Privacy Policy
Last updated: 2026-05-02
This Privacy Policy explains how CoreTools collects, uses, and protects your personal data when you visit coretools.app, create an account, or use our software. We are committed to processing your data lawfully, transparently, and with respect for your rights under the UK GDPR, the EU GDPR, and other applicable privacy laws.
1. Data Controller
The data controller responsible for your personal data is Zak Noble-Clarke, trading as CoreTools, established in the United Kingdom. Our trading address is 124 City Road, London, EC1V 2NX, United Kingdom. You can contact the controller at support@coretools.app for any privacy-related matter, including to exercise your rights under this policy.
2. What Data We Collect
Account data: your email address and metadata such as account creation date and last sign-in. We use passwordless authentication (email magic links / one-time codes) and do not set, ask for, or store passwords.
Purchase data: the billing details you provide at checkout, order identifiers, the product purchased, the amount and currency, and a transaction reference. Payment is processed by Stripe. CoreTools never sees or stores your full card number, CVC, or card expiry.
Licence data: a licence record stored in our Appwrite database, linked to your CoreTools account and to one or more device-slot entries. Each device slot records a hardware identifier (machine id) that the software generates to enforce the per-seat scope of your licence. This machine id is a non-reversible identifier derived from hardware and operating system characteristics.
Analytics data: we run our own lightweight, first-party analytics to understand how coretools.app is used. For each page view we record the URL of the page you requested, the referring URL, your browser user-agent (browser type, version, and operating system family), and an approximate time on page. We do not use Google Analytics or any advertising-network tracker, we do not set persistent advertising identifiers, we do not fingerprint you, and we do not build cross-site profiles or share analytics data with third parties.
Support correspondence: if you contact support@coretools.app we retain your message, our reply, and associated metadata so we can respond and keep a record of the matter.
3. Lawful Bases for Processing
We process account, purchase, and licence data on the basis of performance of a contract with you (Article 6(1)(b) UK/EU GDPR) so that we can sell, deliver, and maintain the software you have bought.
We process analytics data and security logs on the basis of our legitimate interests (Article 6(1)(f)) in understanding how our site is used and in protecting the service from abuse. We have assessed that this processing is proportionate and does not override your rights.
Where consent is the appropriate basis, for example for any optional communications, we will ask for your consent and you can withdraw it at any time without affecting prior processing.
We process certain records, such as financial transaction records, to comply with our legal obligations (Article 6(1)(c)) under UK tax and accounting law.
4. Retention Periods
Account data: retained until you request deletion, or for a reasonable period after prolonged inactivity. On deletion we remove or anonymise personal identifiers, except where retention is required by law or to resolve an outstanding dispute.
Purchase records: retained for six (6) years from the end of the relevant tax year, to comply with UK tax and accounting law (HMRC record-keeping requirements).
Licence data: retained for as long as the licence is active. On refund, the licence is revoked and associated device fingerprints are removed within a reasonable period unless required for fraud prevention.
Analytics data: retained for up to fourteen (14) months, after which it is deleted or aggregated into non-identifying statistics.
Support correspondence: retained for up to three (3) years from the date of the last message, unless a longer period is required to handle an ongoing matter or a legal obligation.
5. Subprocessors
We use the following subprocessors to deliver CoreTools. Each has been assessed for security and privacy and is bound by a data processing agreement.
Stripe, Inc. (United States) - payment processing. Acts as a data processor for payment details and as an independent controller for fraud-prevention purposes. International transfers are covered by the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.
Appwrite Cloud (Frankfurt, Germany - European Union) - database, authentication, and licence record hosting. Stores account data, licence records, and device-slot entries within the European Union.
Resend (Ireland - European Union sending region) - transactional email delivery for sign-in magic links, order receipts, and licence emails. We use the EU sending region, so message processing for delivery takes place within the European Union. Processes your email address and the contents of the message we send you. Resend is operated by a US parent company; transfers outside the UK/EU that may occur for support and operational purposes are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
Cloudflare, Inc. (global content delivery network) - CDN, Web Application Firewall, and bot protection. Processes request metadata to route traffic and block abusive activity. Cloudflare operates globally, and transfers outside the UK/EU are covered by the Standard Contractual Clauses and the UK Addendum.
6. International Transfers
Where personal data is transferred outside the United Kingdom or the European Economic Area to a country that has not received an adequacy decision, we rely on the European Commission Standard Contractual Clauses (for EU data) and the UK International Data Transfer Addendum (for UK data), supplemented by additional technical and organisational measures where appropriate. You can request more information about the safeguards in place by contacting support@coretools.app.
7. Your Rights
Under the UK GDPR and the EU GDPR, and subject to the conditions and exceptions set out in those laws, you have the right to: access your personal data; have inaccurate data corrected (rectification); have your data erased in certain circumstances; receive the data you provided in a portable, machine-readable format (portability); restrict the processing of your data; object to processing based on legitimate interests; and withdraw any consent you have given.
You can exercise these rights by emailing support@coretools.app. We will respond within one month, extendable by a further two months for complex requests as permitted by law. We may ask you to verify your identity before acting on a request.
If you are unhappy with how we have handled your data, you have the right to complain to a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the European Union, you may complain to your local Data Protection Authority.
8. Children
CoreTools is not directed at, and is not intended for use by, anyone under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact support@coretools.app and we will delete it promptly.
9. Breach Notification
We maintain procedures to detect and respond to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (the ICO in the UK, or another relevant European DPA) within 72 hours of becoming aware of it, as required by law. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
10. Security Measures
We apply technical and organisational measures appropriate to the risk, including transport-layer encryption (TLS) for all traffic to coretools.app, encryption at rest for account data held by Appwrite, passwordless authentication via short-lived single-use magic links and one-time codes, least-privilege access controls for administrative accounts, DDoS and bot protection via Cloudflare, and secure handling of payment flows through Stripe so that payment card data never touches our own systems.
11. Contact
For any privacy-related question, request, or concern, please contact CoreTools at support@coretools.app.