This Privacy Policy explains how CodeStringers ("CodeStringers", "we", "us", or "our") collects, uses, shares, and protects personal information about visitors to codestringers.com (the "Site") and people who contact us through it.
1. Who we are; our role
CodeStringers is the controller of personal information collected through the Site, meaning we determine the purposes and means of processing. Our headquarters are in Santa Cruz, California, USA. The third-party service providers listed in Section 5 act as processors (or, where the law uses different terminology, equivalent service providers) on our behalf.
For questions about this Policy, contact our Privacy Office at privacy@codestringers.com.
2. Information we collect
We collect personal information in three ways:
- Automatically through hosting. The Site is hosted on the Wix platform (operated by Wix.com, Ltd.). When you visit, Wix processes standard server-side information on our behalf to deliver, secure, and analyse traffic, including: IP address; browser type and user-agent string; device type; approximate location derived from IP; requested URL and pages viewed; referring URL; date, time, and duration of the visit.
- Through Google Analytics 4 ("GA4"), provided by Google LLC. GA4 collects page views and navigation paths, events you trigger (clicks, scroll depth), session duration and engagement, approximate geographic location from IP, and device and browser characteristics. We use GA4 only for aggregate analytics and not for individual identification or advertising.
- Through our contact form. When you submit the contact form, we and Wix collect the information you provide — typically your name, email address, and the contents of your message — so that we can respond to your inquiry.
We do not knowingly collect special categories of personal information (such as racial or ethnic origin, religious beliefs, health, biometric, or sexual-orientation data) through the Site. Please do not submit such information through the contact form.
3. How we use information and our lawful bases
We use personal information for the purposes below. For visitors in the European Economic Area ("EEA") and the United Kingdom, we identify our lawful basis under Article 6 of the EU/UK General Data Protection Regulation (GDPR).
- Operate and deliver the Site — to render pages, route requests, and keep the Site available. Lawful basis: legitimate interests (running our business and providing a working website).
- Secure the Site and prevent abuse — to detect and mitigate fraud, denial-of-service activity, and unauthorised access attempts. Lawful basis: legitimate interests (protecting our systems and visitors).
- Respond to inquiries you submit — to read your message and reply. Lawful basis: your consent when you submit the form, and where applicable steps taken at your request prior to entering a contract.
- Understand aggregate traffic (Wix Analytics and GA4) — to measure how visitors find and use the Site. Lawful basis: your consent in the EEA and the United Kingdom (collected via Wix's consent prompt where required), and legitimate interests elsewhere (improving the Site).
- Comply with law and respond to legal process — to meet our legal obligations and exercise or defend legal claims. Lawful basis: legal obligation and, where applicable, legitimate interests.
Where we rely on legitimate interests, you have the right to object as described in Section 9.
4. Cookies and tracking technologies
The Wix platform sets cookies on our behalf to operate the Site. These fall into a few categories:
- Essential cookies — required for the Site to function (session management, load balancing, security, and fraud prevention). Without these the Site cannot work properly.
- Functional cookies — remember preferences such as language or display options.
- Analytics cookies — used by Wix's built-in analytics to give us aggregate, non-identifying traffic data.
- Google Analytics cookies — set by Google Analytics 4 (for example
_ga,_ga_*,_gid) to distinguish unique visitors and sessions for aggregate reporting. These are not used for advertising.
For the current list of cookies set on the Site and instructions for managing your preferences, see the Wix Cookie Policy. You can also block or delete cookies through your browser settings, though doing so may affect Site functionality. Where required by law, Wix will request your consent before any non-essential cookies are set.
Opting out of Google Analytics. You can install the Google Analytics Opt-out Browser Add-on to prevent GA from collecting data from your browser on any site that uses it.
5. Sub-processors and third-party services
We engage the following sub-processors to operate the Site. Each handles personal information under contractual commitments substantially consistent with this Policy and applicable law.
- Wix.com, Ltd. — Israel / United States. Hosting platform, content management, built-in analytics, form processing, and related infrastructure. Wix Privacy Policy · Wix Cookie Policy.
- Google LLC — United States. Google Analytics 4 for aggregate traffic and engagement measurement. Google Privacy Policy.
- Cloudflare, Inc. — United States / global edge. Content delivery and DDoS mitigation engaged by Wix as part of its hosting service. Cloudflare Privacy Policy.
We will update this list when we add or remove a material sub-processor. The list on this page is authoritative. Outbound links to third parties we link from the Site (for example our LinkedIn page) are not sub-processors; their services are governed by their own privacy policies, over which we have no control.
6. Sharing and disclosure
We do not sell, rent, or share personal information for advertising, marketing, or profiling purposes, and we have no advertising partners.
We may disclose personal information:
- To our sub-processors listed in Section 5, who process information on our behalf under written agreement.
- When required by law, regulation, subpoena, court order, or other legal process; to protect our rights, property, or safety, or that of our users or others; or to investigate suspected fraud or abuse.
