CoreRail Privacy Policy
Last updated: June 4, 2026
This version applies from the date above. It takes effect for you when you accept the Terms of Service or continue using the Service.
Plain-language summary (not part of the policy): CoreRail is software that coffee-shop businesses use to run their operations. This policy explains what personal information we handle, why, and who we share it with. For most data about staff and a shop's own customers, the coffee-shop business decides what to collect and is responsible for it — we process it on their behalf. We use a small number of trusted providers (Square, Resend, our hosting provider) to run the Service. We do not sell personal information or use advertising trackers. This summary does not override the policy below.
This Privacy Policy describes how CoreRail LLC ("CoreRail," "we," "us") collects, uses, and shares personal information in connection with the CoreRail service (the "Service"). It is incorporated by reference into the CoreRail Terms of Service.
1. Our two roles
CoreRail handles personal information in two capacities:
- As a service provider / processor. Most information in the Service is
submitted by a coffee-shop business (the "Account Owner") and its authorized users — for example, information about staff, schedules, and the shop's own event-booking customers. The Account Owner decides what to collect and how to use it (it is the "controller" / "business"), and we process that information on the Account Owner's behalf to provide the Service. If you are a staff member or a customer of a coffee shop and you have questions about your data, please contact that business directly.
- As a controller. For information we collect to operate our own business —
such as account-registration details, billing records, and security and audit logs — CoreRail decides how it is used and acts as the controller.
2. Information we collect
a. Account and contact information. When an Account Owner registers, we collect names, business name, email address, and (optionally) phone number for the people who administer the account.
b. Authentication and security data. Hashed passwords (we never store passwords in plain text), session identifiers, CSRF tokens, password-reset and invitation tokens, and security/audit logs. Our audit logs record actions taken in the Service together with a keyed hash of the client IP address — we do not store raw IP addresses.
c. Staff and operational data (processed on the Account Owner's behalf). Information the business enters about its staff and operations, such as staff names, emails, phone numbers, availability, time-off, shift swaps, schedules, shift notes and checklists, recipes, inventory, internal messages, metrics, and uploaded images.
d. Event-booking and shop-customer data (processed on the Account Owner's behalf). Where the business uses booking features, contact details for its own customers (such as customer name, email, and phone) tied to event bookings.
e. Point-of-sale (POS) and payment-related data. When an Account Owner connects Square, we receive POS and sales data through Square's API to power reporting and operational features. POS access credentials are stored encrypted (AES-256-GCM). Subscription payments are processed by Square; we do not collect or store full payment-card numbers — Square handles that.
f. Device and notification data. If a user enables push notifications, we store the browser/device push subscription needed to deliver them.
g. Technical and usage data. Limited technical data needed to operate and secure the Service, such as request logs, error logs, and the hashed IP described above.
3. Cookies and similar technologies
The Service uses strictly necessary cookies only — a session cookie (httpOnly, Secure, SameSite=Lax) to keep you logged in and a CSRF-protection cookie to keep the Service secure. We do not use advertising cookies, and we do not use third-party analytics or cross-site tracking. Because these cookies are essential to the Service, it will not function properly if they are blocked.
4. How we use information
We use personal information to:
- provide, operate, maintain, and secure the Service;
- authenticate users and prevent fraud, abuse, and unauthorized access;
- deliver transactional emails (e.g., invitations, password resets, billing and
account notices) and, where enabled, push notifications;
- process subscriptions and billing through our payment processor;
- provide support and respond to requests;
- generate aggregated or de-identified analytics that do not identify any
individual, to understand and improve the Service; and
- comply with legal obligations and enforce our Terms.
We do not sell personal information, and we do not use it for third-party advertising.
5. How we share information
We share personal information only as needed to run the Service:
- Subprocessors / service providers (see Section 6) that host our
infrastructure, send email, deliver push notifications, and process payments.
- As directed by the Account Owner, including with integrations the Account
Owner connects.
- Legal and safety — when required by law, subpoena, or legal process, or to
protect the rights, safety, or property of CoreRail, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing,
or sale of assets, subject to this policy.
6. Subprocessors
We rely on a small set of third-party providers to deliver the Service. As of the effective date, these include:
| Provider | Purpose | Data involved |
|---|---|---|
| Square | POS integration and subscription payment processing | POS/sales data; billing/payment information (handled by Square) |
| Resend | Transactional email delivery | Recipient email address and message content |
| DigitalOcean | Cloud hosting and storage of the Service and its databases | All Service data, at rest on our hosted infrastructure |
| Web push services (browser/OS vendors) | Delivery of push notifications, where enabled | Device push subscription |
Each provider is bound by its own terms and privacy commitments and is permitted to use the data only to provide its service to us. We may update this list as our providers change; material changes will be reflected in this policy.
7. Data retention
We retain personal information for as long as an account is active and as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, except where longer retention is required for legal, accounting, security, or dispute-resolution purposes. Following termination, the Account Owner may request a data export for 30 days, after which we may delete Customer Data as described in the Terms of Service. Backups and audit logs may persist for a limited additional period before routine deletion.
8. Security
We use reasonable technical and organizational measures to protect personal information, including: encryption of POS credentials (AES-256-GCM), password hashing with scrypt, encrypted transport (HTTPS/TLS), httpOnly/Secure session cookies with CSRF protection, keyed-hash (not raw) storage of IP addresses, and per-tenant data isolation. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Account Owners and users are responsible for safeguarding their credentials and managing who has access to their account.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, or to object to or restrict certain processing.
- If you are a staff member or a customer of a coffee shop that uses
CoreRail, your information is generally controlled by that business. Please direct your request to the business; we will assist that business in responding as its service provider.
- For information CoreRail controls (such as Account Owner registration and
billing data), contact us at Pedeaux@gmail.com and we will respond as required by applicable law. We will not discriminate against you for exercising your rights.
We may need to verify your identity before acting on a request.
10. Children's privacy
The Service is a business tool and is not directed to children under 13, and we do not knowingly collect personal information from them. If a business uses the Service in connection with minor employees, the business is responsible for obtaining any consents required by law.
11. International users
The Service is operated from and hosted in the United States. If you access it from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide notice by email or in-product notice and update the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact us
CoreRail LLC 1043 Independence St., New Orleans, LA 70117 Email: Pedeaux@gmail.com