Legal
Privacy Policy
What we collect, why, how long we keep it, and the rights you have — in plain English.
Last updated · 11 August 2026
Clause 1. Who we are
Coruve ("Coruve", "we", "us") provides a privacy-first web and product analytics service available at coruve.com. This policy explains what personal data we handle, why, and the rights you have over it. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025.
Clause 2. Our two roles: controller and processor
Coruve handles data in two distinct capacities, and your rights run differently in each:
- As a controller — for data about our own customers and website visitors: your account, billing, support conversations, and visits to coruve.com. This policy governs that data directly.
- As a processor — for analytics data our customers collect from their websites using Coruve. The site owner is the controller of that data; we process it on their instructions under our Data Processing Agreement.
If you visited a website that uses Coruve and want to exercise your data protection rights over that site's analytics, contact the site owner — they control the data. We assist them with every such request, and you can also write to us and we will point your request to the right place.
Clause 3. Data we collect as a controller
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, hashed password, plan type | You, at registration |
| Billing data | Subscription status and history. Card details are collected and stored by Paddle, our merchant of record — they never touch our servers | You, via Paddle checkout |
| Communications | Support requests, contact-form messages, emails you send us | You |
| Usage of coruve.com | Pages viewed, referrer, coarse location (country, region, city — never precise coordinates), device class — collected with Coruve's own cookieless analytics | Your browser, automatically |
| Security signals | Bot-protection tokens (Cloudflare Turnstile) on login and registration; rate-limiting counters | Your browser, automatically |
Clause 4. What the Coruve tracker collects (on customers' sites)
For transparency to everyone — customers and their visitors alike — this is exactly what the Coruve snippet collects on a site where it is installed:
- Events: page views (including route changes in web apps), clicks, maximum scroll depth, and Core Web Vitals performance metrics — plus any custom events the site owner defines.
- Click detail: the position of the click on the page, and the clicked element's tag, id and CSS classes. This covers clicks on buttons and links, and — capped at 10 per page view — clicks that land on something that is not interactive, which is how Coruve finds things that look clickable and are not. No text from the page is recorded with either kind.
- Page context: URL and path, referrer, and UTM campaign parameters.
- Technical context: browser and operating system family, viewport size.
- Coarse location: a country code, region code, and city name derived from the IP address at the moment of ingestion. This is city-level geography at its finest — never precise coordinates. The IP address itself is discarded immediately and never stored.
- A pseudonymous visitor identifier: a salted hash that rotates every day, so visitors cannot be tracked across days, devices, or websites. It is hashed again on our servers with a secret salt before storage.
- A session identifier kept in the browser's
localStoragefor the site you are visiting, so that one visit reads as one session even when you open several tabs of that site. It expires after 30 minutes without activity, at which point your next action starts a new one. It is readable only by the site that stored it and is never shared across sites. - If a measurement cannot be sent — you are offline, or the request fails — the events waiting to be sent are held in the browser's
localStorageuntil your next visit, for at most 24 hours, and then discarded. They hold the same information listed above and no additional identifier. A site owner who has excluded their own visits from their statistics also has that choice stored there, so their browser stays excluded. Both are readable only by the site you are visiting, and neither is ever shared across sites.
The tracker deliberately does not:
- Set cookies — none, of any kind.
- Use fingerprinting techniques such as canvas, WebGL, or font enumeration.
- Collect the text of buttons or form fields by default, or ever collect form input values.
- Track anyone who has Do Not Track or Global Privacy Control enabled — the tracker fully disables itself.
- Follow visitors across different websites.
Clause 5. Why we process data (lawful bases)
| Processing | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing your account, the dashboard, and the analytics service | Performance of a contract |
| Billing and subscription management | Performance of a contract; legal obligation (tax and accounting records) |
| Understanding how coruve.com itself is used (cookieless analytics) | Legitimate interests — improving our product with minimal, pseudonymised data |
| Security: bot protection, rate limiting, abuse prevention | Legitimate interests — keeping the service safe |
| Service emails (verification, security, billing notices) | Performance of a contract |
| Product updates and marketing emails | Consent — and every such email contains a working unsubscribe link |
Clause 6. AI features and what they see
Coruve uses a large language model (Anthropic's Claude) for one narrow purpose: turning raw developer event names (like btn_submit_final_v2) into readable labels and categories. Only the event names and their draft labels are sent to Anthropic — never visitor identifiers, page URLs, IP-derived data, or any other analytics content. Suggested labels remain pending until the site owner approves them.
Clause 7. How long we keep data
Analytics event data is kept for the retention period of the customer's plan and then deleted automatically — enforced by a time-to-live rule at the storage layer, not by a manual cleanup process:
| Plan | Event data retention |
|---|---|
| Free | 30 days |
| Starter | 1 year (365 days) |
| Pro | 2 years (730 days) |
| Growth | 3 years (1,095 days) |
Account data is kept while your account is active. When an account is closed, we delete or irreversibly anonymise personal data within a reasonable period, except where we must keep records longer (for example, invoicing records under tax law).
Clause 9. International transfers
Where data leaves the UK (see the table above), we rely on safeguards recognised by UK GDPR: UK adequacy regulations (including the UK–US Data Bridge for providers certified under the UK Extension to the EU–US Data Privacy Framework), or the ICO's International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, supplemented by technical measures such as encryption in transit and pseudonymisation.
Clause 10. How we protect data
- All traffic is encrypted in transit (TLS).
- Visitor identifiers are salted and hashed — twice: once in the browser, once on our servers with a secret salt.
- Passwords are stored only as bcrypt hashes.
- Internal access tokens follow least-privilege scoping; production and staging are fully separated environments.
- Data past its retention period is deleted automatically at the storage layer.
Clause 11. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased
- Restrict or object to processing, including any processing based on legitimate interests
- Receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent
To exercise any of these, email [email protected]. We acknowledge data protection complaints within 30 days and respond to rights requests within one calendar month. You also have the right to complain to the UK's supervisory authority, the Information Commissioner's Office — ico.org.uk.
Clause 12. Children
Coruve is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 through account registration. If you believe a child has provided us personal data, contact us and we will delete it.
Clause 13. Changes and contact
When we make material changes to this policy we will update the date at the top and, for significant changes affecting customers, notify you by email. Questions about this policy or our data practices: [email protected].