Privacy Policy
CoreLens Cloud is committed to protecting the personal information of our customers, users, and visitors. This policy explains how we collect, use, share, and safeguard your data when you use our platform and services.
Introduction
This Privacy Policy describes how CoreLens Cloud, Inc. (“CoreLens Cloud,” “we,” “our,” or “us”) collects, uses, discloses, and protects information about you when you visit our website at corelenscloud.com, access our observability platform, use our APIs, or otherwise interact with our services (collectively, the “Services”).
This policy applies to all users of CoreLens Cloud, including prospective customers who visit our marketing site, registered account holders, administrators and developers who integrate our APIs, and any individuals whose personal data is processed through our platform on behalf of our customers. It does not apply to third-party websites or services that link to or from our Services.
We believe privacy is a foundational component of a trustworthy observability platform. The infrastructure data you send to CoreLens Cloud often contains sensitive operational detail, and we treat that responsibility seriously. By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please discontinue your use of our Services.
Information We Collect
We collect information in several ways: information you provide directly to us, information generated automatically when you use our Services, and information we receive from third parties.
Account and Billing Data
When you register for an account or subscribe to a paid plan, we collect information necessary to establish and maintain your account and process payment.
- Identity information: your full name, job title, and company or organization name.
- Contact information: your work email address, phone number (when provided), and mailing address.
- Billing information: payment card details (processed and vaulted by our payment processor, Stripe — we do not store raw card numbers), billing address, and transaction history.
- Account credentials: hashed passwords, SSO identifiers, and multi-factor authentication tokens.
Usage and Platform Data
As you use the CoreLens Cloud platform we collect data about how you interact with it, as well as the telemetry data you explicitly send us for analysis.
- Platform activity: dashboards created or modified, alert rules configured, queries executed, integrations enabled, and team member management actions.
- Log, metric, and trace data: the telemetry you ingest through our ingestion APIs. You control what you send; we process and store it on your behalf as a data processor.
- API usage records: API call timestamps, endpoints, response codes, and data volumes, used for rate limiting, billing calculation, and capacity planning.
Technical Data
- Network identifiers: IP address, geolocation derived from IP, and referring URL.
- Device and browser data: browser type and version, operating system, screen resolution, and timezone.
- Session data: session identifiers, pages viewed, feature interactions, and time spent in the application.
Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies. For full detail on what we place, why, and how to control them, see the Cookies section below.
How We Use Information
We use the information we collect for the following purposes, each of which has a legitimate basis under applicable privacy laws:
- Service delivery: provisioning your account, ingesting and processing telemetry, generating dashboards and alerts, and providing customer support and documentation.
- Billing and payments: calculating resource consumption, processing subscription charges, issuing invoices, and managing renewals and cancellations.
- Product improvement: analyzing aggregate and anonymized usage patterns to understand which features are most valuable, identify friction in onboarding flows, and guide our engineering roadmap.
- Security monitoring: detecting and responding to unauthorized access attempts, abuse of our APIs, platform vulnerabilities, and fraudulent activity.
- Communications: sending transactional emails (account confirmation, password reset, billing receipts, incident notifications) and, with your consent, product announcements and feature updates.
- Legal obligations: complying with applicable laws, responding to lawful government requests, enforcing our Terms of Service, and protecting the rights, property, or safety of CoreLens Cloud, our users, or others.
We do not use your telemetry data (the logs, metrics, and traces you send us) to train machine learning models, derive insights about your end-users for advertising, or for any purpose other than delivering the Services back to you.
Data Sharing
We do not sell your personal information, and we share it only in the circumstances described below.
Service Providers
We engage carefully vetted third-party vendors to help us operate our business. These providers access your data only to perform services on our behalf and under contractual obligations that prohibit any other use.
- Amazon Web Services (AWS): our primary infrastructure and cloud platform for compute, storage, databases, and networking. Data is stored in AWS us-east-1 and eu-west-1 regions by default.
- Stripe: payment processing, subscription management, and invoicing. Stripe is PCI DSS Level 1 certified.
