recore
Sign inStart Free Trial

Privacy Policy

Last updated: July 17, 2026

Overview

reCore is an ITAD operations platform. We process the minimum data necessary to provide the Service. We do not sell your data, we do not serve ads, and we do not share your information with third parties except as described below.

Information we collect

Account information. When you register, we collect your organization name, contact email, and administrator name. Technician accounts are created by your administrator with a name and PIN. We do not collect personal email addresses for technicians.

Device data. When devices are processed through reCore, the client software collects hardware specifications (serial number, manufacturer, model, CPU, RAM, storage), diagnostic test results, data wipe records, and cosmetic grades. This data is tied to your organization's account, not to individual end users.

Usage data. We collect basic usage metrics: login timestamps, operations processed, and subscription usage counts. This is used for billing and service reliability.

Payment information. Payments are processed by Stripe. We do not store credit card numbers or bank account details on our servers. See Stripe's privacy policy for details on their data handling.

How we use your data

We use your data to:

  • Provide and operate the reCore platform
  • Generate compliance certificates and audit reports
  • Process billing and manage your subscription
  • Send transactional emails (account confirmations, billing receipts)
  • Monitor service reliability and fix issues

We do not use your device data for any purpose other than providing the Service to you. We do not train machine learning models on your data. We do not profile your processing activities for marketing purposes.

Data isolation and multi-tenancy

reCore is a multi-tenant platform. Every database query is filtered by your organization's tenant ID. Your device records, test results, wipe certificates, and user accounts are logically isolated from all other organizations. No other customer can access your data.

Data storage and security

Your data is stored in PostgreSQL databases hosted on infrastructure secured with encryption at rest and in transit (TLS 1.2+). Access to production systems is restricted to authorized personnel. Authentication tokens are stored server-side and expire after inactivity.

Wipe certificates include a SHA-256 file integrity hash to detect any post-generation modifications. Audit logs are append-only and cannot be modified or deleted through the application interface.

Third-party services

We use the following third-party services:

  • Stripe: payment processing and subscription management
  • DigitalOcean: server hosting (data stored in the US)

We do not use third-party analytics, advertising networks, or tracking pixels on the reCore platform or this website. The full list, including what each processor is used for, is maintained on our subprocessors page.

Data retention

Your data is retained for as long as your account is active. If you cancel your subscription, your data remains accessible in read-only mode. Upon account deletion, we retain data for 90 days to allow retrieval, after which it is permanently deleted from all systems including backups.

Wipe certificates and compliance records may be retained longer if required by applicable regulations. We will notify you if this applies to your data.

Your rights

You have the right to:

  • Export your data at any time through the platform's reporting features
  • Delete your account and all associated data by contacting us
  • Correct inaccurate account information through your admin dashboard
  • Restrict processing by cancelling your subscription (data preserved, processing stops)

For data subject requests under GDPR, CCPA, or equivalent regulations, contact us at the address below. We respond to all requests within 30 days.

California privacy rights

reCore's current size does not meet the CCPA's applicability thresholds: we are well under the revenue and data-volume levels that make compliance legally mandatory. We describe the rights below anyway, and extend them as a matter of policy to every user regardless of location, because we think that's the right default for a company handling ITAD compliance data.

We do not sell or share personal information. We have not sold or shared personal information in the preceding 12 months, and we do not use personal information for cross-context behavioral advertising. Because of this, there is no "Do Not Sell or Share My Personal Information" link on this site. There is nothing to opt out of.

Categories of personal information we collect, in the statutory sense:

  • Identifiers: name, work email, organization name
  • Professional information: job role (administrator, technician), organization affiliation
  • Internet or network activity: login timestamps, session activity, operations processed
  • Commercial information: subscription plan, billing history (via Stripe)
  • Account credentials: statutorily "sensitive" personal information, but used only to authenticate you, which is a permitted purpose. We do not use or disclose it for anything beyond that, so there is no "Limit the Use of My Sensitive Personal Information" link either.

Sources: directly from you or your organization's administrator at signup, and automatically through your use of the Service.

Purposes: operating the Service, generating compliance certificates and reports, billing, transactional email, and service reliability. See "How we use your data" above.

Recipients: our service providers (Stripe and DigitalOcean, see the subprocessors page for detail). We do not disclose personal information to any other category of third party.

Your rights under the CCPA, which we extend to all users: the right to know what personal information we hold about you, the right to delete it, the right to correct inaccuracies, the right to opt out of sale or sharing (inapplicable, we do neither), the right to limit use of sensitive personal information (inapplicable, see above), and the right to non-discrimination for exercising any of these rights. You may also designate an authorized agent to submit a request on your behalf.

How to exercise these rights: email privacy@replugit.com. Because reCore operates exclusively online with a direct account relationship with you, email is our designated request method. We don't maintain a toll-free number. We verify your identity by matching the request to your existing, authenticated account. We'll confirm receipt within 10 business days and respond substantively within 45 calendar days, with one possible 45-day extension for complex requests (we'll tell you if that applies).

Cookies

The reCore dashboard uses session cookies for authentication. This website (recore.replugit.com) uses a theme preference cookie. We do not use tracking cookies, third-party cookies, or cookie-based analytics.

Changes to this policy

We may update this policy to reflect changes in how we handle data. Material changes will be communicated via email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

Privacy questions or data subject requests? Contact us at privacy@replugit.com