HeadFirstServices LLC · Last updated: June 2026
HeadFirstServices LLC ("we", "us", or "our") operates the following mobile applications (collectively, "the Apps"):
This Privacy Policy applies to all of the above. Where practices differ between apps, that is noted explicitly.
When you create an account you provide your email address and a password (stored as a salted hash — we never see it in plain text). A unique user ID is generated and associated with all your data.
You may optionally provide a home currency and passport / nationality. This is used to personalise the app experience and is never sold or shared with advertisers.
Trip records you create include: destination country, city, start and end dates, passport used for entry, and optional free-text notes. This data is stored securely in your account and is not accessible to other users.
Packing lists you create include: destination(s), travel dates, trip purpose, transport type, bag type, and individual packing items with their status (packed / used / not used / wish I'd brought). Post-trip feedback you submit is stored to power personalised future recommendations — within your account only.
If you enable push or email notifications, we store your configured alert rules (e.g. days before visa expiry) and your device push token. You can delete or disable these at any time from within the app.
We do not collect analytics, crash reports, advertising identifiers, or behavioural tracking data. We do not use any third-party analytics SDK.
Subscription purchases are processed by RevenueCat and the underlying app store (Apple App Store or Google Play). We receive only a subscription status flag (active / expired). Your payment card details are never transmitted to or stored by us.
We do not use your data for advertising, profiling, or sale to third parties.
We use the following sub-processors. Each is bound by a Data Processing Agreement (DPA) where required.
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | All user account and app data | US East (AWS) |
| Resend Inc. | Transactional email delivery | Your email address and message content | United States |
| RevenueCat Inc. | Subscription management | App store purchase receipts, subscription status | United States |
| Open-Meteo | Weather forecasts PackLite | Destination coordinates (no personal identifiers) | European Union |
No other third parties receive your personal data. The Apps contain no advertising SDK, social login, or third-party tracking library.
Your data is retained for as long as your account exists. If you delete your account, all personal data associated with that account is permanently deleted from our systems within 7 days, except where retention is required by applicable law.
Anonymised, non-identifiable aggregates may be retained indefinitely.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@headfirstservices.com. We will respond within 30 days.
If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
You can delete your account directly within each app (Profile → Delete Account). This opens an email to privacy@headfirstservices.com; your account and all associated data will be permanently deleted within 7 days.
Deleting your account in one app does not affect accounts in our other apps — each app maintains a separate data scope.
You may also submit a deletion request here: delete-account page.
In the event of a personal data breach likely to result in risk to your rights and freedoms, we will:
Your data is stored on servers in the United States (Supabase / AWS US East). If you are in the European Economic Area, this constitutes a transfer of personal data outside the EEA. Such transfers are covered by Standard Contractual Clauses (SCCs) incorporated into our agreement with Supabase.
The Apps are not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@headfirstservices.com and we will delete it promptly.
We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, row-level security on all database tables so users can only access their own data, and bcrypt password hashing. No method of internet transmission is 100% secure, but we take reasonable precautions to protect your information.
When we update this policy, we will revise the "Last updated" date above. For material changes, we will notify you by email or in-app notice at least 14 days before the change takes effect. Continued use of the Apps after that date constitutes acceptance.
HeadFirstServices LLC — Washington State, USA
Email: privacy@headfirstservices.com
For GDPR enquiries or to exercise your data rights, use the same address. We aim to respond within 30 days.