Legal · Privacy Policy
The short version
Your data stays yours
Everything you create inside Core — invoices, employees, inventory — belongs to you. We never analyse or sell it.
No trackers, ever
We don't use Google Analytics or Facebook Pixel. Zero third-party tracking cookies. Our analytics are first-party only.
Delete anytime
One click in Settings permanently and irreversibly deletes your account and all associated data within 30 days.
Table of Contents
Account Data
When you register, we collect your name, email address, company name, job title, and a hashed password. We never store plaintext passwords.
Usage Data
We log which pages you visit, which actions you perform (create, update, delete), and approximate timestamps. This forms the audit trail you can view inside the platform.
Device & Connection
We record your IP address, browser type, and operating system for security monitoring. Unusual login locations trigger alerts visible in the Audit Trail module.
Business Data
All inventory records, invoices, HR data, financial transactions, and reports you create inside Core belong entirely to you. We treat them as confidential and never analyse them for our own purposes.
To Run the Platform
Your data powers the features you pay for: forecasting, anomaly detection, report generation. Without it the platform cannot function.
Security & Fraud Prevention
We analyse login patterns and API call volumes to detect abuse. Anomalous activity triggers automated alerts and, if necessary, account suspension.
Product Improvement
We use aggregated, anonymised usage patterns (e.g. 'X% of users open the Procurement tab first') to decide what to build next. Individual records are never included.
Communications
We send transactional emails (password resets, invoice alerts, SLA notifications) and, only if you opt in, product update newsletters. You can unsubscribe from marketing at any time.
Encryption in Transit
All data between your browser and our servers is encrypted with TLS 1.3. Our API endpoints do not accept unencrypted connections.
Encryption at Rest
All database volumes are encrypted using AES-256. Backups are separately encrypted before being written to cold storage.
Role-Based Access
Inside Core, your own RBAC system controls who sees what. Our own internal staff follow the same principle — engineers cannot access your tenant's data without a support ticket you opened.
Penetration Testing
We commission independent penetration tests quarterly. Critical findings are patched within 48 hours. Reports are available to Enterprise clients on request under NDA.
Access & Portability
You can export all of your company's data at any time via Settings → Data Export. The export is a structured JSON archive you can import into any system.
Correction
If any of your account data is inaccurate, you can update it directly in Settings. For data inside your business records (invoices, employees, etc.), you have full CRUD access.
Deletion
You can delete your account and all associated data from Settings → Danger Zone. Deletion is irreversible and completed within 30 days, after which no backup retains identifiable records.
GDPR & CCPA
If you are in the EU or California, you have specific statutory rights including the right to object to processing and the right to restrict processing. Contact privacy@coreerp.io to exercise these rights.
Questions about this policy?
Our Data Protection Officer responds to all privacy inquiries within 5 business days. For GDPR erasure or portability requests, response time is within 30 days as required by law.