Privacy Policy

Effective: April 16, 2026

Privacy Policy

Effective Date: April 2026

Last Updated: April 2026

Introduction

Boxie ("we," "us," "our," or "Company") believes that if you respect your customers, they appreciate and respect you back. We think analytics and tracking have gotten out of hand across our industry and others, and we've chosen to do things differently.

Boxie collects only the first-party data needed to operate our service — full stop. We don't track you across our app, we don't build behavioral profiles, and we don't collect data to sell or monetize. We already have what we need to serve you well just by doing business with you. Interacting with a brand should be your choice, based on the quality of the service and experience we offer — not because we've tracked you into a corner.

This Privacy Policy explains what we collect, why, and what we do with it when you use our website (getboxie.com), mobile application, and related services (collectively, the "Services"). We are a Colorado-based cardboard recovery and recycling service and we comply with applicable privacy laws, including the Colorado Privacy Act.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Services.

1. Information We Collect

We collect only the information necessary to operate our Services. We do not track app usage patterns, behavioral analytics, or advertising metrics.

1.1 Information You Provide Directly

Account Registration Information:

  • Full name
  • Email address
  • Phone number
  • Physical address(es) for pickup and delivery
  • Account login credentials

Service Request Information:

  • Delivery and pickup location details
  • Photos of cardboard items you wish to have picked up or delivered
  • Special instructions or notes about your service requests
  • Preferred service dates and times

Payment Information:

  • Payment card details are collected and stored exclusively by Stripe, our payment processor. Boxie never sees, stores, or has access to your full card number, CVV, or bank account information.
  • Boxie retains only non-sensitive transaction metadata (order total, last 4 digits of card, Stripe transaction ID, billing name, and transaction status) for receipt, refund, and record-keeping purposes.

Communication Information:

  • Messages you send us via email, chat, or our contact forms
  • Feedback, surveys, and reviews you submit
  • Customer service inquiries and correspondence

Sustainability Tracking:

  • Data about cardboard weight and types recycled
  • Preferences for sustainability reports and recycling certificates

1.2 Information Collected Automatically

Location Data:

  • For Customers: We collect your delivery and pickup addresses to fulfill service requests.
  • For Drivers: We collect GPS location data during driver shifts to optimize routes, dispatch services, and ensure safety. This data is retained for 30 days.

Device and Crash Reporting Data:

  • Device type, operating system, and version (collected only when a crash or error occurs)
  • IP address (used for security and to route requests; not used for tracking)
  • Crash logs and error diagnostics to identify and fix bugs

We do not collect device advertising identifiers (IDFA/GAID), and we do not track which pages you visit, how long you spend in the app, or your interaction patterns.

Cookies and Similar Technologies:

  • Session cookies to maintain your login
  • Preference cookies to remember your settings

We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Service Fulfillment

  • Schedule and execute cardboard pickups and deliveries
  • Optimize driver routes and dispatch logistics
  • Provide gently used box inventory matching to your needs
  • Process payments and generate receipts
  • Send order confirmations and service updates

2.2 Bug Fixes and Reliability

  • Diagnose crashes and errors to keep the app working reliably
  • Troubleshoot technical issues reported by users

2.3 Sustainability Tracking

  • Calculate the environmental impact of cardboard recycled
  • Generate sustainability reports and recycling certificates
  • Support our partners' municipal sustainability initiatives
  • Prepare anonymized impact statistics

2.4 Communication

  • Send transactional emails (order updates, receipts, confirmations)
  • Respond to customer inquiries and support requests
  • Send service notifications and important announcements
  • Send marketing communications (only if you opt-in)

2.5 Compliance and Legal Obligations

  • Comply with applicable laws and regulations
  • Maintain financial records for tax and legal purposes
  • Prevent fraud and unauthorized access
  • Enforce our Terms of Service and other agreements

3. How We Share Your Information

We will never sell your personal information. Not now, not ever. We do not rent, trade, or otherwise monetize your data to third parties. We share your information only with trusted third-party service providers who help us deliver our Services, and they are bound by confidentiality and data protection obligations.

