← CoreRail

CoreRail Privacy Policy

Last updated: June 4, 2026

This version applies from the date above. It takes effect for you when you accept the Terms of Service or continue using the Service.

Plain-language summary (not part of the policy): CoreRail is software that coffee-shop businesses use to run their operations. This policy explains what personal information we handle, why, and who we share it with. For most data about staff and a shop's own customers, the coffee-shop business decides what to collect and is responsible for it — we process it on their behalf. We use a small number of trusted providers (Square, Resend, our hosting provider) to run the Service. We do not sell personal information or use advertising trackers. This summary does not override the policy below.


This Privacy Policy describes how CoreRail LLC ("CoreRail," "we," "us") collects, uses, and shares personal information in connection with the CoreRail service (the "Service"). It is incorporated by reference into the CoreRail Terms of Service.

1. Our two roles

CoreRail handles personal information in two capacities:

submitted by a coffee-shop business (the "Account Owner") and its authorized users — for example, information about staff, schedules, and the shop's own event-booking customers. The Account Owner decides what to collect and how to use it (it is the "controller" / "business"), and we process that information on the Account Owner's behalf to provide the Service. If you are a staff member or a customer of a coffee shop and you have questions about your data, please contact that business directly.

such as account-registration details, billing records, and security and audit logs — CoreRail decides how it is used and acts as the controller.

2. Information we collect

a. Account and contact information. When an Account Owner registers, we collect names, business name, email address, and (optionally) phone number for the people who administer the account.

b. Authentication and security data. Hashed passwords (we never store passwords in plain text), session identifiers, CSRF tokens, password-reset and invitation tokens, and security/audit logs. Our audit logs record actions taken in the Service together with a keyed hash of the client IP address — we do not store raw IP addresses.

c. Staff and operational data (processed on the Account Owner's behalf). Information the business enters about its staff and operations, such as staff names, emails, phone numbers, availability, time-off, shift swaps, schedules, shift notes and checklists, recipes, inventory, internal messages, metrics, and uploaded images.

d. Event-booking and shop-customer data (processed on the Account Owner's behalf). Where the business uses booking features, contact details for its own customers (such as customer name, email, and phone) tied to event bookings.

e. Point-of-sale (POS) and payment-related data. When an Account Owner connects Square, we receive POS and sales data through Square's API to power reporting and operational features. POS access credentials are stored encrypted (AES-256-GCM). Subscription payments are processed by Square; we do not collect or store full payment-card numbers — Square handles that.

f. Device and notification data. If a user enables push notifications, we store the browser/device push subscription needed to deliver them.

g. Technical and usage data. Limited technical data needed to operate and secure the Service, such as request logs, error logs, and the hashed IP described above.

3. Cookies and similar technologies

The Service uses strictly necessary cookies only — a session cookie (httpOnly, Secure, SameSite=Lax) to keep you logged in and a CSRF-protection cookie to keep the Service secure. We do not use advertising cookies, and we do not use third-party analytics or cross-site tracking. Because these cookies are essential to the Service, it will not function properly if they are blocked.

4. How we use information

We use personal information to:

account notices) and, where enabled, push notifications;

individual, to understand and improve the Service; and

We do not sell personal information, and we do not use it for third-party advertising.

5. How we share information

We share personal information only as needed to run the Service:

infrastructure, send email, deliver push notifications, and process payments.

Owner connects.

protect the rights, safety, or property of CoreRail, our users, or the public.

or sale of assets, subject to this policy.

6. Subprocessors

We rely on a small set of third-party providers to deliver the Service. As of the effective date, these include:

ProviderPurposeData involved
SquarePOS integration and subscription payment processingPOS/sales data; billing/payment information (handled by Square)
ResendTransactional email deliveryRecipient email address and message content
DigitalOceanCloud hosting and storage of the Service and its databasesAll Service data, at rest on our hosted infrastructure
Web push services (browser/OS vendors)Delivery of push notifications, where enabledDevice push subscription

Each provider is bound by its own terms and privacy commitments and is permitted to use the data only to provide its service to us. We may update this list as our providers change; material changes will be reflected in this policy.

7. Data retention

We retain personal information for as long as an account is active and as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, except where longer retention is required for legal, accounting, security, or dispute-resolution purposes. Following termination, the Account Owner may request a data export for 30 days, after which we may delete Customer Data as described in the Terms of Service. Backups and audit logs may persist for a limited additional period before routine deletion.

8. Security

We use reasonable technical and organizational measures to protect personal information, including: encryption of POS credentials (AES-256-GCM), password hashing with scrypt, encrypted transport (HTTPS/TLS), httpOnly/Secure session cookies with CSRF protection, keyed-hash (not raw) storage of IP addresses, and per-tenant data isolation. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Account Owners and users are responsible for safeguarding their credentials and managing who has access to their account.

9. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, or to object to or restrict certain processing.

CoreRail, your information is generally controlled by that business. Please direct your request to the business; we will assist that business in responding as its service provider.

billing data), contact us at Pedeaux@gmail.com and we will respond as required by applicable law. We will not discriminate against you for exercising your rights.

We may need to verify your identity before acting on a request.

10. Children's privacy

The Service is a business tool and is not directed to children under 13, and we do not knowingly collect personal information from them. If a business uses the Service in connection with minor employees, the business is responsible for obtaining any consents required by law.

11. International users

The Service is operated from and hosted in the United States. If you access it from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide notice by email or in-product notice and update the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact us

CoreRail LLC 1043 Independence St., New Orleans, LA 70117 Email: Pedeaux@gmail.com