Legal
    Last updated · September 30, 2026

    Privacypolicy.

    We build software for a living, so we know exactly what this website does with your data — and we keep it to the minimum. This policy explains what we collect, why, who helps us process it and the choices you have.

    The short version

    • We only collect what you send us through the contact form or by email, plus the technical data any website needs to run securely.
    • No analytics, no advertising trackers, no tracking cookies — and we never sell or rent your personal information.
    • Your enquiry is stored on our own server in Germany and shared with a few service providers only to run this website and reply to you.
    • You can ask us at any time to see, correct or delete your data by writing to [email protected].

    01 / 15

    Who we are

    CodeLoom LLC ("CodeLoom", "we", "us") is an independent digital product studio. We design and engineer websites, web applications, AI-powered products and cloud infrastructure for clients around the world.

    We are a distributed team. Most of our designers and engineers are based in California, New York and London, and we work across every time zone. We do not operate public offices; in-person meetings can be arranged in those three cities on request.

    CodeLoom is the controller of the personal information collected through codeloom.io and through your correspondence with us. You can reach us about anything in this policy at [email protected].

    02 / 15

    Scope of this policy

    This policy covers codeloom.io, the contact form on it and the conversations that follow when you get in touch with us.

    It does not cover the products and websites we build for clients. When we work on a client's systems or process personal data on a client's behalf, we act as that client's service provider (processor) under our agreement with them, and the client's own privacy notice applies. Our own products — for example MindClerk — have their own privacy policies.

    03 / 15

    Information we collect

    Information you give us. When you use the contact form we collect your name, email address, company (optional), budget range, project type and the project description you write. If you email us or talk to us on a call, we keep the correspondence and anything you choose to share in it.

    Information collected automatically. Like every website, ours receives technical data each time a page loads:

    • your IP address, browser and device type, the pages you request, the referring page and the time of the request, recorded in short-lived server and security logs;
    • security signals from Cloudflare Turnstile — such as browser characteristics and interaction timing — which are evaluated when you submit the form to tell people apart from bots.

    What we don't collect. We do not use analytics, advertising or social media tracking tools, we don't build profiles about visitors, and we don't collect sensitive personal information. Please don't include sensitive details — for example health or financial information — in your enquiry.

    04 / 15

    How we use your information

    We use personal information only for the purposes below:

    • to read and reply to your enquiry, schedule calls and prepare estimates or proposals;
    • to deliver and manage our services if you become a client;
    • to keep the website secure — preventing spam, fraud and abuse of the contact form;
    • to meet legal, tax and accounting obligations and to establish or defend legal claims.

    We don't use your information for automated decision-making or profiling, and we won't add you to a mailing list unless you ask us to.

    06 / 15

    Cookies and local storage

    We don't use tracking or advertising cookies, so there is no cookie banner to click through.

    • Preferences stored in your browser. The site's colour theme is remembered in your browser's local storage ("theme"), and a session flag ("cl-preloaded") remembers that you have already seen the intro animation during the current visit. Neither is sent to us.
    • Security cookies from Cloudflare. Our network provider may set strictly necessary cookies (such as "__cf_bm" or "cf_clearance") to protect the site from bots and attacks. They are not used for tracking or advertising.
    • Web fonts. Our typefaces are delivered by Google Fonts. To send the font files, Google receives your IP address and basic browser information; Google Fonts does not set cookies.

    You can clear local storage and cookies in your browser settings at any time; the website will keep working.

    07 / 15

    Who we share information with

    We never sell or rent personal information, and we don't share it for cross-context behavioural advertising. We share it only with service providers who help us run the website and our business, under agreements that limit their use of the data:

    • netcup GmbH — hosts our website, content management system and the database where form submissions are stored, on servers in Germany;
    • Cloudflare, Inc. — DNS, content delivery, security and the Turnstile anti-spam check;
    • Telegram — when you submit the form, a copy of your enquiry is sent to our team through a private Telegram bot so that we can respond quickly;
    • Google LLC — delivery of the web fonts used on the site;
    • our email and productivity providers — to send and store correspondence with you.

    We may also disclose information to professional advisers such as lawyers and accountants, when the law requires it, to protect our rights and the safety of others, or to a successor if CodeLoom is involved in a merger, acquisition or sale of assets — in which case this policy will continue to protect your information.

    08 / 15

    International transfers

    We work across the United States, the United Kingdom and Europe, and some of our providers operate globally. Your information may therefore be processed in countries other than the one you live in.

    When we transfer personal information out of the EEA or the UK, we rely on adequacy decisions — including the EU–U.S. Data Privacy Framework and its UK extension where a provider is certified — or on the European Commission's Standard Contractual Clauses and the UK Addendum.

    09 / 15

    How long we keep it

    • Enquiries that don't lead to a project are kept for up to 24 months after our last contact, so that we have the context if you get back in touch, and then deleted.
    • Client records are kept for the length of our engagement and afterwards for as long as needed for legal, tax and accounting purposes — typically up to seven years.
    • Server and security logs are kept only as long as needed to operate and secure the website and to investigate incidents.
    • Backups. Our database is backed up daily and only the seven most recent backups are kept, so deleted information disappears from backups within about a week.

    10 / 15

    How we protect it

    We treat security as part of the craft. The website is served only over encrypted HTTPS connections; our content management system requires authenticated access and is used only by our team; the contact form is protected against automated abuse; and we follow the principle of least privilege for everyone with access to our systems.

    No method of transmission or storage is completely secure, but we work hard to protect your information and will notify you and the relevant authorities of a breach where the law requires it.

    11 / 15

    Your privacy rights

    Depending on where you live, you may have the right to:

    • access the personal information we hold about you and receive a copy of it;
    • correct information that is inaccurate or incomplete;
    • delete your information;
    • restrict or object to certain processing, including processing based on legitimate interests;
    • data portability — receive your information in a structured, machine-readable format;
    • withdraw consent at any time, where we rely on consent.

    To use any of these rights, email [email protected]. We may need to verify your identity before acting on a request, and we will respond within one month — or within the period your local law sets. You can also complain to your local data protection authority, such as an EU supervisory authority or the UK Information Commissioner's Office, although we'd appreciate the chance to resolve your concern first.

    12 / 15

    California privacy rights

    If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect, use and disclose; to request its deletion or correction; to opt out of its sale or sharing; and not to be discriminated against for exercising these rights.

    In the past 12 months we have collected identifiers (such as your name, email address and IP address), professional information (such as your company) and internet activity information (such as security logs), from you and your device, for the purposes described in this policy. We have not sold or shared personal information, and we do not knowingly sell or share the information of anyone under 16. We honour Global Privacy Control signals — though there is nothing to opt out of, because we don't sell or share.

    You can make a request yourself or through an authorised agent by emailing [email protected].

    13 / 15

    Children

    Our website and services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, please contact us and we will delete it.

    15 / 15

    Changes to this policy

    We may update this policy as our website, services or the law change. When we do, we'll revise the "Last updated" date at the top of this page, and if the changes are significant we'll make that clear on the website.

    Questions about your data?

    Write to us at [email protected] with "Privacy" in the subject line — a real person on our team will reply.

    Read our Terms of Service