3.1 Third-Party Service Providers

Stripe (Payment Processing):

  • All payment transactions are processed directly by Stripe. Boxie never stores, accesses, or transmits your payment card numbers, CVV, or bank account details. Payment information is entered directly into Stripe's secure PCI DSS-compliant environment.
  • We receive only a transaction token and basic confirmation data (amount, last 4 digits of card, transaction status) necessary to associate a payment with your order.
  • Stripe's own privacy policy governs their handling of your payment data: https://stripe.com/privacy

Resend (Transactional Email):

  • We share your email address with Resend to deliver order confirmations, receipts, and service notifications
  • Resend processes only transactional emails you have requested

Google Places API (Address Autocomplete):

  • We use Google Places API to verify and autocomplete addresses you enter
  • Limited address information is shared to provide this functionality
  • Google's privacy policy applies to this service

Anthropic (AI-Powered Photo Analysis):

  • When you submit photos of cardboard for pickup estimation, we may share these images with Anthropic's AI services
  • Anthropic analyzes photos to estimate cardboard quantity and type
  • Photos are used only for this estimation purpose
  • Anthropic is bound by confidentiality obligations

Supabase (Database Hosting):

  • Your account data and service information are stored on Supabase infrastructure
  • Supabase maintains security and confidentiality of hosted data

3.2 Legal Requirements and Safety

We may disclose your information if required by law or when we believe in good faith that disclosure is necessary to:

  • Comply with court orders, legal processes, or government requests
  • Enforce our Terms of Service and other agreements
  • Protect the security or integrity of our Services
  • Prevent or address fraud, security, or technical issues
  • Protect the rights, privacy, safety, or property of Boxie, our users, or the public

3.3 Business Transfers

If Boxie is involved in a merger, acquisition, bankruptcy, or asset sale, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

4. Data Retention

Boxie retains your account data for the life of your account. We do not automatically delete your personal information on a rolling schedule. Your data remains available so that you can access your full service history, past receipts, recycling certificates, and sustainability metrics whenever you need them.

4.1 When We Do Delete Data

We delete your personal information in the following circumstances:

  • Account deletion: When you delete your account (available directly in the app), your personal information is anonymized immediately.
  • Short-retention data categories: Certain narrow categories of operational data are deleted on a shorter schedule regardless of account status, because they are not needed beyond their immediate operational purpose (see below).
  • Legal obligation: When we are legally required to delete data.

4.2 Short-Retention Operational Data

The following narrow categories are retained only as long as needed for their operational purpose:

Data Type Retention Period Reason Driver GPS location data (shift tracking) 30 days Route optimization and dispute resolution only Cardboard estimation photos 30 days Service fulfillment and dispute resolution

Your customer service addresses, order history, ratings, and sustainability metrics are retained for the life of your account.

4.3 Post-Deletion Retention Exceptions

Even after account deletion, we may retain limited information where legally required or necessary, including:

  • Financial records and transaction history: Retained for 7 years for tax, accounting, and audit compliance.
  • Fraud prevention and abuse records: Retained as needed to prevent fraud and protect the Services.
  • Anonymized or aggregated data: Data that no longer identifies you (such as total tonnage recycled across all users) may be retained indefinitely for analytics and sustainability reporting.

4.4 Data Deletion Process

Upon account deletion, your personal information is anonymized immediately, except as noted in Section 4.3. No waiting period, no runaround.

5. Your Privacy Rights and Choices

Depending on your location and applicable laws, you may have certain rights regarding your personal information.

5.1 Access and Portability

You have the right to request access to the personal information we hold about you and to receive it in a portable format.

5.2 Deletion

You can delete your account and anonymize your data directly from the app at any time — no hoops to jump through, no email required, no waiting period. Unless you choose to delete, we retain your data for the life of your account so you keep full access to your service history. Upon deletion, your personal information is anonymized immediately, subject only to the limited exceptions described in Section 4.3 (financial records required by law and anonymized/aggregated data).

5.3 Correction

You have the right to request correction of inaccurate personal information. You can update much of your information directly in your account settings.

5.4 Opt-Out of Communications

You may opt-out of non-essential communications (such as marketing emails) by:

  • Clicking the "unsubscribe" link in any promotional email
  • Adjusting your notification preferences in your account settings
  • Contacting us at privacy@getboxie.com

Note: We will continue to send transactional communications (order confirmations, receipts, service notifications) as these are necessary for service fulfillment.

5.5 California and Colorado Privacy Rights

If you are a Colorado resident, you have rights under the Colorado Privacy Act (CPA). If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA). Even if you may not qualify for statutory protections due to our size, we honor applicable privacy rights as a matter of policy.

