Privacy Policy

Last updated June 2026.

Who we are

CustodyLinx provides compliance, track-and-trace, and chain-of-custody software for licensed operators that move controlled cannabis and hemp product. This policy explains what we collect, how we use it, the legal bases for processing, and the choices available to operators and their users.

Information we collect

Account information (name, work email, role) for the users an operator invites. Operational records the operator enters or generates: packages and regulator UIDs, manifests, custody events, lab results, incidents, and documents. Operational telemetry needed to run the service, including GPS positions for active trips and sensor snapshots (seal, door, temperature). Standard request metadata captured for security and audit: IP address, user agent, and server timestamps. We do not collect consumer purchase data, and we are not built for the dispensary shopper.

How we use information

To deliver and operate the service; to pre-validate manifests and file to the government systems of record on the operator's instruction; to maintain the evidentiary, append-only chain of custody and the audit log; to detect and report diversion within regulator deadlines; to secure the platform and prevent abuse; and to meet legal, tax, and regulatory obligations.

Legal bases

We process personal data to perform our contract with the operator, to pursue legitimate interests in operating and securing the service, and to comply with legal obligations, including the recordkeeping and reporting rules that govern controlled-substance logistics.

Sharing and subprocessors

We file to the government track-and-trace systems the operator directs us to (for example Metrc). We use a small set of subprocessors for cloud hosting, database, object storage, and communications, each under contractual confidentiality and security terms. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Data retention

The custody log and audit trail are append-only and immutable by design. We retain operational and compliance records for as long as the operator's account is active and thereafter as required by applicable cannabis and controlled-substance recordkeeping rules. Backups expire on a rolling schedule.

Security

Tenant data is isolated with row-level security on a default-deny model, enforced in the database rather than only in the application. The custody chain is hash-chained and tamper-evident. Sensitive identifiers are protected, document storage is private with short-lived signed access, and every mutating action is recorded with actor and source.

Your choices and rights

Operator administrators control who has access and at what role. Subject to applicable law and to the operator's compliance obligations, users may request access to or correction of their personal information through their operator administrator. Some records cannot be deleted because they are required regulatory evidence.

International transfers

Where data is processed across borders, we rely on appropriate safeguards and process it consistent with this policy and applicable law.

Changes and contact

We will update this policy as the product and our obligations evolve and will note material changes. Questions can be directed to your CustodyLinx administrator or to the contact channel on this site.