Res LabsLegal & Policies

Effective date: 21st July 2026
Service provider: Verares Labs Inc.

2. Privacy Policy

2.1 Scope and controller

This Privacy Policy explains how Verares Labs Inc., doing business as Res Labs (“Res Labs,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information through the Services.

It applies to:

  1. public Buyers who tap a Tag or open a verification page;
  2. Supplier and operator account holders;
  3. Lab representatives and people whose professional information appears in a Lab profile or COA;
  4. people who submit issue reports, support requests, or other communications; and
  5. visitors to Res Labs websites and users of related APIs or tools.

For the processing described in this Policy, Res Labs generally acts as the data controller, business, or equivalent entity that determines the purposes and means of processing. A Supplier, Lab, or other third party may separately control personal information it collects through its own website, sales process, testing relationship, or customer records. Their privacy policies apply to their processing.

2.2 Important note about “anonymous” buyer taps

A Buyer can open a public verification page without creating an account, providing a name, entering an email address, installing an app, or connecting a wallet. We therefore ordinarily do not know the Buyer’s direct identity from the tap alone.

The tap is not data-free or fully anonymous. When a phone requests a verification page, the Services automatically receive and log network, device, Tag, and event data that can qualify as personal information. We call this “Buyer Tap Data.” It is used primarily to authenticate the request, prevent replay, detect suspected clones or fraud, maintain audit integrity, and secure the Services.

2.3 Buyer Tap Data and public-page data

When a Buyer taps a Tag, opens a verification URL, retaps, or interacts with a public page, we may collect:

  1. Tag and event identifiers: Tag UID or other identifier, sticker or batch reference, tap counter, server-issued tap identifier, signature-validation result, verification status, anomaly flags, and related protocol data;
  2. Network data: IP address, request headers, referring page where available, network and security signals, and server-log information;
  3. Approximate location: country-level location by default and, where enabled or reasonably necessary, city-level or regional location inferred from the IP address; we do not intentionally collect precise GPS location from the public verification page;
  4. Device and browser data: user-agent string, browser type, operating system, device category, language, time zone, and technical compatibility information;
  5. Timing and interaction data: date and time, page requested, first and repeat taps, link clicks, error events, and whether an on-chain proof or COA link was opened where our systems can observe that interaction;
  6. Security and fraud inferences: indicators of unusual frequency, geography, dormancy, replay, counter regression, automated traffic, or possible copying; and
  7. Local-device state: where enabled, strictly necessary cookies, session data, or local storage used for security, continuity, or to remember that a device previously opened the same Tag. Such local state is not proof that the same person made each tap.

We do not use Buyer Tap Data for behavioral advertising or to build a consumer marketing profile.

2.4 Buyer reports and optional claim features

If you voluntarily report an issue, contact support, upload a photo, or use an optional ownership-claim feature, we may collect:

  1. your name, email address, account identifier, or other contact information;
  2. report category, message, photos, files, and supporting details;
  3. the relevant Tag, tap, batch, Supplier, Lab, and COA references;
  4. communications and resolution history; and
  5. if a claim feature is enabled, the account-to-Tag claim record, claim timestamp, and a masked owner indicator.

Do not submit health information, dosing information, medical records, government identifiers, financial credentials, or other sensitive personal information in a report. An ownership claim is a platform record only and is not proof of legal ownership.

2.5 Supplier and operator account data

When a Supplier or operator is invited, creates or uses an account, orders Tags, or manages a batch, we may collect:

  1. name, business name, job title, email address, telephone number, country, and other professional contact information;
  2. business registration or vetting information provided during onboarding;
  3. fulfillment and shipping address, tracking information, delivery confirmations, and inventory records;
  4. products the Supplier intends to ship, batch codes, production dates, vial counts, photos, notes, Lab selections, and workflow status;
  5. COA URLs, pass/fail/retest selections, confirmations, hashes, IPFS CIDs, blockchain transaction data, and related provenance records;
  6. wallet address provided for attribution or possible future payments; Res Labs does not take custody of private keys or wallet credentials;
  7. account and authentication identifiers from Clerk or another identity provider, login timestamps, session and security signals, role, organization identifier, and access history;
  8. dashboard actions, Tag activations, state transitions, overrides, audit entries, support communications, and incident reports;
  9. order, invoice, payment-status, tax, credit, and commercial records; where a payment processor is used, we ordinarily do not receive full payment-card details;
  10. IP address, device, browser, and usage information associated with account access; and
  11. information provided by authorized users, business contacts, Labs, carriers, service providers, public records, or other legitimate sources.

