Summary
Pallet is built to collect as little about you as possible.
- No account required. No name, email, or phone number.
- No advertising, no behavioral analytics, no third-party trackers.
- Crash reports and usage metrics use Apple's standard anonymous diagnostics — nothing else.
- We do not sell or share your data.
- The only information our servers hold is an opaque CloudKit identifier provided by Apple and the tracking numbers you ask us to track.
What We Collect
CloudKit user identifier. We use Apple's CloudKit service to identify your account. CloudKit gives us an opaque identifier that is unique to you within Pallet but is not your Apple ID, name, email, or any other personal information. We cannot use it to identify you outside the app. It is provided by Apple and is stable across your devices signed into the same iCloud account, which is how your tracked packages stay in sync.
Tracking numbers. When you add a package, the tracking number is sent to our servers and associated with your CloudKit identifier. We use it to fetch and forward status updates from the relevant carrier.
Carrier-supplied tracking events. Status, timestamps, and scan locations returned by the carrier for each tracking number you've added.
Push notification token. If you enable notifications, Apple provides a token tied to your device. We use it solely to deliver status-change updates for your packages.
Subscriptions and Purchases
If you purchase a Pallet Pro subscription, the purchase is processed entirely by Apple. Pallet does not receive or store your payment card details or other billing information.
To provide Pro features, our servers store your subscription status and tier and an Apple-provided original transaction identifier associated with your CloudKit identifier. We also receive App Store Server Notifications from Apple about your subscription (for example, renewals, cancellations, or billing issues) so we can keep your Pro status current. This information is used only to manage entitlements and is not used for advertising.
What Stays on Your Device
Anything you personalize stays on your device and is never sent to our servers. This includes the title or label you assign to a package, notes, custom sort order, and app preferences. Our servers only ever see the raw tracking number, not what you've named it.
How We Use This Information
- To fetch package status from carriers and display it to you.
- To send a push notification when a package's status changes.
- To synchronize your tracked packages across your devices.
- To diagnose crashes and improve reliability.
Who We Share It With
Only the parties needed to deliver the service:
- 17track and AfterShip — our tracking data aggregators. We send tracking numbers to these services so they can return up-to-date carrier status. They do not receive your CloudKit identifier.
- Shipping carriers (e.g., FedEx) — for carriers we integrate with directly, receive tracking numbers when we query their tracking endpoints. They do not receive your identifier.
- Apple Push Notification service (APNs) — receives notification payloads addressed to your device token.
- Our cloud hosting provider — stores the data described above under standard data-processing terms.
We do not share data with advertisers, data brokers, or analytics networks. We may disclose information if required by valid legal process.
Analytics and Crash Reporting
We use Apple's standard, anonymous diagnostics — the same crash reports and usage metrics that any iOS app receives through App Store Connect when users opt in at the system level. This data is aggregated by Apple, is not tied to your identity, and is shared with us only in anonymous form. You can disable it at any time in iOS Settings → Privacy & Security → Analytics & Improvements → Share with App Developers.
We do not use Google Analytics, Firebase Analytics, Mixpanel, or any other third-party analytics SDK.
Retention and Deletion
You can remove any package at any time from within the app. When you do, we delete the association between your CloudKit identifier and that tracking number.
The tracking events themselves (status, timestamps, scan locations) are public carrier data and may be retained in an unassociated form so they can be served to other users tracking the same package.
To remove your data, delete the app or use the in-app delete option. This removes all associations between your CloudKit identifier and the tracking numbers you've added.
Security
Data in transit is encrypted with HTTPS/TLS. Data at rest is stored under industry-standard access controls.
Children
Pallet is not directed to children under 13, and we do not knowingly collect information from them.
California Residents
We do not sell or share personal information as defined under the California Consumer Privacy Act. California residents may exercise their rights of access and deletion by emailing support (at) getpallet (dot) app. Because we hold only an opaque CloudKit identifier and tracking numbers, requests should reference the tracking number(s) in question.
International Users
Pallet is operated from the United States, and our servers and cloud hosting are located there. If you use Pallet from outside the United States, the information described above — your opaque CloudKit identifier, the tracking numbers you add, and the carrier events returned for them — is transferred to and stored in the United States.
Wherever you live, you may ask us what we hold about you, ask for a copy of it, or ask us to delete it. Email support (at) getpallet (dot) app. Because we hold no name, email address, or phone number, we cannot look you up by identity — please include the tracking number(s) in question so we can locate the records. We respond within 30 days.
Our tracking data aggregators (17track and AfterShip) and the carriers themselves operate internationally and may process a tracking number in the country the shipment is travelling through. We do not send them your CloudKit identifier.
United Kingdom and European Economic Area
Where the UK GDPR or EU GDPR applies, Pallet is the controller of the data described in this policy.
We rely on these lawful bases:
- Performance of a contract — storing your tracking numbers and fetching carrier status is the service you asked us for.
- Consent — push notifications, which you turn on yourself and can turn off at any time in iOS Settings.
- Legitimate interests — keeping the service reliable and preventing abuse of our carrier quotas. We have weighed this against your interests; the data involved is a tracking number and an opaque identifier, and it is never used to profile you.
You have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and the right to receive it in a portable form. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. Exercise any of these by emailing us at the address above.
Pallet's delivery-window estimates are informational only. We do not carry out automated decision-making that produces legal or similarly significant effects.
Transfers to the United States are made under the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, as applicable, together with the data minimisation described in this policy.
If you believe we have handled your data improperly, we would like the chance to put it right — but you may also complain to your national supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
Canada
We handle personal information in accordance with PIPEDA and, for residents of Quebec, Quebec's Law 25. We do not sell personal information or use it for cross-context behavioural advertising.
Our privacy contact is reachable at support (at) getpallet (dot) app. You may ask for access to, or correction or deletion of, the information we hold. If a confidentiality incident presents a risk of serious injury, we will notify affected users and the applicable regulator as required.
You may also complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec.
Australia and New Zealand
We handle personal information in accordance with the Australian Privacy Principles and, in New Zealand, the Privacy Act 2020. As described above, tracking numbers and carrier events are stored on servers in the United States and shared with our tracking aggregators, which may process them overseas.
You may request access to or correction of your information by emailing us at the address above. Complaints can be made to the Office of the Australian Information Commissioner (oaic.gov.au) or the New Zealand Office of the Privacy Commissioner (privacy.org.nz).
Changes
We may update this policy. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by an in-app notice.
Contact
Pallet
support (at) getpallet (dot) app
For privacy questions, use the same address and include the tracking number(s) your request concerns.