Privacy Policy
Effective Date: April 29, 2026
Last Updated: May 19, 2026
CapCore Systems, LLC (“Company,” “CapCore,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal information when you visit capcoresystems.com or use our AI-powered tools, including the SmartHire Toolkit and LaunchPad pillars (collectively, the “Service”). By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.
This Policy is incorporated by reference into our Terms and Conditions. In the event of any conflict between this Policy and the Terms and Conditions, the Terms and Conditions govern.
1. Data Controller and Contact Information
The data controller responsible for your personal information under this Policy is CapCore Systems, LLC, an Indiana limited liability company. Privacy contact: info@capcoresystems.com. Website: capcoresystems.com. For all privacy-related inquiries, including requests to exercise your data rights, please contact us at info@capcoresystems.com with the subject line “Privacy Request.”
2. Information We Collect
2.1 Information You Provide Directly
- Account information: name, email address, password (stored as a salted hash), and account preferences.
- Payment information: billing name, billing address, and payment details. All cardholder data is collected and processed directly by Stripe under PCI DSS Level 1 standards. We do not store full credit card numbers, CVV codes, or full bank account numbers on our servers.
- Career and professional content (SmartHire Toolkit users): resume text, job titles, target roles, job descriptions, cover letter inputs, LinkedIn content, interview answers, salary information, and related career materials you submit to our AI tools.
- Business content (LaunchPad users): business plans, financial inputs, brand strategy materials, marketing copy, operations documentation, and related business inputs you submit to our AI tools.
- Communications: name, email address, subject, and message content when you contact us.
- Marketing preferences: email subscription preferences, opt-in records, and engagement data when you sign up for our mailing list.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, tools accessed, timestamps, session duration, and frequency of use.
- Device information: browser type and version, operating system, IP address, device identifiers, screen resolution, and language settings.
- Cookies and similar technologies: session cookies, persistent cookies, web beacons, and pixel tags. See Section 7 for details.
- Referral information: the website or source you came from before reaching the Service.
2.3 Information We Do Not Collect
We do not knowingly collect: government identification numbers, biometric identifiers, health or genetic information, precise geolocation data, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, or trade union membership unless you voluntarily disclose this information in content you submit to our tools.
3. How We Use Your Information
We process your personal information for the following purposes: to provide, maintain, operate, and improve the Service and its features; to process AI requests and generate the career and business outputs you request; to process subscriptions, payments, refunds, and tax obligations; to send you transactional, service-related communications, including account confirmations, billing notices, and security alerts; to send marketing communications where you have opted in, and to manage opt-outs; to respond to inquiries and provide customer support; to monitor and enforce subscription tier usage limits and prevent abuse; to detect, prevent, investigate, and address fraud, security incidents, and technical issues; to enforce our Terms and Conditions and other legal agreements; to comply with legal, regulatory, accounting, and tax obligations; and to analyze and improve the performance and effectiveness of the Service.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under one or more of the following legal bases: performance of a contract; legitimate interests (providing and improving the Service, ensuring security, preventing fraud, conducting business analytics); consent for specific purposes such as marketing; legal obligation; and vital interests where applicable. You may withdraw consent at any time by contacting info@capcoresystems.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. AI Processing — How Your Inputs and Outputs Are Handled
- Real-time processing only: Career content, business content, and other inputs you submit to our AI tools are transmitted to our processing gateway in real time, used to generate your output, and not retained on our servers in raw input form after processing completes.
- No model training on your data: We do not use your inputs, outputs, or any personal data to train, fine-tune, or improve any artificial intelligence model owned, controlled, or commercialized by the Company.
- AI provider: We use Anthropic’s Claude AI through the Anthropic API to process your requests. Anthropic does not use API submissions to train its models.
- Saved outputs: If you choose to save generated outputs to your dashboard, those outputs are stored in encrypted form within our infrastructure. You may delete saved outputs at any time through your account portal.
- Aggregate analytics: We retain de-identified, aggregated usage statistics to monitor system performance, but these aggregate metrics cannot be used to identify any individual user.
6. Disclosure of Your Information — Sub-processors and Service Providers
We do not sell or rent your personal information to third parties. We disclose your information only to the following categories of recipients, each of whom is contractually bound to handle your data securely and consistent with this Policy:
- Anthropic, PBC — AI model provider. Receives the inputs you submit to our AI tools, processes them through Claude AI, and returns outputs. Anthropic does not use API submissions to train its models.
- Stripe, Inc. — Payment processor. PCI DSS Level 1 certified.
- Cloudways (a DigitalOcean company) — Managed hosting provider.
- WordPress.com / Automattic, Inc. — Platform infrastructure for the Site.
- WooCommerce / Automattic, Inc. — E-commerce engine for product catalog, subscription management, and order records.
- Klaviyo, Inc. — Email marketing platform.
- Railway Corp. — Application infrastructure hosting our AI processing gateway.
- Jetpack / Automattic, Inc. — Site statistics pixel and security utilities. Data: page views, referrer URL, anonymized IP address, and user agent. Used to measure site traffic and provide infrastructure-level abuse protection.
- Google LLC — Analytics and anti-spam services. Specifically: (a) Google Analytics 4 via measurement ID G-RZVW3PVL30 and Google Tag Manager container GT-P3JCPBXG, which collect page views, session duration, referrer, device and browser information, and approximate location derived from IP address; and (b) Google reCAPTCHA where deployed, which collects interaction data to distinguish human users from automated traffic.
- Brevo (Sendinblue SAS) — Transactional email delivery for account confirmations, billing notices, password resets, and other service-related messages. Data: email address, recipient name if provided, and email engagement events (delivered, opened, bounced).