Res Labs does not receive plaintext account passwords from Clerk.

2.6 Lab and COA data

We may collect or display:

  1. Lab name, public domain, logo, public contact details, accreditation or license information, receiving information, and public professional details;
  2. names, titles, signatures, credentials, or contact information of Lab personnel that appear on a public COA or are provided for professional verification;
  3. the canonical COA URL and source-domain information;
  4. the COA document during transient retrieval and processing;
  5. a SHA-256 or other cryptographic hash, IPFS CID, issue date, Lab domain, batch code, and blockchain anchor or transaction data;
  6. status, correction, replacement, recall, void, or retraction information; and
  7. where enabled, automatically extracted COA fields and confidence scores.

For the current MVP, Res Labs is designed not to retain a permanent local byte-copy of a COA after processing. We retain the canonical Lab URL, document hash, IPFS pin metadata, and related provenance records. Transient copies, provider storage, IPFS copies, network caches, security logs, and backups may nevertheless exist.

A COA pinned to public IPFS can be retrieved by anyone who has or discovers its CID. A blockchain anchor is public and generally cannot be edited or deleted. We do not place Buyer IP addresses, Buyer geolocation, Buyer account information, or raw scan-event logs on IPFS or the blockchain.

2.7 Website, communication, and business data

We may also collect:

  1. information submitted through contact forms, emails, surveys, meetings, partnership discussions, or support requests;
  2. website and API logs, pages viewed, links clicked, and performance or error information;
  3. marketing preferences for business communications;
  4. security, abuse, legal, and compliance records; and
  5. information relating to a prospective or completed corporate transaction.

2.8 Sources of personal information

We collect personal information:

  1. directly from you or your organization;
  2. automatically from devices, browsers, networks, Tags, and use of the Services;
  3. from Suppliers, Labs, account administrators, carriers, payment or authentication providers, and other service providers;
  4. from public Lab websites, public accreditation or business records, and other public sources; and
  5. from people who report a concern or provide information relevant to fraud, security, recall, or legal compliance.

2.9 How we use personal information

We use personal information to:

  1. authenticate Tags and taps, verify counters and signatures, route requests, and generate verification pages;
  2. link Tags to Batch Records and COA provenance records;
  3. detect, investigate, and respond to suspected replay, copying, cloning, geographic anomalies, fraud, abuse, counterfeit activity, stolen Tags, or security incidents;
  4. operate recall, void, suspension, revocation, warning, and issue-reporting workflows;
  5. maintain append-only audit history and evidence of state transitions;
  6. create and administer accounts, roles, invitations, authentication, and access controls;
  7. process Tag orders, inventory allocation, shipments, delivery, activation, billing, tax, and support;
  8. validate Lab domains and COA sources, retrieve and hash COAs, pin public COAs to IPFS, and anchor integrity evidence on Tempo or another blockchain;
  9. display public Lab, Supplier, batch, and COA information;
  10. communicate about the Services, support, security, legal changes, orders, and business relationships;
  11. troubleshoot, test, measure performance, improve usability, and develop features;
  12. enforce agreements, protect rights and safety, prevent misuse, and establish, exercise, or defend legal claims;
  13. comply with law, court orders, regulatory requests, sanctions, tax, accounting, and recordkeeping obligations; and
  14. complete a merger, financing, acquisition, reorganization, sale, or similar transaction.

We do not infer the chemical contents of a vial from Buyer Tap Data, and we do not use Buyer Tap Data to make a medical determination.

2.10 Legal bases under the EEA and UK data-protection laws

Where the EU GDPR, UK GDPR, or a similar law applies, we rely on the following legal bases:

  1. Contract: to provide account, ordering, dashboard, authentication, support, and other services requested by a Supplier, operator, or account holder; to take steps at your request before entering a contract; and to administer our agreement.
  2. Legitimate interests: to authenticate Tags, prevent replay and counterfeiting, detect fraud and security threats, maintain audit integrity, protect Suppliers, Labs, Buyers, and Res Labs, operate a reliable provenance system, troubleshoot, improve the Services, enforce agreements, and establish or defend legal claims. For Buyer Tap Data, our specific interests are the integrity of the verification result, prevention and investigation of suspected copying or misuse, network and information security, and preservation of a reliable audit trail. We assess necessity, proportionality, reasonable expectations, and the impact on individuals.
  3. Legal obligation: to comply with tax, accounting, sanctions, law-enforcement, regulatory, court, recordkeeping, and other legal requirements.
  4. Consent: where required for optional marketing, non-essential cookies or similar technologies, or another specific processing activity. You may withdraw consent at any time, without affecting earlier lawful processing.
  5. Vital interests or substantial public interest: only in unusual circumstances where applicable law permits and the processing is necessary to protect a person or address a serious safety or fraud matter.

