Legal and privacy
Cookie and analytics notice
This is the complete list. Every row below is generated from the code that runs this site, so if the site starts storing something new, this page changes with it · it cannot be quietly left behind.
What is switched on right now
Optional analytics is enabledon this deployment · the first-party measurement described below and the hosting provider's aggregate reach and performance measurement (Vercel Web Analytics and Speed Insights). Both still only run for visitors who have affirmatively allowed the analytics category · if you have not, or you refused, nothing described in the Analytics rows below is collected about your visit.
Google Analytics is installed on this deployment. Unlike everything else on this page, the Google tag file is requested by every visitor on every page, whether or not you have chosen · with Google’s permissions set to “denied” before the request is made, so it stores nothing in your browser and cannot identify you unless you allow the Analytics category. The section “Google Analytics (the Google tag)” below sets out exactly what that means and what Google receives either way.
Three independent switches all have to be on before a single event can be stored: the consent platform must be built in, a server-side ingestion switch must be on, and a storage location plus a secret key must be configured. Any one of them turns collection off immediately.
Everything that can be stored
“Strictly necessary” items are needed for the site to work and to honour your choices; they are not used for measurement. Everything marked Analytics or Marketing and visitor identification is optional and off until you say otherwise · and the two are separate choices: allowing analytics never enables visitor identification. Media on this site · including the home-page background video · is served from Pckup’s own origin, so displaying it involves no third-party host and needs no consent category.
| What | Category | Exactly what is stored | Why | Kept for |
|---|---|---|---|---|
| Your privacy choice | Strictly necessary | A first-party cookie named pk_consent holding the policy version (currently v8), the time you chose, and one on/off value per optional category. Nothing else. | So the site knows what you allowed, can stop when you withdraw, and can re-ask when the disclosure changes. | 182 days, or immediately when you change it, or sooner if the disclosure materially changes |
| Consent receipt | Strictly necessary | The policy version, the categories you allowed or refused, the timestamp, whether your browser sent Global Privacy Control, and a random receipt id your browser generates. No IP address, no device details, no account link. | Accountability: the record that a choice of this shape was made at this time. Refusals are recorded too · that record is the proof optional processing stayed off. | 400 days |
| Theme preference | Strictly necessary | Your light/dark appearance choice, in this browser only. | To render the site the way you asked for it. | Until you clear your browser storage |
| Administrator return preference | Strictly necessary | For a browser that successfully used the protected Utility Dashboard, one yes/no reminder marker, the shortcut's normalized on-screen position, and whether it is minimized to its compact bubble. No account identity, role, IP address, token, or browsing history. | To offer that browser a convenient sign-in reminder on public pages, keep the movable shortcut where it was placed, and restore its chosen display state. The marker never grants administrator access. | Until this browser's site data is cleared; the position and the minimized preference persist the same way so the shortcut stays where you put it |
| Random browser and session ids | Analytics | Two random values this browser generates for itself · one per browser, one per visit. They are not derived from you, your device, or your network, and they mean nothing outside this site. | To count sessions and returning browsers without identifying anyone. Deleted from your browser the moment you withdraw consent. | 30 days on the server; removed from your browser immediately on withdrawal |
| Pages viewed and the order you viewed them in | Analytics | The path only, with any query string and fragment stripped and long numeric or id-shaped segments replaced · for example /track/_ rather than /track/12345. Never the full URL. | To see which pages are used and how visitors move between them. | 30 days for the session record, 366 days for the daily counts |
| Entry page, exit page, and referring site | Analytics | The first and last page of the visit, and the host name of the site you arrived from (for example news.ycombinator.com) · never the full referring URL. | To understand how people reach Pckup and where they leave. | 30 days / 366 days |
| Timestamps and engaged time | Analytics | Event times, and seconds during which the page was both visible and focused (event types: page-view, heartbeat, click, page-dwell). | To distinguish a page someone read from a tab left open in the background. | 30 days / 366 days |
