Privacy policy
Last updated: September 3, 2026
Short version
We collect the minimum we need to ship PacketMole to you, plus what Stripe needs to process your card. We don't see, route, or store any of your internet traffic. We don't sell customer data. We share the information needed to process orders, deliver packages, operate our systems, and provide support with the providers below.
What we collect
- Your email address (so we can send order confirmation and tracking)
- Your shipping address (so we can ship to you)
- Your name as it appears on the shipping label
- The optional setup-card name and order notes you provide at checkout
- Order ID, payment status, and order timestamps
- The policy version and time you accept the Terms before checkout
- Tracking, delivery status, address-verification results, and fulfillment records
- A device identifier and the time it last authenticated to our update server
- Messages and diagnostic information you choose to share when asking for support
What we don't collect
- Your credit card number — Stripe handles that; we never see it
- The content of your internet traffic or browsing history through routine product operation
- Your Tailscale account password. If you explicitly share a device for support, we can access the diagnostics and settings needed for that session; revoke the share when support is finished.
Who we share it with
- Stripe — for payment processing. See their privacy policy at stripe.com/privacy.
- The shipping carrier (USPS / UPS) — your name and shipping address are on the label.
- Pirate Ship — recipient and shipment information to purchase shipping labels.
- EasyPost — address information for verification and carrier/tracking information for delivery monitoring.
- Cloudflare — website, order database, update hosting, security, and operational request processing. A pending, unreleased Away-unit firmware update is designed to use Cloudflare's public 1.1.1.1/1.0.0.1 DNS resolvers for connected clients; this disclosure applies when that update is installed.
- Resend — recipient addresses and content of transactional or support emails we send through it.
- Dropbox and our business email providers — private fulfillment records, support correspondence, and internal operational access.
We use order information for fulfillment, support, fraud/compliance checks, and recordkeeping. We may disclose information when legally required. Accepting purchase Terms does not subscribe you to promotional email. Tailscale operates your separate account under its own privacy policy; its coordination and relay services process their own connection metadata.
How long we keep it
Device last-contact entries expire after 90 days without a successful authenticated request to our update server. Device registration credentials remain separately while needed for updates and recovery. Support records are retained while needed to resolve your request and related warranty or recordkeeping obligations. Ask us about access, correction, or deletion using the contact below; some records must be retained for legal obligations.
Order records are kept for as long as we need to fulfill warranty, returns, and tax obligations (typically 7 years for tax records). If you want your record removed sooner, email hello@packetmole.com and we'll discuss what we can remove vs. what we need to retain for compliance.
Cookies / analytics
We use Cloudflare Web Analytics on public informational pages to count visits and referrers and to measure aggregate page performance, including Core Web Vitals. It does not use analytics cookies or local storage, and Cloudflare states that it does not fingerprint individual visitors for this service. We do not enable the browser analytics beacon on checkout, order-status, API, or archived-policy pages. We do not use advertising pixels or cross-site behavioral tracking.
We also keep a separate cookie-free aggregate count for the same reviewed public pages. Before anything is sent, the browser reduces the page to a fixed category and the HTTPS referrer to Google referral, recognized AI assistant, direct, or other. The aggregate contains only those two categories, a count, and Cloudflare's event timestamp. It does not contain a URL or path, query string, raw referrer, IP address, user agent, cookie, geography, visitor or session identifier, or any customer or order information. It is not enabled on checkout, order-status, API, manuals, archives, assets, redirects, or error pages. These counts can include bots and reloads and are not unique people, sessions, or conversions.
Cloudflare also provides hosting and security processing. Like other hosting providers, it processes request metadata such as IP addresses and user agents. That operational metadata and the aggregate website measurements above are distinct from the content of traffic passing through your PacketMole routers, which we do not see, route, or store.
Contact
Privacy questions: hello@packetmole.com.