Privacy Policy

Last updated: July 9, 2026

1. Who we are

ParcelTag is a personal hobby project operated by an individual based in Switzerland ("we", "us", "our"). It is not a commercial product. Questions about this policy can be sent to [email protected].

2. Data we collect

We collect the minimum data needed to run the service:

  • Account data — your email address, display name, and profile picture (optional, only if you choose to upload one).
  • Parcel data — tracking numbers, carrier names, labels you assign, and tracking events fetched from carrier websites (location names, timestamps, status codes). We do not store delivery addresses.
  • Technical data — authentication tokens managed by our auth provider, and standard server request logs (IP address, timestamp, HTTP method) retained for security purposes. When you use the public parcel tracking preview (/track), your IP address is temporarily recorded to prevent abuse and protect service availability; these records are deleted automatically after 24 hours.
  • Browser extension data — if you use the ParcelTag browser extension: visible text on the page you choose to scan is analysed locally inside your browser to detect tracking numbers; it is never stored or transmitted anywhere. Tracking numbers you explicitly select and import are added to your account in exactly the same way as adding them manually through the website.
  • Analytics data — we run a self-hosted instance of Rybbit, an open-source, cookieless analytics tool hosted in Switzerland. It records aggregate page-view counts, referrer URLs, browser type, operating system, device category, and the visitor's country (derived from the IP address, which is immediately discarded and never stored). We also record a small number of anonymous product-usage events — for example that a parcel was added, a theme was switched, or a carrier link was opened — together with non-identifying context like a carrier code or status. These events are never linked to your name, email address, account ID, or tracking numbers, and cannot be used to identify you or build a profile of you individually. No personal data is collected, no cookies are set, and data is never sold or shared with third parties.

We do not use advertising trackers or fingerprinting of any kind.

3. How we use your data

  • To create and manage your account.
  • To track parcels and display their status to you.
  • To send transactional emails (delivery status updates, password resets, account notifications). No marketing emails.
  • To detect and prevent abuse of the service.

4. Legal basis for processing (GDPR)

If you are located in the EU or EEA, we process your data on the following bases under Art. 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)) — for operating your account and delivering the service.
  • Legitimate interests (Art. 6(1)(f)) — for server logs and security measures.

For users in Switzerland, processing is governed by the Federal Act on Data Protection (nDSG).

5. Infrastructure & data processors

The web application, email delivery, and analytics are self-hosted on servers in Switzerland. We use one external processor:

  • Supabase Inc. — database, authentication, and file storage. Data is stored on Supabase servers located in Switzerland. Supabase Inc. does not use your data for any purpose other than providing the service.

All data remains in Switzerland. No personal data is transferred outside Switzerland.

6. Data retention

  • Account data is retained while your account is active and deleted within 30 days of an account deletion request.
  • Parcel data is retained until you delete the parcel or your account.
  • Server logs are retained for up to 90 days.

7. Cookies

We use a single session cookie set by Supabase Auth to keep you logged in. This cookie is strictly necessary and does not track you across other websites. We do not use analytics or advertising cookies.

The browser extension reads this session cookie from parceltag.app solely to synchronise your login state inside the extension. The cookie value is processed locally within your browser and is not transmitted to any third party.

8. Browser extension

The ParcelTag browser extension is available for Chrome and Firefox. It operates as follows:

  • Session synchronisation — the extension reads the Supabase authentication cookie set by parceltag.app to synchronise your logged-in session. No data leaves your browser during this step.
  • Page scanning— when you click "Scan this page", the extension reads the visible text of the current tab to detect potential tracking numbers. The text is processed entirely within your browser; it is never stored or transmitted anywhere.
  • Parcel import — tracking numbers you explicitly select and confirm are sent to our database (Supabase) identically to adding them manually through the website.
  • Local storage— the extension stores your authentication session tokens and a short-lived cache of carrier names in the browser's extension-local storage (browser.storage.local). This storage is accessible only to the extension and is not shared with any website or other extension.

The extension requests the following browser permissions: activeTab and scripting (to read page text on demand), cookies (to read the ParcelTag session cookie for login synchronisation), storage (to persist session and carrier cache), and tabs (to detect when you navigate to the ParcelTag dashboard so the session can be imported automatically).

9. Your rights

Under the nDSG and GDPR you have the right to access, correct, delete, export, restrict, or object to the processing of your personal data. To exercise any of these rights, contact us at [email protected].

You can delete your account yourself from Settings → Danger Zone. All associated data will be removed within 30 days.

You also have the right to lodge a complaint with a supervisory authority:

  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC / EDÖB): www.edoeb.admin.ch
  • EU / EEA — your local data protection supervisory authority.

10. Security

We use industry-standard measures including encrypted connections (HTTPS), hashed passwords (managed by Supabase Auth), and row-level security on the database. No system is 100% secure; use the service accordingly.

11. Children

ParcelTag is not directed at children under 16. We do not knowingly collect data from anyone under 16.

12. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top will reflect any changes. Continued use of the service after changes constitutes acceptance of the updated policy.

13. Contact

For any privacy-related questions or requests, email us at [email protected].

See also: Terms of Service