| Controls you activate, and time actively reading a page | Analytics | When you activate a control · a button, link, tab, menu, or toggle · what is stored is the control's KIND and its visible label (for example the button named Get an estimate), bounded to 64 characters, with anything address-shaped refused outright. A form field records only that a field with that label was activated · NEVER what you typed, and never any value. Beside that, the seconds a page was actively read (visible and focused time only · a background tab counts nothing), floored at one second. No coordinates, no keystrokes, no scroll positions, no page text beyond the one label. | To learn which controls visitors actually use and how long pages genuinely hold attention, not just which pages were opened. | 30 days |
| Coarse device category | Analytics | One of "desktop", "mobile", "tablet", or "bot". The full user-agent string is never stored. | To know whether the site is being used on a phone or a computer. | 366 days |
| Approximate network location (country, region/state, city) | Analytics | An approximate network location derived SERVER-SIDE from the public network address the hosting network reports: a two-letter country code (for example US), a first-level region/state code (for example CA), and an approximate city name · counted once per consenting session as an aggregate bucket. VPNs, corporate networks, mobile carriers, shared networks, proxies, and privacy relays can make it inaccurate; it is not GPS, not a residence, and not an exact physical location. Missing or invalid values are recorded as Unknown. No coordinates, no postal code, and no raw network address are ever retained. | To know roughly where Pckup is used from · countries, regions, and cities in aggregate, never anyone's position. | 366 days |
| Aggregate reach and performance measurement by the hosting provider (Vercel Web Analytics and Speed Insights) | Analytics | Only after you allow analytics, same-origin scripts report the sanitized page path (query strings and fragments stripped, identifier-shaped segments collapsed before anything leaves your browser) to Vercel, the site's hosting provider. Web Analytics supplies aggregate reach data; Speed Insights supplies real-user Web Vitals and related performance context such as network speed, browser, device, operating system, and country. The tools are cookieless · nothing is stored in your browser · and administrator, authentication, and application sections are never reported. | To understand aggregate reach and real-user page performance on the infrastructure that already serves the site, without adding an advertising or cross-site tracker. | Managed by Vercel for the project's plan; nothing is stored in your browser |
| Google Analytics (the Google tag, third party) | Analytics | On this deployment your browser requests one Google file (googletagmanager.com/gtag/js) on eligible pages, before and regardless of any consent choice · that request alone discloses to Google what any web request discloses: your network address, your user agent, and the page you were on. ELIGIBLE excludes the sections whose URL is itself sensitive: payment links (/u/order/pay), shared-chat links (/ai/s, /customer-ai-agent/s), your dashboard, administrative pages, and every sign-in route load the tag not at all, so Google never learns those addresses. Where it does load, Google Analytics' automatic page view is turned OFF and the address reported is the sanitized path · query strings and fragments stripped, identifier-shaped segments collapsed · and the script is fetched with no referrer. Before the file is requested, the page sets Google's consent permissions (analytics storage, ad storage, ad user data, ad personalization) to DENIED, and while they are denied Google Analytics sets no cookie, reads no cookie, and creates no identifier for you; what it still sends is an anonymous cookieless signal that a page was viewed, carrying no identifier of yours. Only when you allow the Analytics category does the permission become granted, and only then does Google Analytics set its cookies (_ga, _gid, _gat, _ga_V6E53SET9C, _gcl_au, _gcl_aw, _gcl_dc, _gac_gb_V6E53SET9C) and measure your visit normally. The three ADVERTISING permissions stay denied unless you separately allow "Marketing and visitor identification" · allowing analytics never enables advertising. | Aggregate measurement of how the site is used, in the tool the business already reports on. | Google's cookies are set and retained by Google; when you withdraw, Pckup switches the permission back to denied and deletes Google's documented cookies from this browser. You can also opt out of Google Analytics on every site with Google's own browser add-on (link in the cookie notice). |
