Legal and privacy
Privacy policy
Pckup is built so that measuring how the site is used does not require knowing who you are. This page explains what that means in practice, in plain language, and what we deliberately gave up in order to do it.
The short version
- Nothing optional is stored, and nothing measures your visit, until you affirmatively allow it. Refusing is one click and costs you nothing. One file · Google’s analytics tag · does load before you choose, switched off and storing nothing; it is described in the cookie & analytics notice, and it is never loaded at all on payment links, shared-chat links, your dashboard, or any sign-in page.
- We never store your IP address, never use fingerprinting, and never record what you type or where you move your mouse.
- There is no advertising and no cross-site ad tracking. One optional, clearly separate choice exists for marketing: RB2B, a third-party visitor-identification service that · only if you enable it yourself · attempts to identify visiting companies and business contacts and shares that with Pckup. It is off by default, off under Global Privacy Control, and never enabled by the analytics choice.
- The measurement identifiers are random values your own browser generates. They are meaningless anywhere else, and they are deleted from your browser the moment you withdraw consent.
- Location is an approximate NETWORK location · country, region/state, and approximate city · derived server-side from the public network address, only for sessions that allow analytics. VPNs, corporate networks, carriers, proxies, and privacy relays make it inaccurate; it is never GPS, a residence, or an exact position, and missing data is recorded as Unknown. Precise location is switched off at the browser-policy level.
- Optional analytics is enabled on this deployment · first-party plus the hosting provider's aggregate reach and real-user performance measurement · for consenting visitors only.
Who is responsible for this data
This site is operated by Senpex, Inc., doing business as Pckup · one company, one operator. The data described here is used only for the purposes this notice states, and is not shared with anyone else for their own purposes.
- Legal entity name of the operator
- Senpex, Inc., doing business as Pckup
- Postal address for privacy correspondence
- 3566 Stevens Creek Blvd, San Jose, CA 95117, United States
- Privacy contact email address
- contact@senpex.com
- Legal establishment (state and country of incorporation)
- State of Delaware, United States
- This states where the company is legally established (incorporated). The governing law and venue of the customer and courier service agreements are stated in each agreement itself and are not changed by this fact.
What we collect, and what we refuse to collect
The complete, itemized list · every value, its purpose, the consent category that gates it, and its retention period · is in the cookie and analytics notice. It is generated from the running code rather than written by hand, so the two cannot drift apart.
In summary, when you allow analytics we record which pages were visited and in what order, which controls you activate on our pages · a button’s or link’s visible label only, never what you type and never a form field’s value · how long a page was actually read (visible and focused time only), whether a browser is new or returning, a coarse device category, and an approximate network location (country, region/state, and approximate city; Unknown when absent) · all tied to random identifiers, never to you.
Pckup’s own pipeline does not collect your IP address, precise location, query strings, names, email addresses, phone numbers, postal addresses, payment details, form contents, keystrokes, mouse movement, session replay, device fingerprints, full user-agent strings, or any cross-site identifier. Those are enforced prohibitions with tests behind them, not aspirations.
Separately, if you enable the optional “Marketing and visitor identification” category, RB2B · a third-party service whose stated purpose is identifying visitors · may resolve the visiting company and, where its service supports it, business contact details such as a name and work email, and share them with Pckup for sales and marketing follow-up. What RB2B resolves, Pckup keeps beside the pseudonymous visit records it belongs to · for the same short window as those records (30 days by default), visible only to Pckup staff on internal tooling, deletable on request, and matched to the visit only approximately (and labeled as such). That category is described in full in the cookie and analytics notice, runs only on public marketing pages, and never runs unless you switch it on.
About IP addresses, and the “returning visitor” question
Any web server necessarily sees the IP address of a request in order to reply to it. Pckup never writes yours down. For the fraction of a second it is in memory, it is combined with the current calendar week and a secret key that lives only on the server to produce a one-way value, and then it is discarded. That value is what gets stored.
