Privacy Policy
Effective 2026-08-13. What CoreBeacon collects, why, who else sees it, and how long it is kept.
1. Two kinds of data, two different roles
CoreBeacon is business software, so most of the personal data flowing through it is not ours to decide about. The distinction matters and runs through everything below:
- Account data — the people who sign up, their names, work email addresses and billing details. We decide how this is used, so we are the controller.
- Workspace content — the tickets, assets, documents and records your organization puts in, including any personal data about your own staff or customers. Your organization decides what goes in and why; we only process it on your instructions. You are the controller, we are the processor.
If you are an employee whose company uses CoreBeacon and you want your data corrected or removed, ask your own IT or HR team first — they control that workspace and can act immediately. We will help them, but we will not alter a customer’s data on the request of a third party.
2. What we collect
- To create an account: your name, work email address, organization name, and a password (stored only as an Argon2id hash — we cannot read it, and neither can anyone who obtains the database).
- To keep you signed in: a session token, stored only as a SHA-256 hash.
- If you enable it: multi-factor secrets (encrypted at rest with AES-256-GCM) or passkey public keys.
- To take payment: billing contact details and a Stripe customer reference. Card numbers are entered on Stripe’s pages and never reach our servers.
- To run the service: operational logs containing timestamps, IP addresses, request paths and workspace/user identifiers, and an audit trail of security-relevant actions inside your workspace.
- Whatever you put in: the content of your workspace.
3. What we never do
- We do not sell personal data, and we do not share it for advertising.
- We do not use your workspace content to train machine-learning models.
- We do not use advertising or analytics cookies. The only cookies we set are the ones that keep you signed in and remember your workspace and theme.
- Our staff do not read your workspace content. Our internal operator console shows only metadata — workspace name, plan, user and ticket counts, signup date — and no route behind it can reach a ticket, an asset or a document.
4. Who else processes it
We use the following providers to run the service. Each is bound to process data only on our instructions.
| Provider | What for | What they receive |
|---|---|---|
| Render | Application hosting and the PostgreSQL database where your data lives | All service data |
| Stripe (optional) | Payment processing for paid plans | Billing contact and payment details — card numbers are entered on Stripe’s own pages and never reach us |
| Resend | Sending transactional email (verification, password reset, notifications) | Recipient email address and message contents |
| Sentry (optional) | Crash reporting, so faults are noticed and fixed | Error type, message, stack trace, HTTP route, and workspace/user identifiers — never request bodies, message contents or email addresses |
| Anthropic (optional) | The optional AI assistant (ticket summaries, suggested replies) | Only the ticket text sent to it, and only for workspaces that switch the feature on |
| Cloudflare | DNS and network protection for core-beacon.com | Connection metadata (IP address, request routing) |
Providers marked optional are only involved if the relevant feature is switched on — the AI assistant, for instance, sends ticket text to Anthropic only for workspaces that have explicitly enabled it.
5. How long we keep it
- Workspace content: for as long as your account is open. When you delete your workspace it is held for a 30-day recovery window, then permanently removed.
- Sessions: expire after at most 30 days, and immediately when you sign out or change your password.
- Audit records: retained according to the period your workspace administrator sets; a scheduled job removes anything older.
- Operational logs: a short rolling window for diagnosing faults.
- Billing records: kept as long as tax and accounting law requires, even after an account closes.
6. How it is protected
- Encrypted in transit (TLS) and at rest.
- Workspaces are isolated by the database itself through row-level security, not only by application code — so a bug in a query cannot return another organization’s rows.
- The application connects using a restricted database role that cannot bypass that isolation.
- Passwords are Argon2id hashes; session and API tokens are stored only as hashes.
- Multi-factor authentication, passkeys and single sign-on are available on all plans.
No system is perfectly secure. If a breach affects your data we will tell affected workspace administrators without undue delay, and regulators where the law requires.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data, to object to or restrict processing, and to complain to a data-protection authority. Much of this you can do yourself in the application at any time.
For anything else, write to privacy@core-beacon.com. We will respond within 30 days. For workspace content, see section 1 — the request usually belongs with the organization that controls the workspace.
8. International transfers
Our providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
9. Children
CoreBeacon is workplace software and is not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
We may update this policy. Material changes are announced to workspace administrators by email at least 30 days in advance, and the effective date above always reflects the current version.
11. Contact
CoreBeacon
[registered address]
privacy@core-beacon.com