Privacy Policy
Version 1 · platform default policy
This policy explains how this platform processes, on behalf of the brand, the personal data you provide during product registration and after-sales service.
Introduction and scope
The platform is a business-to-business, multi-tenant platform for one-item-one-code product authentication and warranty. Each brand that uses the platform is the data controller of its consumers' personal data, and the platform acts solely as its data processor, handling data on the brand's documented instructions. This policy describes, in general terms, how such data is processed on the platform; where a brand publishes its own privacy notice, that notice governs its consumers.
Personal data we collect
During product registration, warranty activation and after-sales service we collect the identity and contact details you provide — name, email address, country/region and preferred language — and, optionally, phone number, purchase date, purchase channel and proof of purchase (such as a receipt). We also process warranty, repair-ticket and support-message records associated with your product.
Scan and anti-counterfeiting data
When a code is scanned, we record limited technical data to detect counterfeiting and grey-market diversion: a coarse location (country and city inferred from your network, with NO precise or GPS geolocation), a daily-salted SHA-256 hash of your IP address (the raw IP address is NOT stored), and your browser type. This data is processed for anti-counterfeiting and channel-integrity purposes; the salt rotates daily, so the hash cannot be linked back to an individual over time.
How we use personal data
We use the data to register products, manage warranties, provide repair and support services, send essential service notifications, detect and investigate counterfeiting or grey-market activity, and maintain the security and integrity of the platform. Marketing messages are sent only where you have given separate, opt-in consent.
Legal bases for processing
Where the GDPR applies, we rely on: performance of a contract (Art. 6(1)(b)) for product registration, warranty and repair services; legitimate interests (Art. 6(1)(f)) for anti-counterfeiting, grey-market detection, fraud prevention and platform security; consent (Art. 6(1)(a)) for optional marketing communications; and compliance with legal obligations (Art. 6(1)(c)) where retention or disclosure is required by law. You may object to processing based on legitimate interests as described under Your rights.
Data retention
We retain data only as long as necessary for the purposes above. Scan events are retained for 90 days; evidence attached to scan alerts is retained for 3 years to support counterfeit investigations; audit logs are retained for compliance and security purposes. Consumer account and warranty data are retained while you own the product and for legally required periods, unless you request erasure earlier. If a brand tenant is deleted, its data is retained for a 90-day recovery window and then permanently purged.
Sharing and sub-processors
We do not sell personal data. We share data with vetted sub-processors that help us operate the service under contractual data-protection terms, including: Supabase (database and authentication), Vercel (hosting), Cloudflare (Turnstile CAPTCHA / bot protection) and Resend (transactional email); and — only where the brand connects it — Anthropic (Claude, via MCP) and e-commerce platforms the brand integrates (such as Shopify, Shopline, Shopee or WooCommerce). Data may also be disclosed to comply with law or to protect rights and safety.
International data transfers
Your data is primarily hosted and processed in Australia (Sydney region, ap-southeast-2). Our service providers may also process data in other countries outside your own, including outside the EEA/UK and outside Japan. Where such transfers occur, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, to ensure your data receives an equivalent level of protection.
Cookies and similar technologies
We use strictly necessary cookies to keep you signed in, maintain your session and secure forms. On public verification and registration pages we use Cloudflare Turnstile, a privacy-preserving CAPTCHA that helps block automated abuse without traditional tracking. We do not use advertising cookies. You can control non-essential cookies through your browser settings.
Data security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, role-based access control, tenant isolation, audit logging and the IP-hashing described above. No system is perfectly secure, but we work to protect your data and to notify the relevant brand and, where required, authorities and affected individuals in the event of a personal-data breach.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interests. On this platform, a consumer erasure request is fulfilled by anonymising your data (GDPR-compliant erasure), which removes its link to you while preserving aggregate integrity. Because the brand is the data controller, you may exercise these rights through the brand or its support channel; we will assist the brand in responding.
Children's privacy
The service is intended for use by adults and is not directed at children. We do not knowingly collect personal data from children below the age of digital consent in their jurisdiction. If you believe a child has provided personal data, please contact the brand or the platform so it can be removed.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology or legal requirements. Material changes will be indicated by updating the version number and, where appropriate, through additional notice. Continued use of the service after an update constitutes acceptance of the revised policy.
Contact us
For questions about this policy or to exercise your rights, contact the brand through its support channel or reach the platform via your account. Because each brand is the controller of its consumers' data, requests are best directed to the relevant brand, which the platform will support as processor.