Privacy Policy
Last updated: August 31, 2026
Core InSites ("Core InSites," "we," "us," or "our") is a trade name of Oak Hill Business Consultants, LLC, a New Hampshire limited liability company, doing business as Core InSites. References to "Core InSites," "CoreInSites," "coreinsites.com," or any similar variation mean the same entity and its offering, collectively provided through the "Service" described below.
Core InSites provides a website-analytics dashboard for businesses ("Customers"). Customers install a snippet on their own websites, and the resulting analytics data is collected, stored, and retrieved through underlying first-party data infrastructure operated by Mosa.Click, a service of Merandian LLC. Core InSites holds the direct relationship with the Customer; Mosa.Click operates the data layer beneath it. See How the Service is built.
This Privacy Policy describes what information we collect and how we use it, for the two groups of people we have a direct relationship with:
- Visitors to our website — people browsing the Core InSites website, no account required.
- Customers — businesses that use the Service and sign in to the Core InSites dashboard.
This Policy is not the privacy notice for a Customer's website, and does not replace one. Our service relationship is with the Customer, not with that Customer's website visitors. Each Customer is solely responsible for maintaining its own privacy notice, providing any required disclosures, obtaining and honoring any required consent, and otherwise complying with the law that applies to how it collects and uses data about its own visitors. The Data we collect on behalf of a Customer section below describes what is collected on a Customer's instruction and may be used as a reference when a Customer drafts its own disclosure, but it does not substitute for one.
If you are a visitor to a website that uses Core InSites, the operator of that website — not Core InSites — decides what is collected about you and why. Refer to that website's own privacy notice, and contact that operator with any request about your data. See Your rights and choices.
By using our website or dashboard (collectively, the "Service"), you agree to the practices described in this policy.
How the Service is built
The Core InSites dashboard is built on data infrastructure operated by Mosa.Click, a service of Merandian LLC, a Virginia limited liability company. When a Customer installs the Core InSites snippet, analytics data about that website is collected and stored by Mosa.Click's systems, and the Core InSites dashboard reads that data using access provisioned to us.
What this means in practice:
- Your relationship is with us. We collect and manage your account information, we configure the Service for your websites, and we are the party you contact about your data.
- Mosa.Click is our infrastructure provider for analytics data. It processes analytics data on our instruction and on yours, as a subprocessor, and does not use that data for its own purposes.
- One category of processing is Mosa.Click's own. Mosa.Click logs technical request information — including IP address — for security and abuse prevention, independent of any instruction from us or from you. Mosa.Click, not Core InSites, decides what is collected for that purpose, how long it is kept, and how it is used. Neither we nor our Customers can instruct, expand, or disable that collection. See Security logging.
You may cancel, suspend, or remove our access to the data stored on your behalf at any time by closing your account or contacting us.
Information we collect
When you browse our website (no account required)
You may visit the Core InSites website without creating an account. We collect limited, non-identifying information about your visit — such as pages viewed, time spent on them, and the referring source (for example, a search engine or a link) — to help us operate, maintain, and improve the site. This information is tied to your browsing session, not to you as an individual, and we do not use it to build a profile of you across visits or devices.
We do not use third-party analytics, advertising networks, or tracking SDKs on our own site, and we do not use persistent cookies to track you across sessions. We do not respond to browser Do Not Track (DNT) signals because we do not track visitors across other websites or services.
When you create a Customer account
To use the Core InSites dashboard, you sign in with your email address:
- Email address — used to identify your account and to send a one-time sign-in code. We do not store passwords; sign-in is code-based.
- Sign-in activity — we log sign-in attempts and their outcome for account security and abuse prevention.
- Account association — your account is linked to the Customer it belongs to and to the website(s) registered under that Customer. Where more than one person is authorized under the same Customer, their accounts share access to the same registered websites and data.
Account information is collected and held by Core InSites. It is not the same as the analytics data stored on the underlying infrastructure, and we do not pass your account credentials to that infrastructure.
