Privacy Policy
This policy explains how Po-Ko Pack processes merchant, worker, order, and packing-proof data.
Last updated: August 12, 2026
1. Who operates Po-Ko Pack
Po-Ko Pack is operated by S.I.T. Technology Co., Ltd. / 喜德科技有限公司, 9F, 3-2, YuanQu Street, Nankang District, Taipei 11503, Taiwan, R.O.C. Privacy questions can be sent to hello@poko-go.com.
2. Data we process
Through Shopify, the app uses the shop domain, order ID and reference, line-item ID, item title, SKU and quantity, fulfillment tracking number, and app-owned order tags and metafields. The app does not request Shopify API access to customer names, addresses, email addresses, or phone numbers.
Merchants can add worker names and optional work email addresses. Packing proofs contain timestamps, activity records, quantities, tracking-match status, receiver notes, and two merchant-captured photos. A photo might incidentally show personal information printed on a package or shipping label. Po-Ko Pack does not extract that information for advertising or profiling. Standard security logs can include request time, IP address, browser or device information, and error details.
3. Why we process it
We process this data only to create, authenticate, display, and retain packing evidence; match a parcel to its Shopify order; operate worker access; prevent abuse; provide support; and meet legal, security, and privacy obligations. We do not sell personal data or use it for targeted advertising or automated decisions.
4. Sharing and international processing
Data is shared only with service providers needed to run the product, including Shopify and DigitalOcean hosting and object storage. Those providers may process data in countries different from the merchant or recipient, including the United States. We use contractual and technical safeguards appropriate to the service and restrict provider use to operating Po-Ko Pack.
5. Security and retention
Network traffic uses TLS. Proof photos and database backups are encrypted before off-site storage. Each merchant selects a proof retention period of 30, 90, 180, or 365 days; the default is 180 days. Encrypted database backups expire after 30 days. Access credentials are restricted, worker codes are stored as keyed hashes, and private worker QR capabilities expire.
6. Privacy requests and deletion
Shopify sends required customer access and deletion requests to Po-Ko Pack. We provide the relevant proof data to the merchant and delete matching proofs and photo objects when required. Shopify sends a shop-deletion request after uninstall, and the app then deletes that shop's sessions, workers, proofs, and photo objects. To ask about access, correction, deletion, restriction, or a data copy, contact the merchant that supplied the proof or email hello@poko-go.com.