- In connection with a corporate transaction such as a merger, acquisition, reorganisation, financing, or sale of all or part of our business or assets, in which case we will require the recipient to handle personal information in a manner consistent with this Policy and applicable law, and will notify affected individuals where required.
7. Data retention
We retain personal information only as long as needed for the purposes described:
- Server logs (Wix). Retained by Wix according to its standard retention policies as described in the Wix Privacy Policy.
- Google Analytics data. Retained per our GA4 property's configured retention setting. Aggregate reports remain with Google for as long as Google retains them. We do not export individual GA records.
- Contact-form submissions. Retained only as long as needed to respond and keep a reasonable business record — typically up to 24 months — after which the inquiry is deleted or anonymised, unless a longer period is required by law.
- Client-engagement records. Where a contact leads to a client engagement, related records are retained for the duration of the engagement and for the period required by the applicable Master Services Agreement, tax law, and professional-records rules (typically up to seven years after the engagement ends).
- Backups. Backups containing personal information are retained for up to 90 days, after which they are overwritten as part of normal rotation.
8. International data transfers
We are headquartered in the United States and primarily store personal information there. Our sub-processors (Wix, Google, Cloudflare) operate globally distributed infrastructure, which means personal information may be processed in countries other than your own, including countries that have not been deemed by the European Commission or the UK to provide an adequate level of data protection.
Where required by EU or UK GDPR, transfers from the EEA, the United Kingdom, or Switzerland to such countries are protected by Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent transfer mechanisms that our sub-processors have implemented. Wix and Google publish their respective SCCs and data-processing terms on their public sites.
9. Your rights
Depending on where you live and the law that applies, you may have the following rights regarding your personal information:
- Know what personal information we hold about you
- Access a copy of that information
- Correct inaccurate or incomplete information
- Request deletion of your information
- Restrict or object to certain processing, including direct marketing
- Receive your information in a portable, machine-readable format
- Withdraw consent where processing is based on consent
- Not be subject to solely automated decisions producing significant effects
- Lodge a complaint with your data-protection authority (see below)
California residents (CCPA / CPRA) have additional rights to know the categories and specific pieces of personal information we collect, to delete that information, to correct it, to limit use of sensitive personal information, and to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law. We will not discriminate against you for exercising any of these rights.
Other US-state residents (Colorado, Connecticut, Utah, Virginia, and other states with comparable laws) have similar rights of access, correction, deletion, portability, and opt-out from targeted advertising or profiling — none of which we engage in.
How to exercise your rights. Email privacy@codestringers.com. We will respond within 30 business days, or within the period required by applicable law if shorter. Because we do not collect identifying information through the Site, we may need additional information from you to verify your identity before responding. We will fulfil verified requests free of charge, except where a request is manifestly unfounded or excessive (in which case we may charge a reasonable fee or decline the request, as permitted by law). You may authorise an agent to act on your behalf, subject to verification.
Right to complain. You may lodge a complaint with your supervisory authority. Examples:
- EEA — the data-protection authority in your country of residence or where the alleged infringement occurred.
- United Kingdom — the Information Commissioner's Office (ICO), ico.org.uk.
- California — the California Privacy Protection Agency (CPPA) or the California Attorney General.
- Colorado / Connecticut / Utah / Virginia — the State Attorney General (or, in Utah, the Division of Consumer Protection).
We would, of course, appreciate the chance to address your concern first.
10. Security measures
We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, and destruction. These include encryption in transit (HTTPS/TLS), multi-factor authentication on our internal business systems, endpoint protection and full-disk encryption on staff devices, role-based access control, and security review of our material sub-processors.
No method of transmission or storage is completely secure. For a fuller description of our security program, see our Digital Security page.
11. Breach notification
If we become aware of a personal-data breach that affects the security of personal information processed through the Site, we will notify affected individuals and the relevant supervisory authorities to the extent and within the timeframes required by applicable law — including, where required by EU/UK GDPR, notification to the competent supervisory authority within 72 hours of becoming aware of the breach. We will provide as much information as we reasonably can about what happened, the categories of information involved, and the steps we are taking in response.
12. Automated decision-making and profiling
We do not use personal information collected through the Site to make decisions about you based solely on automated processing that produce legal or similarly significant effects.
13. Children's privacy
The Site is not directed to children under the age of 13 (or under 16 in the EEA and the United Kingdom), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
14. International visitors
The Site is operated from the United States. If you access it from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States and other countries where our sub-processors operate. By using the Site, you consent to such transfer and processing, subject to the safeguards described in Section 8.
15. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective" date at the top of this page. For material changes — for example, new categories of personal information or new processing purposes — we will provide reasonable advance notice on this page (typically 30 days) before the change takes effect. Non-material clarifying changes are effective on posting. We encourage you to review this Policy periodically.
16. Contact us
Questions, requests, or complaints regarding this Policy or your personal information can be sent to:
Privacy Office
CodeStringers
Santa Cruz, CA, USA
privacy@codestringers.com