Privacy policy

Core Mint Software Solutions: System & Infrastructure Privacy Policy

Effective Date: 01-01-2026

This System Privacy Policy explains how Core Mint Software Solutions ("we," "our," or "us") collects, processes, and protects data across our institutional management SaaS platform, cloud infrastructure, and integrated hardware systems.

This policy applies to school administrators, institutional clients, and visitors to our main website and administrative portals.

1. Our Role as a Data Processor

Core Mint operates primarily as a Data Processor for our institutional clients (schools and colleges). The institution remains the Data Controller. We only process student, parent, and staff data based on the explicit instructions and operational requirements of the institution using our software.

2. Information We Collect at the System Level

To provide and maintain our SaaS infrastructure, we collect the following:

  • Client Account Data: Administrator names, institutional billing details, and contact information required to set up and manage the software license.

  • System Logs & Telemetry: IP addresses, browser types, and API request logs generated when administrators use our web dashboards or when integrated hardware communicates with our servers.

  • Hardware Sync Data: Device IDs, heartbeat logs, and sync statuses from connected RFID scanners, biometric terminals, and barcode readers to ensure system uptime.

3. How We Handle Biometric and RFID Data

We take the processing of physical access data highly seriously:

  • Biometric Templates, Not Images: When integrated with compatible hardware, our centralized push servers do not store actual images of fingerprints or faces. The system only processes encrypted mathematical templates that cannot be reverse-engineered.

  • Hardware-to-Cloud Security: All data transmitted between physical terminals and our cloud servers is encrypted in transit to prevent interception.

4. Data Storage and Security

Our platform is built on secure, industry-leading cloud infrastructure.

  • Cloud Hosting: System databases and centralized servers are hosted on secure, isolated cloud environments equipped with strict firewall and access controls.

  • Encryption: Data is encrypted both at rest within our SQL databases and in transit.

  • Access Control: Core Mint engineering and support staff do not access institutional databases unless explicitly requested by the school administrator for troubleshooting or maintenance.

5. Data Retention and Deletion

Because the institution owns their data:

  • We retain system data and end-user records only for as long as the institution maintains an active subscription with us, or as required by law.

  • Upon termination of a contract, school administrators can request a full data export.

  • Following contract termination, all associated institutional data, including hardware sync logs and user databases, is permanently purged from our servers within [Insert Number, e.g., 30 or 60] days.

6. Third-Party Integrations

We do not sell data to data brokers or advertising platforms. System data may be shared strictly with essential third-party infrastructure providers necessary to run the service, such as:

  • Cloud hosting providers.

  • SMS gateway providers (for sending automated parent notifications).

  • Payment processors (for client billing).

7. Contact Us

For questions regarding system security, infrastructure compliance, or data processing agreements, please contact our administrative team at: