Privacy Policy
Effective date: August 15, 2026
CoreStack Technologies (“CoreStack,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the information entrusted to us. This Privacy Policy describes how we collect, use, disclose, process, and safeguard information when you visit our website, use the CoreStack Traceability & Anti-Counterfeit Platform, scan product QR codes through AuthentiScan, communicate with us, or otherwise interact with CoreStack.
This Privacy Policy applies to information collected through our websites, platform services, consumer verification features, business communications, and related activities for food traceability and anti-counterfeit operations.
1. Information We Collect
Depending on how you interact with us, we may collect the following categories of information:
Contact and account information
Information such as your name, company name, title, email address, phone number, mailing address, and the contents of communications submitted through forms, support channels, or email.
Traceability and facility data (business customers)
Information related to food traceability operations, including lot and unit identifiers, scan events (receiving, transformation, shipping), aggregation records, shipment data, recall queries, traceability plans, facility identifiers, and related operational metadata processed through the Serialization System.
AuthentiScan consumer verification data
When a consumer or other end user scans a product QR code through AuthentiScan (mobile app or browser), we may collect scan timestamps, verification results, product and lot identifiers, IP address, approximate geographic location derived from IP, device type and browser, and — where you grant permission in the mobile app — GPS coordinates. This data supports counterfeit detection, revocation enforcement, and audit trails.
Internet and device information
Information such as IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, approximate geographic location derived from IP address, usage activity, and timestamps.
Cookies and similar technologies
Information collected through cookies, analytics tools, pixels, local storage, and related tracking technologies. Additional details are described in the Cookies & Tracking Technologies section below.
2. Legal Bases for Processing
Where applicable under law, we process information where necessary to:
- Provide requested services and operational support;
- Operate, maintain, and improve our platforms and systems;
- Comply with legal obligations;
- Protect the security, integrity, and reliability of our services;
- Pursue legitimate business interests, including analytics, operational improvements, fraud prevention, and platform optimization; and
- Process information based on consent where required.
3. How We Use Information
We may use information to:
- Provide, operate, and improve the Traceability & Anti-Counterfeit Platform;
- Capture lot data, process scan events, support recall scoping, and export traceability records;
- Verify product authenticity, detect clones, and enforce revocation lists through AuthentiScan;
- Respond to inquiries, demo requests, pilot partnerships, and support requests;
- Share traceability or verification data with brand customers, regulators, or law enforcement when required by law or authorized by the brand customer;
- Send administrative communications, service notices, security alerts, and updates;
- Analyze usage trends, monitor operational performance, and improve user experience;
- Support analytics, automation, reporting, and AI-readiness initiatives;
- Detect, prevent, investigate, or address fraud, abuse, security incidents, or technical issues;
- Protect the rights, safety, and property of CoreStack, our customers, partners, users, and others; and
- Comply with applicable legal obligations and enforce agreements.
4. How We Share Information
We may share information with:
Service providers
Third-party vendors and service providers that support hosting, analytics, cloud infrastructure, communications, customer relationship management, operational systems, security, or technical support services, subject to contractual confidentiality obligations.
Brand customers and regulators
Traceability records and AuthentiScan verification events may be shared with the food manufacturer or brand customer that deployed the platform, and with regulatory authorities when required by law, lawful process, or to protect public health.
Professional advisors
Lawyers, auditors, accountants, consultants, insurers, or similar professional advisors where reasonably necessary.
Legal and regulatory authorities
Government entities, regulators, courts, law enforcement agencies, or third parties where required by law, legal process, or to protect rights, property, systems, or safety.
We do not sell personal information for monetary compensation as traditionally understood. Where required by applicable law, we will honor rights related to certain disclosures or sharing activities that may be classified as a “sale” or “sharing.”
5. Third-Party Platforms and Integrations
Our services may integrate with or rely on third-party systems and providers, including:
- Cloud infrastructure and database hosting;
- ERP, WMS, and commerce system integrations;
- Email, notification, and communication providers;
- Analytics and monitoring platforms; and
- Security and audit tooling.
Information processed through those services may also be governed by the respective privacy policies and terms of those third parties.
6. Business Transfers
Information may be transferred, disclosed, or otherwise processed as part of a merger, acquisition, financing transaction, reorganization, bankruptcy proceeding, sale of assets, or similar corporate transaction, subject to applicable confidentiality and legal requirements.
7. Your Privacy Rights (United States)
Depending on your jurisdiction, you may have rights to:
- Access personal information we maintain about you;
- Request correction of inaccurate information;
- Request deletion of certain information;
- Obtain a copy of certain information;
- Opt out of certain processing activities, including targeted advertising or sharing activities as defined by law; and
- Appeal decisions regarding privacy requests.
California residents (CCPA/CPRA)
California residents may have additional rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), including the right to know, correct, delete, and opt out of certain sharing activities.
We do not knowingly sell personal information of individuals under 16 years of age.
Requests may be submitted using the contact information listed below. We may verify requests as required by applicable law.
8. Do Not Track Signals
Our website does not currently respond to browser “Do Not Track” signals or similar automated mechanisms.
9. Children’s Privacy (COPPA)
Our services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13.
If you believe a child under 13 has provided us with personal information, please contact us and we will take appropriate steps to delete such information.
10. Cookies & Tracking Technologies
We and our analytics or service partners may use cookies, pixels, local storage, session identifiers, and related technologies to:
- Remember preferences and settings;
- Understand site usage and operational performance;
- Improve user experience;
- Measure content and campaign effectiveness; and
- Support analytics, security, and platform optimization.
You may control cookies through browser settings. Disabling certain cookies may affect site functionality.
11. Security & Retention
We implement commercially reasonable administrative, technical, organizational, and physical safeguards designed to protect information against unauthorized access, disclosure, misuse, or destruction.
While we strive to protect information using industry-aligned practices, no method of transmission, storage, or security system can guarantee absolute security.
We retain information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, or support legitimate business operations.
12. International Users (including GDPR)
If you access our services from outside the United States — including the European Economic Area — information may be transferred to, processed in, or stored in the United States or other jurisdictions where privacy laws may differ from those in your location.
Where GDPR applies, we process personal data based on legitimate interests (platform security, fraud prevention, traceability compliance), contract performance, legal obligation, or consent (e.g., GPS in the mobile app). You may have rights to access, rectify, erase, restrict, or port your data, and to object to certain processing. Contact us using the details below to exercise these rights.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically.
When updates are made, we will revise the effective date and post the updated version on this page. Where required by law or where changes are material, additional notice may be provided.
14. Contact Us
For privacy-related questions, requests, or concerns, contact:
CoreStack Technologies
- Email: info@corestacktechnologies.com
- Careers: career@corestacktechnologies.com