Coruve

Legal

Privacy Policy

What we collect, why, how long we keep it, and the rights you have — in plain English.

Last updated · 11 August 2026

Clause 1. Who we are

Coruve ("Coruve", "we", "us") provides a privacy-first web and product analytics service available at coruve.com. This policy explains what personal data we handle, why, and the rights you have over it. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025.

Company details: the registered legal entity name, company number, and registered office address for Coruve will be published here upon incorporation. Until then, you can reach the team responsible for data protection at [email protected].

Clause 2. Our two roles: controller and processor

Coruve handles data in two distinct capacities, and your rights run differently in each:

  • As a controller — for data about our own customers and website visitors: your account, billing, support conversations, and visits to coruve.com. This policy governs that data directly.
  • As a processor — for analytics data our customers collect from their websites using Coruve. The site owner is the controller of that data; we process it on their instructions under our Data Processing Agreement.

If you visited a website that uses Coruve and want to exercise your data protection rights over that site's analytics, contact the site owner — they control the data. We assist them with every such request, and you can also write to us and we will point your request to the right place.

Clause 3. Data we collect as a controller

CategoryWhat it includesWhere it comes from
Account dataName, email address, hashed password, plan typeYou, at registration
Billing dataSubscription status and history. Card details are collected and stored by Paddle, our merchant of record — they never touch our serversYou, via Paddle checkout
CommunicationsSupport requests, contact-form messages, emails you send usYou
Usage of coruve.comPages viewed, referrer, coarse location (country, region, city — never precise coordinates), device class — collected with Coruve's own cookieless analyticsYour browser, automatically
Security signalsBot-protection tokens (Cloudflare Turnstile) on login and registration; rate-limiting countersYour browser, automatically

Clause 4. What the Coruve tracker collects (on customers' sites)

For transparency to everyone — customers and their visitors alike — this is exactly what the Coruve snippet collects on a site where it is installed:

  • Events: page views (including route changes in web apps), clicks, maximum scroll depth, and Core Web Vitals performance metrics — plus any custom events the site owner defines.
  • Click detail: the position of the click on the page, and the clicked element's tag, id and CSS classes. This covers clicks on buttons and links, and — capped at 10 per page view — clicks that land on something that is not interactive, which is how Coruve finds things that look clickable and are not. No text from the page is recorded with either kind.
  • Page context: URL and path, referrer, and UTM campaign parameters.
  • Technical context: browser and operating system family, viewport size.
  • Coarse location: a country code, region code, and city name derived from the IP address at the moment of ingestion. This is city-level geography at its finest — never precise coordinates. The IP address itself is discarded immediately and never stored.
  • A pseudonymous visitor identifier: a salted hash that rotates every day, so visitors cannot be tracked across days, devices, or websites. It is hashed again on our servers with a secret salt before storage.
  • A session identifier kept in the browser's localStorage for the site you are visiting, so that one visit reads as one session even when you open several tabs of that site. It expires after 30 minutes without activity, at which point your next action starts a new one. It is readable only by the site that stored it and is never shared across sites.
  • If a measurement cannot be sent — you are offline, or the request fails — the events waiting to be sent are held in the browser's localStorage until your next visit, for at most 24 hours, and then discarded. They hold the same information listed above and no additional identifier. A site owner who has excluded their own visits from their statistics also has that choice stored there, so their browser stays excluded. Both are readable only by the site you are visiting, and neither is ever shared across sites.

The tracker deliberately does not:

  • Set cookies — none, of any kind.
  • Use fingerprinting techniques such as canvas, WebGL, or font enumeration.
  • Collect the text of buttons or form fields by default, or ever collect form input values.
  • Track anyone who has Do Not Track or Global Privacy Control enabled — the tracker fully disables itself.
  • Follow visitors across different websites.

Clause 5. Why we process data (lawful bases)

ProcessingLawful basis (UK GDPR Art. 6)
Providing your account, the dashboard, and the analytics servicePerformance of a contract
Billing and subscription managementPerformance of a contract; legal obligation (tax and accounting records)
Understanding how coruve.com itself is used (cookieless analytics)Legitimate interests — improving our product with minimal, pseudonymised data
Security: bot protection, rate limiting, abuse preventionLegitimate interests — keeping the service safe
Service emails (verification, security, billing notices)Performance of a contract
Product updates and marketing emailsConsent — and every such email contains a working unsubscribe link

Clause 6. AI features and what they see

Coruve uses a large language model (Anthropic's Claude) for one narrow purpose: turning raw developer event names (like btn_submit_final_v2) into readable labels and categories. Only the event names and their draft labels are sent to Anthropic — never visitor identifiers, page URLs, IP-derived data, or any other analytics content. Suggested labels remain pending until the site owner approves them.

Clause 7. How long we keep data

Analytics event data is kept for the retention period of the customer's plan and then deleted automatically — enforced by a time-to-live rule at the storage layer, not by a manual cleanup process:

PlanEvent data retention
Free30 days
Starter1 year (365 days)
Pro2 years (730 days)
Growth3 years (1,095 days)

Account data is kept while your account is active. When an account is closed, we delete or irreversibly anonymise personal data within a reasonable period, except where we must keep records longer (for example, invoicing records under tax law).

Clause 8. Who we share data with

We never sell personal data and never share it with advertising networks. We use a small number of service providers (sub-processors) to run Coruve:

ProviderPurposeLocation
RailwayCloud hosting, application servers, and the application databaseNetherlands (Amsterdam)
HostingerCloud infrastructure for our self-hosted analytics event store (ClickHouse, operated by Coruve)Germany (Frankfurt)
PaddleMerchant of record: payment processing, subscription billing, and sales taxUnited Kingdom / global
ResendTransactional email deliveryUnited States
AnthropicAI event labeling (event names only — see section 6)United States
CloudflareBot protection (Turnstile) on authentication pagesGlobal

We may also disclose data where the law requires it — for example, to comply with a binding court order — and we will challenge requests that are overbroad.

Clause 9. International transfers

Where data leaves the UK (see the table above), we rely on safeguards recognised by UK GDPR: UK adequacy regulations (including the UK–US Data Bridge for providers certified under the UK Extension to the EU–US Data Privacy Framework), or the ICO's International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, supplemented by technical measures such as encryption in transit and pseudonymisation.

Clause 10. How we protect data

  • All traffic is encrypted in transit (TLS).
  • Visitor identifiers are salted and hashed — twice: once in the browser, once on our servers with a secret salt.
  • Passwords are stored only as bcrypt hashes.
  • Internal access tokens follow least-privilege scoping; production and staging are fully separated environments.
  • Data past its retention period is deleted automatically at the storage layer.

Clause 11. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Have your data erased
  • Restrict or object to processing, including any processing based on legitimate interests
  • Receive your data in a portable format
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these, email [email protected]. We acknowledge data protection complaints within 30 days and respond to rights requests within one calendar month. You also have the right to complain to the UK's supervisory authority, the Information Commissioner's Office — ico.org.uk.

Clause 12. Children

Coruve is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 through account registration. If you believe a child has provided us personal data, contact us and we will delete it.

Clause 13. Changes and contact

When we make material changes to this policy we will update the date at the top and, for significant changes affecting customers, notify you by email. Questions about this policy or our data practices: [email protected].

Privacy Policy | Coruve