Privacy Policy

Last updated 2026-10-09. This explains what Pallet King stores, where it is stored, who else is involved, and what you can ask us to do about it. It is written against this application’s actual behaviour, not a template.

The short version

QuestionAnswer
Do you upload my booking files?No. Excel, CSV and PDF booking lists are parsed in your browser. There is no upload path in the application.
Do you see my cargo data?No. Build records and parsed lines live on your device. They reach our servers only if you use a save or share action that sends them.
Are there advertising or analytics trackers?No. There are no third-party analytics, advertising, social or session-replay scripts on this site.
Are there cookies?No cookies are set. We use browser storage instead — listed in section 4.
Do you sell or rent personal data?No.
Is payment data handled here?Paid checkout is not live. When it is, a third-party merchant of record processes payment; we do not receive card numbers.

1. Who is responsible

珠海市香洲区卓浚零售和批发商行 (Zhuojun Retail and Wholesale Firm, an individual business operator registered in Zhuhai, Guangdong, China) operates https://www.aircargo.hk. Contact for privacy matters: support@aircargo.hk. Registered or place of business: Xiangzhou District, Zhuhai, Guangdong, China (个体工商户 / individual business operator).

2. Account data

If you register, we store the identifier you sign up with and the minimum needed to authenticate and gate features:

DataWhyBasis
Phone number (SMS sign-in) or email and a password hash (email sign-in), or the profile from a third-party sign-in providerCreating and authenticating your accountPerformance of a contract — you asked for the account
Display name, if providedShowing who is signed inPerformance of a contract
Access and refresh tokens, held in your browserKeeping you signed inPerformance of a contract
Entitlement record: plan level, trial end date, quota used and totalDeciding which features you may useLegitimate interests — operating the plan you signed up for

3. Booking and build data (on your device)

Cargo lines, dimensions, weights, pallet build plans, completion records, unit and theme preferences are written to your browser’s own storage — local storage, session storage and IndexedDB. They are not transmitted to us. Practical consequences you should know:

4. Browser storage we use

No cookies are set. The storage keys, all first-party, are:

KeyWherePurposeNecessary?
pka-locale, pka-unit, pka-mode, pka-rolelocal storageYour language, metric/imperial, office/field and role choicesYes — you set them
pka_trial_recordlocal, session storage and IndexedDB (AES-GCM encrypted)Counting guest build-plan usage so the free tier worksYes — for the free tier as offered
pka-fp-v1, pka_fp, pka_fp_legacysession storageA device identifier used with the trial count; recalculated when the tab closesSee section 5
pka-analytics-sessionsession storageA random session id so funnel events can be grouped within one visitNo — but see section 6
pka-lead-fallbacklocal storageHolds a contact request locally if the network fails, so you can retryYes — protects what you typed

5. Device fingerprinting — disclosed plainly

To count a guest’s free build-plan uses when there is no account, the application computes a device identifier from slowly-changing browser characteristics: the user-agent family, language, platform, time zone, CPU and memory tiers, a canvas rendering signature, a WebGL renderer signature, and screen dimensions and colour depth. It is hashed in the browser, kept in session storage, and sent to our own backend only as an opaque identifier when the trial quota is checked.

We call this out because it is the one item here that a reader should reasonably object to. Our stated purposes are limited to free-tier accounting and basic abuse prevention. Our legal basis is legitimate interests, weighed against the fact that the signal is coarse, not persisted across browser sessions, and not combined with advertising data. We do not use it to identify individuals, and we do not treat it as a security boundary — it is deliberately a soft measure.

6. Product analytics we operate ourselves

Pricing-page interactions are recorded in our own database, not in a third-party service. The event set is fixed and small: pricing_view, plan_card_click, billing_toggle, cta_click, lead_form_open, lead_form_submit, lead_form_abandon, feature_table_scroll, free_limit_hit, paywall_view. Each row may carry the plan and billing cycle involved, your interface language, a session id, and your user id if you are signed in.

