Privacy Policy
Last updated: [TBD] · This is a working draft pending legal review.
This Privacy Policy explains how Coded B.V. ("Coded", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Coded commerce platform, our websites, and related services (together, the "Platform"). It applies worldwide to everyone who interacts with the Platform, and it is written to meet the requirements of the EU and UK General Data Protection Regulation (GDPR/UK GDPR), United States state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act, "CCPA/CPRA"), and comparable privacy laws in other jurisdictions, in a single document.
We designed the Platform around privacy-by-design: we collect the minimum data needed to run the service, we use cookieless analytics, and we do not sell or share personal data for cross-context behavioural advertising.
1. Who we are (controller identity)
Coded B.V. is the controller responsible for the personal data described in this Policy in connection with the Coded Platform. Coded B.V. is a private limited company (besloten vennootschap) registered in the Netherlands and is a subsidiary of Coded Holding B.V.
- Legal entity: Coded B.V.
- Parent company: Coded Holding B.V.
- Registered address: De Taling 15, 2761 SL Zevenhuizen, The Netherlands
- Chamber of Commerce (KVK) number: 42027097
- VAT number: NL869368795B01
- Privacy contact: privacy@coded.eu
Coded is an international company. The Netherlands is our place of registration and initial launch market, and the Platform serves merchants and their customers worldwide.
1.1 Controller vs. processor roles
The Platform lets a merchant operate one or more branded online shops and other projects under an Organization.
- For data we process to operate, secure, bill, and improve the Platform, and for the accounts of the people who sign up to use Coded, Coded acts as a controller.
- For personal data that a merchant collects from its own end customers through its projects (for example, a shopper's order and contact details), the merchant is the controller and Coded acts as a processor on the merchant's behalf, under our Data Processing Agreement. In that role we process such data only on the merchant's documented instructions. This Policy describes Coded's own controller processing; merchants are responsible for the privacy notices they present to their customers.
2. The personal data we collect
We collect the following categories of personal data. Not every category applies to every person.
2.1 Data you provide
- Account and identity data: name, email address, password (stored hashed), and Organization details when you create or join an Organization.
- Merchant and billing data: business name, billing contact, tax/VAT identifiers, subscription plan, and payout configuration. Payment card numbers are handled by our payment processors and are not stored by Coded.
- Support and communications: the contents of messages, support tickets, and correspondence you send us.
- Content you upload: product information, catalog selections, project configuration, and other content you add to the Platform.
2.2 Data we collect automatically
- Service and device data: IP address, browser and device type, operating system, and timestamps, collected to operate and secure the service.
- Usage and diagnostic data: logs, error/crash reports, and feature-usage events used to keep the Platform running and to debug problems.
- Cookieless analytics: aggregate, non-tracking measurement that does not build a cross-site profile of you and does not rely on advertising cookies or device fingerprinting (see Section 6).
2.3 Data from third parties
- Payment processors (Stripe, Mollie): transaction status, payout, and fraud-prevention signals related to merchant payments.
- Authentication and integration providers: limited profile or status data where you connect a third-party login or integration.
We do not seek to collect special categories of data (such as health, biometric, or precise geolocation data) for our own purposes, and we ask that you do not submit such data to us except where strictly necessary and lawful.
3. Why we use personal data and our legal bases
The table below sets out our purposes and, where GDPR applies, the legal basis for each. Where another jurisdiction's law applies, we rely on the equivalent lawful ground (for example, processing necessary to provide a requested service, or our legitimate business interests).
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and administer accounts and Organizations | Performance of a contract |
| Provide, maintain, and operate the Platform and its projects | Performance of a contract |
| Process subscription billing and merchant payouts | Performance of a contract; legal obligation |
| Secure the Platform, prevent fraud and abuse | Legitimate interests; legal obligation |
| Provide support and respond to requests | Performance of a contract; legitimate interests |
| Measure and improve the Platform (cookieless, aggregate) | Legitimate interests |
| Send service and transactional messages | Performance of a contract; legitimate interests |
| Send optional product updates or marketing | Consent (withdrawable at any time) |
| Comply with legal, tax, and accounting obligations | Legal obligation |
| Establish, exercise, or defend legal claims | Legitimate interests |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to such processing as described in Section 9.
4. How we share personal data
We share personal data only as described here, and we require recipients to protect it.