You may object to processing based on legitimate interests as described in Section 2.20. We may continue where we demonstrate compelling legitimate grounds or need the information for legal claims.

2.11 Why the public verification page may not show a cookie-consent banner

The public verification page does not use advertising cookies or cross-site behavioral tracking. Buyer Tap Data is generated primarily through the server request needed to authenticate and render the page, not through an advertising cookie. We process that server-side data under legitimate interests for authentication, anti-counterfeit controls, fraud prevention, audit, and security rather than relying on consent.

We may use strictly necessary cookies, session storage, or local storage for security, fraud prevention, continuity, accessibility, or a feature the user requests. Where applicable law requires consent for a non-essential technology, we will request consent before using it. If we add advertising or non-essential cross-site tracking, we will update this Policy and provide legally required controls.

2.12 Automated analysis and decisions

The Services may automatically:

  1. validate a Tag signature and counter;
  2. classify a tap as accepted, replayed, malformed, unknown, or anomalous;
  3. infer approximate location from an IP address;
  4. flag unusual frequency, geography, dormancy, or other patterns;
  5. compare a COA source or hash; and
  6. where enabled, extract or summarize fields from a COA.

These systems can make mistakes. Warning and anomaly outputs are risk indicators and may be reviewed by an operator. Res Labs does not use automated processing to make a decision that produces legal or similarly significant effects about a Buyer. Account suspension, Supplier revocation, and safety actions may use automated signals but can be reviewed by Res Labs. Contact info@reslabs.ai to contest a decision or request human review where applicable law gives that right.

2.13 How we disclose personal information

We may disclose personal information to:

  1. Service providers and processors that provide hosting, content delivery, authentication, databases, security, logging, email, support, shipping, payments, analytics, document retrieval, IPFS pinning, blockchain access, and related services;
  2. Suppliers and Labs associated with a Tag, batch, COA, or issue report, where necessary to investigate a warning, resolve a report, manage a recall, or provide limited batch analytics;
  3. Professional advisers such as lawyers, accountants, auditors, insurers, and consultants;
  4. Authorities and affected parties where required by law or reasonably necessary to respond to legal process, protect rights or safety, investigate fraud or crime, enforce agreements, or address a security incident;
  5. Transaction participants in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction; and
  6. The public, for information intentionally published on verification pages, public IPFS, or a public blockchain.

We do not ordinarily disclose raw Buyer IP addresses to Suppliers or Labs. We may provide limited data such as tap counts, country or region, timestamps, and anomaly indicators for the Supplier’s batch or the Lab’s COA. We may disclose more specific information when reasonably necessary to investigate fraud, a recall, a legal issue, or a security incident and permitted by law.

2.14 Core providers and decentralized systems

Current core providers and systems may include:

  1. Vercel: hosting, content delivery, edge processing, and technical logs;
  2. Clerk: Supplier and operator authentication, organization accounts, session management, and transactional authentication communications;
  3. Pinata and IPFS: pinning and retrieval of public COA documents and storage of IPFS CIDs;
  4. Tempo: public blockchain anchoring of COA integrity evidence, currently on chain ID 4217, and access through blockchain nodes or explorers;
  5. Database, monitoring, email, and infrastructure providers: storage, security, error reporting, communications, and operations; and
  6. Carriers and fulfillment providers: shipment and delivery of Tags, not Research Materials.

Providers may use their own subprocessors. Their processing locations and provider lists can change. We require contractual privacy and security commitments where applicable and select providers based on the role they perform.

2.15 Public and effectively irreversible data

Public verification pages may display a Supplier name, product name, batch code, Lab name and domain, COA link, COA issue date, accreditation information, batch photo, status, hash, IPFS CID, and blockchain transaction details.

Public IPFS is a distributed network. Unless encrypted, content placed there may be public, copied, cached, or re-pinned by others. A CID is content-addressed, so changing the document creates a different CID. Stopping our own pin does not guarantee that every copy disappears.

Public blockchains replicate records across independent nodes. A transaction, timestamp, address, hash, batch identifier, Lab domain, or related on-chain data may remain public indefinitely and may be impossible for Res Labs to modify or delete.

We minimize personal information placed in these systems. We do not intentionally anchor names, buyer contact details, IP addresses, or scan logs. A public COA may nevertheless contain a Lab signatory’s professional name, signature, credentials, or contact details. Anyone submitting a COA must ensure that public and persistent processing is lawful.

