Skip to main content

Legal

Privacy Policy

Version 1.1 · Effective August 26, 2026

Last updated: August 26, 2026

This Privacy Policy explains what information Corelim collects, why, and what you can do about it. Corelim is operated by OYA Holding OYA, an Israeli sole proprietorship based in Haifa, Israel, which is the controller of the personal information described here.

You can reach us about privacy at oya@oyaholding.com.

Corelim is a workspace product. Most of what it stores is business information about products, suppliers, customers and operations, entered by workspace users. This policy covers that as well as the personal information involved in running the Service.

1. Who This Policy Covers

This policy applies to:

  • People who create a Corelim account and use a workspace
  • People whose details are recorded in a workspace by its users, such as supplier and customer contacts
  • People who open a Shared Link without a Corelim account
  • People who contact us for support or about a legal matter

Where a workspace belongs to an organization, that organization decides what business information goes into it and who may see it. We process that information to provide the Service to them.

2. Information You Provide

Account and identity

  • Email address, used as your sign-in identity
  • Password, stored only in hashed form by our authentication provider — we never see or store your plaintext password
  • Display name and avatar image, if you add one
  • Interface preferences

Workspace and team

  • Workspace and organization names and settings
  • Team membership, roles, and whether a member is scoped to particular Brands
  • Invitations you send or accept, including the invited email address and the role and scope offered

Customer Content and business records

  • Brands, collections, items, SKUs and variants
  • Product information, specifications, designs and tech packs
  • Uploaded files, images, documents and other assets
  • Suppliers and supplier contact details
  • Customers and customer contact details
  • Purchase orders, costings and other commercial information
  • Inventory records and stock movements
  • Tasks, notes and comments

Supplier and customer records often contain other people's contact details. If you enter them, you are responsible for having a lawful basis to do so.

Billing

  • Plan, subscription status, billing interval and renewal state
  • Records of subscription events such as upgrades, cancellations and resumptions
  • Any discount or access code you redeem

Card details are entered on our payment provider's hosted checkout, not in Corelim. We do not receive or store full payment card numbers.

Support and contact

  • Messages you send us and the contact details you send them from
  • Feedback you give us, such as a reason given when cancelling a subscription

3. Information Collected Automatically

Authentication and session

  • Session and refresh tokens issued when you sign in, held in your browser's local storage so you stay signed in
  • Sign-in and email-confirmation events recorded by our authentication provider
  • Failed sign-in attempts, used locally in your browser to slow down repeated password guessing

Activity and audit history

  • A record of changes to workspace records — what changed, when and by which user
  • Version history for records that support it
  • Administrative actions such as role changes, invitations and Shared Link creation or revocation

Audit and version history is a product feature. Workspaces rely on it for accountability, so these records are retained as workspace history rather than cleared as they age.

Security and abuse prevention

  • Rate-limiting counters used to detect and slow abusive request patterns
  • Records of blocked or throttled requests
  • Operational logs generated by our hosting and infrastructure providers

Performance measurement

The public website and application use Vercel Speed Insights to measure page performance. It reports aggregate loading and responsiveness metrics for pages. It is active on the site today.

4. Shared Link Visitors

Shared Links let a workspace share selected records with someone who does not have a Corelim account. If you open one, we do not create an account for you and do not ask you to sign in.

To protect shared content from abuse, we record access events for the link. Those records contain:

  • A hashed identifier derived from the visitor's IP address — the raw IP address is not stored in the access log
  • A shortened, sanitized version of the browser user agent string
  • The time of access and what action was attempted, such as viewing, previewing or downloading
  • Whether the attempt succeeded, and if not, why

These records exist so a workspace owner can see how their link is being used, and so we can enforce rate limits and block abuse. They are not used to build profiles of visitors.

As with any web request, our hosting and infrastructure providers process the connecting IP address in order to route and serve the request, and may retain it briefly in their own operational logs.