Basis: legitimate interests, in understanding whether the pricing we offer is workable. This is not cross-site tracking and no analytics script from another domain runs on this page.

7. Contact requests (leads)

If you submit the “request access” form we store the email you give us, and optionally your company name, contact name, the plan and billing cycle you chose, a seat estimate, your message, and your interface language. Purpose: to reply and to prepare a quote. Basis: your request. We do not add you to a marketing list on the strength of a contact request.

8. Error reporting

An optional error-reporting endpoint can be configured by the operator. When configured, client-side errors are sent with a message, a truncated stack trace and the page URL. These fields are scrubbed before sending, because a stack trace can contain values parsed from a booking file and a URL can contain sign-in tokens. When no endpoint is configured, nothing leaves the browser.

9. Who else is involved

ProviderRoleWhat they see
VercelHosting and content deliveryRequests for pages and files, including IP address and user-agent in platform logs
SupabaseAuthentication, database and serverless functionsAccount data, entitlements, leads and analytics events described above
CloudflareDNS and the contact mailboxMail sent to the contact address
A merchant of record (not yet enabled)Payment processing, invoicing, taxYour billing details at checkout, under their own terms

We do not maintain a separate list of sub-processors beyond these, and we will disclose changes here before using a new provider for personal data.

10. Where your data is stored, and what that means for transfers

Account, lead and analytics data are stored in the Supabase project backing this application, in ap-south-1 (Mumbai, India) — that is, on infrastructure physically located in India. Booking and build data is stored only on your device and never reaches this region.

Stated plainly, because it is the part an operator would otherwise gloss over: India is not covered by an adequacy decision of the EU, the United Kingdom or Switzerland. For a user in those jurisdictions, therefore, personal data associated with an account, a contact request or an analytics event is a third-country transfer rather than a domestic one.

Your locationWhat appliesWhat we rely on
EEA / UK / SwitzerlandGDPR or UK GDPR, including its Chapter V transfer rulesThe standard contractual clauses published by Supabase and by our hosting provider, plus the minimisation described in sections 2 to 8
China (mainland)PIPL, including cross-border transfer rulesWe keep the personal information we hold to the account, contact and event fields listed above
ElsewhereLocal privacy law as it applies to youThe same disclosures and the same deletion route in section 11

11. Retention — stated as it actually is

We do not currently run an automated deletion schedule for contact requests or analytics rows. Account data is kept while the account exists. Device-side data is kept until you clear it, and session-scoped items disappear when the tab closes.

On request we will delete your account, your contact request, and any analytics rows tied to your user or session identifier. Contact ${CONTACT()} and we will confirm when it is done.

12. Your rights

Depending on where you are — including under the EU/UK GDPR, California’s CPRA, and China’s PIPL — you may be able to access, correct, delete, or port your personal data, object to or withdraw consent for processing, restrict processing, and complain to your supervisory authority. Where we rely on legitimate interests, you can object and we will assess our grounds against yours.

There is no self-service export yet, so these are handled by email. We will not require more identity information than we need to confirm the request, and we will not ask you to create an account in order to exercise a right.

13. Do Not Track and Global Privacy Control

A GPC or DNT signal is honoured in substance because there is nothing to opt out of: no third-party trackers, no advertising, and no sale or sharing of personal data for cross-context behavioural advertising.

14. Security

Row-level security gates database access so a signed-in user cannot read another user’s records; the content security policy restricts which scripts and connections the page may make; device trial records are encrypted before being written to browser storage. No system is perfect, and browser storage is readable by anyone with access to the device or its profile — which is why the sensitive material, your cargo data, is never sent to us in the first place.

15. Children, and changes to this policy

This is a business tool for air cargo professionals and is not directed at children under 16; we do not knowingly collect their data. If material changes are made to this policy we will update the date above and, for changes that reduce rights, announce them in the application.