Privacy Policy

Last updated: August 31, 2026

Core InSites ("Core InSites," "we," "us," or "our") is a trade name of Oak Hill Business Consultants, LLC, a New Hampshire limited liability company, doing business as Core InSites. References to "Core InSites," "CoreInSites," "coreinsites.com," or any similar variation mean the same entity and its offering, collectively provided through the "Service" described below.

Core InSites provides a website-analytics dashboard for businesses ("Customers"). Customers install a snippet on their own websites, and the resulting analytics data is collected, stored, and retrieved through underlying first-party data infrastructure operated by Mosa.Click, a service of Merandian LLC. Core InSites holds the direct relationship with the Customer; Mosa.Click operates the data layer beneath it. See How the Service is built.

This Privacy Policy describes what information we collect and how we use it, for the two groups of people we have a direct relationship with:

This Policy is not the privacy notice for a Customer's website, and does not replace one. Our service relationship is with the Customer, not with that Customer's website visitors. Each Customer is solely responsible for maintaining its own privacy notice, providing any required disclosures, obtaining and honoring any required consent, and otherwise complying with the law that applies to how it collects and uses data about its own visitors. The Data we collect on behalf of a Customer section below describes what is collected on a Customer's instruction and may be used as a reference when a Customer drafts its own disclosure, but it does not substitute for one.

If you are a visitor to a website that uses Core InSites, the operator of that website — not Core InSites — decides what is collected about you and why. Refer to that website's own privacy notice, and contact that operator with any request about your data. See Your rights and choices.

By using our website or dashboard (collectively, the "Service"), you agree to the practices described in this policy.

How the Service is built

The Core InSites dashboard is built on data infrastructure operated by Mosa.Click, a service of Merandian LLC, a Virginia limited liability company. When a Customer installs the Core InSites snippet, analytics data about that website is collected and stored by Mosa.Click's systems, and the Core InSites dashboard reads that data using access provisioned to us.

What this means in practice:

You may cancel, suspend, or remove our access to the data stored on your behalf at any time by closing your account or contacting us.

Information we collect

When you browse our website (no account required)

You may visit the Core InSites website without creating an account. We collect limited, non-identifying information about your visit — such as pages viewed, time spent on them, and the referring source (for example, a search engine or a link) — to help us operate, maintain, and improve the site. This information is tied to your browsing session, not to you as an individual, and we do not use it to build a profile of you across visits or devices.

We do not use third-party analytics, advertising networks, or tracking SDKs on our own site, and we do not use persistent cookies to track you across sessions. We do not respond to browser Do Not Track (DNT) signals because we do not track visitors across other websites or services.

When you create a Customer account

To use the Core InSites dashboard, you sign in with your email address:

Account information is collected and held by Core InSites. It is not the same as the analytics data stored on the underlying infrastructure, and we do not pass your account credentials to that infrastructure.

When a Customer registers a website with us

When a Customer registers a website, we collect the onboarding responses that determine which aspects of the Service apply to that site and how visitor data is collected on the Customer's behalf. We collect these from the Customer, not from that website's visitors, and rely on them to configure how the Service operates for that site. Customers are responsible for the accuracy of these responses, which determine what the Service collects and how. Inaccurate responses may cause the Service to operate in a manner inconsistent with the law applicable to that Customer's website. See our Terms of Service.

Data we collect on behalf of a Customer

When you visit a website that has installed the Core InSites snippet, data is collected on behalf of that website's operator (the "Customer"), for two distinct purposes.

Analytics

To help the Customer understand how visitors use its site. Where the applicable configuration and any required consent permit it, this may include:

Where a Customer's configuration does not permit the above — including sites configured as directed to or likely to reach children, and visits where consent is declined, pending, or a recognized opt-out signal is present — the Service records only aggregate counts of traffic, with no identifier and no information stored on the visitor's device.

Security logging

Separately from analytics, and independent of the analytics configuration or any consent state, technical information associated with every request made to the underlying systems is logged, including IP address and standard information a browser or client transmits with a web request. This includes requests that are incomplete, malformed, automated, or that never result in a recorded visit. The purpose is to detect and prevent bots, crawlers, fraud, and abuse of the infrastructure and of our Customers' sites, and to maintain the integrity and availability of the Service.

This information is maintained in a separate system from analytics data, is not joined to it, is not used to build a profile of any individual's visits, is not used for advertising, measurement, or any analytics purpose, and is not sold, shared, or made available to any third party for their own purposes, except as required by law or valid legal process. It is processed for a legitimate interest in network and information security, and for our Customers' corresponding interest in the security of their websites.

This processing is carried out by Mosa.Click as controller of that information. Mosa.Click decides what is collected for this purpose, how long it is kept, and how it is used. Core InSites does not receive IP addresses or raw request data, and neither we nor our Customers can instruct, expand, or disable this collection.

The information is used to classify traffic into categories — for example, identifying a request as coming from a particular type of crawler or automated agent — and, where permitted by applicable law, to identify malicious or automated traffic patterns across the infrastructure generally, including patterns affecting more than one customer. Customers may be able to choose, for their own website, whether traffic classified into a given category is permitted to reach that site. Customers, and Core InSites itself, see only these classifications and the relevant site's traffic categories — never IP addresses, raw request data, or any information capable of identifying an individual visitor.

Scope

Analytics data is processed solely as instructed by, and on behalf of, the Customer that operates the website you visited. The Customer's own privacy notice governs how it uses that data.

The specific information collected for any given website depends on that Customer's configuration, the audience type it has declared, and the consent state applicable to the visit. We do not describe detection, gating, or scoring logic here, and nothing in this section should be read as a commitment to collect, or not collect, a specific field for a specific site.

