01 / 15
Who we are
CodeLoom LLC ("CodeLoom", "we", "us") is an independent digital product studio. We design and engineer websites, web applications, AI-powered products and cloud infrastructure for clients around the world.
We are a distributed team. Most of our designers and engineers are based in California, New York and London, and we work across every time zone. We do not operate public offices; in-person meetings can be arranged in those three cities on request.
CodeLoom is the controller of the personal information collected through codeloom.io and through your correspondence with us. You can reach us about anything in this policy at [email protected].
02 / 15
Scope of this policy
This policy covers codeloom.io, the contact form on it and the conversations that follow when you get in touch with us.
It does not cover the products and websites we build for clients. When we work on a client's systems or process personal data on a client's behalf, we act as that client's service provider (processor) under our agreement with them, and the client's own privacy notice applies. Our own products — for example MindClerk — have their own privacy policies.
03 / 15
Information we collect
Information you give us. When you use the contact form we collect your name, email address, company (optional), budget range, project type and the project description you write. If you email us or talk to us on a call, we keep the correspondence and anything you choose to share in it.
Information collected automatically. Like every website, ours receives technical data each time a page loads:
- your IP address, browser and device type, the pages you request, the referring page and the time of the request, recorded in short-lived server and security logs;
- security signals from Cloudflare Turnstile — such as browser characteristics and interaction timing — which are evaluated when you submit the form to tell people apart from bots.
What we don't collect. We do not use analytics, advertising or social media tracking tools, we don't build profiles about visitors, and we don't collect sensitive personal information. Please don't include sensitive details — for example health or financial information — in your enquiry.
04 / 15
How we use your information
We use personal information only for the purposes below:
- to read and reply to your enquiry, schedule calls and prepare estimates or proposals;
- to deliver and manage our services if you become a client;
- to keep the website secure — preventing spam, fraud and abuse of the contact form;
- to meet legal, tax and accounting obligations and to establish or defend legal claims.
We don't use your information for automated decision-making or profiling, and we won't add you to a mailing list unless you ask us to.
05 / 15
Legal bases (EEA and UK visitors)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Steps before a contract — replying to your enquiry and preparing a proposal you asked for;
- Legitimate interests — running and securing our website, answering general questions and improving our services, balanced against your rights and expectations;
- Legal obligation — keeping records required by law;
- Consent — where we ask for it; you can withdraw consent at any time.
08 / 15
International transfers
We work across the United States, the United Kingdom and Europe, and some of our providers operate globally. Your information may therefore be processed in countries other than the one you live in.
When we transfer personal information out of the EEA or the UK, we rely on adequacy decisions — including the EU–U.S. Data Privacy Framework and its UK extension where a provider is certified — or on the European Commission's Standard Contractual Clauses and the UK Addendum.
09 / 15
How long we keep it
- Enquiries that don't lead to a project are kept for up to 24 months after our last contact, so that we have the context if you get back in touch, and then deleted.
- Client records are kept for the length of our engagement and afterwards for as long as needed for legal, tax and accounting purposes — typically up to seven years.
- Server and security logs are kept only as long as needed to operate and secure the website and to investigate incidents.
- Backups. Our database is backed up daily and only the seven most recent backups are kept, so deleted information disappears from backups within about a week.
10 / 15
How we protect it
We treat security as part of the craft. The website is served only over encrypted HTTPS connections; our content management system requires authenticated access and is used only by our team; the contact form is protected against automated abuse; and we follow the principle of least privilege for everyone with access to our systems.
No method of transmission or storage is completely secure, but we work hard to protect your information and will notify you and the relevant authorities of a breach where the law requires it.
11 / 15
Your privacy rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy of it;
- correct information that is inaccurate or incomplete;
- delete your information;
- restrict or object to certain processing, including processing based on legitimate interests;
- data portability — receive your information in a structured, machine-readable format;
- withdraw consent at any time, where we rely on consent.
To use any of these rights, email [email protected]. We may need to verify your identity before acting on a request, and we will respond within one month — or within the period your local law sets. You can also complain to your local data protection authority, such as an EU supervisory authority or the UK Information Commissioner's Office, although we'd appreciate the chance to resolve your concern first.
12 / 15
California privacy rights
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect, use and disclose; to request its deletion or correction; to opt out of its sale or sharing; and not to be discriminated against for exercising these rights.
In the past 12 months we have collected identifiers (such as your name, email address and IP address), professional information (such as your company) and internet activity information (such as security logs), from you and your device, for the purposes described in this policy. We have not sold or shared personal information, and we do not knowingly sell or share the information of anyone under 16. We honour Global Privacy Control signals — though there is nothing to opt out of, because we don't sell or share.
You can make a request yourself or through an authorised agent by emailing [email protected].
13 / 15
Children
Our website and services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, please contact us and we will delete it.
14 / 15
Links to other websites
Our website links to other sites and services — for example LinkedIn, GitHub, Dribbble, X and the websites of projects in our portfolio. Their privacy practices are their own, and we encourage you to read their policies.
15 / 15
Changes to this policy
We may update this policy as our website, services or the law change. When we do, we'll revise the "Last updated" date at the top of this page, and if the changes are significant we'll make that clear on the website.
Questions about your data?
Write to us at [email protected] with "Privacy" in the subject line — a real person on our team will reply.
Read our Terms of Service