- Customer support tools: we use ticketing and live-chat platforms to manage support requests. Representatives have access only to the minimum information required to resolve your inquiry.
- Analytics services: aggregate product analytics processed under strict data processing agreements.
Business Partners
Where we integrate with third-party software at your explicit request (for example, a PagerDuty or Slack integration you configure), we share only the data necessary to enable that integration and only with your authorization.
Legal Disclosures
We may disclose your information where required by law, court order, or government regulation, or when we believe disclosure is necessary to protect the safety of any person, prevent fraud, or defend our legal rights. We will notify you of such requests where legally permitted to do so.
Corporate Transactions
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our platform before your data becomes subject to a materially different privacy policy.
What We Never Do
- We never sell your personal information to data brokers, advertisers, or any third party for their own use.
- We never disclose your telemetry data (logs, metrics, traces) to other customers or any third parties not involved in delivering the Services to you.
- We never use your data to serve you third-party advertising.
Data Security
Security is integral to the CoreLens Cloud platform — we are an infrastructure monitoring company and we hold ourselves to the same standards we help our customers achieve.
- Encryption in transit: all data transmitted between your systems and our platform is encrypted using TLS 1.2 or higher. We enforce HSTS and reject connections on deprecated cipher suites.
- Encryption at rest: stored data is encrypted using AES-256 with customer-specific key envelopes managed through AWS KMS.
- Access controls: access to production data is restricted to authorized CoreLens Cloud engineers on a need-to-know basis, enforced through role-based access control (RBAC), SSO with hardware MFA requirements, and privileged access management tooling.
- SOC 2 Type II compliance: our controls for security, availability, and confidentiality are independently audited annually by a third-party assessor. The most recent report is available to customers under NDA upon request.
- Penetration testing: we engage an independent security firm to conduct penetration tests at least annually and after major platform changes. Findings are triaged and remediated according to severity SLAs.
- Incident response: we maintain a documented incident response plan. In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the breach, or sooner where required by applicable law.
No method of electronic transmission or storage is 100% secure. While we take commercially reasonable measures to protect your information, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and to report any suspected security incidents to security@corelenscloud.com.
Data Retention
We retain information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
- Account data: retained for the duration of your active subscription. Upon account closure or cancellation, account data is held for 30 days to allow for inadvertent closure recovery, then permanently deleted unless we are legally required to retain it (for example, for tax or financial records).
- Log, metric, and trace data: retention is configurable per data type in your account settings. Available retention windows are 30 days, 90 days, and 365 days. Data exceeding your configured retention window is automatically purged on a rolling basis.
- Billing and financial records: retained for a minimum of seven years to comply with applicable tax and accounting obligations.
- Support communications: ticket history and related communications retained for three years to support continuity and quality assurance.
You may request deletion of your personal information at any time. Verified deletion requests are honored within 30 days except where retention is required by law. See Your Rights for how to submit a request.
Your Rights
Depending on your location, you have a number of rights regarding your personal information. We honor these rights regardless of your jurisdiction; legal frameworks below describe the formal basis where applicable.
General Rights (All Users)
- Access: you may request a copy of the personal information we hold about you.
- Correction: you may request that we correct inaccurate or incomplete personal information. Many fields are editable directly in your account settings.
- Deletion: you may request that we delete your personal information, subject to legal retention requirements.
- Portability: you may request your personal data in a structured, machine-readable format (JSON or CSV) for transfer to another service.
- Opt-out of marketing: you may unsubscribe from marketing emails at any time using the unsubscribe link in any marketing email, or by contacting us at privacy@corelenscloud.com. Transactional emails cannot be opted out of while your account is active.
GDPR Rights (EU / EEA / UK Users)
If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right to restrict processing: you may ask us to pause processing of your data in certain circumstances, for example while a correction request is being evaluated.
- Right to object: you may object to processing based on our legitimate interests, including direct marketing.