- Zoho Corporation (Zoho Mail) — Business email hosting and inbound customer correspondence. Data: email content, sender/recipient addresses, attachments, and metadata for messages exchanged with our staff mailboxes (e.g. info@capcoresystems.com).
- TikTok / ByteDance Ltd. — Conversion tracking and advertising attribution pixel. Data: page views, button click events, and hashed email address where you have voluntarily provided one. TikTok is operated by ByteDance Ltd., headquartered in the People’s Republic of China. EEA, UK, and California residents may opt out via browser-level tracker blocking; site-level consent gating is active via our cookie consent banner.
- LinkedIn Corporation — Conversion tracking and professional audience analytics via the LinkedIn Insight Tag. Data: page views, conversion events, and professional profile data of LinkedIn members who visit the Service. See LinkedIn’s privacy policy at linkedin.com/legal/privacy-policy.
- Wordfence (Defiant, Inc.) — Security plugin providing firewall, malware scanning, and brute-force protection. Data: visitor IP address, user agent, request URI, and request method, used for threat analysis and IP-based blocking of malicious traffic.
- Microsoft 365 and similar productivity providers — Used internally by the Company for support and operational purposes.
Legal disclosures: We may disclose your information if required by law, regulation, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to comply with legal obligations, protect rights or safety, investigate fraud or security issues, or enforce our Terms and Conditions.
Business transfers: If CapCore Systems, LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.
7. Cookies and Tracking Technologies
- Strictly Necessary: required for the Service to function. Cannot be disabled.
- Functional: remember your preferences and settings.
- Analytics: help us understand how visitors interact with the Service. Where required by law, loaded only after consent.
- Marketing: deliver relevant marketing communications and measure campaign effectiveness. Loaded only with your consent.
You can control cookie preferences through our cookie consent banner (where shown) and through your browser settings.
Product analytics and session replay. We use Microsoft Clarity, a product-analytics and session-replay service, to understand how visitors interact with our website through usage metrics, heatmaps, and session replays. Clarity uses cookies and similar technologies to record pages visited, links and buttons clicked, and general browsing behavior. Masking is enabled, so sensitive content — including any text you enter into form fields — is obscured and is not captured. We use this information solely to improve the usability, reliability, and performance of our site. Microsoft processes the data it collects in accordance with the Microsoft Privacy Statement.
8. Your Privacy Rights
8.1 General Rights (All Users)
Regardless of your location, you may request that we provide a copy of the personal information we hold about you, correct inaccurate or incomplete personal information, delete your personal information (subject to legal retention obligations), export your personal information in a portable, machine-readable format, or restrict or object to certain processing activities, including marketing communications. To exercise any right, contact info@capcoresystems.com. We will verify your identity before fulfilling the request and respond within thirty (30) days.
8.2 Rights for Residents of the EEA, United Kingdom, and Switzerland (GDPR / UK GDPR)
In addition to the general rights above, you have the right to: withdraw consent at any time where processing is based on consent; object to processing based on legitimate interests, including profiling; lodge a complaint with your local supervisory authority; and receive your personal information in a structured, commonly used, machine-readable format.
International transfers: Personal information of EEA, UK, and Swiss residents is transferred to the United States. We rely on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner’s Office, supplemented by appropriate technical and organizational measures.
8.3 Rights for California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with rights including: right to know; right to delete (subject to legal retention exceptions); right to correct inaccurate personal information; right to opt out of sale or sharing (note: CapCore Systems does not sell or share your personal information for cross-context behavioral advertising); right to limit use of sensitive personal information; right to non-discrimination; and right to designate an authorized agent. To exercise California rights, contact info@capcoresystems.com with the subject line “California Privacy Request.”
8.4 Rights for Other U.S. State Residents
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, and other U.S. states with comprehensive privacy laws have rights similar to those described above. To exercise any state privacy right, contact info@capcoresystems.com.
9. Data Retention
We retain your personal information only as long as necessary for the purposes described in this Policy or as required by law. Account information is retained while your account is active and for thirty (30) days after a deletion request. Saved outputs are retained until you delete them. AI tool inputs are not retained after processing completes. Billing and tax records are retained for at least seven (7) years. Marketing data is retained until you unsubscribe. Logs and security records are retained for up to twenty-four (24) months.
10. Data Security
We implement reasonable technical and organizational security measures including industry-standard 256-bit TLS/SSL encryption for all data in transit, encryption at rest for stored personal information and saved outputs, authentication safeguards including hashed passwords and JWT-based session tokens, rate limiting and brute-force protection, and access controls limiting personal information to authorized personnel on a need-to-know basis. Despite these measures, no method of transmission over the Internet or method of electronic storage is one hundred percent secure. We cannot guarantee absolute security.
11. Children’s Privacy
The Service is not directed to anyone under the age of eighteen (18). We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take immediate steps to delete that information. If you believe we have inadvertently collected information from a child under 18, please contact info@capcoresystems.com immediately.
12. International Data Transfers
CapCore Systems, LLC is based in the United States. Your personal information may be transferred to, stored in, and processed in countries that may have data protection laws different from those of your country of residence. Where required by law, we use appropriate safeguards (including Standard Contractual Clauses) for international transfers.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy to capcoresystems.com with a revised “Last Updated” date. For significant changes affecting how we process your information, we will provide notice by email to active subscribers at least seven (7) days before the changes take effect. Your continued use of the Service after the effective date of any change constitutes acceptance of the revised Policy.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at info@capcoresystems.com. Our response time is within thirty (30) days for formal data rights requests, and within five (5) business days for general inquiries.
This Privacy Policy is effective as of April 29, 2026 and supersedes all prior versions.
