Skip to content
coderband

Legal

Privacy Policy

Last updated October 8, 2026

This policy explains what personal data coderband collects through coder.band and through our business contacts, why we collect it, and what your rights are.

In short:

  • We use cookieless analytics.
  • Payments go through Stripe, and we never see your full card number.
  • Bookings go through Cal.com.
  • Advertising pixels, if we use them, load only after you agree.
  • We don’t sell your data.

1. Who we are

The controller of your personal data is coderband LLC, a Wyoming limited liability company (Wyoming filing ID 2025-001816694), of 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA, trading as “coderband” (“we”, “us”).

Contact: [email protected]

What this policy covers. This policy covers visitors to coder.band, people who email us or book a call, buyers, and contacts at our clients and partners. When we work on a client’s systems, we process the client’s data as their processor under our Data Processing Addendum. In that case, the client’s own privacy policy applies to that data.

2. What we collect and why

When What data Why Legal basis (GDPR)
You visit the site IP address, requested URL, browser and device information, date and time To deliver the site and keep it secure. The site is hosted on Cloudflare, which processes this data for us. Legitimate interests (running a secure website)
Analytics Page views, referring site, browser, operating system, device type and country, all counted in aggregate To understand which pages are useful. We use Cloudflare Web Analytics, which is cookieless: it doesn’t set cookies or use local storage, and it isn’t used to identify you. Legitimate interests (improving our site)
You email us at [email protected] Your name, email address, the content of your message, and anything you attach To reply to you and handle your request Steps before a contract, or legitimate interests (answering business enquiries)
You book a call through Cal.com Name, email address, time zone, chosen time, your answers to booking questions, and video-call details To schedule and hold the call Steps before a contract, or legitimate interests
You buy through Stripe Checkout, a Stripe Payment Link or a Stripe invoice Name, email address, company name, billing address, tax ID (if you give it), what you bought, and payment status. Stripe handles your card or bank details. We see only limited details, such as card brand and last four digits. To take payment, deliver what you bought, issue invoices and refunds, and prevent fraud Performance of a contract; legal obligation (tax and accounting records)
We work together Business contact details of your team, project communications and contract records To run the engagement and keep business records Performance of a contract; legitimate interests; legal obligation
Advertising pixels (only if enabled, see Section 4) See Section 4 To measure our ads and show our ads to past visitors Consent

We don’t ask for special categories of data, such as health or religious beliefs, and we don’t make decisions about you by automated means alone.

3. Cookies and similar technologies

By default, our site sets no cookies for analytics or advertising. Cloudflare Web Analytics is cookieless.

Other providers’ cookies. When you pay on a Stripe-hosted page or book on Cal.com, those providers may set their own cookies on their own sites. Their privacy policies explain them.

Advertising cookies. These are set only if you consent (Section 4).

5. Who we share data with

We share personal data only with:

  • Service providers that act for us. They process your data only on our instructions. Our main providers are:

    • Cloudflare (hosting, CDN, security and analytics);
    • Stripe (payments, invoicing and fraud prevention). For some purposes, such as fraud prevention and its legal obligations, Stripe acts as an independent controller;
    • Cal.com (booking calls);
    • Google (Google Calendar and Google Meet, for scheduled video calls);
    • GitHub (code hosting);
    • Apple (iCloud+ Custom Email Domain, our [email protected] mailbox);
    • Anthropic (Claude Code), OpenAI (Codex) and Anysphere (Cursor, always in Privacy Mode), the AI coding tools we use, under terms that don’t allow them to train on customer code; and
    • Wise (receiving payments; billing data only).

    When our main providers change, we update this list. Our clients also get advance notice of new sub-processors under our Data Processing Addendum.

  • Our contractors in North Macedonia. We work with vetted individual contractors, some of whom are located in North Macedonia. They help us respond to you and deliver our work. They act only under our instructions and are bound in writing to confidentiality.

  • Advertising platforms (Reddit and X), only if you consent (Section 4).

  • Professional advisers, such as accountants and lawyers, under duties of confidentiality.

  • Authorities, where the law requires it.

  • A buyer or successor, if our business is sold or reorganized. They would have to protect your data as this policy describes.

We don’t sell your personal data.

6. International transfers

We are based in the United States. Several of our providers are also in the US, and some of our contractors are located in North Macedonia. When we transfer personal data from the EU, UK or Switzerland to these countries, we use a lawful transfer mechanism. For US providers, that is either the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), where the recipient is certified, or the European Commission’s Standard Contractual Clauses. For our contractors in North Macedonia, which has no EU adequacy decision, we use the Standard Contractual Clauses. Where needed, we add the UK Addendum or the Swiss adjustments. Contact us for a copy of the relevant safeguards.

7. How long we keep data

Data How long
Emails and enquiries that don’t lead to work 2 years after our last contact
Booking records 2 years after the call
Purchase, invoice and contract records 10 years after the end of the tax year, as tax and accounting law requires
Client contact details and project communications For the engagement and 6 years after it ends
Hosting and security logs As set by Cloudflare’s retention periods, which are short
Analytics Aggregated only. Cloudflare holds it under its retention periods.
Advertising pixel data (if enabled) For the lifetime of the cookie (see Section 4), and on the platform under its own policy

When a retention period ends, we delete the data or make it anonymous.

8. Your rights

If GDPR, the UK GDPR or Swiss law applies to you, you have the right to:

  • access your personal data and get a copy of it;
  • correct data that is inaccurate;
  • delete your data in certain cases;
  • restrict our use of your data in certain cases;
  • data portability, meaning you can receive data you gave us in a machine-readable format;
  • object to processing based on legitimate interests. You can always object to direct marketing;
  • withdraw consent at any time, where we rely on consent. Withdrawing doesn’t affect earlier processing; and
  • complain to a data protection authority, in particular in the country where you live or work. EU authorities are listed at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, the authority is the ICO (https://ico.org.uk).

How to use your rights. Email [email protected]. We’ll reply within one month. We may ask you to confirm your identity first. If you live in a US state that gives you privacy rights, you can contact us in the same way.

9. Security

We protect personal data with access controls, multi-factor authentication, encrypted devices, and by keeping data with established providers instead of on our own servers. No system is perfectly secure, but we take reasonable care, and we’ll tell you if a breach affects you where the law requires it.

10. Children

Our site and services are for businesses. They are not directed at children under 16, and we don’t knowingly collect children’s data.

11. Changes

If we update this policy, we’ll change the “Last updated” date. If a change is significant, for example adding a new kind of tracking, we’ll make it clear on the site and, where the law requires it, ask for your consent again.

12. Contact

[email protected]

coderband LLC · 75 E 3rd St, Ste 7, Sheridan, WY 82801, USA