← ProductAuth

Privacy Policy

Last updated: July 6, 2026

This policy explains what ProductAuth (operated by Builder Dogs) collects, why, and what happens to it. It covers both our business customers (brands with accounts) and consumers who scan a product's QR code.

1. What we collect from account holders

2. What we collect when someone scans a QR code

When a consumer scans a product's code, the verification request records:

This exists for one purpose: counterfeit detection. The same code appearing in an unusual number of scans or in geographically scattered locations is a signal of cloned tags, and this data powers that analysis on behalf of the brand that made the product. Scan data is not used for advertising and is not sold to anyone.

3. Who processes data on our behalf

We use a small set of service providers, each receiving only what's needed for their role:

4. Cookies and tracking

We do not use advertising or analytics cookies. Logged-in sessions use your browser's sessionStorage (cleared when the tab closes) to hold your API key. That's it.

5. Blockchain inscriptions

If a brand chooses to inscribe a product record on the Dogecoin blockchain, that inscribed data (product identifiers and a cryptographic hash — never personal information) becomes permanently public and cannot be deleted by us or anyone. Inscription is always opt-in per product.

6. Retention

Account and product data is kept while your account is active. Verification/scan logs are retained to preserve each product's authenticity history — this history is the core of the service, since a product's scan record is what makes clone detection possible. If you delete your account, your account data and products are removed from our active database.

7. Your rights

Depending on where you live (including under GDPR and the California Consumer Privacy Act), you may have rights to access, correct, export, or delete your personal information. Account holders can export all of their data anytime from within the Service. For any privacy request — including consumers who scanned a code and want their scan data addressed — contact us at the email below and we will respond within the timeframe required by applicable law.

8. Security

Passwords are hashed with scrypt and per-user salts. API access is authenticated and rate-limited. Product tokens are signed with RS256 asymmetric cryptography. No system is perfectly secure, but the architecture is designed so that no single leaked credential exposes other customers' data.

9. Children

The Service is for business use and not directed at children under 13. We do not knowingly collect personal information from children.

10. Changes

We'll post any changes to this policy on this page with an updated date. Material changes affecting account holders will also be communicated by email.

11. Contact

Privacy questions or requests: hello@myproductauth.com