Back to Home Terms of Service

Privacy Policy

Effective date: August 15, 2026

CoreStack Technologies (“CoreStack,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the information entrusted to us. This Privacy Policy describes how we collect, use, disclose, process, and safeguard information when you visit our website, use the CoreStack Traceability & Anti-Counterfeit Platform, scan product QR codes through AuthentiScan, communicate with us, or otherwise interact with CoreStack.

This Privacy Policy applies to information collected through our websites, platform services, consumer verification features, business communications, and related activities for food traceability and anti-counterfeit operations.

1. Information We Collect

Depending on how you interact with us, we may collect the following categories of information:

Contact and account information

Information such as your name, company name, title, email address, phone number, mailing address, and the contents of communications submitted through forms, support channels, or email.

Traceability and facility data (business customers)

Information related to food traceability operations, including lot and unit identifiers, scan events (receiving, transformation, shipping), aggregation records, shipment data, recall queries, traceability plans, facility identifiers, and related operational metadata processed through the Serialization System.

AuthentiScan consumer verification data

When a consumer or other end user scans a product QR code through AuthentiScan (mobile app or browser), we may collect scan timestamps, verification results, product and lot identifiers, IP address, approximate geographic location derived from IP, device type and browser, and — where you grant permission in the mobile app — GPS coordinates. This data supports counterfeit detection, revocation enforcement, and audit trails.

Internet and device information

Information such as IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, approximate geographic location derived from IP address, usage activity, and timestamps.

Cookies and similar technologies

Information collected through cookies, analytics tools, pixels, local storage, and related tracking technologies. Additional details are described in the Cookies & Tracking Technologies section below.

Where applicable under law, we process information where necessary to:

3. How We Use Information

We may use information to:

4. How We Share Information

We may share information with:

Service providers

Third-party vendors and service providers that support hosting, analytics, cloud infrastructure, communications, customer relationship management, operational systems, security, or technical support services, subject to contractual confidentiality obligations.

Brand customers and regulators

Traceability records and AuthentiScan verification events may be shared with the food manufacturer or brand customer that deployed the platform, and with regulatory authorities when required by law, lawful process, or to protect public health.

Professional advisors

Lawyers, auditors, accountants, consultants, insurers, or similar professional advisors where reasonably necessary.

Legal and regulatory authorities

Government entities, regulators, courts, law enforcement agencies, or third parties where required by law, legal process, or to protect rights, property, systems, or safety.

We do not sell personal information for monetary compensation as traditionally understood. Where required by applicable law, we will honor rights related to certain disclosures or sharing activities that may be classified as a “sale” or “sharing.”

5. Third-Party Platforms and Integrations

Our services may integrate with or rely on third-party systems and providers, including:

Information processed through those services may also be governed by the respective privacy policies and terms of those third parties.

6. Business Transfers

Information may be transferred, disclosed, or otherwise processed as part of a merger, acquisition, financing transaction, reorganization, bankruptcy proceeding, sale of assets, or similar corporate transaction, subject to applicable confidentiality and legal requirements.

7. Your Privacy Rights (United States)

Depending on your jurisdiction, you may have rights to:

California residents (CCPA/CPRA)

California residents may have additional rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), including the right to know, correct, delete, and opt out of certain sharing activities.

We do not knowingly sell personal information of individuals under 16 years of age.

Requests may be submitted using the contact information listed below. We may verify requests as required by applicable law.

8. Do Not Track Signals

Our website does not currently respond to browser “Do Not Track” signals or similar automated mechanisms.

9. Children’s Privacy (COPPA)

Our services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13.

If you believe a child under 13 has provided us with personal information, please contact us and we will take appropriate steps to delete such information.

10. Cookies & Tracking Technologies

We and our analytics or service partners may use cookies, pixels, local storage, session identifiers, and related technologies to:

You may control cookies through browser settings. Disabling certain cookies may affect site functionality.

11. Security & Retention

We implement commercially reasonable administrative, technical, organizational, and physical safeguards designed to protect information against unauthorized access, disclosure, misuse, or destruction.

While we strive to protect information using industry-aligned practices, no method of transmission, storage, or security system can guarantee absolute security.

We retain information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, or support legitimate business operations.

12. International Users (including GDPR)

If you access our services from outside the United States — including the European Economic Area — information may be transferred to, processed in, or stored in the United States or other jurisdictions where privacy laws may differ from those in your location.

Where GDPR applies, we process personal data based on legitimate interests (platform security, fraud prevention, traceability compliance), contract performance, legal obligation, or consent (e.g., GPS in the mobile app). You may have rights to access, rectify, erase, restrict, or port your data, and to object to certain processing. Contact us using the details below to exercise these rights.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically.

When updates are made, we will revise the effective date and post the updated version on this page. Where required by law or where changes are material, additional notice may be provided.

14. Contact Us

For privacy-related questions, requests, or concerns, contact:

CoreStack Technologies

Back to Home Terms of Service