Legal
Privacy Policy
v1.0 — Last updated: 08 August 2026
1. Who We Are
CoreOps (“CoreOps”, “we”, “us”, “our”), based in South Africa, is a cloud operational software platform for manufacturers, wholesalers, distributors, and other growing businesses internationally. This Privacy Policy explains how we handle information on our public website (coreopsapp.com) and within the CoreOps application used by our customers.
2. Scope
This Policy covers two distinct things, which we deal with separately throughout this page because different rules apply to each:
- The public website— what happens when you browse coreopsapp.com, fill in the Contact form, or click “Book a Demo”.
- The CoreOps application— the software our paying customers use to run their business, and the data they enter into it.
3. Information We Collect
On the public website, we collect:
- Contact form submissions — name, email address, company name (optional), and your message.
- Standard technical information collected by our hosting infrastructure as part of normal web operation — such as IP address, browser and device information, and pages visited — used for security, performance, and troubleshooting.
Within the CoreOps application, we (on behalf of our customers) process:
- Account information for people who log in — name, email address, role, and PIN (stored as a secure hash, never in plain text).
- Business data our customers enter or generate through use of the platform — inventory, sales, purchasing, manufacturing, and financial records — which may include personal information belonging to our customers’ own employees, customers, and suppliers (for example, an employee record, or a customer’s name and contact details on an order).
4. How We Use Information
- To respond to enquiries and demo requests.
- To provide, operate, secure, and maintain the CoreOps application for our customers.
- To measure the effectiveness of our advertising (see Cookies and Tracking below).
- To provide customer support.
- To comply with our legal obligations.
5. Website and Contact Forms
When you submit the Contact form, your name, email, company (if provided), and message are sent by email directly to our inbox (info@coreopsapp.com) via our transactional email provider, Resend. The submission is not written to a marketing database or CRM, and we do not add you to a mailing or newsletter list because of it.
“Book a Demo” buttons on our site open your own email application (amailto:link) addressed to info@coreopsapp.com. Nothing is sent to CoreOps until you actually send that email yourself — we have no visibility of the button being clicked.
6. Cookies and Tracking
We use Google Ads conversion tracking (Google’s advertising tag) on the public website to measure how effective our advertising is. If you arrive from a Google ad, this may set a cookie via Google, and a conversion signal is recorded when you successfully submit the Contact form. This is the only advertising/analytics tracking on our public website today — we do not use Google Analytics, Meta/Facebook Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, or any other behavioural analytics or session-recording tool. You can control Google’s advertising cookies through your browser settings or Google’s own Ad Settings.
Our hosting provider, Vercel, may use standard technical mechanisms to serve and secure the site, in line with normal web hosting practice. Inside the CoreOps application itself, we use essential session cookies and local storage to keep you signed in and remember preferences such as your chosen theme — these are necessary for the application to work and are not used for advertising.
7. CoreOps Application Data
When you interact with our public website as a visitor or prospective customer, CoreOps is the controller of that limited information (see clause 5).
When a business subscribes to CoreOps and its staff enter data into the application, CoreOps acts as a service provider (in South Africa, an Operatorunder POPIA) processing that data on the customer’s instructions, for the purpose of providing the service. The customer is the controller(Responsible Party) of that data and is responsible for the lawfulness of collecting it and entering it into CoreOps. If you are an employee, customer, or supplier of a business that uses CoreOps and you have a question about how your personal information is used within their account, please contact that business directly rather than CoreOps — CoreOps does not control what a customer chooses to record about you.
8. Third-Party Integrations
CoreOps can be connected, only where a customer chooses to, to the following third-party services:
- Xero— a customer connects their own Xero organisation via a self-service OAuth connection. CoreOps requests access limited to accounting settings/chart of accounts, contacts, manual journals, invoices, attachments, bank transactions, and payments (plus the connecting user’s basic profile), which is what is needed to post and reconcile transactions. CoreOps does not request access to Xero payroll or other data outside these scopes. Xero is a separate product operated by Xero Limited and is governed by Xero’s own terms and privacy policy.
- Sales channels— Shopify, WooCommerce, Takealot, Amazon, and Wix can be connected to a customer’s own store or seller account, at the customer’s election, so that orders sync into CoreOps. Each is a separate service governed by its own terms.