2.16 Sale, sharing, and advertising

Res Labs does not sell personal information for money. Res Labs does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act. In the preceding twelve months, Res Labs has not sold or shared personal information for those purposes.

We do not use Buyer Tap Data for targeted advertising, and we do not provide financial incentives in exchange for personal information. If these practices change, we will update this Policy and provide required choices, including honoring applicable opt-out preference signals.

2.17 Data retention

We retain personal information only for as long as reasonably necessary for the purposes described, subject to legal, security, audit, dispute, and backup requirements.

Our general retention periods are:

  1. Full Buyer Tap Data: generally twenty-four months from the event. We may retain a de-identified or aggregated event record for longer to measure Tag history, investigate counterfeiting, and maintain statistical security models. A record connected to an active investigation, recall, dispute, security incident, or legal hold may be retained longer.
  2. Append-only character: scan and audit records are append-only while retained so prior events cannot be silently rewritten. Append-only is an integrity control, not a promise to retain personal information forever.
  3. Supplier and operator account data: for the life of the account or commercial relationship and generally seven years after closure or the last relevant transaction, to support tax, accounting, contract, fraud, and legal obligations.
  4. Batch, Tag, COA, shipment, and provenance records: for the operational life of the record and generally seven years after the batch is closed, recalled, or last active. Public hashes, CIDs, and blockchain entries may persist indefinitely outside our control.
  5. Issue reports and support records: generally three years after resolution, or longer if connected to a recall, fraud matter, dispute, or legal requirement.
  6. Security logs: for a period proportionate to the security purpose, commonly between thirty days and twenty-four months, unless needed longer for an incident.
  7. Marketing preferences: until you opt out and for a suppression record needed to honor that choice.
  8. Backups: until overwritten or deleted under our ordinary backup cycle, subject to legal holds and technical limitations.

We may shorten or extend a period where necessary and lawful. At the end of a retention period, we delete, anonymize, aggregate, or restrict the information, except for public decentralized records or copies controlled by others.

2.18 Security

We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, authentication, encryption in transit, role restrictions, audit logging, separation of cryptographic secrets from public interfaces, monitoring, backup, and incident-response practices appropriate to the nature of the data.

No system is perfectly secure. Internet transmission, phones, browsers, Tags, third-party providers, public blockchains, and IPFS involve risks outside our complete control. You are responsible for securing your account, devices, email, authentication factors, wallet credentials, and any exported data.

If we identify a personal-data breach, we will investigate and provide legally required notices.

2.19 International transfers

Res Labs and its providers may process personal information in the United States and other countries that may have different data-protection laws from your country.

Where required, we use recognized transfer safeguards, which may include adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework or its UK or Swiss extensions where available, or another lawful mechanism. You may contact info@reslabs.ai for information about applicable safeguards.

Public IPFS and blockchain data can be replicated globally by independent participants, and Res Labs cannot control every location in which a public copy exists.

2.20 EEA, UK, and similar data-subject rights

Depending on where you live and subject to exceptions, you may have rights to:

  1. access personal information about you;
  2. correct inaccurate or incomplete information;
  3. request deletion;
  4. restrict processing;
  5. object to processing based on legitimate interests;
  6. receive certain information in a portable format;
  7. withdraw consent where processing is based on consent;
  8. request human review of certain automated decisions; and
  9. complain to your local data-protection authority.

To exercise a right, email info@reslabs.ai. We may ask for information reasonably necessary to verify your identity and locate the relevant data.

Because a public Buyer does not have an account, we may be unable to connect a named person to a tap. To help locate Buyer Tap Data, you may provide the Tag identifier, approximate tap time, verification URL, server-issued tap identifier, and the IP address or device information used at the time. Possession of a vial or shared URL alone does not prove that you made every prior tap, so we will not disclose another person’s IP address or device data without sufficient verification.

Deletion and objection rights are not absolute. We may retain information needed for security, fraud prevention, legal obligations, public-interest exceptions, establishment or defense of claims, or integrity of an active recall. We may be unable to erase a public blockchain record or content independently retained on IPFS, but may stop linking, stop our own pin, mark a record revoked, or take other reasonable steps within our control.

2.21 California privacy notice

This Section supplements the rest of the Policy for California residents and uses terms defined by the California Consumer Privacy Act, as amended.

