Privacy

Privacy policy.

Written from what the software actually does, not from a template. If a sentence here does not match the code, the sentence is the bug.

Last updated: 17 September 2026

Corker is a platform for running client work: leads, projects, time, quotes, invoices and support. This policy covers the public website at this domain, the waitlist, and the Corker application itself.

Who we are

Corker is operated by [legal entity name], company registration number [registration number], of [registered postal address]. In this policy "we" and "us" mean that company.

For the personal data described below we are the data controller, except where this policy says otherwise — see "Your clients' data".

Data protection contact: [privacy contact email address]. [FOUNDER: state here whether a Data Protection Officer has been appointed, or that one is not required.]

What we collect

If you join the early access waitlist

The waitlist form stores exactly four things: your name, your email address, your company name if you give one, and the message you write if you write one. Your email address is lowercased and trimmed before it is stored. Nothing else from the form is kept — the hidden anti-spam field is discarded.

Your IP address is used, but not stored alongside your submission. It goes into a short-lived rate-limiting counter that allows five waitlist submissions per hour from the same address; that counter lives in our own database and expires one hour after your last attempt.

Submitting the form triggers two emails: a confirmation to you, and an internal notification to us containing the four fields above.

If you have a Corker account

Your account record holds your name, an optional display name, your email address, whether and when you verified it, a hash of your password, an optional avatar image, an avatar colour, your timezone and your language preference. We never store your password itself — only a bcrypt hash of it.

If you turn on two-factor authentication we store your authenticator secret and your recovery codes, both encrypted with the application key rather than in plain text.

Signing in creates a session record containing your IP address, your browser user-agent string, the session payload and the time you were last active. If you tick "remember me", a long-lived sign-in cookie is issued as well.

We also keep a record of the devices you have signed in from, holding a one-way hash of a random device token, the IP address, the user-agent string, a device label and, where our network provider supplies it, a two-letter country code. This is what lets us tell you when a new device signs in to your account.

Your workspace records who invited whom: an invitation holds the invited email address, who sent it, and a single-use token.

What you put into a workspace

Corker holds whatever you put into it. In practice that includes your client organisations and contacts (names, email addresses, phone numbers, addresses, notes), leads, projects, issues, logged time and the comments on it, quotes, invoices, payments, support tickets and replies, uploaded attachments and documents, and the emails Corker sends and receives on your behalf.

Actions inside a workspace are written to an activity history: which user performed the action, what changed, and when. That history does not record IP addresses or browser details.

Technical records

Our servers keep application logs for troubleshooting, and a record of every email Corker sends: the recipient, any copied addresses, the subject, which mail provider handled it, its delivery status, and — where the provider reports them — whether it was opened or a link in it was clicked.

Why we use it, and our lawful basis

We process personal data on these grounds under the EU General Data Protection Regulation:

  • Waitlist entries — our legitimate interest in evaluating who to admit to a private beta and in replying to people who asked us to get in touch. You asked us to contact you; you can ask us to stop at any time.
  • Accounts, workspaces and everything you put in them — performance of the contract under which we provide Corker to you.
  • Security records: sessions, known devices, rate-limit counters, sign-in throttling and the activity history — our legitimate interest in keeping accounts and client data safe, and our legal obligation to secure the data we hold.
  • Application logs, error reports and performance monitoring — our legitimate interest in keeping the service working and in fixing it when it does not.
  • Service emails such as verification, password resets, invitations and delivery notifications — performance of the contract.

We do not sell personal data, we do not share it with advertising networks, and we do not build behavioural profiles or use automated decision-making that produces legal effects.

Cookies and tracking

There are no analytics scripts, no advertising pixels, no session recording, no chat widgets and no third-party fonts on this website. Every page you are reading loads its stylesheet, its fonts and its images from this domain and nowhere else. The only JavaScript on the public pages is a few lines that open and close the mobile menu.

The cookies Corker sets are all strictly necessary or functional, which is why you are not being asked to consent to them:

  • A session cookie, needed to keep you signed in and to make forms work. It is HTTP-only, SameSite=Lax, encrypted, and expires after two hours of inactivity.
  • A CSRF token cookie, which stops other websites submitting forms as you.
  • A device cookie holding a random token, set once you sign in, so we can recognise a device you have used before. Only a one-way hash of the token is stored on our side.
  • A "remember me" cookie, set only if you tick that box when signing in.
  • A preference cookie inside the application that remembers whether you collapsed the sidebar.