4.1 Service providers (processors)
We use vetted service providers that process personal data on our instructions under written data processing terms. Key categories include:
- Payment processing: Stripe and Mollie process merchant payment transactions and related fraud-prevention and payout functions.
- Hosting and infrastructure: our managed database and core infrastructure are hosted in the European Union (Frankfurt, Germany).
- Communications and email delivery: providers that deliver transactional and service messages.
- Error monitoring and logging: providers that help us detect and fix faults; we configure these to avoid sending personal data where reasonably possible.
4.2 Payments and the 0% platform fee
Merchant payment transactions are processed by Stripe and Mollie. Coded charges a 0% platform fee on a merchant's payment transactions — merchants pay only the pass-through processing cost charged by Stripe or Mollie. Coded does not take a transaction or platform fee on those payments. (Separate subscription fees may apply for publishing a project; those are described in our commercial terms.) The personal and payment data involved in a transaction is handled by the payment processor under its own role and terms.
4.3 Between merchant and Coded
When you use a merchant's project, the merchant (as controller) and Coded (as processor) each handle relevant data as described in Section 1.1.
4.4 Legal, safety, and corporate transactions
We may disclose personal data where required to comply with law or valid legal process, to protect the rights, safety, and security of Coded, our users, or the public, or in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and continued protection of the data.
4.5 No sale or sharing for advertising
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable laws. We do not use advertising-tracking cookies or build advertising profiles. Because we do not sell or share personal data, there is nothing to opt out of for that purpose — but you may still exercise your rights under Section 9 at any time.
5. International data transfers
Coded's managed database and core infrastructure are hosted in the European Union (Frankfurt, Germany). We chose EU hosting as a deliberate privacy feature.
Because Coded is an international company and some of our service providers operate globally, personal data may be processed in, or accessed from, countries outside your own. Where we transfer personal data internationally, we use a lawful transfer mechanism, which may include:
- transfers to countries the European Commission (or another competent authority) has recognised as providing an adequate level of protection; or
- the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with any additional safeguards required.
You may request information about the safeguards that apply to a specific transfer using the contact details in Section 13.
6. Cookies and cookieless analytics
We use only the cookies and similar technologies that are strictly necessary to provide and secure the Platform — for example, to keep you signed in and to protect against fraud and abuse. We do not use advertising or cross-site tracking cookies, and we do not fingerprint your device for advertising.
For product measurement we use cookieless analytics that produce aggregate statistics without building a personal profile of you across sites. Where any non-essential technology requires consent under applicable law, we will ask for it before it is used and let you withdraw consent at any time.
7. How long we keep personal data (retention)
We keep personal data only for as long as needed for the purposes described in this Policy, after which we delete or anonymise it. Our retention is guided by:
- the lifetime of your account or Organization (account data is retained while the account is active);
- the period required to provide and support the Platform and resolve disputes;
- legal, tax, and accounting retention obligations (for example, retaining invoicing records for the period required under applicable law); and
- the period needed to establish, exercise, or defend legal claims.
When you close your account, we delete or anonymise your personal data within a reasonable period, except where we are required or permitted by law to retain it.
<!-- OPEN: confirm concrete retention periods per data category with counsel/finance -->8. How we protect personal data (security)
We apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, and alteration. These measures include encryption in transit, access controls and least-privilege principles, network and application protections, logging and monitoring, and regular review of our security practices.
EU-based hosting (Frankfurt) is part of this posture. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; we work continuously to improve our protections. To report a security concern, contact security@coded.co.
9. Your privacy rights
We provide the following rights to everyone, worldwide, regardless of where you live. Some rights have specific legal sources, and some are subject to conditions and exceptions under the law that applies to you. We will not discriminate against you for exercising your rights.
9.1 Rights for everyone (universal baseline)
- Access the personal data we hold about you and obtain a copy.
- Correct inaccurate or incomplete data.
- Delete your personal data, subject to legal retention requirements.
- Object to or restrict certain processing.
- Portability — receive your data in a portable format and have it transmitted where technically feasible.
- Withdraw consent at any time, where we rely on consent, without affecting prior processing.
- Lodge a complaint with us or with a supervisory authority.
9.2 Rights under GDPR / UK GDPR (EU/EEA/UK)
If you are in the EEA, the UK, or another GDPR-aligned jurisdiction, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests and to direct marketing), and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. You also have the right to lodge a complaint with your local data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens (AP) — without prejudice to any other remedy.
