1. Scope & roles
Qorrelate (“we,” “us”) operates the observability services described at qorrelate.io. Depending on context, we act as:
- Business / controller for account, billing, support, and website information we collect about customers and visitors.
- Processor / service provider for Customer Data that you configure your systems to send to Qorrelate (for example logs, metrics, traces, and session replay payloads). You decide what to send and for which purposes; you are responsible for notices and consents to your end users where required.
2. Information we collect
2.1 Account & identity
Name, email, organization name, authentication identifiers, role and permissions, and preferences. We may use identity providers (for example Auth0) to authenticate users; those providers receive and process data under their own policies.
2.2 Billing
Payment-related information is processed by our payment partners (for example Stripe). We typically receive limited billing metadata (such as subscription status and last four digits of a card), not full card numbers.
2.3 Customer Data (telemetry & replay)
Data your applications and agents send to Qorrelate, which may include IP addresses, device or browser metadata, user identifiers you choose to pass, stack traces, URLs, and recorded DOM events for session replay—depending on your instrumentation and configuration.
2.4 Usage & diagnostics
Service usage, API calls, feature interactions, error logs, performance metrics, and security signals to operate and improve the platform.
2.5 Communications
Content of support tickets, emails, and optional surveys.
2.6 Cookies & similar technologies
See Cookies & analytics below.
3. How we use information
We use information to:
- Provide, operate, and secure the Services (including multi-tenant isolation, quotas, and abuse prevention).
- Process transactions and send service-related notices.
- Provide support and respond to requests.
- Improve reliability and develop features; we may use de-identified or aggregated data that does not identify individuals.
- Comply with law and enforce our Terms.
Where GDPR applies, we rely on appropriate bases such as contract (providing the Services), legitimate interests (security, product improvement, proportionate marketing to business contacts), and consent where required (for example certain cookies or marketing).
5. International transfers
We may process data in the United States and other countries where we or our providers operate. Where we transfer personal data from the EEA, UK, or Switzerland to countries not deemed adequate, we use appropriate safeguards such as Standard Contractual Clauses and supplementary measures as needed.
6. Retention
We retain account and billing records as needed for legal, tax, and operational purposes. Customer Data is retained according to the retention settings and product behavior associated with your workspace (including TTL and deletion features). When data is deleted from active systems, residual copies may persist for a limited period in backups before being overwritten.
7. Security
We implement technical and organizational measures designed to protect information, including encryption in transit, access controls, monitoring, and least-privilege practices. No method of transmission or storage is 100% secure; we encourage you to use strong authentication, API key hygiene, and masking or sampling for sensitive telemetry.
8. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or export personal information we hold about you, or to object to or restrict certain processing. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights, contact privacy@qorrelate.io. We will respond in line with applicable law. For Customer Data processed on your behalf, we may need to route requests through your organization’s administrators.
9. California residents (CCPA)
California residents may have additional rights under the CCPA/CPRA, including rights to know, delete, and correct personal information, and to opt out of “sharing” or “selling” (we do not sell covered personal information in the conventional sense). You may designate an authorized agent where permitted by law. We will not discriminate against you for exercising rights.
11. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will post the revised Policy with a new effective date and, where appropriate, provide additional notice. Continued use after the effective date constitutes acceptance of the updated Policy.
13. Contact
Privacy questions and requests: privacy@qorrelate.io
General support: support@qorrelate.io