To exercise any of these rights, please contact us at privacy@getboxie.com with a clear description of your request. We will respond within 45 days (or as required by applicable law).

5.6 Do Not Track

We honor "Do Not Track" (DNT) and Global Privacy Control (GPC) signals. Because we do not engage in behavioral tracking, analytics, or targeted advertising, there is very little to disable — but we respect these signals as a matter of principle. When your browser sends a DNT or GPC signal, we treat it as an opt-out of any non-essential data collection. Essential cookies required for the Services to function (such as login sessions) will continue to operate.

6. Data Security

We implement industry-standard security measures to protect your personal information against unauthorized access, disclosure, alteration, and destruction.

6.1 Security Measures

  • Encryption of data in transit (HTTPS/TLS)
  • Secure payment processing through PCI DSS-compliant Stripe
  • Access controls and authentication mechanisms
  • Regular security audits and vulnerability assessments
  • Employee confidentiality agreements

6.2 Limitations

While we implement comprehensive security measures, no method of data transmission or storage is completely secure. We cannot guarantee absolute security, and you use our Services at your own risk. Please notify us immediately of any suspected security breaches.

7. Children's Privacy

Our Services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will take steps to delete such information and terminate the child's account.

For users between 13 and 18, we provide additional privacy protections and limit the collection of location data and photos.

If you believe we have collected information from a child under 13, please contact us at privacy@getboxie.com.

8. International Data Transfers

Boxie operates in the United States (Colorado). If you access our Services from outside the United States, your information may be transferred to, stored in, and processed in the United States. By using our Services, you consent to the transfer of your information to the United States and the application of U.S. laws.

9. Third-Party Links and Services

Our website and app may contain links to third-party websites and services that are not operated by Boxie. This Privacy Policy applies only to information collected through our Services. We are not responsible for the privacy practices of third-party websites and encourage you to review their privacy policies.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Posting the updated policy on our website
  • Sending you an email notification for significant changes

Your continued use of our Services after changes become effective constitutes your acceptance of the updated Privacy Policy.

11. Data Protection Officer and Privacy Contact

For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us by email. If a physical mailing address is required by law for a specific request (such as formal legal notices), one will be provided upon request.

Email: privacy@getboxie.com

Response Time: We will respond to privacy inquiries within 30 days of receipt.

12. Additional Information for Specific Jurisdictions

12.1 Colorado Residents

Under the Colorado Privacy Act, you have the right to:

  • Know what personal information is collected, used, and shared
  • Access the personal information we maintain
  • Delete personal information
  • Correct inaccurate personal information
  • Opt-out of targeted advertising and sales

To exercise these rights, contact privacy@getboxie.com.

12.2 California Residents

Under the California Consumer Privacy Act (CCPA), you have the right to:

  • Know what personal information is collected and how it is used
  • Delete personal information collected from you
  • Opt-out of the sale or sharing of personal information
  • Non-discrimination for exercising your rights

Boxie does not sell personal information. We share data with third-party service providers strictly to operate our Services under contracts that prohibit them from using your data for their own purposes. We also honor Global Privacy Control (GPC) signals as a universal opt-out. For any questions, contact privacy@getboxie.com.

13. Accountability and Transparency

13.1 Data Processing

We process personal information only for the purposes stated in this policy. We do not use personal information for purposes unrelated to our business operations without your explicit consent.

13.2 Data Minimization

We believe the best way to protect data is to not collect it in the first place. We do not track app usage patterns, run behavioral analytics, or collect advertising identifiers. The data we do collect is already what we need to understand how to improve our service and serve you better — we don't need to follow you around the internet to do that. We collect only what is needed to operate the service, fix bugs, and meet legal obligations.

14. Glossary of Terms

Personal Information: Any information that identifies, relates to, or could reasonably be linked with an individual.

Processing: Any operation performed on personal information, including collection, use, storage, disclosure, or deletion.

Third-Party Service Provider: A company that processes personal information on our behalf under a contract that includes confidentiality obligations.

Location Data: Information about the geographic location of a user or device, including GPS coordinates and addresses.

Contact and Support

If you have questions, concerns, or complaints about our privacy practices, please contact us at:

privacy@getboxie.com

We are committed to working with you to resolve any privacy concerns. If you are unsatisfied with our response, you may have the right to lodge a complaint with your state's attorney general or the appropriate regulatory authority.

Last Updated: April 2, 2026 Version: 1.0