| Visitor identification by RB2B (third party) | Marketing and visitor identification | Only if you separately allow "Marketing and visitor identification", your browser loads a script from RB2B, a third-party visitor-identification service · NOT anonymous analytics. RB2B attempts to identify who is visiting (for example the visiting company and, where its service supports it, business contact details such as a name and work email · RB2B states its person-level identification works for United States traffic) and shares the result with Pckup for sales and marketing follow-up. RB2B sets its own first-party cookies in your browser (documented names begin with _reb2, for example _reb2bgeo, _reb2bloaded, _reb2bref; RB2B's own articles spell its session cookie two ways, and withdrawal removes both). It runs only on public marketing and editorial pages · never on legal, account, tracking, quote, or administrative pages. | Sales and marketing follow-up: knowing which companies and business contacts visit Pckup. | RB2B's cookies are set and retained by RB2B; when you withdraw, Pckup persists your refusal, deletes RB2B's documented cookies from this browser, and reloads the page so nothing further loads. You can also opt out with RB2B directly (links in the cookie notice). |
| A rotating network signal (never your IP address) | Analytics | Your IP address is used for a fraction of a second in memory to compute a keyed one-way HMAC-SHA256 value that mixes in the current ISO week and a secret key held only on the server, and is then discarded. The resulting value is stored; your IP address is not. Because the week and the key change, the value cannot be linked across weeks or back to an address, and it never appears anywhere in the administrator interface. | To rate-limit abuse of the collection endpoint and to count roughly how many visits come from a network already seen this week. It is a NETWORK signal, not proof that the same person returned · offices, homes, schools, VPNs and mobile carriers share networks. | 14 days |
| AI delivery chats you save, share, or place an order in | Strictly necessary | When you SAVE a chat with a Pckup AI delivery agent, or SHARE it with a link, the conversation is stored so it can appear in your history and behind the link you created · the messages you and the agent exchanged, the surface it happened on, and the delivery cards it produced. PLACING AN ORDER also stores the conversation the same way: the moment an order is confirmed, the chat is kept so the secure link in your payment email can reopen it on any device · this happens for every confirmed order, whether or not you are a returning customer. Saving before signing in, or placing an order, holds the chat against a functional cookie (pckup_chat_holder) that is minted when you save, share, star, or confirm an order, and is adopted into your account when you sign in or open a recognized link. A SHARE link exposes only a REDACTED, point-in-time copy: on the delivery cards, contact details, order identifiers, and payment-link tokens are removed and addresses are shortened to city level before the copy is stored; in the message text itself, email addresses, phone numbers, card-like numbers, and web links are masked, while everything else you and the agent typed · including an address written inside a message · stays visible to anyone with the link. The link stops working the moment you revoke it. A chat you neither save, share, sign in to keep, nor place an order in is not retained. | So your delivery chats can live in your history and dashboard, so a shared link shows a helpful, redacted copy of a conversation to anyone you send it to, and so the secure link in a payment email can reopen the chat that placed the order. | Saved and account chats stay until you delete them; a shared copy stays until you revoke it; an unsaved, signed-out chat · including one kept only because you placed an order · self-expires after 30 days of inactivity |
| Company details | Strictly necessary | The company name, an optional website, and an optional billing email an owner enters. The billing email may be a personal address if the owner chooses to use one. | To identify the company and reach it for billing and support. | For the life of the company; owner-editable. There is no in-product way to delete a company · an owner can request a database purge. |
| Company membership | Strictly necessary | If you belong to a Company Account: your display name and the email on your account, so the other members of your company can see who is on the team. Only your own company's members see this. When you send an invite, your display name also appears on that invite's accept page to whoever holds the single-use link. | So a company's members can see their own team roster · who belongs, and who placed which order · and so an invited person can see who invited them. | For as long as you are a member. If an owner removes you, your team visibility ends going forward; order rows already attributed to you remain in the company's history. |
