Last updated September 17, 2026
Partner Privacy Policy
This policy explains what personal information the Packflip Partner Services collect, how we use it, and the choices you have. It covers the Partner Console, the Partner API, and the Partner sandbox. The Packflip consumer site has its own Privacy Notice.
1. Who we are
The Partner Services at partner.packflip.xyz and sandbox.partner.packflip.xyz are operated by Packflip ("we", "us"). For privacy questions or requests, contact support@packflip.xyz.
For information about the people who use the Partner Console, we decide how it is used. For information about your customers that you send through the API, you decide why it is collected, and we process it to provide the Partner Services to you.
2. Information we collect
Console users. When you create an account or sign in, we collect your name, email address, profile picture, and the organizations you belong to. If you sign in with Google or another identity provider, we receive this information from that provider (see Section 3). We do not receive your provider password.
Organization and account data. Organization names, API key names and usage times, webhook endpoint URLs, deposit addresses, balances, and the operations your organization creates. API keys and webhook signing secrets are stored hashed or encrypted.
Customer data you send through the API. Pseudonymous customer identifiers and analytics attributes you choose, wallet addresses you mint cards to, shipping details you send with a redemption, such as name, address, and phone number, the email address you give us for shipment notifications, and any metadata you attach to operations. Customer attributes must not contain contact details or other directly identifying data, and please do not send more than an operation needs.
Blockchain data. Wallet addresses, transaction hashes, and transfers on Base and Base Sepolia. Blockchain data is public by design and cannot be deleted by us.
Technical and usage data. IP addresses, browser and device information, pages viewed and features used on the Partner website and Console, request logs, and security events generated when you use the Console or call the API.
3. Signing in with Google
If you choose Sign in with Google, we request only the basic scopes needed to identify you: your name, email address, and profile picture (openid, email, and profile). We do not request access to Gmail, Google Drive, Google Calendar, contacts, or any other Google data.
We use this information only to create and secure your Console account, show who you are to other members of your organization, and contact you about your account. We do not sell it, use it for advertising, or use it to develop or train generalized artificial intelligence or machine learning models, and we do not transfer it to others except to the service providers that run authentication and hosting for us, as needed to provide the Partner Services, or as required by law.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove Packflip's access at any time from your Google Account permissions page; you will then need another sign-in method to use the Console.
4. How we use information
- to provide the Partner Services: authenticating users, running operations, crediting deposits, holding, minting, buying back, and shipping cards, and delivering webhooks;
- to send shipment notifications where you request them;
- to analyze purchasing behaviour across packs and customers, and to provide you with reports about your own customers;
- to secure the Partner Services, prevent fraud and abuse, and investigate incidents;
- to communicate with you about your account, service changes, and support requests;
- to meet legal, tax, accounting, and compliance obligations; and
- to understand how the Partner website and Console are used, and to improve the Partner Services.
We do not sell personal information, and we do not use customer data you send us to market our own products to your customers.
7. Retention
We keep Console account information while your account is active. Operation, ledger, and funding records are kept for as long as needed to provide the Partner Services and to meet legal, tax, and accounting obligations. Webhook payloads and technical logs are kept for a limited period for delivery, replay, and security. Sandbox data may be deleted at any time.
8. Security
We use encryption in transit, encryption of secrets at rest, access controls, and monitoring to protect information. No system is perfectly secure; if we learn of a breach that affects your information, we will notify you as required by law.
9. International transfers
We and our service providers may process information in countries other than yours, including the United States. Where required, we use appropriate safeguards for those transfers.
10. Your choices and rights
You can update your profile and leave an organization from the Console. Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To make a request, email support@packflip.xyz. We may need to verify your identity, and we may keep information we are legally required to retain.
If you are a customer of one of our partners, please contact that partner first; we will help them respond to your request.
11. Children
The Partner Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 18 through the Console.
12. Changes to this policy
We may update this policy. We will post the new version with its date and, for material changes, notify organization administrators before the change takes effect.
Questions? Contact support@packflip.xyz. See also the Terms of Service and Privacy Policy.