obligation on anyone who receives it.
Automated output is not a decision about you. Classifications and estimates the product produces are aids for a person to review. We do not use automated processing to make decisions that produce legal or similarly significant effects about you.
Section 8.3 of the Platform Terms of Service is the contractual statement of the same commitments.
9. Who we share it with
We disclose personal information to the following categories of recipient, for the business purposes in Section 7. The categories below are the disclosure; we will provide our current list of named service providers on request, to an account holder or to a store asking on behalf of its customers. Write to us at the address in Section 18.
| Category | Why |
|---|---|
| Carriers and postal providers | To rate, buy, track, and resolve claims on shipments. Recipient names and addresses are necessarily disclosed. |
| Payment processors and acquirers | To take your subscription payment, fund your wallet, and board and operate your merchant account. |
| Insurance providers and program administrators | To quote, bind and administer parcel coverage and claims. |
| Cloud hosting and object storage | To run the platform and hold documents and images. |
| Email and messaging providers | To deliver transactional and marketing messages. |
| AI and OCR providers | To classify commodities and read scanned documents, subject to Section 8. |
| Accounting, marketplace and other systems you connect | Only at your direction, and only what the integration requires. |
| Professional advisors, auditors and insurers | Where necessary and under confidentiality obligations. |
| Authorities and third parties in legal process | Where the law requires or permits, and to establish, exercise or defend legal claims. |
| A successor | In a merger, acquisition, financing or sale of assets, subject to this notice continuing to apply. |
Every service provider is bound by written contract to obligations at least as protective as the ones we owe, to use the information only for the purpose we engaged them for, and not to sell or share it.
Where data is held. In the United States. We do not transfer personal information outside the United States for storage.
10. If you are a store's customer
Ask the store. The store holds the relationship, and it is the store — not us — that can verify who you are.
How the store verifies you. A store answers a request in person, at the counter, against government photo identification — the same check its staff already perform for a USPS Form 1583. An email address is a claim, not an identity, and there is deliberately no self-serve route by which someone can submit an email address and receive that address's file. A request the store cannot verify is refused, not answered cautiously.
What the store can produce. Everything it holds about you in its own records, gathered systematically. The response deadline is 30 days by default, and a store may shorten it.
What is outside that procedure. The automated procedure covers a store's customers, including mailbox renters who have a customer record. It does not cover a store's own staff — those are employment records held by the employer under a different basis — and it does not cover dealers or sales representatives, whose records are held by us rather than by a store. Requests of those kinds are handled individually.
The bundle says what it covers. Every export a store produces carries, inside the file itself, a statement of what it does and does not include, and the retention boundary that applies to it — so you can see the edges without reading this notice.
11. The network archive — a carve-out, named
This is the most important limit in this notice, and it is stated here rather than left to be discovered.
We maintain a permanent, network-level archive of certain operational records — including package and mail-piece history, arrival photographs and proof-of-delivery signatures. It exists so that a store can answer a non-delivery dispute, defend a claim, and meet mail-receiving record obligations. A proof-of-delivery signature is evidence, and its value depends on it not being editable afterwards.
A store's erasure process does not reach this archive. When a store erases or anonymizes a customer record, the archived operational history remains.
We retain the archive on our own basis — evidence of a completed service, defence of disputes and claims, and mail-receiving record obligations — and we use it only to answer a dispute, to respond to a lawful request, or as this notice otherwise permits. There is no self-serve route into it; retrieval is an operator action.
If you want to know whether the archive holds records relating to you, contact us at privacy@packandkin.net.
12. How long we keep it
We state the criteria we use rather than a table of periods, and that is deliberate. A period written into this notice would drift from the one the software actually enforces the first time either changed, and a published promise we do not keep is worse than no number at all.
The criteria. How long we hold a given category of personal information is determined by:
- (a) How long we need it to provide the Services — an account's data is held while the account is open, and a record is held while it is still being used to serve you.
- (b) Whether a law, tax rule, or postal or carrier requirement sets a minimum. Where one does, that minimum governs, and it can be longer than we would otherwise keep the data.