Who else processes it

We use a small number of service providers, and only these:

  • Resend — delivers the email Corker sends, receives the email Corker takes in, and reports delivery, bounce, open and click events back to us.
  • Laravel Nightwatch — application performance and error monitoring. Where it is switched on it receives request URLs, route names, IP addresses, request headers other than authentication and cookie headers, response status and timing, database query timings, and exception details including the source code around the error. Request bodies are not sent, and the passwords and CSRF tokens within them are redacted before anything leaves the server.
  • Our hosting and infrastructure provider, which runs the servers and the database, and an object storage provider where file storage is configured to use one.

Named providers and the region each one operates in: [hosting provider], [object storage provider]. We have a data processing agreement in place with each provider that handles personal data on our behalf.

We will also disclose personal data where the law requires it, and to our professional advisers where we need advice. If Corker is ever sold or merged, personal data would transfer with it, and you would be told before that happened.

Where it is stored and transferred

Corker's database and file storage run in [hosting region]. Some of the providers listed above process data outside the European Economic Area. Where they do, the transfer relies on [transfer mechanism — for example the European Commission's standard contractual clauses], and you can ask us for a copy of the safeguards.

How long we keep it

Some retention periods are enforced automatically by the software, and those are the ones we can state precisely:

  • Records of sent email, including subjects and delivery events: 180 days.
  • Known-device records: 365 days after the device was last used.
  • Expired workspace invitations: 30 days after they expire.
  • In-app notifications: 90 days once read, 365 days if never read.
  • Failed background jobs: 7 days. Password reset tokens: cleared every 15 minutes once expired.
  • Server log files: 14 days.
  • Rate-limiting counters holding an IP address: one hour.
  • Signed links emailed to your clients so they can track a support request, once that portal is switched on: 30 days.

Other periods are a policy decision rather than something the software enforces, and are set as follows: waitlist entries are kept for [retention period] after you join or until you ask us to remove you, whichever comes first; workspace content and its activity history are kept for [retention period] after a workspace is closed, after which it is deleted.

When you delete your own user account, we do not leave your details in the database. Your name, email address, avatar, password and two-factor credentials are irreversibly overwritten, your sessions and known devices are deleted, and your memberships and roles are removed. The record itself remains only so that historical entries elsewhere still have something to point at, and it no longer identifies you.

How it is protected

Passwords are stored as bcrypt hashes, two-factor secrets and recovery codes are encrypted, cookies are encrypted and HTTP-only, uploaded attachments sit on a private disk and are streamed only to people the permission system says may see them, and every workspace is isolated from every other. The security page sets this out in detail.

No system is perfectly secure. If we ever suffer a personal data breach that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it and tell you directly where we are required to.

Your rights

Under the GDPR you can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict what we do with it, or hand it over in a portable format. You can object to processing we carry out on the basis of legitimate interests, and you can withdraw consent where we relied on it.

Some of this you can do yourself. Your profile page edits your own details, the security page in your profile manages two-factor authentication and signs other sessions out, and deleting your account from your profile anonymises it immediately. Time entries export from the application, and every quote and invoice downloads as a PDF.

For anything else, email [privacy contact email address]. We will respond within one month. We do not charge for this, and we will not ask you for more identification than we need to be sure it is you.

If you think we have got it wrong, you can complain to a data protection supervisory authority — ours is [supervisory authority and country] — or to the authority in the EU country where you live or work.

Your clients' data

When you put your own clients into Corker — their contacts, their projects, their invoices, their support requests — you decide what goes in and why. For that data you are the controller and we are your processor: we hold it and act on your instructions, and we do not use it for our own purposes.

That means it is you, not us, who answers a request from one of your clients to see or delete their data. You can do both from inside the application. If you need a data processing agreement covering our role as your processor, ask and we will provide one.

Two details worth knowing. Files attached to tickets, quotes and invoices are stored privately and can only be fetched by someone the permission system authorises. Images pasted into a text editor inside the application are stored at an unguessable public address instead, so anyone holding that exact link can open it — treat them as you would an unlisted link, and use file attachments for anything confidential.

Children

Corker is a tool for businesses. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We will update this policy when what we do changes. The date at the top of the page is the date of the current version. If a change materially affects how we handle your personal data, we will tell account holders by email rather than quietly editing the page.

How to contact us

Privacy questions, rights requests and complaints: [privacy contact email address]. By post: [postal address].

Terms of service · Security · About Corker

Want to see it from the inside?

Corker is in private beta. Join the waitlist and tell us what you run today.

Request early access