The content you see through a Shared Link belongs to the workspace that created the link. Questions about that content should go to whoever sent you the link.

5. Why We Process This Information

  • To provide the Service and its features to you and your workspace
  • To authenticate you and keep your session working
  • To enforce plan limits, quotas and entitlements
  • To take payment for paid plans and manage subscriptions
  • To keep the Service secure and to detect, prevent and respond to abuse and fraud
  • To provide support when you ask for it
  • To maintain audit and version history as a product feature
  • To measure and improve performance and reliability
  • To comply with legal, accounting and tax obligations

Where data protection law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is what applies. We do not treat your acknowledgement of this policy as consent for processing that has a different legal basis.

6. What We Do Not Do

  • We do not sell your personal information or your Customer Content
  • We do not use your Customer Content for advertising
  • We do not use your Customer Content to build commercial profiles
  • We do not use your Customer Content to train generative AI or machine-learning models
  • We do not scan or moderate your Customer Content using AI or automated content-analysis systems
  • We do not share your information with third parties for their own marketing

If we ever wanted to use Customer Content to train AI or machine-learning models, we would give affected users advance notice and ask for separate affirmative opt-in consent first. Continued use of the Service would not be treated as agreement, and a change to the Terms alone would not be enough.

7. Who Can See Your Information

Inside your workspace

Workspace members see workspace records according to their role, and where their access is Brand-scoped, according to the Brands they have been granted. Owners and administrators can see team membership and billing information for the workspace.

Our team

Access to production systems is limited to the small number of people who operate the Service. We access workspace content only where necessary — to investigate a fault or security issue, to respond to a support request, or to meet a legal obligation — not routinely, and not for advertising or profiling.

Service providers

We use the providers listed in the next section to run the Service. They process information only as needed to provide their service to us.

Legal requests

We may preserve and disclose information where we are legally required to, or where it is reasonably necessary to investigate suspected unlawful conduct, enforce our Terms, or protect the rights and safety of users, third parties or the public. Where we are permitted to tell the affected customer, we will.

8. Service Providers

These providers are confirmed active in the current Service:

  • Vercel — hosting and delivery of the web application, including its operational request logs
  • Vercel Speed Insights — aggregate page performance measurement
  • Supabase — application database, file storage, authentication and server-side functions. This is where workspace records, uploaded files and account credentials live
  • Lemon Squeezy — payment processing, hosted checkout, invoices and the billing portal for paid subscriptions
  • Google (Gmail SMTP) — account emails such as sign-up confirmation, password reset and workspace invitations are delivered through Google's SMTP service, which processes the recipient's email address and the contents of those messages

This provider is built into the product but is not active in the Service today:

  • Upstash — a hosted Redis service the product can use for Shared Link rate limiting. It is not currently configured, so rate limiting runs in-process and nothing reaches Upstash. If we turn it on, this policy will say so

For completeness about what is not present: Corelim does not currently send data to a third-party observability or analytics vendor beyond Vercel Speed Insights — the Service's operational metrics are written to its own platform logs. No AI moderation or content-analysis provider is used.

We will keep this list current. If we add a provider that processes personal information, it will appear here.

9. Cookies and Local Storage

Corelim does not use advertising cookies, tracking cookies or third-party marketing pixels.

The application uses your browser's local storage for things it needs to work: your authentication session, which workspace is currently active, and interface preferences. Clearing it signs you out.

Our hosting provider may set strictly necessary cookies to route and secure requests.

10. Security

Corelim is built so that workspace data is private to the workspace. Access is enforced in the database itself through row-level security, not only in the interface, so a request for records you have no access to returns nothing regardless of how it is made.

Other measures include:

  • Encryption in transit for traffic to the application and its APIs
  • Role-based access control, including Brand-scoped access within a workspace
  • Shared Links that carry only the scope you set, with expiry and revocation
  • Rate limiting and abuse protection on public endpoints
  • Audit history of administrative and record changes
  • Restricted, need-based access to production systems

No service can promise perfect security, and we do not claim to. If a breach affects your personal information and the law requires us to notify you or a regulator, we will.

