Privacy Policy

Website: p4p.pro4soft.com · Last updated: May 13, 2026

This Privacy Policy describes how Pro4Soft Inc. ("Pro4Soft", "we", "us") collects, uses, and protects personal information through the P4P Packing website at p4p.pro4soft.com and the associated REST API (collectively, the "Service"). It applies to visitors of the Service, registered API users, and anyone who contacts us via the website.

1. Personal Information We Collect

We collect only what is needed to operate the Service. Specifically:

  • Contact form submissions. When you fill in the form at /contact, we receive the name, email, optional company, and message you provide. This is delivered to our support inbox by email.
  • Account registration. If you register for an API key, we store your email address, a hashed password, your API key, and your account balance (starter credit and any subsequent top-ups).
  • API usage data. Requests made with your API key are logged with timestamps and request size so we can compute usage and enforce rate limits. Packing results that you submit are retained for thirty (30) days to support result retrieval via the public result-by-ID endpoint, then deleted automatically.
  • Server log files. Standard web logs capture IP address, user agent, request path, and timestamp.
  • Analytics. We use Google Analytics to measure traffic. Google sets cookies and may receive your IP address (truncated where supported), referrer, page URL, and basic device data. We do not link this analytics data to your account.

2. Cookies and Log Files

We use the following cookies:

  • Authentication cookies (P4PMember, P4PAdmin) — set after login, used to keep you signed in. HttpOnly and SameSite=Strict.
  • Google Analytics cookies (_ga, _ga_*) — set by Google's gtag script to measure unique visitors and sessions.

You can refuse or delete cookies through your browser settings. Doing so may break the login flow on this site. The use of cookie-blocking extensions or browser settings is at your own discretion, and we are not responsible for any resulting loss of functionality.

3. How We Share Personal Information

We do not sell personal information. We share it only with the following categories of service providers ("sub-processors"), and only to the extent needed for them to perform their function:

  • Google LLC — analytics (Google Analytics).
  • Microsoft Corporation — cloud hosting and database infrastructure (Microsoft Azure).
  • SMTP / email delivery provider — used to deliver contact-form messages to our support inbox.

We do not transmit personal information to any party outside this list, except where required by law (court order, lawful regulatory request, or to protect our rights).

4. Storage Period

We retain personal information for as long as it serves the purpose for which it was collected:

  • Contact-form messages: up to twelve (12) months after the last reply.
  • Account registration data: for the lifetime of the account, plus a six (6) month grace period after account closure.
  • API usage logs: thirteen (13) months.
  • Packing result payloads: thirty (30) days from submission, then deleted by automatic TTL.
  • Server log files: six (6) months.

5. Hosting

The Service is hosted on Microsoft Azure, operated by Microsoft Corporation (One Microsoft Way, Redmond, WA 98052, USA) and its affiliates. Microsoft's security, compliance, and data-protection commitments for Azure are described at learn.microsoft.com/azure/compliance and in the Microsoft Products and Services Data Protection Addendum.

6. Data Controller

The controller for personal information collected through this Service is Pro4Soft Inc. Contact: support@pro4soft.com, or use the form at /contact.

Pro4Soft commits to protecting personal information in its possession, not sharing it with third parties beyond the sub-processors listed in Section 3, and notifying affected users in the event of a confirmed data breach.

7. Right of Objection and Withdrawal

You may, at any time, object to the processing of your personal information for purposes you did not consent to, or withdraw your consent for purposes where consent is the lawful basis. To do so, email support@pro4soft.com with your account email so we can verify your identity.

8. Right of Access, Rectification, and Erasure

You may request a copy of the personal information we hold about you, ask us to correct inaccurate data, or ask us to delete it entirely. Send the request to support@pro4soft.com from the email address on file. We respond within thirty (30) days.

9. Security

We protect personal information using:

  • HTTPS (TLS) for all traffic to and from the Service.
  • HTTP Strict Transport Security (HSTS).
  • Passwords stored using a one-way salted hash, never in plain text.
  • HttpOnly and SameSite=Strict authentication cookies.
  • Role-based access to backend systems, restricted to authorized Pro4Soft personnel.

No system is perfectly secure. We cannot guarantee that an attack will not occur, but we do commit to investigating any breach, notifying affected users, and reporting it to applicable regulators where required.

10. Changes to This Policy

This policy is published at p4p.pro4soft.com/privacy and may be updated from time to time. Material changes will be reflected in the "Last updated" date above. We recommend reviewing this page periodically.

11. Acceptance

Your use of the Service constitutes acknowledgement of this Privacy Policy. If you do not agree with any part of it, do not use the Service.

12. Applicable Law

This policy is governed by:

  • Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5 (Canada);
  • Personal Information Protection Act (PIPA), SA 2003, c P-6.5 (Alberta).

Additional rights for users in the European Economic Area and California are set out in Sections 13 and 14.

13. Information for Users in the European Economic Area (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation ("GDPR") applies to our processing of your personal data.

Lawful bases

We rely on the following lawful bases under Article 6 GDPR:

  • Contract performance (Art. 6(1)(b)) — for account registration, API key issuance, billing, and processing API requests you submit.
  • Legitimate interests (Art. 6(1)(f)) — for security logging, rate-limit enforcement, fraud prevention, and short-term aggregated traffic analytics.
  • Consent (Art. 6(1)(a)) — for optional analytics cookies where consent is the appropriate basis under local rules. You may withdraw consent at any time via your browser settings.
  • Legal obligation (Art. 6(1)(c)) — where we must retain records for tax, accounting, or law-enforcement purposes.

Your rights

Under GDPR you have the right to: access your data, request rectification, request erasure ("right to be forgotten"), restrict processing, object to processing, request data portability, and lodge a complaint with your local supervisory authority. Contact support@pro4soft.com to exercise any of these rights.

International transfers

Personal data hosted on Microsoft Azure may be stored in or accessed from regions outside the European Economic Area, including the United States. Microsoft relies on the EU–U.S. Data Privacy Framework and the European Commission's Standard Contractual Clauses as the safeguards for such transfers. Google Analytics data may similarly be processed in the United States under Standard Contractual Clauses.

14. Information for California Residents (CCPA / CPRA)

If you are a resident of California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you the following rights with respect to personal information we collect about you:

  • Right to know what categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it. This is disclosed in Sections 1, 2, and 3 of this policy.
  • Right to delete personal information we hold about you, subject to limited exceptions (e.g., active billing records).
  • Right to correct inaccurate personal information.
  • Right to opt out of the "sale" or "sharing" of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • Right of non-discrimination — we will not deny service, charge a different price, or provide a different level of service because you exercised a CCPA right.

To exercise any of these rights, email support@pro4soft.com from the address on your account, or submit a request through /contact. We will verify your identity before fulfilling the request and respond within forty-five (45) days.

15. Children

The Service is not intended for, and we do not knowingly collect personal information from, persons under the age of 16. If we learn that we have collected such information, we will delete it.