Plain-English draft — have an attorney review before commercial launch. Last updated July 2026.
When a dispensary scans a patient card, we process the information printed in the card's barcode: name, card number, license type, and issue/expiration dates. We also store dispensary account details (business name, license number, staff emails) and a log of check-ins.
One thing: help licensed Kentucky dispensaries verify patients at the door and keep a compliance record of those checks. We do not sell data, share it with third parties for marketing, or use it for advertising. Ever.
Each dispensary chooses a retention period (30–365 days, default 90). After that, patient names and card numbers are automatically stripped from check-in records; anonymous counts remain for the dispensary's statistics.
Connections are encrypted in transit (HTTPS). Integration keys (Metrc, Dutchie) are encrypted at rest with AES-256-GCM. Staff accounts see only the scan station; integration keys are visible to managers only. Passwords are stored as salted hashes, never as plain text.
Live verification links use the Commonwealth of Kentucky's public card-verification endpoint. Where a dispensary connects its own Metrc facility key, lookups occur under that dispensary's authorization for its own operations only.
Dispensaries may export or delete their scan history and revoke integration keys at any time. Patients may direct questions about their registry data to the Kentucky Office of Medical Cannabis; questions about a specific dispensary's records go to that dispensary.
[Your business name] · [email] · [address]