What PickPack reads
When you open the app, filter orders, print or fulfil, PickPack reads your orders from your store's order service using the permission you granted at install. That includes order numbers, dates, payment and fulfillment status, line items, product names, SKUs, quantities, product photo links, checkout fields the buyer filled in, buyer notes, and the shipping name, company, phone and address needed to print a packing slip.What PickPack stores
Only five things: your app installation record (installation identifier, site identifier, plan state, an authentication token, and whether you have been asked for a review and your answer), your print preferences (photo size, page size, whether checkout fields and notes are printed, default carrier and the logo you upload), a record of each run (what kind, when, the filter you used, the order identifiers and how many orders), the per-order result of each fulfillment run (order identifier, order number, success or failure, the error code and the tracking number you entered), and a record of each installation, uninstallation and plan change (installation identifier, site identifier, event kind, plan and time), which is our billing and support record and is kept after the rest has been deleted.What PickPack deliberately does not store
Buyer names, email addresses, phone numbers, shipping addresses, checkout field values, buyer notes, product names and the rendered PDFs are never written to our database. They are read for one request, placed on the document you asked for, and dropped. Printing the same run again re-reads your orders, so a corrected address appears on the reprint.How the data is used and shared
Order data is used only to draw your documents and to fulfil the orders you selected. It is not sold, not used for advertising and not used to build buyer profiles. PickPack sends nothing to any third-party service beyond your store's own API: there is no carrier account, no external order system and no analytics vendor in this app.The service is hosted on Fly.io and its database is provided through Supabase. Those vendors process data only to host and operate PickPack.Retention and deletion
Preferences and run history exist while the app is installed. When the app-removal event is delivered, PickPack immediately deletes your preferences, your uploaded logo and your entire run history, and clears its authentication token. A minimal removal record remains so the installation cannot be treated as live again. To request access, correction or deletion at any other time, email shin@sognoragroup.com. We verify that the requester is authorised for the site before acting.Security and international processing
Every inbound request from the platform is verified cryptographically: dashboard sessions with an HMAC-SHA256 signature, webhooks with an RS256 signature. Data is encrypted in transit and isolated to this app's own database schema, which no other app on the same server can read. Sognora operates from South Korea; the hosting infrastructure may process data in other countries, including the United States.Changes and contact
Material changes appear on this page with a new effective date. Privacy, security and deletion questions go to shin@sognoragroup.com.