| Pending team invites | Strictly necessary | The email address an owner invited to their company, and a ONE-WAY HASH of the single-use invite token (never the raw token). To deliver the invite the address is sent to our email provider, and a truncated hash of it is held for two days to rate-limit sending. The pending list is visible only to the company's owner. | So an owner can send, resend, and revoke invites, and so an accepted invite joins the right company. | An invite link expires 14 days after it is created. The invite record survives acceptance, revocation, or expiry and is removed the next time an owner opens the team page once it has been settled for 30 days more · at least 44 days after creation, and longer if no owner returns. |
| Company order attribution | Strictly necessary | For an order placed while you are a company member: a record linking that order to you and to your company, WITH the order's total, so your team's shared order history shows who placed what and for how much. | So a company's shared order history is honest about which teammate placed each order and its amount. | Kept as the company's history for the life of the company · an attribution is not removed when a member is removed, and there is no in-product way to delete a company (an owner can request a database purge). |
| Order form draft · shared across devices | Strictly necessary | ONLY if you click “Make this link work on other devices” while filling out the order form: the draft you have so far · addresses, contact names and phone numbers, notes, package details, timing · is saved to Pckup under the same random id your page's link carries, so that link can restore the form on another device. The price quote is never included. Anyone who has the link can view that draft copy; changing or deleting it needs a separate key that only your original browser holds and that never appears in any link. | So a link you save or send to yourself restores your in-progress order on another device or browser. Without that click, your draft never leaves your device. | Deleted when the order is placed, and we delete it when you sign out (that request is best-effort · if it does not reach us, the copy still expires 14 days after your last edit, which the storage system enforces itself). |
| Order form draft | Strictly necessary | As you fill out the delivery order form, everything you have entered so far · pickup and drop-off addresses, contact names and phone numbers, delivery notes, package details, timing · is saved ON THIS DEVICE in browser storage, under an opaque random id. The page's address bar carries ONLY that id (?d=…), never the entries themselves, so your addresses and phone numbers never appear in the URL, browser history, shared links, or analytics (every analytics path strips query strings). This draft sends nothing to our servers. | So an in-progress order survives a reload or an accidentally closed tab, and so the page's link can bring the form back to where you left off on this device. | A draft is deleted when its order is placed and when you sign out, and otherwise expires 14 days after its last edit (your browser may clear site storage sooner · Safari caps script-written storage at about 7 days of inactivity). At most 10 drafts are kept per browser. |
What Pckup never collects
These are not omissions from the table above · they are prohibitions Pckup’s own first-party pipeline enforces, and there are automated tests that fail the build if any of them appears in a stored record:
- Your IP address, in any stored form, and no plain or unsalted hash of it.
- Precise location or coordinates. The AI page’s background map may ask your browser for your location to center itself · the answer is used on your device only and is never sent to Pckup or stored anywhere, and a browser policy header keeps the geolocation API off for every embedded third party.
- Query strings and URL fragments · stripped before anything is written.
- Names, email addresses, phone numbers, postal addresses, payment details, or anything you type into a form.
- Keystrokes, mouse movement, scroll recordings, or session replay of any kind.
- Device fingerprints: no canvas, font, audio, or hardware probing; not even the full user-agent string.
- Cross-site or cross-device identifiers. Nothing Pckup stores means anything on any other website.
- Advertising profiles. There is no advertising vendor, and analytics data is never sold or shared for anyone else’s purposes.
The one deliberate, separately disclosed exception is the optional “Marketing and visitor identification” category: RB2B, a third-party service whose entire stated purpose is identifying visitors. It is described in its own section below, it never runs unless you switch it on yourself, and enabling analytics does not enable it. The prohibitions above describe what Pckup’s own first-party pipeline stores; Google Analytics is a separate processor with its own data practices, disclosed in its own section below, and Google’s advertising permissions stay off unless you enable the marketing category · allowing analytics never turns them on.