If you operate a website using the Core InSites snippet, you are responsible for updating your own privacy notice to disclose this collection to your visitors. You may use this section as a reference, or point to it directly — for example: "This site uses Core InSites for analytics and security. See Core InSites' Privacy Policy, 'Data we collect on behalf of a Customer,' for what may be collected and why."

Information we do not collect

Our systems are not designed to collect, about visitors to our website or Customers using our dashboard:

We do not knowingly permit the Service to be configured to collect special categories of personal data from a Customer's website visitors, and our Terms of Service prohibit Customers from doing so.

Our third-party service providers may collect additional data as part of their own operations, as described in Sharing your information.

How we use your information

We do not use any of this information to serve advertisements, build cross-site behavioral profiles, or sell data to any third party. We do not use Customer or visitor data to train artificial intelligence models.

Where required by law, we process personal data on the following bases:

Our commitments as a processor

Where we process personal data on a Customer's behalf, we commit to the following, and these commitments form part of our agreement with each Customer:

A summary of our technical and organizational security measures is available to Customers on request.

How we store your data

Data is transmitted over encrypted connections and stored encrypted at rest, using infrastructure provided by our third-party hosting, analytics-infrastructure, and database providers. Each Customer's data is logically separated and access is scoped to that Customer.

We do not publish details of our system architecture, infrastructure configuration, or internal controls.

Sharing your information

We do not sell, rent, or trade your information. We do not share your information with advertisers, data brokers, or marketers. We do not process your information through any third-party artificial intelligence tool or model.

A current list identifying our providers and subprocessors by name is available to Customers on request.

We may disclose information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, court order, or other legal process; to enforce our agreements or investigate potential violations; to protect the security or integrity of the Service; or to protect the rights, property, or safety of Core InSites, our Customers, or the public.

The data available in response to legal process is limited to what is described in this Privacy Policy. Where the request seeks data we process on a Customer's behalf and we are not legally prohibited from doing so, we will make reasonable efforts to notify that Customer before producing it. We may, but are not obligated to, challenge a request we believe to be invalid or overbroad.

Business transfers

If Core InSites or Oak Hill Business Consultants, LLC is involved in a merger, acquisition, asset sale, or similar transaction, information may be transferred as part of that transaction. Customers will be notified by email or a notice within the dashboard before such a transfer takes effect, and the information will remain subject to this Privacy Policy until updated in accordance with Changes to this policy.

Data retention

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, or to withdraw consent, and to be free from discrimination for exercising those rights.

Customers may access, correct, or request deletion of their account and configuration data by contacting us using the information below. We may need to verify your identity before acting on a request, and may decline or limit a request where an exception applies under applicable law.

Visitors to a Customer's website should contact the operator of that website directly — refer to that website's own privacy notice for how to reach them. Core InSites is not the correct point of contact for that request. We hold that data only as instructed by the Customer who operates the site, and in most cases we hold no information capable of identifying an individual visitor or of linking a request to a particular visit. Where we receive such a request directly, we will forward it to the relevant Customer where we are able to identify one, and will not respond substantively unless legally required to do so.

We do not sell or share personal information as those terms are defined under U.S. state privacy laws, and we do not use personal information for cross-context behavioral advertising or profiling. Because we do not engage in these practices, there is no opt-out action required on your part.

To make a formal privacy request about your own Core InSites account, or to reach us about a right not otherwise available through the Service, contact us using the information at the bottom of this policy. You may also have the right to lodge a complaint with your local supervisory authority.

Security

We take reasonable, industry-standard precautions to protect information, including encryption in transit and at rest, access controls scoped to authorized personnel, and logical separation of each Customer's data. No security system is impenetrable, and we do not guarantee absolute security.

We deliberately do not publish details of our technical controls, detection logic, or infrastructure configuration.

Children's privacy

The Core InSites dashboard is intended for business use and is not directed at children. We do not knowingly collect personal information from children through our own website or dashboard. If we become aware that we have collected personal information from a child in a manner inconsistent with this policy, we will delete it.

Each Customer is solely responsible for complying with applicable law — including laws directed at children's privacy, such as COPPA and the UK Age Appropriate Design Code — with respect to visitors to its own website, and for accurately declaring at onboarding whether its site is directed to or likely to be accessed by children. The Service applies a reduced-collection configuration to sites declared as such; that configuration is a technical accommodation and does not discharge the Customer's own obligations.

International users

Core InSites is operated from the United States. If you access the Service from outside the United States, information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer and processing. We configure our infrastructure to use United States-based regions where that option is available; any transfer of data between countries is decided and carried out by our third-party hosting and infrastructure providers as part of how they operate their own global infrastructure, and we do not directly control where or how those providers route, store, or process data on their systems.

Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland on a Customer's behalf, transfers are governed by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable, as described under Our commitments as a processor.

Our third-party service providers may transfer, store, or process data on infrastructure located outside the United States as part of their own operations, governed by their own privacy policies and data processing commitments. We comply with applicable data protection laws in the jurisdictions where we operate.

This Privacy Policy is governed by the terms set forth in our Terms of Service, including disclaimers, limitations of liability, governing law, and dispute resolution.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page and append a summary of changes in the Change log below. For material changes affecting how we handle personal information, we will make reasonable efforts to notify Customers with accounts before the changes take effect.

Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Feedback and information

Any feedback provided through the Service is considered non-confidential, and we may use it without restriction or obligation to you.

The information contained in this website is subject to change without notice.

Contact: privacy@coreinsites.com

Change log

August 31, 2026 — Original publish date.


© 2026 Core InSites, a trade name of Oak Hill Business Consultants, LLC. All rights reserved.

Privacy · Terms