PagePack

Privacy Policy

Last updated August 28, 2026

Replaces: the privacy notice dated 20 December 2023

1. Introduction

pagepack is a document-authoring and assembly service. Organizations use it to build documents ("pagepacks") from reusable sections and templates, fill in custom fields, and export finished PDFs.

This policy explains what personal information we collect when you use pagepack, why we collect it, who we share it with, and what rights you have over it. It covers:

  • the pagepack web application, wherever we publish it;
  • our marketing website;
  • our email correspondence with you about your account.

It does not cover the content your organization chooses to put into pagepack. That content is handled under Section 5 and under your organization's agreement with us, not under this policy's consent model.

If you are an employee or member of an organization that uses pagepack: your employer or organization controls your account and the documents in it. Questions about why your organization put your information into pagepack should go to your organization first. We will refer such requests to them.

2. Who we are, and how to reach us

pagepack is operated by:

pagepack Software Inc. 10438 76 Ave Edmonton, Alberta T6E 1L1 Canada

Privacy contact: hello@pagepack.io

Person accountable for privacy: our Privacy Officer, reachable at hello@pagepack.io. Address access requests, corrections, complaints and any other privacy question to that address.

3. The two roles we play

pagepack handles two different kinds of information, and our responsibilities differ between them.

Account information — we decide how it is used. Your name, email address, username, password, organization membership and role, and the technical logs generated when you use the service. We determine what we collect and why, and we are accountable for it. This policy describes that processing.

Customer content — your organization decides how it is used. The documents, sections, custom field values, and images your organization creates or uploads. We store and process this only to run the service for you, and only as instructed by your organization. If that content contains personal information about other people — your clients, your staff, the subjects of a report — your organization is responsible for having a lawful reason to put it there, and for answering those people's privacy requests. We will help you respond.

If you signed up on your own rather than being added to an employer's organization, you decide how the content in your own organization is used, and we handle it on your instructions.

4. Account information we collect

4.1 Information you or your administrator gives us

An account can be created in three ways: you can register yourself with an email address and password, you can sign in with a Google account (which creates an account if you do not already have one), or an administrator of an existing organization can create one for you. In the first two cases we also create a new organization for you and make you its administrator.

WhatWhenNotes
UsernameAccount creationRequired; must be unique. When you sign in with Google we generate one from your email address
Email addressAccount creationStored lowercased; used for sign-in, password reset, and service email
PasswordAccount creation, password changeStored only as a salted hash. We never store or can retrieve your plaintext password. Not collected if you only ever sign in with Google
Given name and family nameAccount creation, profile updateOptional when you register yourself; supplied by Google if you sign in with Google; supplied by your administrator when they create your account
Organization membership and roleSet on account creation, or assigned by your administratorDetermines what you can see and do

When an administrator creates an account for you, we email you an invitation link so you can set your own password. The administrator never sees or sets your password.

We do not verify that a self-registered email address belongs to you before the account is created; we rely on Google's verification when you sign in with Google.

4.2 Sign-in with a Google account

Google is the only third-party sign-in provider pagepack accepts. Sign-in attempts using any other provider are refused.

If you sign in with Google, we receive from Google your email address, your Google account identifier (the "subject" ID), and, if you have made it available, your given and family name. We store the account identifier so we can recognise you on your next sign-in. We do not receive your Google password, and we do not get access to your Gmail, Drive, contacts, or any other Google service.

If no pagepack account exists for the verified email address Google gives us, signing in creates one, along with a new organization that you administer.

4.3 Authentication and session information

To keep you signed in and to let you recover a lost password we create and store:

  • Access tokens, valid for one hour, held in your browser's local storage. The same token is also written to a strictly necessary cookie named BEARER, so that requests your browser makes directly — fetching an image or a preview page, for example — are authenticated. That cookie is HttpOnly, so page scripts cannot read it, expires with the token after one hour, and is not used for analytics or tracking.
  • Refresh tokens, valid for three years, stored in our database and in your browser's local storage, so your session can be renewed without you signing in again.
  • Password reset tokens, valid for one hour and single-use, created only when a reset is requested.
  • Your browser's local storage also holds your active user ID and active organization ID, so the app knows which organization's documents to show you. This information stays in your browser; clearing your browser storage removes it.

When you request a password reset we apply a rate limit based on your IP address (currently ten requests per fifteen minutes) to stop attackers from probing which email addresses have accounts. That IP address is used for the rate-limit counter and appears in our server logs; it is not attached to your profile.

4.4 Technical and log information

Our servers record standard operational logs: request paths, response codes, timestamps, error messages and stack traces, and identifiers for the user and organization involved in a request. These logs let us keep the service running, diagnose failures, and investigate abuse. Logs are collected into a self-hosted logging system that we operate; they are not sent to a third-party log analytics vendor.

4.5 Analytics and tracking

We do not use analytics or tracking technologies. There is no third-party analytics service in pagepack, and no advertising pixels, retargeting tags, session-replay tools, or marketing trackers. We do not build a profile of you, and we do not track you across other websites.