How the choice works
- Nothing optional is measured before you choose. No first-party analytics request and no visitor-identification request is made while the banner is still waiting for an answer. There is exactly one thing that does load beforehand, and we would rather name it than let you find it: the Google tag file itself, which arrives switched off · every optional Google permission is set to “denied” before the file is even requested, so it stores nothing in your browser and cannot identify you until you allow the Analytics category. What it does still send Google in that switched-off state, and what requesting the file discloses, is spelled out in its own section below.
- Accept all, Reject all, and Customize choices are equally easy · same layer, same size, same styling. Refusing is one click, exactly like accepting.
- Nothing is pre-ticked, and closing the banner, scrolling, or continuing to browse is not consent. Only pressing one of the buttons is.
- Withdrawal is one click, at any time, from “Privacy and cookie settings” in the footer of every page. Collection stops immediately and the random identifiers are deleted from your browser.
- Global Privacy Control is honoured. If your browser sends the GPC signal, both optional categories · analytics and marketing / visitor identification · start off, the banner says so, and neither runs unless you personally switched it on in the settings dialog afterwards. There is no weaker rule for the marketing category.
- “Accept all” never grants location access. It covers the two disclosed optional categories · analytics and marketing / visitor identification · and nothing else. If any future feature ever needs your location, your browser will ask you separately, at the moment of use.
- Refusing costs you nothing. Every page, including the home-page background video, works and looks identical whether you accept or refuse.
Your choice is recorded against policy version v8 and we ask again after 182 days, or sooner if what we disclose materially changes · a new disclosure means the old answer no longer covers the question.
Google Analytics (the Google tag)
Google Analytics runs under the optional Analytics category, alongside the first-party measurement described above. It works differently from everything else on this page, so it gets its own section.
The tag file loads for everyone. On the live site your browser requests one Google file (googletagmanager.com/gtag/js) on every page, whether or not you have decided anything. Requesting any file from another company’s server discloses to that company the things every web request discloses: your IP address, your user agent, and the page you were on. We are naming that plainly rather than describing the tag as absent until consent.
It arrives switched off. Before the file is even requested, the page sets Google’s consent permissions · analytics storage, ad storage, ad user data, and ad personalization · to denied. While they are denied, Google Analytics sets no cookie, reads no cookie, creates no identifier for you, and cannot recognise you across pages, visits, or sites. What it does still send is an anonymous cookieless signal that a page was viewed, which Google uses for aggregate estimates; it carries no identifier of yours.
Your choice changes the permissions immediately. Allowing Analytics switches analytics storage to “granted”, and only then does Google Analytics set its cookies and measure your visit normally. Turning it back off switches the permission to “denied” again and this site deletes Google’s cookies from your browser · you do not have to wait for them to expire.
The advertising permissions are separate. Google’s three advertising permissions stay denied unless you enable the “Marketing and visitor identification” category below. Allowing analytics never enables advertising · exactly the same boundary that keeps analytics consent from enabling RB2B.
Global Privacy Control:if your browser sends the GPC signal, the analytics permission stays denied unless you personally switched analytics on in the settings dialog afterwards, and the advertising permissions stay denied unless you personally switched the marketing category on. That suppression is Pckup’s own conservative policy applied before Google is told anything · it is not a feature of Google’s service.
Cookies: when · and only when · you have allowed analytics, Google Analytics sets _ga and a per-property _ga_… cookie in this browser to recognise a returning visit and group page views into one session. Their retention is set by Google. Withdrawing deletes both.
Opting out with Google directly: independent of your choice here, Google publishes a browser add-on that opts you out of Google Analytics on every site at tools.google.com/dlpage/gaoptout. Google’s own handling of what it receives is described in its privacy policy.