11. How Long We Keep Information

We keep information for as long as reasonably necessary for the purposes described in this policy, subject to applicable legal, accounting, security and operational requirements.

In practice that means:

  • Workspace records stay until you delete them or the workspace is closed. Deleting a record moves it to Trash first, and Trash can be restored
  • Audit and version history is retained as workspace history, because accountability is what it is for
  • Billing and subscription records are retained to meet accounting and tax obligations
  • Shared Link access logs are retained to support abuse investigation and workspace visibility
  • Support correspondence is retained while it may still be needed

We have not yet set fixed retention periods for every category. Where a fixed period is not stated, we keep information only as long as it is reasonably necessary for the purpose it was collected for, and we will publish specific schedules here as we formalize them.

12. Deleting Your Account

You can delete your Corelim account from your account settings, once you no longer hold active memberships that would block it.

When you do, we anonymize the identifying information on your profile — your email address, display name, avatar and preferences are replaced with an anonymized placeholder — and we neutralize the login so the account can no longer be used to sign in.

We do not erase the workspace records you contributed to. Corelim is a shared operational system, and purchase orders, inventory movements, audit entries and version history belong to the workspace's business history, which other people rely on. Those records are kept and are attributed to an anonymized deleted user rather than to you by name.

We also keep information where it is necessary to comply with law, to meet accounting and tax obligations, to maintain security and prevent fraud, to resolve disputes, or where it belongs to another workspace or customer.

Retained information about a deleted user is not sold, used for advertising, used for profiling unrelated to security and service operation, used to train AI models, or used for any unrelated commercial purpose. Our service providers may process it only where necessary to operate, secure, support or legally comply with the Service.

We are not able to say that no third party ever processes retained information, because the infrastructure providers listed above necessarily do so in order to store and serve it.

13. Your Rights

Depending on where you live, you may have rights over your personal information, including to:

  • Ask what we hold about you and get a copy
  • Have inaccurate information corrected
  • Ask for deletion, subject to the retention limits described above
  • Ask us to restrict or object to certain processing
  • Receive certain information in a portable format
  • Withdraw consent where consent is what we rely on
  • Complain to your local data protection authority

Which of these apply to you depends on your local law; we are not claiming that every right listed is available to everyone everywhere.

To exercise a right, write to oya@oyaholding.com. We will respond within the period your applicable law requires, and we may need to verify your identity first.

If your information is in a workspace controlled by an organization — for example your employer, or a brand that recorded you as a supplier contact — that organization decides what is stored there. We will point you to them and help them respond.

14. International Use and Transfers

Corelim is available globally and is operated from Israel. Our infrastructure providers operate internationally, so your information may be processed in countries other than your own, including the United States.

We work to have appropriate contractual protections in place with our providers. We are not claiming to have completed every transfer-compliance framework that may apply to every customer, and we do not currently offer a standard data processing agreement.

If your organization needs a data processing agreement or standard contractual clauses before using Corelim — for example because we would be processing personal data on your behalf and your compliance obligations require it — contact oya@oyaholding.com and we will work through it with you. Preparing one is a priority for us.

15. Children

Corelim accounts are for people aged 18 or older. The Service is not directed at children and we do not knowingly collect personal information from them.

If you believe a child has given us personal information, contact oya@oyaholding.com and we will remove it.

16. Changes to This Policy

We may update this policy as the Service develops. Each version carries a version number and an effective date.

For material changes we will give reasonable advance notice through the Service or by email. Where a change requires your consent, we will ask for it rather than assume it from your continued use.

17. Contact

Privacy questions, requests and complaints: oya@oyaholding.com.

OYA Holding OYA, Haifa, Israel.