When a Customer registers a website with us
When a Customer registers a website, we collect the onboarding responses that determine which aspects of the Service apply to that site and how visitor data is collected on the Customer's behalf. We collect these from the Customer, not from that website's visitors, and rely on them to configure how the Service operates for that site. Customers are responsible for the accuracy of these responses, which determine what the Service collects and how. Inaccurate responses may cause the Service to operate in a manner inconsistent with the law applicable to that Customer's website. See our Terms of Service.
Data we collect on behalf of a Customer
When you visit a website that has installed the Core InSites snippet, data is collected on behalf of that website's operator (the "Customer"), for two distinct purposes.
Analytics
To help the Customer understand how visitors use its site. Where the applicable configuration and any required consent permit it, this may include:
- Visit activity — which pages were viewed, the order they were viewed in, time spent on the site, how the visit ended, and how the visit arrived (for example, a search engine, a link, or a campaign parameter in the address). Each visit is assigned a new, randomly generated identifier that is not persistent, is not shared with any third party, and is not used to link separate visits together. The systems are not designed to tell that two separate visits came from the same person or device.
- General location — the country and, in some cases, region a visit originates from, so the Customer can see a general geographic breakdown of traffic. This is derived from network information; a precise or device-based location is not collected.
Where a Customer's configuration does not permit the above — including sites configured as directed to or likely to reach children, and visits where consent is declined, pending, or a recognized opt-out signal is present — the Service records only aggregate counts of traffic, with no identifier and no information stored on the visitor's device.
Security logging
Separately from analytics, and independent of the analytics configuration or any consent state, technical information associated with every request made to the underlying systems is logged, including IP address and standard information a browser or client transmits with a web request. This includes requests that are incomplete, malformed, automated, or that never result in a recorded visit. The purpose is to detect and prevent bots, crawlers, fraud, and abuse of the infrastructure and of our Customers' sites, and to maintain the integrity and availability of the Service.
This information is maintained in a separate system from analytics data, is not joined to it, is not used to build a profile of any individual's visits, is not used for advertising, measurement, or any analytics purpose, and is not sold, shared, or made available to any third party for their own purposes, except as required by law or valid legal process. It is processed for a legitimate interest in network and information security, and for our Customers' corresponding interest in the security of their websites.
This processing is carried out by Mosa.Click as controller of that information. Mosa.Click decides what is collected for this purpose, how long it is kept, and how it is used. Core InSites does not receive IP addresses or raw request data, and neither we nor our Customers can instruct, expand, or disable this collection.
The information is used to classify traffic into categories — for example, identifying a request as coming from a particular type of crawler or automated agent — and, where permitted by applicable law, to identify malicious or automated traffic patterns across the infrastructure generally, including patterns affecting more than one customer. Customers may be able to choose, for their own website, whether traffic classified into a given category is permitted to reach that site. Customers, and Core InSites itself, see only these classifications and the relevant site's traffic categories — never IP addresses, raw request data, or any information capable of identifying an individual visitor.
Scope
Analytics data is processed solely as instructed by, and on behalf of, the Customer that operates the website you visited. The Customer's own privacy notice governs how it uses that data.
The specific information collected for any given website depends on that Customer's configuration, the audience type it has declared, and the consent state applicable to the visit. We do not describe detection, gating, or scoring logic here, and nothing in this section should be read as a commitment to collect, or not collect, a specific field for a specific site.
If you operate a website using the Core InSites snippet, you are responsible for updating your own privacy notice to disclose this collection to your visitors. You may use this section as a reference, or point to it directly — for example: "This site uses Core InSites for analytics and security. See Core InSites' Privacy Policy, 'Data we collect on behalf of a Customer,' for what may be collected and why."
Information we do not collect
Our systems are not designed to collect, about visitors to our website or Customers using our dashboard:
- Cross-site or cross-device advertising identifiers
- Persistent cookies used to recognize you across separate visits
- Special categories of personal data (such as health, biometric, or government identifiers)
We do not knowingly permit the Service to be configured to collect special categories of personal data from a Customer's website visitors, and our Terms of Service prohibit Customers from doing so.
Our third-party service providers may collect additional data as part of their own operations, as described in Sharing your information.
How we use your information
- Email address and sign-in activity — to authenticate your Customer account, send sign-in codes, notify you of material changes to this policy or our Terms, and detect and prevent unauthorized access.