Marketing and visitor identification (RB2B)
RB2B is a third-party visitor-identification service · not anonymous analytics. If, and only if, you enable the “Marketing and visitor identification” category, your browser loads RB2B’s script and RB2B attempts to identify who is visiting: the visiting company and, where its service supports it, business contact details such as a name and work email (RB2B states its person-level identification works for United States traffic). RB2B shares what it resolves with Pckup for sales and marketing follow-up.
What Pckup keeps. RB2B delivers what it resolves to Pckup server-to-server (a name, business email, title, company, and LinkedIn URL, where resolved). Pckup stores that beside the pseudonymous visit session it belongs to · matched approximately by visit time and page, and labeled as approximate wherever it is shown · visible only to Pckup staff on internal tooling, never published. It is kept for the same short window as the visit records it annotates (30 days by default), is deleted automatically after that, and can be deleted on request at any time via contact@senpex.com · name the business email RB2B resolved and every matching record is removed. Withdrawing this consent stops any new identification immediately; records already received are not re-read on withdrawal and simply age out within that same window, or sooner on request.
- Off by default, always.It is a separate choice from Analytics · allowing analytics never enables it, and it is never pre-ticked. “Reject all” keeps it off.
- Global Privacy Control keeps it offunless you personally enable it in the settings dialog · the same rule as analytics, with no weaker exception. This is Pckup’s own conservative policy, applied before RB2B is ever contacted; it is not a feature of RB2B’s service.
- It only runs on public marketing and editorial pages. A central allowlist excludes legal pages, account and sign-in areas, order tracking, quotes and estimates, administrative tools, and every page not explicitly approved · unknown pages are excluded by default.
- Cookies: RB2B sets its own cookies in this browser; the names it documents begin with
_reb2(for example_reb2bgeo,_reb2buid; RB2B’s own articles spell its session cookie both_reb2sessionIDand_reb2bsessionID). Their retention is set by RB2B. - Withdrawal:switch the category off in “Privacy and cookie settings”. Your refusal is saved first, RB2B’s documented cookies · including both spellings of its session cookie · are deleted from this browser, and the page reloads so the script is gone. RB2B does not document a way to stop its script mid-page, so the reload is how Pckup guarantees the stop.
- Opting out with RB2B directly: independent of your choice here, RB2B offers its own opt-outs · you can opt out of this advertising-related identification at app.retention.com/optout and, for visitors in regions covered by the GDPR, at rb2b.com/rb2b-gdpr-opt-out. These remove you from RB2B’s systems, not just from this site.
- Enablement is a deployment switch. The integration is also controlled server-side by configuration; when that switch is off · or on any non-production deployment · the script never loads for anyone, regardless of consent.
Conversion counting
Pckup counts completed business outcomes in aggregate only (quote-requested, account-registered, order-placed, order-completed). A count carries no customer identity, no form contents, and no order details · only the type, the time, and a number. Repeated deliveries of the same event are de-duplicated for 7 days.
How to reach us, and how to exercise your rights
You can change or withdraw your privacy choices yourself at any time, with no request and no waiting: use Privacy and cookie settings at the bottom of every page. Withdrawing stops collection immediately and deletes the random identifiers from your browser.
For anything else · a question, a complaint, or a request to access or delete data · these are the channels this site currently offers:
- Email contact@senpex.com· the operator's published contact mailbox, which also handles privacy questions and requests.
- The business enquiry form on the delivery API page, which reaches the Pckup team.
- If you have a Pckup account, the support form in your dashboard.
Because the analytics described here is deliberately built so that no record can be traced to a person, there is in practice nothing person-specific for us to look up, export, or delete on request · the identifiers are random, the network value is one-way and rotating, and your IP address is never stored. The one record you control directly is your own consent choice, and the settings link above deletes it.
The broader picture · legal bases, processors, and your rights · is in the privacy policy. The engineering decision record behind all of this lives in the repository as docs/PRIVACY_BOUNDARY.md.