GLYPHLOCK PRIVACY // PUBLIC POLICY

PRIVACY POLICY

Last updated: August 25, 2026

This policy explains how GlyphLock LLC handles personal information across GlyphLock websites, applications, APIs, developer tools, AI-assisted services, QR and verification tools, financial workflows, and the NUPS venue operations platform.

NUPS PRIVACY COVERAGE

NUPS users, venue operators, staff, guests, contractors, drivers, and customers are covered by this policy where GlyphLock processes information through the platform.

OPEN NUPS

Scope and Purpose

This Privacy Policy applies when GlyphLock LLC determines how personal information is handled through our own products and services. In some NUPS deployments, a venue or enterprise customer may determine the purpose and means of processing certain records. In those cases, that customer may have its own privacy notice and may act as the primary business, controller, or data owner for those records.

Using the platform does not waive privacy rights provided by applicable law. Contract terms, enterprise agreements, and governance records may affect retention, access, and operational responsibilities, but they do not override rights that cannot legally be waived.

Information We Collect

Depending on the product, role, configuration, and workflow you use, we may process the following categories:

Account and identity data

Name, email, phone number if provided, organization, role, account identifiers, authentication settings, and account status.

Content and assets

Images, files, QR payloads, metadata, hotspot maps, project settings, uploaded documents, prompts, instructions, and generated outputs.

Usage and device data

IP address, browser and device details, session identifiers, timestamps, referring pages, performance information, errors, and operational telemetry.

Security and audit data

Authentication events, access events, key activity, role changes, admin actions, API usage, anomaly flags, integrity records, and audit logs.

Transaction and financial workflow data

Transaction references, payment status, refunds, chargebacks, settlement records, payout records, receipts, ledger entries, and related audit information.

Support and communications

Messages, consultation requests, feedback, support conversations, and information you provide when contacting GlyphLock.

GlyphLock does not sell personal information for money.

NUPS Venue Operations Data

NUPS is GlyphLock's venue operations platform. Depending on a venue's enabled features and operating configuration, NUPS may process operational records relating to staff, guests, contractors, drivers, transactions, contracts, access, and venue activity.

Staff and role records

Role assignment, clock-in/clock-out records, shift activity, permissions, operational actions, and related audit history.

Guest and customer records

Names or account identifiers, visit or transaction context, QR identifiers, service records, and other information entered or captured by enabled venue workflows.

Identity verification

Information derived from supported identity-verification workflows, including document or scanner data where enabled. Venues are responsible for using these features lawfully and providing any required notices.

Biometric-enabled workflows

If a venue enables a biometric feature, applicable consent, notice, retention, and deletion requirements must be addressed by the venue and GlyphLock according to the deployment and applicable law.

Contracts and signatures

VIP or other venue agreements, signatures, timestamps, document images, status information, and record links used to preserve the transaction history.

Registers, payouts, and settlement

Register records, shift close information, payout calculations, settlement summaries, reconciliation information, and audit events.

A venue or enterprise customer may be responsible for notices, permissions, lawful-basis decisions, employee communications, and responding to certain privacy requests for records it controls.

How We Use Information

  • Provide the service: operate requested platform features, NUPS workflows, QR and verification tools, AI-assisted functions, developer tools, and customer support.
  • Security and fraud prevention: authenticate users, enforce roles, detect abuse, investigate suspicious activity, protect accounts, and preserve system integrity.
  • Transactions and operations: support purchases, refunds, settlements, payouts, receipts, accounting workflows, and dispute records.
  • Reliability and improvement: diagnose errors, measure performance, improve interfaces, maintain availability, and develop features.
  • Legal and contractual obligations: maintain records where needed for compliance, disputes, legal holds, contracts, security investigations, and regulatory obligations.

Master Covenant and Governance Records

The Master Covenant is part of GlyphLock's governance and documentation framework. It may be incorporated into agreements, policies, records, or workflows where the relevant parties receive notice and the applicable contractual requirements are satisfied.

GlyphLock may preserve provenance, verification, consent, acceptance, audit, and integrity records associated with platform actions. We do not rely on this Privacy Policy to claim that passive viewing, mere exposure to content, or machine processing by itself creates a contract where applicable law requires additional elements of agreement.

Security

GlyphLock uses layered technical and organizational safeguards appropriate to the service and deployment. These may include encrypted network transport, protected storage, role-based access, multi-factor authentication, key-management practices, audit logging, monitoring, and tamper-evident records.

No online system can be guaranteed completely secure. Security controls reduce risk but cannot eliminate all threats, misuse, failures, or unauthorized access.

Service Providers and Data Sharing

We may use infrastructure, hosting, database, authentication, analytics, communications, AI, payment, storage, security, and integration providers to operate GlyphLock and NUPS. These providers may process information only as needed for the service they provide and subject to applicable agreements and legal requirements.

We may also disclose information when required by law, to protect rights or safety, investigate abuse or fraud, enforce agreements, respond to lawful requests, or support a business transaction such as a financing, merger, acquisition, or asset transfer subject to appropriate safeguards.

Payments — Stripe Is Our Only Payment Processor

Stripe, Inc. is the sole payment processor used by GlyphLock and NUPS. We do not process card payments through any other gateway, aggregator, or processor. Where a venue chooses to run card authorization on its own merchant account or terminal, that authorization happens outside GlyphLock and GlyphLock records only the resulting reference data described below.