2.21.1 Categories collected, sources, purposes, and disclosure

During the preceding twelve months, we may have collected the following categories:

California categoryExamples in the ServicesMain sourcesMain purposesCategories of recipients
IdentifiersName, business email, account ID, IP address, shipping address, wallet address, Tag or tap IDYou, devices, Suppliers, authentication and shipping providersVerification, accounts, security, orders, support, legal complianceService providers, relevant Suppliers or Labs, authorities where required
Customer records and commercial informationOrders, invoices, Tag purchases, shipment, batch and claim recordsYou, your organization, carriers, payment providersFulfillment, billing, support, auditService providers, advisers, transaction participants
Internet or electronic activityUser agent, browser, pages, links, logs, session and verification eventsDevices, browsers, Tags, hosting and security providersAuthentication, fraud prevention, security, operation, improvementHosting, authentication, security, database, and analytics providers
GeolocationCountry and optional city or region inferred from IPNetwork and geolocation providersClone detection, fraud prevention, security, analyticsService providers; limited batch analytics to relevant Suppliers or Labs
Professional or employment-related informationBusiness role, Supplier contact, Lab signatory, accreditation and credentialsYou, organizations, public Lab sources, COAsAccount administration, provenance, public Lab identificationService providers and the public where intentionally displayed
Audio, electronic, visual, or similar informationBatch photos, issue photos, uploaded files, support communicationsYou, Suppliers, reportersBatch comparison, support, investigation, public verification where selectedService providers, relevant Suppliers or Labs, the public where posted
InferencesSuspected replay, clone, anomaly, risk or fraud indicatorsBuyer Tap Data and account activitySecurity, anti-counterfeit review, enforcementOperators, service providers, relevant Suppliers or Labs as needed
Sensitive personal informationAuthentication credentials are processed by Clerk; Res Labs receives account and session identifiers, not plaintext passwords. We do not intentionally collect precise geolocation, health data, government identifiers, or other sensitive buyer information.You and authentication providersAccount security and requested serviceAuthentication and security providers

We collect these categories for the purposes in Section 2.9 and disclose them as described in Sections 2.13 and 2.14. We do not sell or share these categories for cross-context behavioral advertising.

2.21.2 California rights

Subject to scope and exceptions, California residents may request:

  1. the categories and specific pieces of personal information we collected;
  2. the categories of sources, purposes, and third parties involved;
  3. deletion;
  4. correction;
  5. opt-out of sale or sharing;
  6. limitation of certain uses of sensitive personal information; and
  7. equal treatment for exercising privacy rights.

Res Labs does not sell or share personal information for cross-context behavioral advertising, so there is no sale or sharing to opt out of under our current practices. We use sensitive personal information, if any, only for permitted operational and security purposes and not to infer characteristics.

Submit a request to info@reslabs.ai. Because Res Labs operates online, email is our designated request method. We will verify and respond as required by law. An authorized agent may submit a request if the agent provides legally sufficient authorization and we can verify the consumer or the agent’s authority.

We will not discriminate against you for exercising a right. A request may affect functionality where the information is necessary to provide or secure the Service.

2.21.3 Global Privacy Control and Do Not Track

Because we do not sell or share personal information for cross-context behavioral advertising, a Global Privacy Control signal does not change our current processing. We will honor applicable signals if our practices change or the law otherwise requires. Browsers also offer “Do Not Track” signals, but there is no uniform industry response standard; our verification and security logging remains necessary to provide the requested page.

2.22 Rights in other U.S. states and jurisdictions

Residents of other jurisdictions may have similar rights to access, correct, delete, obtain a copy, opt out of targeted advertising or certain profiling, or appeal a denied request. Submit a request or appeal to info@reslabs.ai. We will apply rights that are legally available to you and explain any denial as required.

2.23 Children

The Services are not directed to children. You must be at least eighteen and the age of legal majority to use the Services. We do not knowingly collect personal information from a child through an account. If you believe a child provided personal information, contact info@reslabs.ai.

2.24 Third-party websites

A verification page may link to a Lab, Supplier, IPFS gateway, blockchain explorer, or another website. Their privacy practices apply after you leave the Services. Res Labs is not responsible for their collection, cookies, security, or use of personal information.

2.25 Changes to this Policy

We may update this Policy as the Services, providers, laws, or practices change. The new version will show a revised effective date. We will provide additional notice for material changes when required. Continued use after the effective date is subject to the updated Policy.

2.26 Contact and complaints

For privacy questions, rights requests, objections, or complaints, contact:

Verares Labs Inc.
18 Ocean Ave, Jamestown, RI 02835
info@reslabs.ai

You may also complain to the data-protection authority where you live or work if applicable.


Related policies

Terms of ServicePrivacy PolicyAcceptable UseSupplier AgreementWhat Verification Means