Because the week and the key both change, the value cannot be linked back to an address or followed from one week to the next, and it never appears anywhere in the administrator interface. It is kept for 14 days.
We are careful about what this can and cannot tell us. It shows that two visits came from the same network in the same week. A network is not a person: offices, households, schools, cafés, VPNs, and mobile carriers all put many people behind one address, and one person moving between home, work, and a phone looks like several networks. So Pckup describes this as a repeat network signal and nothing more. We will not present it as evidence that a particular person came back.
Why we are allowed to do this
Strictly necessary items · your privacy choice, the consent record, your theme preference, and the administrator login session · exist because the site cannot work or honour your choices without them. Storing your refusal is what proves optional processing stayed off.
Everything optional runs on your consent, which we ask for before anything happens, record with a version, and let you withdraw as easily as you gave it. Where consent is the basis, you can withdraw at any time without giving a reason and without losing access to anything.
We do not rely on “legitimate interests” to switch measurement on without asking, and we do not treat continued browsing as agreement.
How long anything is kept
- Session and event records: 30 days.
- Daily aggregate counts: 366 days.
- The rotating network signal: 14 days.
- Consent records: 400 days. These are kept longest on purpose · they are the accountability trail for choices, and they contain no identifiers.
- Your own consent cookie: 182 days, or until you change it, or sooner if the disclosure materially changes.
Retention is enforced by the storage layer itself: every record is written with an expiry, so nothing survives its period through neglect.
Payments
When an order is paid through a payment link on pckup.com, the checkout page is hosted by Pckup, but your card never is: On a live checkout, card details are entered into payment fields hosted by Stripe inside the page and exchanged for a single-use token · the card number, expiry date, and security code never exist in the page's own state or on a Pckup server. The only card-derived values a Pckup server ever handles are that single-use token and the card's last four digits, passed once to the delivery network. (Demonstration deployments that cannot take real payment show a clearly labeled mock form instead · no real card should ever be entered there.)
The single-use token is passed once to Senpex, Pckup's delivery network, which charges the card for exactly the order total held in its own records · no amount is ever taken from the browser.
Pckup never stores card numbers, expiry dates, or security codes · the hosted payment page keeps no payment record beyond the order's paid status. The payment processor's charge identifier is never returned to the browser · the success response carries only the paid status, and error messages are scrubbed of processor identifiers before they are shown · and it is never stored by Pckup. The payment page resolves the order it displays from the unguessable link token, server-side. It shows the order as the delivery network carries it · including the sender's and recipient's names and phone numbers, which the person paying legitimately needs · while the payment contact details Senpex keeps about the payer themselves (their email and phone from the payment request) are filtered out before the page renders.
The checkout page participates in the same consent-gated page-view analytics as every other page, with one extra safeguard: the payment link's token is removed from the recorded path (only the section /u/order/pay is stored), and the page is excluded from third-party web analytics entirely. Nothing typed on the page · names or card fields · is ever read by any measurement.
Administrative account access
Pckup's support tooling includes a super-administrator feature called Emulator: a small, server-verified set of senior administrators can open a customer's or courier's account view and see what that person sees on their own dashboard, and · behind a separate per-action confirmation · take a limited set of actions on that person's behalf during support.
The person whose account is opened is not notified · not by email, not in the app, not afterward. This is a deliberate product decision, and it is why every use is recorded: the record described below is the only account of the access that exists.
Every entry into an account (with the administrator's stated reason) and every action taken on someone's behalf is written to an append-only audit ledger that names both the administrator and the person, and the sensitive views opened inside the account are written to the same ledger on a best-effort basis. Append-only means the application and its database triggers refuse every edit, deletion, and truncation of these records; it is not a cryptographic guarantee, and the infrastructure role that owns the database could in principle alter it.