Card data never touches our systems

Card numbers, magnetic-stripe track data, chip data, CVV/CVC values, and PINs are never stored in GlyphLock or NUPS databases. Card entry and authorization occur in Stripe-hosted checkout, Stripe Elements, or a Stripe-connected physical terminal.

What we do store

Stripe identifiers (customer, checkout session, payment intent, charge, refund, subscription, and event IDs), payment status, currency, amount, brand, card expiration, the last four digits, approval/authorization code, and timestamps.

Server-side only credentials

Stripe secret keys and webhook signing secrets are held exclusively in server-side secret storage and are never exposed to browser code, mobile clients, agent prompts, or logs.

Webhook-confirmed truth

Payment success, failure, refund, dispute, and subscription state are recorded only from Stripe's signature-verified webhook events. A browser redirect or client message is never treated as proof of payment.

Information Stripe receives

To create a payment, GlyphLock transmits to Stripe the amount, currency, product or price reference, your email address, an internal account reference, and workflow metadata such as venue, transaction, or contract identifiers. Stripe additionally collects payment and billing details directly from you.

Stripe as an independent controller

Stripe processes your payment details under its own privacy policy and as an independent controller for fraud prevention, regulatory, and financial-reporting purposes. Review Stripe's privacy notice at stripe.com/privacy.

Refunds and chargebacks

Refunds are issued through Stripe and mirrored into our transaction, receipt, and ledger records. For a dispute, GlyphLock may compile evidence packages containing transaction records, receipts, delivery/service history, audit events, and communications, and submit them to Stripe.

Reconciliation and retention

Stripe references are retained alongside our transaction, receipt, settlement, and ledger records so that application transaction, Stripe transaction, receipt, and audit entry can be reconciled. These financial records are retained for the periods required by accounting, tax, dispute, and legal-hold obligations, which may outlast account deletion.

Where an Adesso or similar card reader is used inside NUPS for guest-record purposes, it captures only cardholder name, brand, expiration, and last four digits for identification on the venue record. It does not authorize funds. All authorization remains with Stripe or the venue's certified terminal.

Refund eligibility is governed by the applicable purchase, subscription, venue, or service terms and by rights that apply under law. GlyphLock does not sell, rent, or share payment data for advertising or marketing purposes.

Oracle Hospitality Integration Platform (OHIP)

GlyphLock's Oracle Hospitality Integration Cloud Service (OHIP) is provisioned. NUPS has completed an authenticated, controlled read-only request in the OHIP Partner Sandbox. Oracle separately approved and activated GlyphLock's Oracle Cloud Marketplace program enrollment on August 25, 2026, and GlyphLock submitted a formal Simphony Integration Partner Program request for review. These are documented program and intake milestones, not a published NUPS Marketplace listing, production approval, Simphony Solution Validation, certification, endorsement, or a separate commercial partnership.

No authorized OPERA Cloud customer environment is currently connected. Until Oracle and an authorized customer provide the required production environment and credentials, and read-only production validation succeeds, NUPS does not exchange production guest, reservation, folio, payment, posting, token, or raw Oracle payload data.

Customer-controlled

A future production workflow requires an authorized OPERA Cloud customer environment. The customer determines which approved workflows are enabled and controls the records held in its Oracle environment.

Credential handling

OHIP client identifiers, secrets, hotel and enterprise identifiers, application keys, and access tokens remain in server-side secret storage and are never exposed to client code.

Current scope

Current validation is read-only in the Partner Sandbox. No guest, reservation, payment, token, or raw Oracle payload is returned to the browser, and no production write workflow is enabled.

Separate Oracle gates

The Cloud Marketplace program enrollment is active, while Publisher Account status, listing submission and acceptance, production access, customer authorization, production validation, Simphony request approval/onboarding/Solution Validation, and supplier or banking onboarding remain separate processes.

Retention and Deletion

We retain information for as long as reasonably necessary for the purpose for which it was collected, including platform operation, security, accounting, contractual obligations, fraud prevention, legal requirements, disputes, and backup cycles.

Retention differs by record type. Some audit, transaction, contract, security, and legal-hold records may need to be retained after an account or individual content item is deleted. Where a venue controls NUPS records, requests may need to be directed to that venue.

Your Privacy Rights and Choices

Depending on your location and relationship with GlyphLock, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about how personal data is handled. Some rights are subject to exceptions and verification requirements.

If your request concerns NUPS data controlled by a specific venue or enterprise customer, we may direct you to that organization or assist it in responding.

Compliance and Security Framework References

GlyphLock designs parts of its architecture and operational controls with reference to recognized privacy and security frameworks, including GDPR principles, U.S. state privacy requirements, SOC 2 control concepts, ISO/IEC 27001 security-management concepts, PCI DSS requirements where payment-card scope applies, and HIPAA requirements only where GlyphLock is actually acting in a regulated covered-entity or business-associate context.

Framework references describe design alignment, program goals, or applicable obligations. They do not mean GlyphLock holds a third-party certification, attestation, or regulatory approval unless that status is explicitly identified and supported by current documentation.

Contact the Privacy Officer

GlyphLock LLC · El Mirage, Arizona · United States

carloearl@glyphlock.com