- (c) Whether the record is evidence. Records of a transaction, of an agreement and of what a party was shown when they agreed to it, and records of a completed delivery, are retained while a dispute or claim could still arise from them.
- (d) Whether the record is append-only or archival by design. Some records — the audit trail, the operational ledgers, and the network archive described in Section 11 — are not edited or deleted in ordinary operation, because a record that can be altered afterwards cannot be relied on in the dispute it exists to answer.
Categories we retain indefinitely, applying those criteria: sales and transaction history; the operational ledgers; the audit trail; records of your acceptance of our terms; and the network archive in Section 11.
Categories on an automatic schedule. Some records are purged on a fixed schedule rather than held under the criteria above — among them stored copies of API responses, and mailbox and package history where a store has enabled pruning. Those schedules are enforced by the software rather than by anyone remembering.
On request, we will tell you the retention period that currently applies to a category of personal information we hold about you. Write to us at the address in Section 18.
Account data after termination is governed by Section 7.7 of the Platform Terms of Service: a 30-day export window, after which access ends. We do not commit to deleting data on a particular date.
13. Your rights
Depending on the state you live in, you may have the right to:
- Know and access the categories and specific pieces of personal information we hold about you, where we got it, why we use it, and who we disclose it to.
- Delete personal information we hold about you, subject to the exceptions the law allows.
- Correct inaccurate personal information.
- Opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of — but you may still make the request.
- Limit the use of sensitive personal information. We do not use it for purposes that trigger this right.
- Not be discriminated against for exercising any of these rights. We will not deny you the Services, charge you a different price, or give you a lower quality of service for making a request.
- Appeal a refusal, in states that provide for one. Our refusal will tell you how.
How to exercise them. Email privacy@packandkin.net. We will verify your identity in a manner proportionate to the sensitivity of what you are asking for, and we may ask for information to do so. An authorized agent may act for you with proof of authorization, and we may still ask you to verify your own identity.
Timing. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, and we will tell you if we extend.
Limits. We may decline where the law permits — for example where the information is subject to a legal retention obligation, is needed to complete a transaction or defend a claim, or is in the archive described in Section 11. We will tell you which exception we are relying on.
14. Security
We maintain administrative, technical and physical safeguards designed to protect personal information, including: encryption in transit; encryption at rest for credentials, merchant-boarding identity material and other sensitive fields; tenant isolation enforced at the database itself, so one store's queries cannot reach another store's rows; role-based access control; multi-factor authentication; audit logging of access; and redaction of personal information from application logs.
Documents and images are held in private storage with no public route and are reachable only through a signed, tenant-scoped path.
No system is perfectly secure, and we do not warrant that the Services will be free from unauthorized access. If a security incident affects your personal information, we will notify you without undue delay after confirming it, and as applicable law requires.
15. Cookies and similar technologies
We use a small number of first-party cookies, and we do not use them for advertising.
| Purpose | What it does |
|---|---|
| Session | Keeps you signed in. Expires after a period of inactivity — 8 hours by default. |
| Security | Cross-site request forgery protection. Cookies are set SameSite=Lax. |
| Preferences | Remembers choices such as the store you are working in and interface settings. |
We do not deploy third-party advertising or cross-site tracking technologies in the Services, and this is enforced rather than merely promised: the Services send a Content-Security-Policy that permits scripts and network connections only from our own origin and from our payment provider's hosted card entry. An advertising or analytics tag could not load in the portal even if someone added one.
We do not respond differently to a Global Privacy Control signal, because there is no sale or sharing to opt out of. A website a store publishes through us is the store's own — its cookies and its disclosures are the store's responsibility, not ours, and the policy above does not apply to it.
16. Children
The Services are business software, are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, contact privacy@packandkin.net and we will delete it.
17. Changes to this notice
We may update this notice. A material change is notified under Section 2.3 of the Platform Terms of Service, and every version stays permanently readable at its own address, so you can see what applied at any point in time.
18. Contact
Mail and More LLC An Arizona limited liability company Privacy: privacy@packandkin.net Security: security@packandkin.net