PickupDock · Legal
Privacy notice
This draft describes the information involved in using PickupDock and the decisions that must be finalized before this notice takes effect.
The legal operator, privacy contact, retention schedule, and jurisdiction-specific terms have not been approved for publication. This page is a review draft, not a finalized policy or agreement.
Who this notice covers
PickupDock provides software for merchants to manage service and event businesses. Account information about a merchant user is distinct from customer information that a merchant enters or collects through a form, storefront, or other customer-facing workflow.
For questions about a specific merchant’s products, booking, marketing consent, or customer records, contact that merchant through its published contact details. The platform operator’s identity and direct privacy contact must be added before this notice becomes effective.
Information processed
The application can process account email and profile information; business identity, branding, location, and settings; customer names, emails, phone numbers, addresses, and notes; inquiries, quotes, agreements, signatures, bookings, orders, loyalty records, and communication preferences.
Payment records can include amounts, currency, payment status, refunds, provider references, and a card brand or last four digits when supplied. Payment credentials are handled through the configured payment provider. Contract-signing records include the signed version, timestamp, signer name, IP address, and user agent.
Operational information can include session cookies, request identifiers, security and audit records, delivery status, and available form attribution such as referrer, page URL, and UTM parameters. Do not put passwords, payment credentials, or unnecessary sensitive information in free-text fields.
Why information is used
The intended purposes are to authenticate accounts, separate merchant workspaces, deliver requested business workflows, process and reconcile payments, preserve agreements, operate consent-aware communications, provide reports, and investigate reliability or security issues.
Customer marketing preferences are recorded per merchant and communication channel. A merchant’s marketing consent does not authorize unrelated businesses to contact that customer.
Service providers and AI
The architecture uses Supabase for authentication, database, and storage, and Stripe for payment and subscription processing. Email, SMS, and AI depend on the providers configured for the deployment. The final notice must identify applicable providers, processing locations, and transfer arrangements before launch.
When Ask AI is enabled, requests, bounded conversation context, and approved business-tool results may be sent to the configured AI provider. Provider retention and model-training practices must be reviewed and disclosed; this draft makes no unverified no-training or zero-retention promise.
Retention and requests
The production retention and deletion schedule has not yet been approved. It must account for account closure, backup retention, signed agreements, payments, security records, and applicable legal obligations before publication.
Privacy rights and response procedures depend on the applicable jurisdiction and processing relationship. A verified request channel and process for access, correction, export, and deletion must be established before this draft becomes effective. Do not treat a missing contact in this draft as a waiver of any rights.
Security and updates
The application is designed with organization-scoped access controls, server-side validation, restricted public projections, and audit records. No system can guarantee absolute security, and a local preview is not evidence of production certification.
The final notice must include an effective date, a verified privacy contact, and the process for communicating material changes.