9.3 Rights under US state laws (CCPA/CPRA and similar)
If you are a resident of California or another US state with a comprehensive privacy law, you have the right to:
- know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients;
- access and obtain a copy of your personal information;
- delete personal information, subject to legal exceptions;
- correct inaccurate personal information;
- opt out of the "sale" or "sharing" of personal information and of targeted advertising — note that Coded does not sell or share personal information and does not engage in cross-context behavioural advertising, so there is no such activity to opt out of; and
- limit the use of sensitive personal information — we do not use sensitive personal information for purposes that require an option to limit.
You will not be discriminated against for exercising these rights. You may use an authorised agent to submit a request where the law permits, subject to verification.
9.4 Rights in other jurisdictions
If you are protected by another privacy law (for example, in Brazil, Canada, the UK, Switzerland, or elsewhere), you have the equivalent rights granted by that law, and you may contact us to exercise them. The mandatory consumer- and data-protection law of your own jurisdiction may apply to you in addition to this Policy and our governing-law terms.
9.5 How to exercise your rights
To exercise any right, contact us at privacy@coded.eu. We will verify your identity before acting on a request, respond within the timeframe required by applicable law, and tell you if an exception prevents us from fully complying. There is normally no charge, although we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, as the law allows. If we act as a processor for a merchant, we will direct your request to the relevant merchant (the controller) or assist them in responding.
10. Children
The Platform is intended for businesses and is not directed to children. We do not knowingly collect personal data from children below the age set by applicable law. If you believe a child has provided us personal data, contact us and we will take appropriate action.
11. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you without a lawful basis and appropriate safeguards. We may use automated checks to detect fraud and abuse; where such processing has a significant effect, you may request human review.
12. Changes to this Policy
We may update this Policy to reflect changes to the Platform, our practices, or the law. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Your continued use of the Platform after an update takes effect means you are subject to the revised Policy.
13. Governing law
This Policy and any dispute relating to it are governed by the laws of the Netherlands, and the courts of Amsterdam have jurisdiction, except where mandatory consumer- or data-protection law of your country of residence grants you the protection of, or jurisdiction in, your local courts and authorities. Nothing in this Policy limits non-waivable rights you have under the law that applies to you.
Contact
For privacy questions, to exercise your rights, or to reach our privacy function:
- Email (privacy): privacy@coded.eu
- Email (security): security@coded.co
- Email (general legal): legal@coded.eu
- Postal: Coded B.V., De Taling 15, 2761 SL Zevenhuizen, The Netherlands
- Chamber of Commerce (KVK): 42027097
If you are in the EEA/UK and are not satisfied with our response, you may contact your local supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
Effective date: 11 June 2026
<!-- OPEN ITEMS FOR COUNSEL: - Confirm whether a formal DPO is appointed/required (Art. 37 GDPR) and, if so, add DPO name + contact; current draft uses a privacy function contact, not a named DPO. - Confirm need for an EU representative (Art. 27) and/or UK representative; add if Coded lacks EU/UK establishment for any in-scope processing. - Confirm exact controller vs. processor split and reconcile with the DPA; verify merchant-as-controller framing for shopper data is correct for all project types. - Confirm concrete retention periods per data category (esp. statutory NL tax/invoicing retention, typically 7 years) — Section 7 currently uses general language. - Verify the precise list and roles of sub-processors (Stripe, Mollie, hosting in Frankfurt, email delivery, error monitoring) and whether each is processor or independent controller; confirm the public sub-processor list/URL. - Confirm international transfer mechanisms actually in place (SCCs executed? UK IDTA? adequacy reliance?) before stating them as fact. - Validate the CCPA/CPRA "no sale / no share / no cross-context behavioural advertising" statements against actual data flows, including any analytics/error-monitoring vendor that could constitute a "sale" or "share" under California law. - Confirm cookieless-analytics vendor and that it requires no consent banner in any in-scope jurisdiction; confirm whether any strictly-necessary cookie still needs disclosure/consent. - Confirm legal basis choices in the Section 3 table, especially marketing consent mechanics and legitimate-interest balancing documentation. - Confirm children's-data age thresholds per jurisdiction and whether a higher GDPR Art. 8 digital-consent age applies. - Confirm correct legal email domain (coded.eu (legal/privacy) · coded.co (ops)) and finalize KVK, VAT, registered address, and effective date. - Decide whether a separate "Categories of personal information collected/disclosed in the last 12 months" CCPA table is required and add if so. -->