Sandbox

Go to production
PackflipPartner

Last updated September 17, 2026

Partner Privacy Policy

This policy explains what personal information the Packflip Partner Services collect, how we use it, and the choices you have. It covers the Partner Console, the Partner API, and the Partner sandbox. The Packflip consumer site has its own Privacy Notice.

1. Who we are

The Partner Services at partner.packflip.xyz and sandbox.partner.packflip.xyz are operated by Packflip ("we", "us"). For privacy questions or requests, contact support@packflip.xyz.

For information about the people who use the Partner Console, we decide how it is used. For information about your customers that you send through the API, you decide why it is collected, and we process it to provide the Partner Services to you.

2. Information we collect

Console users. When you create an account or sign in, we collect your name, email address, profile picture, and the organizations you belong to. If you sign in with Google or another identity provider, we receive this information from that provider (see Section 3). We do not receive your provider password.

Organization and account data. Organization names, API key names and usage times, webhook endpoint URLs, deposit addresses, balances, and the operations your organization creates. API keys and webhook signing secrets are stored hashed or encrypted.

Customer data you send through the API. Pseudonymous customer identifiers and analytics attributes you choose, wallet addresses you mint cards to, shipping details you send with a redemption, such as name, address, and phone number, the email address you give us for shipment notifications, and any metadata you attach to operations. Customer attributes must not contain contact details or other directly identifying data, and please do not send more than an operation needs.

Blockchain data. Wallet addresses, transaction hashes, and transfers on Base and Base Sepolia. Blockchain data is public by design and cannot be deleted by us.

Technical and usage data. IP addresses, browser and device information, pages viewed and features used on the Partner website and Console, request logs, and security events generated when you use the Console or call the API.

3. Signing in with Google

If you choose Sign in with Google, we request only the basic scopes needed to identify you: your name, email address, and profile picture (openid, email, and profile). We do not request access to Gmail, Google Drive, Google Calendar, contacts, or any other Google data.

We use this information only to create and secure your Console account, show who you are to other members of your organization, and contact you about your account. We do not sell it, use it for advertising, or use it to develop or train generalized artificial intelligence or machine learning models, and we do not transfer it to others except to the service providers that run authentication and hosting for us, as needed to provide the Partner Services, or as required by law.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove Packflip's access at any time from your Google Account permissions page; you will then need another sign-in method to use the Console.

4. How we use information

  • to provide the Partner Services: authenticating users, running operations, crediting deposits, holding, minting, buying back, and shipping cards, and delivering webhooks;
  • to send shipment notifications where you request them;
  • to analyze purchasing behaviour across packs and customers, and to provide you with reports about your own customers;
  • to secure the Partner Services, prevent fraud and abuse, and investigate incidents;
  • to communicate with you about your account, service changes, and support requests;
  • to meet legal, tax, accounting, and compliance obligations; and
  • to understand how the Partner website and Console are used, and to improve the Partner Services.

We do not sell personal information, and we do not use customer data you send us to market our own products to your customers.

5. How we share information

We share information only as needed to operate the Partner Services, with:

  • Clerk, which provides Console sign-in and organization management;
  • Amazon Web Services, which hosts the Partner Services and their databases;
  • Alchemy, which provides blockchain access and notifies us about transfers to deposit addresses;
  • PostHog, which provides product analytics for how the Console is used and for aggregate purchasing behaviour;
  • Resend, which delivers shipment emails to the addresses you provide;
  • custodians, graders, and shipping carriers, which store and deliver physical cards; and
  • professional advisers, and authorities where the law requires it.

Members of your organization can see the organization's data in the Console. If we are involved in a merger or acquisition, information may be transferred as part of that transaction under this policy.

6. Cookies

The Console uses cookies that are strictly necessary to keep you signed in and to protect against request forgery. The Partner website and Console also use first-party analytics cookies and local storage from PostHog to understand how pages and features are used; these are linked to your account when you sign in. The Partner Services do not use advertising or cross-site tracking cookies.

7. Retention

We keep Console account information while your account is active. Operation, ledger, and funding records are kept for as long as needed to provide the Partner Services and to meet legal, tax, and accounting obligations. Webhook payloads and technical logs are kept for a limited period for delivery, replay, and security. Sandbox data may be deleted at any time.

8. Security

We use encryption in transit, encryption of secrets at rest, access controls, and monitoring to protect information. No system is perfectly secure; if we learn of a breach that affects your information, we will notify you as required by law.

9. International transfers

We and our service providers may process information in countries other than yours, including the United States. Where required, we use appropriate safeguards for those transfers.

10. Your choices and rights

You can update your profile and leave an organization from the Console. Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To make a request, email support@packflip.xyz. We may need to verify your identity, and we may keep information we are legally required to retain.

If you are a customer of one of our partners, please contact that partner first; we will help them respond to your request.

11. Children

The Partner Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 18 through the Console.

12. Changes to this policy

We may update this policy. We will post the new version with its date and, for material changes, notify organization administrators before the change takes effect.

Questions? Contact support@packflip.xyz. See also the Terms of Service and Privacy Policy.