← Home

Privacy Policy

Effective date: April 10, 2026

Halion Technologies, LLC ("we", "us", "our") operates StuffPack ("the Service"). This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.

1. Information We Collect

Account information

When you create an account, we collect your email address and display name. If you sign in with Google, we receive your name, email, and profile photo from Google.

Gear and trip data

You provide gear items, packs, trips, and related details (weights, categories, notes, images). This is the core data you create and manage in StuffPack.

Payment information

When you subscribe to a paid plan, payment details (card number, billing address) are collected and processed directly by Stripe, Inc. We do not store your full card number. Stripe provides us with a token, the last four digits of your card, and your billing email. See Stripe's Privacy Policy.

Usage data

We use PostHog to collect anonymous usage analytics such as pages visited, features used, and device type. This helps us understand how the Service is used and where to improve. See PostHog's Privacy Policy.

Session recordings

PostHog also records sessions on the Service so we can diagnose bugs and understand how users interact with features. A session recording captures page navigation, clicks, scrolls, and the layout of what was on screen.

What is masked in recordings:

  • All form inputs, including text fields, dropdowns, textareas, and password fields
  • Specific elements marked for masking by our code (for example, any sensitive text we choose to protect)

What is not masked:

  • Your handle and display name — these are public by design (they appear on your profile and on any gear lists you share), so they may appear in recordings
  • General page layouts, buttons, links, and non-sensitive text you did not type into a form

We do not record keystrokes inside form fields, and payment details never reach our servers or recordings — all payment data is handled directly by Stripe on their own pages.

Recordings are stored on PostHog's infrastructure (not on StuffPack servers) and are retained for approximately 30 days under PostHog's standard retention policy. Our lawful basis for processing session recordings under the GDPR is our legitimate interest in diagnosing bugs and improving the Service. You may object to this processing at any time by contacting us as described below.

Opting out: If you would prefer that your sessions not be recorded, contact us through your account settings and we will exclude your account from recordings.

Log data

Our servers automatically record information such as your IP address, browser type, and request timestamps. This data is used for security, debugging, and service reliability.

2. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To process payments and manage your subscription
  • To send transactional emails (account verification, password resets, billing receipts)
  • To analyze usage patterns and improve the user experience
  • To detect, prevent, and address security issues or abuse
  • To comply with legal obligations

We do not sell your personal information to third parties.

3. Third-Party Services

We use the following third-party services that may receive or process your data:

  • Google Firebase — authentication, database, file storage, and hosting. Firebase Privacy
  • Stripe — payment processing. Stripe Privacy
  • PostHog — product analytics and feature flags. PostHog Privacy

4. Cookies and Local Storage

We use cookies and browser local storage for authentication sessions and user preferences. PostHog may set cookies for analytics purposes. You can disable cookies in your browser settings, but this may affect your ability to use the Service.

5. Data Retention

We retain your account and gear data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or billing purposes.

6. Data Security

We use industry-standard security measures including encrypted connections (TLS), Firebase security rules, and Stripe's PCI-compliant payment infrastructure. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

7. Your Rights

You may:

  • Access, update, or delete your account information at any time through your account settings
  • Export your gear data
  • Request deletion of your account by contacting us
  • Opt out of analytics by disabling cookies or using a browser extension that blocks tracking scripts

If you are located in the European Economic Area (EEA), you may have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy, sign in to your account and contact us through your account settings. If you don't have an account, you can create one for free.

© 2021–2026 Halion Technologies, LLC. All Rights Reserved.