- Account and website configuration — to operate the Service correctly for each registered site, and to scope dashboard access to the correct Customer's data.
- Website visit information — to operate, maintain, and improve the Core InSites website.
- Traffic classifications — to protect the Service, our Customers, and their sites from bots, crawlers, fraud, and abuse, and to apply the filtering choices a Customer has made for its own site.
We do not use any of this information to serve advertisements, build cross-site behavioral profiles, or sell data to any third party. We do not use Customer or visitor data to train artificial intelligence models.
Legal basis for processing
Where required by law, we process personal data on the following bases:
- Contractual necessity — processing a Customer's account and configuration data is required to provide the Service the Customer signed up for.
- Legitimate interests — operating, securing, and improving the Service and preventing abuse, where those interests are not overridden by an individual's rights and freedoms. This basis covers the security processing described above, which is limited to what is necessary for that purpose, kept separate from analytics data, and not used to profile or make decisions about any individual.
- Legal obligation — maintaining records sufficient to demonstrate compliance with applicable data-protection law, and responding to valid legal process.
- Consent — where consent is the applicable basis for data collected on a Customer's behalf, that consent is obtained and managed by the Customer, not by Core InSites.
Our commitments as a processor
Where we process personal data on a Customer's behalf, we commit to the following, and these commitments form part of our agreement with each Customer:
- We process that data only on the Customer's documented instructions, including the configuration the Customer sets, except where applicable law requires otherwise.
- We do not sell that data, use it for our own purposes, use it for advertising or cross-context behavioral advertising, or combine it with data from other sources for purposes unrelated to providing the Service.
- Personnel with access to Customer data are bound by confidentiality obligations, and access is limited to those who need it to operate and support the Service.
- We engage subprocessors — including Mosa.Click as our analytics data infrastructure provider — under written terms no less protective than those in this Policy, and we remain responsible for their performance. A current list of subprocessors, identified by name, is available to Customers on request.
- We assist Customers, taking into account the nature of the processing, in responding to individual rights requests and in meeting their own security, breach-notification, and assessment obligations.
- We notify affected Customers without undue delay after becoming aware of a personal data breach affecting their data.
- On termination, and at the Customer's election, we delete or return Customer data, subject to any retention required by law and to the backup rotation described under Data retention.
- Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
A summary of our technical and organizational security measures is available to Customers on request.
How we store your data
Data is transmitted over encrypted connections and stored encrypted at rest, using infrastructure provided by our third-party hosting, analytics-infrastructure, and database providers. Each Customer's data is logically separated and access is scoped to that Customer.
We do not publish details of our system architecture, infrastructure configuration, or internal controls.
Sharing your information
We do not sell, rent, or trade your information. We do not share your information with advertisers, data brokers, or marketers. We do not process your information through any third-party artificial intelligence tool or model.
- Analytics data infrastructure — Mosa.Click, a service of Merandian LLC, stores and serves the analytics data collected through the Core InSites snippet, as our subprocessor and under our instruction. Mosa.Click does not use that data for its own purposes. Mosa.Click separately acts as controller of the security log information described under Security logging.
- Third-party service providers — we work with a small number of infrastructure providers, in categories such as cloud database and storage, application hosting and delivery, transactional email, and payment processing, to operate the Service. Each receives only the data necessary for its function and operates under its own privacy policy. We configure our infrastructure to use United States-based regions where that option is available; our providers operate their own global infrastructure and may store or process data on their servers in accordance with their own policies.
A current list identifying our providers and subprocessors by name is available to Customers on request.
Legal requirements and protection of rights
We may disclose information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, court order, or other legal process; to enforce our agreements or investigate potential violations; to protect the security or integrity of the Service; or to protect the rights, property, or safety of Core InSites, our Customers, or the public.
The data available in response to legal process is limited to what is described in this Privacy Policy. Where the request seeks data we process on a Customer's behalf and we are not legally prohibited from doing so, we will make reasonable efforts to notify that Customer before producing it. We may, but are not obligated to, challenge a request we believe to be invalid or overbroad.