Acting on someone's behalf is blocked by construction on the ordinary read path; each consequential action additionally requires the administrator to read and confirm a server-written sentence naming its exact consequence, and is refused outright when its attempt cannot be recorded. Events that assert a real-world or money effect are additionally written to an alert log that every senior administrator can read alongside the ledger itself, inside the same administrative tool.
When the audit store cannot take a write, view records can fail to be recorded while read-only account viewing continues to work; actions are refused entirely in that state because an unrecorded action is never performed. The residual · read-only viewing whose view records did not land · is recorded in the privacy boundary record rather than hidden.
Who else is involved
No data is sold, rented, or shared for advertising. Besides the infrastructure that runs the site and the two payment parties described in the Payments section above (Stripe, which hosts the card fields, and Senpex, which collects the payment), two third parties can receive visit data · Google Analytics under the Analytics category, and RB2B under the separate Marketing and visitor identification category. RB2B loads only with your opt-in. Google’s tag is the one exception to that rule and is described honestly below:
- Vercel · hosting and content delivery. It processes requests in order to serve pages, and it is what supplies the two-letter country code.
- A managed key-value store (Upstash or Vercel KV) · where the aggregate counts and consent records are kept, in a storage area isolated from everything else the site stores.
- Google Analytics· aggregate measurement under the optional Analytics category. Unlike everything else on this list, Google’s tag file is requested on every eligible page whether or not you have chosen, which discloses to Google what any web request discloses: your IP address, your user agent, and the page you were on. It arrives with every optional Google permission set to denied, so it stores nothing in your browser and cannot identify you until you allow Analytics; while denied it sends only an anonymous cookieless signal. It is never loaded on payment links, shared-chat links, your dashboard, administrative pages, or any sign-in page, and the address it reports is always stripped of query strings and identifier-shaped segments. Google’s advertising permissions stay off unless you separately enable the marketing category. Full detail, including opting out with Google directly, is in the cookie & analytics notice.
- RB2B· an optional third-party visitor-identification service, loaded only for visitors who enable the “Marketing and visitor identification” category. Unlike the infrastructure above, RB2B processes visit data to identify who is visiting and shares the result with Pckup; it receives nothing from visitors who have not opted in. You can also opt out with RB2B directly · of this advertising-related identification at app.retention.com/optout, and under the GDPR at rb2b.com/rb2b-gdpr-opt-out.
The home-page background video is a Pckup-owned asset served from this site’s own origin · no third-party media host is contacted to display it.
Because the site is reachable worldwide, data may be processed in countries other than your own by these providers as part of hosting.
Who can see the results
The measurement dashboards are administrator-only and behind a server-enforced login; there is no public visitor dashboard. What an administrator sees is aggregate counts · sessions, page views, engaged time, entry and exit pages, referring hosts, device categories, countries. The random identifiers and the network value are never shown, exported, or logged.
How to reach us, and how to exercise your rights
You can change or withdraw your privacy choices yourself at any time, with no request and no waiting: use Privacy and cookie settings at the bottom of every page. Withdrawing stops collection immediately and deletes the random identifiers from your browser.
For anything else · a question, a complaint, or a request to access or delete data · these are the channels this site currently offers:
- Email contact@senpex.com· the operator's published contact mailbox, which also handles privacy questions and requests.
- The business enquiry form on the delivery API page, which reaches the Pckup team.
- If you have a Pckup account, the support form in your dashboard.
Because the analytics described here is deliberately built so that no record can be traced to a person, there is in practice nothing person-specific for us to look up, export, or delete on request · the identifiers are random, the network value is one-way and rotating, and your IP address is never stored. The one record you control directly is your own consent choice, and the settings link above deletes it.
Children
Pckup is a service for businesses and for people who work as couriers. It is not directed at children, and nothing described here profiles anyone or attempts to infer age.
Changes to this notice
Changes are published with the code that causes them, and every release is listed in the site’s public changelog. If a change materially alters what we disclose, the policy version is raised and you will be asked again · an old answer to a different question is not consent.