Location is used to verify the store—not to follow the person.
What active Recall uses
A valid RedHawk access token, foreground location permission, a customer-confirmed store, and the product identifiers entered or scanned during the active session.
What a confirmed hot-item signal keeps
The recall and product identifiers, time, confirmed store, city/state, a coarse location cell, evidence confidence, and an anonymous token-account reference.
What is not retained in a signal
No continuous movement history, no raw camera frames, no contact list, no advertising identifier, no home route, and no precise GPS coordinate.
Anonymous device continuity for free trials
Recall uses a high-entropy anonymous per-install device identifier plus a secure HttpOnly server binding so an active free trial can be recognized and the same installation cannot repeatedly redeem the same campaign QR. Recall does not request, read, or retain the phone IMEI, serial number, contacts, or advertising ID. Clearing browser/site storage can reset browser-level identity; a normal website/PWA cannot obtain an unresettable hardware identifier.
Orders and payment
Recall keeps order identifiers, plan, billing status, organization name, contact email, payment-provider customer/subscription identifiers, and access entitlement status. Raw card numbers, bank-account credentials, and payment authentication data are entered with and retained by the payment provider, not Recall.
Store outreach
A detection enters a private review queue. RedHawk does not automatically accuse or contact a store from a single unreviewed scan.