Business transfers
If Core InSites or Oak Hill Business Consultants, LLC is involved in a merger, acquisition, asset sale, or similar transaction, information may be transferred as part of that transaction. Customers will be notified by email or a notice within the dashboard before such a transfer takes effect, and the information will remain subject to this Privacy Policy until updated in accordance with Changes to this policy.
Data retention
- Customer account data — retained while the account is active, and removed on request or account closure, subject to any retention required by law.
- Sign-in activity logs — retained for a limited period for security and abuse-prevention purposes.
- Analytics data collected on a Customer's behalf — retained according to that Customer's configuration and our agreement with that Customer, and deleted or returned on termination at the Customer's election.
- Security log information — retained by Mosa.Click for a limited period proportionate to its security purpose, after which it is deleted or reduced to aggregated or de-identified classification signals that do not relate to an identifiable person. Exact retention windows for security data are not published, as doing so would assist those seeking to evade detection.
- Backups — data may persist in encrypted backups after deletion from production systems until those backups are rotated out of service in the ordinary course.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, or to withdraw consent, and to be free from discrimination for exercising those rights.
Customers may access, correct, or request deletion of their account and configuration data by contacting us using the information below. We may need to verify your identity before acting on a request, and may decline or limit a request where an exception applies under applicable law.
Visitors to a Customer's website should contact the operator of that website directly — refer to that website's own privacy notice for how to reach them. Core InSites is not the correct point of contact for that request. We hold that data only as instructed by the Customer who operates the site, and in most cases we hold no information capable of identifying an individual visitor or of linking a request to a particular visit. Where we receive such a request directly, we will forward it to the relevant Customer where we are able to identify one, and will not respond substantively unless legally required to do so.
We do not sell or share personal information as those terms are defined under U.S. state privacy laws, and we do not use personal information for cross-context behavioral advertising or profiling. Because we do not engage in these practices, there is no opt-out action required on your part.
To make a formal privacy request about your own Core InSites account, or to reach us about a right not otherwise available through the Service, contact us using the information at the bottom of this policy. You may also have the right to lodge a complaint with your local supervisory authority.
Security
We take reasonable, industry-standard precautions to protect information, including encryption in transit and at rest, access controls scoped to authorized personnel, and logical separation of each Customer's data. No security system is impenetrable, and we do not guarantee absolute security.
We deliberately do not publish details of our technical controls, detection logic, or infrastructure configuration.
Children's privacy
The Core InSites dashboard is intended for business use and is not directed at children. We do not knowingly collect personal information from children through our own website or dashboard. If we become aware that we have collected personal information from a child in a manner inconsistent with this policy, we will delete it.
Each Customer is solely responsible for complying with applicable law — including laws directed at children's privacy, such as COPPA and the UK Age Appropriate Design Code — with respect to visitors to its own website, and for accurately declaring at onboarding whether its site is directed to or likely to be accessed by children. The Service applies a reduced-collection configuration to sites declared as such; that configuration is a technical accommodation and does not discharge the Customer's own obligations.
International users
Core InSites is operated from the United States. If you access the Service from outside the United States, information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer and processing. We configure our infrastructure to use United States-based regions where that option is available; any transfer of data between countries is decided and carried out by our third-party hosting and infrastructure providers as part of how they operate their own global infrastructure, and we do not directly control where or how those providers route, store, or process data on their systems.
Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland on a Customer's behalf, transfers are governed by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable, as described under Our commitments as a processor.
Our third-party service providers may transfer, store, or process data on infrastructure located outside the United States as part of their own operations, governed by their own privacy policies and data processing commitments. We comply with applicable data protection laws in the jurisdictions where we operate.
Legal
This Privacy Policy is governed by the terms set forth in our Terms of Service, including disclaimers, limitations of liability, governing law, and dispute resolution.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page and append a summary of changes in the Change log below. For material changes affecting how we handle personal information, we will make reasonable efforts to notify Customers with accounts before the changes take effect.
Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Feedback and information
Any feedback provided through the Service is considered non-confidential, and we may use it without restriction or obligation to you.
The information contained in this website is subject to change without notice.
Contact: privacy@coreinsites.com
Change log
August 31, 2026 — Original publish date.
© 2026 Core InSites, a trade name of Oak Hill Business Consultants, LLC. All rights reserved.