- Right not to be subject to automated decision-making: we do not make legally significant automated decisions based solely on automated processing of your personal data.
- You also have the right to lodge a complaint with your local data protection authority. A list of EU data protection authorities is available at edpb.europa.eu.
CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you the following additional rights:
- Right to know and access: the categories of personal information we have collected, the purposes for which it was collected, and the categories of third parties with whom it has been shared.
- Right to delete: request deletion of personal information we have collected, subject to certain exceptions.
- Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising.
- Right to correct: request correction of inaccurate personal information.
- Right to limit use of sensitive personal information: we collect sensitive personal information (financial data, precise location) only as necessary to provide the Services.
- Non-discrimination: we will not discriminate against you for exercising your CCPA rights.
To exercise any of these rights, submit a request to privacy@corelenscloud.com with the subject line “Privacy Rights Request.” We may need to verify your identity before processing the request. We will respond within 30 days (or 45 days for complex requests, with notice).
Cookies
Cookies are small text files placed on your device by websites you visit. We use cookies and similar technologies (local storage, session storage, pixels) across our website and platform.
Types of Cookies We Use
- Strictly necessary cookies: these are required for the platform to function. Examples include authentication session cookies, CSRF protection tokens, and load balancer routing cookies. These cannot be disabled without breaking the Services.
- Analytics cookies: we use first-party analytics cookies to understand aggregate traffic patterns, popular content, and navigation paths on our marketing site. No individual profiles are built from this data.
- Preference cookies: these remember your settings within the platform, such as dashboard layout preferences, timezone selection, and notification preferences, so you don’t have to reconfigure them on each visit.
Third-Party Cookies
Certain pages on our marketing website may include embedded content (such as video players or social share widgets) from third parties that may set their own cookies. We do not control these third-party cookies. We do not use third-party advertising cookies or retargeting pixels on our platform.
How to Control Cookies
You can configure your browser to refuse all cookies, accept only certain cookies, or to notify you when a cookie is being set. Note that disabling cookies other than strictly necessary ones may affect your experience. Browser cookie management instructions are available from your browser’s help documentation. You may also opt out of analytics cookies using our cookie preference center, accessible via the “Cookie Settings” link in the footer.
International Data Transfers
CoreLens Cloud is headquartered in the United States. If you are located outside the United States, your personal information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from those in your home country.
Where we transfer personal data from the EEA, UK, or Switzerland to countries not recognized as providing adequate protection, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs): we incorporate the European Commission’s approved Standard Contractual Clauses into our data processing agreements with sub-processors located in non-adequate countries.
- EU-US Data Privacy Framework: CoreLens Cloud participates in and has certified its compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
- Adequacy decisions: for transfers to countries the European Commission has recognized as providing adequate protection, we rely on the applicable adequacy decision.
For more information about our cross-border data transfer mechanisms, or to obtain a copy of relevant safeguards, contact our Data Protection Officer at dpo@corelenscloud.com.
Children’s Privacy
The CoreLens Cloud Services are not directed to, designed for, or intended to be used by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at privacy@corelenscloud.com.
Upon receiving a verified parental notice, we will promptly delete the relevant information from our systems. If you are between the ages of 13 and 18, please review this policy with a parent or guardian before using our Services.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, legal requirements, or for other operational reasons. We will always post the updated policy on this page with a revised “Last updated” date at the top.
For material changes — those that meaningfully alter your rights or how we use your data — we will provide at least 30 days’ advance notice through one or more of the following channels:
- An in-app notification banner displayed when you log in to the CoreLens Cloud platform.
- An email to the address associated with your account.
- A prominent notice on our website homepage.
The effective date of any updated policy will be clearly indicated. Your continued use of the Services after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you must discontinue use of the Services and may request account deletion as described in Your Rights.
Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please reach out to us. We aim to respond to all privacy inquiries within five business days.
Attn: Privacy Team
100 CoreLens Way
San Francisco, CA 94105
United States
For security vulnerability disclosures, please email security@corelenscloud.com instead of the privacy contacts above.