Legal · Privacy Policy

Privacy
Policy.

Last updated: 1 May 2026Applies to: Core ERP platform (coreerp.io)Questions: privacy@coreerp.io

The short version

Your data stays yours

Everything you create inside Core — invoices, employees, inventory — belongs to you. We never analyse or sell it.

No trackers, ever

We don't use Google Analytics or Facebook Pixel. Zero third-party tracking cookies. Our analytics are first-party only.

Delete anytime

One click in Settings permanently and irreversibly deletes your account and all associated data within 30 days.

01

What We Collect

Account Data

When you register, we collect your name, email address, company name, job title, and a hashed password. We never store plaintext passwords.

Usage Data

We log which pages you visit, which actions you perform (create, update, delete), and approximate timestamps. This forms the audit trail you can view inside the platform.

Device & Connection

We record your IP address, browser type, and operating system for security monitoring. Unusual login locations trigger alerts visible in the Audit Trail module.

Business Data

All inventory records, invoices, HR data, financial transactions, and reports you create inside Core belong entirely to you. We treat them as confidential and never analyse them for our own purposes.

02

How We Use Your Data

To Run the Platform

Your data powers the features you pay for: forecasting, anomaly detection, report generation. Without it the platform cannot function.

Security & Fraud Prevention

We analyse login patterns and API call volumes to detect abuse. Anomalous activity triggers automated alerts and, if necessary, account suspension.

Product Improvement

We use aggregated, anonymised usage patterns (e.g. 'X% of users open the Procurement tab first') to decide what to build next. Individual records are never included.

Communications

We send transactional emails (password resets, invoice alerts, SLA notifications) and, only if you opt in, product update newsletters. You can unsubscribe from marketing at any time.

03

Who We Share Data With

Infrastructure Providers

We use AWS (or your chosen cloud region) for hosting and PostgreSQL for storage. These providers are bound by strict data processing agreements and are ISO 27001 certified.

No Data Brokers, Ever

We do not sell, rent, or trade your personal or business data to third-party advertisers, data brokers, or analytics companies. This is unconditional.

Legal Requirements

If required by a court order or regulatory authority in your jurisdiction, we may be obligated to disclose data. We will notify you as soon as legally permitted if this occurs.

Successors

In the event of a merger or acquisition, your data may transfer to a successor entity. We will notify you 30 days in advance and you can export or delete your data before any transfer.

04

How We Protect Data

Encryption in Transit

All data between your browser and our servers is encrypted with TLS 1.3. Our API endpoints do not accept unencrypted connections.

Encryption at Rest

All database volumes are encrypted using AES-256. Backups are separately encrypted before being written to cold storage.

Role-Based Access

Inside Core, your own RBAC system controls who sees what. Our own internal staff follow the same principle — engineers cannot access your tenant's data without a support ticket you opened.

Penetration Testing

We commission independent penetration tests quarterly. Critical findings are patched within 48 hours. Reports are available to Enterprise clients on request under NDA.

05

Your Rights

Access & Portability

You can export all of your company's data at any time via Settings → Data Export. The export is a structured JSON archive you can import into any system.

Correction

If any of your account data is inaccurate, you can update it directly in Settings. For data inside your business records (invoices, employees, etc.), you have full CRUD access.

Deletion

You can delete your account and all associated data from Settings → Danger Zone. Deletion is irreversible and completed within 30 days, after which no backup retains identifiable records.

GDPR & CCPA

If you are in the EU or California, you have specific statutory rights including the right to object to processing and the right to restrict processing. Contact privacy@coreerp.io to exercise these rights.

06

Cookies

Strictly Necessary

We set one session cookie to keep you logged in. This cookie is httpOnly and SameSite=Strict. It expires when you log out or after 8 hours of inactivity.

No Tracking Cookies

We do not use Google Analytics, Facebook Pixel, Hotjar, or any third-party tracking cookies. Our analytics are first-party and privacy-preserving.

Preference Cookies

If you have enabled dark mode or changed language settings, a small localStorage value stores your preference. This is never transmitted to our servers.

Questions about this policy?

Our Data Protection Officer responds to all privacy inquiries within 5 business days. For GDPR erasure or portability requests, response time is within 30 days as required by law.