What we know about how the service is used comes from the operational logs described in Section 4.4, which we hold ourselves and use to run and secure the service.

4.6 Billing information

pagepack does not process payments in the product. There is no checkout, no stored card, and no payment processor connected to the application. Fees, where they apply, are agreed in a written agreement or order form and invoiced outside the product.

For invoicing we hold ordinary business records: the billing contact's name and email address, the organization's billing address, and the invoices themselves. These are kept in our accounting and email systems, not in the pagepack application. We do not collect or store payment card numbers.

5. Customer content

When your organization uses pagepack, it creates and stores:

  • documents and the sections they are assembled from, including all text and formatting;
  • custom field definitions and the values filled into them;
  • images uploaded into documents;
  • generated PDF exports.

We store this content so we can provide the service. We do not read it, mine it, sell it, or use it to train machine-learning models of our own. Our staff access it only when necessary to operate the service or to provide support you have asked for.

Images are not publicly readable. Every image request is checked against your account and your organization membership before the file is served, and the underlying storage links we generate expire after one hour.

5.1 Document import and AI processing

pagepack offers a document import service that converts existing .docx and PDF files into pagepack sections. This conversion is performed by pagepack staff as an onboarding service using internal administrative tooling; it is not a self-serve feature available inside your account.

During that conversion:

  • Your source file is uploaded to our object storage and converted to HTML by a document-conversion service we operate on Modal, a third-party compute platform.
  • Where a converted document needs correcting, our staff may send the converted HTML, together with a short instruction describing the correction, to Google's Gemini API. Embedded images are stripped out and replaced with placeholder tokens before the content is sent, so image data is not transmitted; the document's text and structure are. The model returns corrected HTML. It is not asked to make decisions about you and its output is reviewed by a pagepack staff member before it is used.

We use Google's paid Gemini API. Under Google's paid API terms, Google commits that prompts and responses sent through it — including the document text and structure we send — are not used to improve Google's products and are not read by human reviewers. That is Google's contractual commitment to us; we pass it on here because it is what governs the content, not as a guarantee we can independently verify. The free Gemini tier carries no such commitment, and we do not use it for customer documents.

6. Why we process your information

PurposeWhat it covers
Providing the serviceCreating and authenticating your account, showing you your organization's documents, saving your work, generating PDF exports
SupportResponding to your questions and diagnosing problems you report
Service communicationPassword reset emails, account invitations, and notices about changes to the service or this policy
Security and abuse preventionRate limiting, access control, detecting and investigating unauthorized access
Reliability and improvementOperational logs and error diagnosis
BillingIssuing and collecting invoices under an order form or written agreement
Legal complianceMeeting our obligations under applicable law and responding to lawful requests

We do not use your personal information for advertising, and we do not sell it.

6.1 Consent

Under PIPEDA and Alberta's PIPA we rely on your consent, which may be express (for example, when you create an account and give us your email address) or implied by your use of the service for an obvious purpose. You may withdraw consent at any time, subject to legal and contractual limits — but withdrawing consent to the processing described in Section 4 means we can no longer provide you an account.

7. Who we share your information with

We do not sell personal information. The providers below are the ones that handle personal information in the course of running pagepack, each on our instructions.

ProviderWhat we send themPurposeWhere they process it
DigitalOceanAll account data, all customer content, database contents, generated PDFs, uploaded images, operational logsApplication hosting, managed database, object storage, container registrySan Francisco (sfo3) — the United States. The application servers, the managed PostgreSQL database and the object storage are all in that region
Postmark (Active Campaign Inc.)Your email address, your display name, and the contents of the messageSending transactional email — password resets and account invitationsUnited States
ModalDocument HTML for PDF rendering; source documents and converted HTML during importPDF generation and document conversionOutside Canada, which may include the United States
Google (Sign-In)The sign-in token issued to you, for verificationVerifying Google sign-inUnited States
Google (Gemini API, paid tier)Converted document text and structure, during staff-performed import only (see 5.1). Image data is masked out before sendingAI-assisted correction of imported documents. Not used to train Google's models and not human-reviewed, under Google's paid API termsUnited States

PDF page rendering also uses Gotenberg and real-time updates use Mercure; both run as services on our own infrastructure and do not send your information anywhere else.

We will provide a current list of these providers to a customer organization on request.

Our support and privacy address, hello@pagepack.io, is a Google Workspace group, so correspondence you send us is stored in Google's systems in the United States.

We may also disclose personal information:

  • When the law requires it — in response to a valid court order, subpoena, warrant, or other lawful request, or to establish or defend legal claims.
  • In a business transfer — if pagepack is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honour this policy, and we will notify you before your information becomes subject to a different policy.

8. Where your information is stored, and transfers outside Canada

pagepack is a Canadian company, but none of our production infrastructure is in Canada. Our application servers, our database, and our object storage are all in DigitalOcean's San Francisco (sfo3) region, in the United States. Our email and AI processing providers are also in the United States.

