Effective Date: July 1, 2026 · Last Updated: July 1, 2026
Stackpine LLC ("Stackpine," "we," "us," or "our") provides AI-powered biometric access control hardware and platform services (the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard information — including biometric identifiers — when you interact with our Services, website, or devices.
1. Information We Collect
1.1 Biometric Data
When our devices (Pine X, Pine One) are used for facial recognition or fingerprint authentication, we or our customers (the deploying organization) may collect:
- Facial geometry templates (mathematical representations, not raw photographs, unless explicitly configured otherwise)
- Fingerprint minutiae templates
- Timestamped access event logs tied to a biometric match
Note: In most deployments, Stackpine devices are sold to a business customer ("Customer") who acts as the data controller for their employees/visitors. Stackpine may act as a data processor/service provider on the Customer's behalf. Where Stackpine directly controls biometric data (e.g., cloud platform accounts), the terms below apply to us as controller.
1.2 Account & Contact Information
Name, work email, phone number, company name, billing address — collected when you request a demo, create a platform account, or contact support.
1.3 Device & Usage Data
IP address, device identifiers, log-in timestamps, diagnostic/telemetry data from installed hardware.
1.4 Cookies & Website Analytics
Standard web analytics cookies on stackpinedetect.com (see Section 8).
2. How We Use Information
- Provide, operate, and maintain the Services (identity verification, access logging, device management)
- Improve accuracy of biometric matching models
- Customer support and account management
- Security, fraud prevention, and abuse monitoring
- Legal compliance and enforcement of our Terms of Service
- Marketing communications (only with consent, where required)
We do not sell biometric data. We do not use biometric data for advertising purposes.
3. Legal Basis & Biometric-Specific Disclosures (BIPA / State Biometric Laws)
In compliance with the Illinois Biometric Information Privacy Act (BIPA) and similar state laws (Texas CUBI, Washington, California):
- We (or our Customer, as applicable) will obtain written consent from an individual before collecting their biometric identifier, disclosing the specific purpose and length of time the data will be collected, stored, and used.
- Biometric identifiers are stored using industry-standard encryption, both at rest and in transit.
- Biometric data is retained only as long as necessary to fulfill the purpose for which it was collected, or no longer than 3 years from the individual's last interaction with the Services, whichever is sooner — unless a shorter period is required by applicable law or Customer policy.
- Biometric data is permanently destroyed upon expiration of the retention period, using secure deletion methods.
- We do not sell, lease, trade, or otherwise profit from biometric identifiers.
- Biometric data will not be disclosed to a third party unless: (a) the individual consents; (b) disclosure is required to complete a financial transaction requested by the individual; (c) disclosure is required by law or valid legal process; or (d) disclosure is to a subcontractor solely to provide the Services.
4. GDPR (EU/UK Users)
If you are located in the EEA, UK, or Switzerland, biometric templates constitute "special category data" under Article 9 GDPR. Where we act as controller:
- Legal basis: explicit consent (Art. 9(2)(a)) or substantial public interest with safeguards, as applicable.
- Your rights: access, rectification, erasure, restriction, portability, and objection. Contact us at info@stackpinedetect.com to exercise these rights.
- International transfers: where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) or an equivalent safeguard.
- You may lodge a complaint with your local Data Protection Authority.
5. CCPA / CPRA (California Residents)
Facial and fingerprint templates are "sensitive personal information" under the CPRA. California residents have the right to:
- Know what personal information is collected and how it is used
- Delete personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of sale/sharing (we do not sell or share biometric data)
- Limit use of sensitive personal information to what is necessary to provide the Services
- Non-discrimination for exercising these rights
Requests can be submitted to info@stackpinedetect.com.
6. Data Sharing & Third Parties
We share information only with:
- Cloud infrastructure/hosting providers, under data processing agreements
- The Customer organization that deployed the Stackpine device (for their own access-control records)
- Law enforcement or regulators, only when legally compelled
- Successors in the event of a merger, acquisition, or asset sale (with notice to affected individuals)
7. Data Security
We employ encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, and SOC 2-aligned security practices. No system is 100% secure; we encourage prompt reporting of suspected vulnerabilities to security@stackpinedetect.com.
8. Cookies
Our website uses essential and analytics cookies. You can control cookie preferences through your browser settings.
9. Children's Privacy
Our Services are not directed to individuals under 18. We do not knowingly collect biometric data from children without verified parental/guardian and, where applicable, school consent (e.g., for education-sector deployments).
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via the website or direct communication to Customers. Continued use of the Services after changes constitutes acceptance.
11. Contact Us