- OCR bill scanning (Google Cloud Document AI) — where a customer enables this optional feature, uploaded supplier invoices are sent to Google Cloud Document AI for automated data extraction. The extracted data (supplier, line items, amounts) is stored in CoreOps; the original file is only stored in CoreOps’ own file storage if the customer separately attaches it to a goods-received record.
- Card payments (Yoco)— card payments are processed on the customer’s own Yoco card machine. CoreOps never receives, transmits, or stores card numbers or other card data — only that a sale was paid by card, for reconciliation.
- Payroll (SimplePay)— CoreOps generates a CSV file formatted for SimplePay’s bulk import. This is a file export, not a live data connection between CoreOps and SimplePay.
9. Service Providers
We use the following providers to deliver the CoreOps service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Resend — transactional email (contact form, receipts, purchase order emails).
- Google Cloud (Document AI) — optional OCR, only for customers who enable bill scanning.
These providers process data on our behalf, and on our customers’ behalf, solely to deliver the service — we do not sell personal information to any third party, and we do not share Contact form submissions or application data with third parties for their own marketing purposes.
10. International Data Transfers
CoreOps is based in South Africa. Our infrastructure providers (Supabase, Vercel, Google, and Resend) operate international cloud infrastructure, and data may as a result be processed or stored outside South Africa. We take reasonable steps to work only with providers who apply appropriate security and confidentiality safeguards.
11. Data Retention
- Contact form messages are retained only in our email inbox per our normal email retention practice — we do not keep a separate marketing database of enquiries.
- Application/customer data is retained for the duration of a customer’s subscription and for a reasonable period after it ends, to allow the customer to export their data (see our Terms of Service). After that period, data may be deleted from active systems, subject to any legal retention requirement.
- Within the application, customers can configure retention policies for specific record types using CoreOps’ built-in retention tooling, described below.
12. Security
- Encryption in transit (TLS) and at rest, provided by our infrastructure providers.
- Row Level Security enforced at the database level, so one customer’s data is never visible to another customer.
- Role-based access control (owner, admin, accountant, manager, and other built-in roles), plus per-user permission overrides.
- Optional multi-factor authentication (TOTP), which a customer can require for specific roles.
- An audit log of privacy- and security-relevant actions, which cannot be altered or deleted.
CoreOps only accesses a customer’s application data where strictly necessary to provide support, investigate a technical issue, comply with a legal obligation, or protect the security of the platform, and CoreOps personnel with such access are bound by confidentiality obligations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your Privacy Rights
Depending on where you are, you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to certain processing. Requests about a CoreOps customer’s application data should generally go to that business (as the controller/Responsible Party for that data); requests about your own interaction with our public website, such as a Contact form enquiry, can be sent to us at info@coreopsapp.com.
14. South Africa / POPIA
CoreOps operates from South Africa and processes personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). For data our customers enter into the application, our customers are the Responsible Party for personal information belonging to their own employees, customers, and suppliers, and CoreOps acts as an Operator, processing that information only on the customer’s documented instructions and for the purpose of providing the service.
The CoreOps application includes built-in privacy tooling that a customer’s own administrators can use, including data subject access request handling, configurable data retention policies with a human approval step before anything is deleted or anonymised, consent tracking, legal holds, and an audit log of privacy-relevant actions. We do not claim any third-party POPIA “certification” — POPIA does not operate a formal certification scheme.
15. International Privacy Rights
CoreOps serves customers outside South Africa, including in New Zealand, the United Kingdom, and other markets. Privacy rights available to you may vary depending on the laws that apply to you and to the CoreOps customer you deal with. We aim to respect applicable privacy rights wherever we operate, but we do not claim formal compliance or certification with any specific foreign privacy law (for example, the UK/EU GDPR or the New Zealand Privacy Act 2020) unless stated otherwise, and we have not appointed a formal EU, UK, or other privacy representative or Data Protection Officer. If you are a customer or prospective customer with specific privacy requirements for your jurisdiction, please get in touch so we can discuss how they apply to your use of CoreOps.
16. Children
The CoreOps website and application are intended for business use and are not directed at children. We do not knowingly collect personal information from children.
17. Changes to This Policy
We may update this Privacy Policy from time to time, for example to reflect changes to our practices or the services we use. Material changes will be reflected by updating the “Last updated” date at the top of this page.
18. Contact Us
Questions about this Privacy Policy? Email us at info@coreopsapp.com.
See also our Terms of Service.