Skip to content
Corveek

Privacy Policy

What Corveek stores about you, why, who inside your organization can see it, and how to get it removed.

Version 2026-07-30 · published July 30, 2026

Who this covers

This policy describes how the Corveek platform handles personal data — both the account you sign in with and the business records you create inside a workspace.

Corveek is business software operated by an organization, so two parties are usually involved: the organization that runs this instance and decides what is stored in it, and Corveek as the platform it runs on. Where you are an employee or contact of a customer organization, that organization decides why your data is held; ask them for their own policy and for the operating entity behind this instance.

What we store

Everything below is data the platform needs to work. Nothing is collected for advertising, and nothing is sold.

  • Your identity: name, email address, and a hash of your password. We never store the password itself, and a hash cannot be turned back into one.
  • Your memberships and roles: which organizations you belong to and what you are permitted to do in each. These are granted by an administrator, not by you.
  • Your consents: which version of this policy and of the Terms of Service you accepted, when, and whether you asked for marketing email — together with the IP address and browser used at that moment, which is what makes the record evidence rather than an assertion.
  • The business records you enter: invoices, expenses, employees, leave, partners, content, and anything else you create in a module. These belong to the organization whose workspace they are in.
  • An audit trail of changes: who changed what, when, from which IP address and browser, and the values before and after. This is required of business software and cannot be switched off.
  • Files you upload, held in private object storage and reachable only through short-lived signed links.
  • Operational logs, which carry a request identifier and the organization involved so a failure can be traced.

Why we store it

To provide the service you or your organization asked for: authenticating you, showing you the records you are permitted to see, and keeping an accurate history of changes.

To keep the platform secure — rate limiting, abuse prevention, and the audit trail all depend on the data above.

To send you email that the service produces: address verification, password resets, notifications, and workspace invitations. These are part of the service and are not marketing.

Marketing email is separate and optional. It is sent only if you asked for it, and you can turn it off at any time on your profile page without affecting anything else.

Who can see it

Your data is isolated per organization. Every query the platform makes is restricted to a single workspace, and there is no path through the product by which one organization can read another's records.

Inside a workspace, what a colleague can see is decided by the role an administrator granted them. Many roles are limited to records the person created themselves; administrators and managers can typically see everything in their organization, including records you created. If that matters to you, ask your administrator which role you hold.

Whoever operates this instance can reach the underlying database and backups, as any system operator can. Beyond that, data is disclosed only where the law requires it.

Cookies and similar technology

Corveek sets cookies only to keep you signed in and to protect forms. There are no advertising or cross-site tracking cookies, and there is no analytics profile built from your browsing.

  • A short-lived access token and a longer-lived refresh token, both marked httpOnly so scripts on the page cannot read them.
  • A cross-site request forgery token, which the browser echoes back on any change so that a request from another site cannot act as you.
  • A theme preference, so the interface stays light or dark as you left it.
  • Public forms are protected by Cloudflare Turnstile, which checks that a submission came from a browser rather than a script. Cloudflare receives the information needed to make that check.

How long it is kept

Business records are kept for as long as your organization keeps them. Deleting a record marks it deleted and removes it from the product rather than erasing the row, because an audit trail with holes in it is not an audit trail.

Sessions expire on their own — a signed-in session ends after a period of inactivity, and the tokens behind it expire sooner.

Audit records are retained for the life of the workspace. They are the history of who changed what, so they outlive the records they describe.

Deleting your account

You can request deletion of your account from your profile page. Because this is business software, the request goes to an administrator of your organization rather than taking effect immediately — records you created may be part of your organization's accounts, and an employee cannot unilaterally remove them.

On approval your account is disabled, your memberships and roles are removed, and your email address is released so it can be registered again from scratch. Business records you created remain with the organization that owns them, as does the audit trail.

Your choices

Your profile page shows what you have agreed to and when, lets you turn marketing email on or off, change your password, and request deletion.

For a copy of your data, a correction, or any request your profile page cannot satisfy, contact your organization's administrator first — they control the workspace your records live in. If that is not possible, use the contact form on this site.

Changes to this policy

Each version of this policy carries a date, shown at the top of this page. When you accept it we record the version you saw, so it is always possible to say which text you agreed to.

If a future version changes materially what happens to your data, you will be asked to accept it rather than being deemed to have done so silently.

Questions about this document? Get in touch.