Privacy Policy
Last updated: 25 July 2026
This policy explains what personal data Packdroid collects when you use our dieline software, why we collect it, who we share it with, and what control you have over it. It describes what the software actually does — not a generic template.
1. Who we are
Packdroid provides browser-based software for generating packaging dielines. We are the data controller for the personal data described in this policy.
You can reach us about anything in this document at [email protected].
[PLACEHOLDER — add your registered company name, trade registry number, and registered address before publishing.]
2. Data we collect
We collect only what the service needs to work. Specifically:
- Account details — your email address, an optional display name, and your password. Your password is never stored: we keep only an Argon2id hash of it, which cannot be reversed back into your password.
- Google sign-in (only if you choose it) — your Google account identifier, your email address, and your name, as supplied by Google. We request only the openid, email, and profile scopes. We never receive your Google password and have no access to your Gmail, Drive, Calendar, or contacts.
- Session data — a hashed session token, its expiry, your IP address, and your browser's user-agent string. The IP and user-agent let you see where your account is signed in and let you sign out a device you no longer recognise.
- Usage records — for each dieline you generate we record the template used, the dimensions and parameters you entered, and whether the render succeeded. This is what lets us reproduce and fix a problem you report.
- Problem reports — if you flag a template as producing wrong output, we store your description, the template, and the parameters that produced it.
3. Data we do not collect
- We do not store your password in a readable form, and nobody at Packdroid can see it.
- We do not collect payment card details. Packdroid does not currently process payments.
- We do not sell your personal data, and we do not share it for advertising.
- We do not claim ownership of the dielines you design. See our Terms of Service.
4. Why we use it
- To create and secure your account, and to keep you signed in.
- To send account emails: confirming your address, and resetting your password. These are transactional messages, not marketing.
- To generate, render, and deliver the dieline files you ask for.
- To investigate and fix incorrect template output that you or another customer reports.
- To protect the service against abuse — rate limiting sign-in attempts, for example, so nobody can guess their way into your account.
5. Cookies
We use as few cookies as we can. Two are strictly necessary and cannot be turned off without breaking sign-in:
- __packdroid_session — keeps you signed in. It is HttpOnly, meaning page scripts cannot read it, and signed so it cannot be forged. It expires after 30 days.
- __packdroid_oauth — exists only during a Google sign-in, for about ten minutes, and protects that sign-in against cross-site request forgery.
- Google Analytics (_ga and related) — measures which parts of the catalogue and workshop people use, so we know what to improve. This is analytics, not advertising. If you block it, Packdroid works normally.
6. Who we share it with
We use two external processors, and only for the purposes below.
- Resend — delivers our account emails (address confirmation and password reset). Resend receives your email address and the contents of those messages. Our sending region is the EU (Ireland).
- Google — if, and only if, you choose to sign in with Google. Google tells us your account identifier, email, and name. Separately, Google Analytics receives usage measurements as described above.
- We may also disclose data where the law requires it, or to protect the rights and safety of our users.
7. How long we keep it
- Account data — for as long as your account exists.
- Sessions — 30 days, then they expire and are deleted automatically.
- Email confirmation links — 24 hours. Password reset links — 1 hour. Both are single-use and only the hash is stored, so a copy of our database would not let anyone reset your password.
- Usage records and problem reports — kept while they remain useful for fixing the templates they describe.
8. How we protect it
- Passwords are hashed with Argon2id, the algorithm currently recommended by OWASP for password storage.
- Session tokens and email links are stored only as SHA-256 hashes. Even a full database disclosure would not yield a working session or a usable reset link.
- All traffic between your browser and Packdroid is encrypted with TLS.
- Changing your password immediately signs out every other device, so a reset actually ends an intruder's access.
9. Your rights
Under the GDPR and, in Türkiye, under KVKK (Law No. 6698), you have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive a copy in a portable format.
To exercise any of these, email [email protected]. We will respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority — in Türkiye, the KVKK Authority (KVKK Kurumu).
10. International transfers
Our email provider processes messages in the European Union. Google may process sign-in and analytics data outside your country under its own safeguards. Where data leaves the EEA or Türkiye, it does so under the legal transfer mechanisms those regimes require.
11. Children
Packdroid is a professional tool for packaging design and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes to this policy
If we change how we handle your data we will update this page and change the date at the top. For significant changes we will tell you by email.