This means your personal information, and the customer content your organization stores with us, is stored and processed in the United States. While it is there, it is subject to United States law, and the courts, law enforcement, and national security authorities of the United States may be able to obtain access to it. We remain accountable for it, and we require our service providers by contract to protect it and to use it only for the purposes we have specified.

If you are in Quebec. Quebec law treats sending personal information outside the province as a transfer subject to its own requirements, including a written agreement with the recipient. Everything described above is a transfer of that kind, because all of our infrastructure is in the United States.

9. How long we keep your information

InformationRetention
Account information (name, email, username, password hash, organization role)For as long as your account is active
Customer content (documents, sections, custom field values, images)For as long as your organization's account is active. After termination, your organization has 30 days to export it, and we delete it from our active systems within 60 days after that window closes
Access tokens1 hour
Password reset tokens1 hour, and invalidated as soon as they are used
Refresh tokens3 years from the sign-in that created them
Generated PDF exportsExport jobs and the PDF bytes they hold are deleted 24 hours after the job is created
Operational logs30 days
Billing records (invoices, billing contact and address)For as long as required by Canadian tax and corporate record-keeping law
Database backups7 days of point-in-time recovery. Information you delete persists in those backups until they age out, and is gone at the end of that window

When you close your account we delete or anonymise your personal information within 60 days, except where we must keep it to meet a legal obligation, resolve a dispute, or enforce our agreements. Information already written to backups is deleted when those backups expire.

10. How we protect your information

  • All traffic between your browser and pagepack is encrypted in transit using TLS.
  • Passwords are stored only as salted hashes, never in a recoverable form.
  • Access to documents and images is checked on every request against your account and your organization membership; you cannot read another organization's content.
  • Signed links to stored files expire after one hour.
  • Password reset requests are rate limited, and reset responses do not reveal whether an email address has an account.
  • Staff access to production systems is limited to those who need it to operate the service.

No system is perfectly secure. We cannot guarantee that a determined attacker will never defeat our safeguards, and information you send us over the internet travels at some risk. If you believe your account has been compromised, contact us immediately at hello@pagepack.io.

If a breach occurs. If we suffer a breach of security safeguards that creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, as PIPEDA requires. PIPEDA also requires us to keep a record of every breach of security safeguards for 24 months, whatever its severity, and we will. Where we hold content on behalf of a customer organization, we will notify that organization without undue delay so it can meet its own obligations.

11. Your rights

Whatever your location, you may:

  • Access the personal information we hold about you, and ask us how we have used and disclosed it.
  • Correct information that is inaccurate or incomplete.
  • Delete your account and the personal information associated with it, subject to the limits in Section 9.
  • Withdraw consent where we rely on it, understanding that this may mean we can no longer provide the service.
  • Complain about how we have handled your information — see Section 14.

We do not make decisions about you by automated means, and we do not profile you.

To exercise any of these rights, email hello@pagepack.io. We will respond within 30 days, as PIPEDA requires, and will tell you if we need longer and why. We may need to verify your identity before acting on a request.

If you are a member of a customer organization: for requests about content your organization put into pagepack, contact your organization directly. If you contact us instead, we will forward your request to them and tell you we have done so.

12. Cookies and similar technologies

Everything pagepack stores in your browser is there to sign you in and keep you signed in. None of it is used for analytics, advertising or tracking, and we set no third-party cookies of any kind.

Local storage holds exactly four items: your access token, your refresh token, your active user ID, and your active organization ID. The last two tell the application which organization's documents to show you. All four are cleared when you sign out or clear your browser data.

One cookie, BEARER, holds the same one-hour access token, so that files and preview pages your browser requests directly are authenticated (see Section 4.3). It is HttpOnly, so page scripts cannot read it, and it expires with the token. It is strictly necessary — blocking it will stop parts of the application working.

Signing out clears the tokens from your browser and expires the BEARER cookie. It does not delete the refresh token record in our database; that record expires on its own schedule (see Section 9).

We do not respond to "Do Not Track" browser signals, because no common standard for interpreting them has been agreed.

13. Children

pagepack is a business tool, intended for use by adults in a professional capacity. We do not direct the service at children and do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.

14. Complaints

If you have a concern about how we have handled your personal information, email hello@pagepack.io. We will investigate and respond.

If you are not satisfied with our response, you may complain to:

  • Canada: the Office of the Privacy Commissioner of Canada — https://www.priv.gc.ca
  • Alberta: the Office of the Information and Privacy Commissioner of Alberta — https://oipc.ab.ca
  • Quebec: the Commission d'accès à l'information du Québec — https://www.cai.gouv.qc.ca

15. Changes to this policy

We may update this policy as the service and the law change. When we do, we will update the "Last updated" date at the top. If the changes are material — a new category of information, a new purpose, or a new provider we share with — we will give you at least 30 days' notice before they take effect, by email or by a prominent notice in the application, and we will not apply the new purposes to information already collected without a fresh basis for doing so.