Cookie Policy
Last updated: [TBD] · This is a working draft pending legal review.
This Cookie Policy explains how Coded B.V. ("Coded", "we", "us") uses cookies and similar storage technologies on the Coded platform and its public websites. It is written to be straightforward, because Coded's approach is straightforward: we run a privacy-by-design platform that does not use analytics, advertising, or cross-site tracking cookies. The only information we store on your device is what is strictly necessary to deliver the service you asked for.
This policy applies to the Coded marketing website, the merchant dashboard where an Organization manages its projects, and the storefronts that merchants publish through Coded, except where a merchant's own published storefront sets additional technologies under that merchant's own control (see "Merchant projects and storefronts" below). It should be read together with our Privacy Policy, which describes how we handle personal data more broadly and the rights you have over it.
Coded is an international company. Coded B.V. is registered in the Netherlands, where the platform first launched, and the platform serves merchants and their customers worldwide. This policy is drafted to meet the cookie and electronic storage rules that apply across the jurisdictions we operate in, including the EU ePrivacy framework and the General Data Protection Regulation (GDPR), United States state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act), and a general international baseline. Where the mandatory law of your own country or region grants you stronger protections, those protections apply to you in addition to this policy.
1. What cookies and similar technologies are
A "cookie" is a small text file that a website asks your browser to store on
your device, so that the site can recognise that device on later requests.
"Similar technologies" include other client-side storage mechanisms such as
localStorage, sessionStorage, and pixels or tags. Throughout this policy,
"cookies" is used as shorthand for cookies and these similar technologies
together.
Cookies and similar storage are commonly grouped by purpose:
- Strictly necessary — required to operate the service you requested, such as keeping you signed in or remembering security state. These cannot be switched off without breaking core functionality.
- Preference — remember choices you have made, such as your interface language.
- Analytics / performance — measure how a site is used.
- Advertising / tracking — build profiles of users across sites and over time to target advertising or share behaviour with third parties.
Coded uses only the first two categories, and uses them sparingly. We do not use analytics or advertising cookies, and we do not permit cross-site tracking on the surfaces we control. The sections below set out exactly what is stored and why.
2. Coded's cookieless posture
Coded is built privacy-first. Three commitments define how we treat your device:
- No analytics cookies. We measure the health and usage of our platform using cookieless, aggregate analytics that do not read from or write to your device for the purpose of identifying you, and do not assign you a persistent identifier. No measurement cookie is set on your device.
- No advertising or cross-site tracking. We do not set advertising cookies, we do not load third-party advertising tags on the surfaces we control, and we do not sell or share your personal data for cross-context behavioural advertising. We do not build advertising profiles and we do not participate in ad-tech tracking networks.
- Strictly necessary only. The only items we store on your device are those required to provide a service you have actively requested — for example, keeping you authenticated after you sign in, protecting a form submission against forgery, or remembering the language you selected. We keep this set as small as possible.
This posture is a deliberate design choice, not a configuration you have to opt into. It applies by default to every visitor.
3. What we store, and why
The table below describes the categories of strictly necessary and preference items Coded sets on the surfaces we control. Exact names, storage mechanism, and lifetimes are confirmed during legal review and kept current in this policy; the categories and purposes are accurate as of the draft date.
3.1 Strictly necessary
| Purpose | What it does | Typical lifetime |
|---|---|---|
| Authentication / session | Keeps you signed in to your Organization and merchant dashboard after you log in, so you do not have to re-authenticate on every page. Stored as an HTTP cookie; never in browser localStorage. | Session, or until you sign out, with periodic refresh |
| Security / anti-forgery | Protects form submissions and sensitive actions against cross-site request forgery and similar attacks. | Session |
| Load balancing / routing | Helps route your request to a healthy server so the platform stays responsive and consistent during your visit. | Session |
| Consent / preference record | If a choice (such as accepting an optional, future feature) is offered, records that choice so we honour it and do not ask again. | Up to 12 months |
3.2 Preference
| Purpose | What it does | Typical lifetime |
|---|---|---|
| Language / locale | Remembers the language you selected so the interface loads in that language on your next visit. | Up to 12 months |
| Interface state | Remembers minor, non-tracking interface choices (such as a dismissed notice) so they do not reappear unnecessarily. | Up to 12 months |
We do not use any item in the tables above to track you across other websites, to profile you, or for advertising. Preference items exist solely to make the service you requested work the way you set it up.
4. Why there is no cookie consent banner
Under the EU ePrivacy framework (Article 5(3) of the ePrivacy Directive as implemented in national law, including the Dutch Telecommunications Act), and under the comparable rules in the other jurisdictions we serve, prior consent is required only for storage that is not strictly necessary to deliver a service the user has explicitly requested. Storage that is strictly necessary for that service — and genuinely cookieless analytics that store nothing on your device for identification — are exempt from the consent requirement.
Because Coded uses only strictly necessary and preference storage, sets no analytics or advertising cookies, and does no cross-site tracking, there is nothing on the surfaces we control that requires consent. We therefore do not show a cookie consent banner. The ePrivacy framework still requires that we tell you, clearly, what we store and why — which is the purpose of this policy.
This is the honest reason for the absence of a banner: not that we have configured a banner away, but that the platform genuinely does not set the kind of cookies a banner would exist to gate. If that ever changes — for example, if we were to introduce an optional feature that relied on non-essential storage — we would request your consent through a clear, granular mechanism before any such storage was set, and we would update this policy and its effective date first.
5. Merchant projects and storefronts
Coded merchants use the platform to build and publish their own projects, including branded online shops. A published storefront is operated by the merchant (the "Organization"), who controls its content and configuration.
Coded provides the underlying technology and applies the same cookieless, strictly-necessary-only defaults to storefronts. However, a merchant may, where the platform permits and subject to the merchant's own obligations, add third-party functionality to its own storefront that sets additional cookies or similar storage. Where that happens, the merchant is the party responsible for those technologies and for obtaining any consent the law requires from that storefront's visitors. This policy describes only the storage that Coded itself sets. If you are shopping on a merchant's storefront, the merchant's own cookie or privacy notice governs any additional technologies that merchant has chosen to add.
6. Payments
Payments on the Coded platform are processed by our payment providers, Stripe and Mollie. When you complete a payment, the payment provider may set cookies or similar storage that are strictly necessary to process the transaction securely and to prevent fraud — for example, to maintain the integrity of a checkout session. These are set by the provider under its own role and its own privacy and cookie notices, and are limited to what is necessary to carry out the payment you initiated. Coded does not charge a platform fee on these transactions; you pay only the payment provider's processing cost. For details of how each provider handles data, see the provider's own notices linked from our Privacy Policy.
7. Where your data is stored
The data behind the Coded platform, including the limited information associated with strictly necessary and preference storage, is hosted in the European Union, in Frankfurt, Germany. We chose EU hosting as a privacy and resilience feature. Because Coded operates internationally, some processing may involve transfers to or access from other countries (for example, by a payment provider completing your transaction); where that occurs, we apply appropriate safeguards as described in our Privacy Policy.
8. How to control or remove cookies
Because we use only strictly necessary and preference storage, there is no Coded setting to switch them off — disabling strictly necessary items would prevent core functionality, such as staying signed in, from working.
You can still control storage at the browser level. Most browsers let you view, block, or delete cookies and clear site storage through their settings or privacy controls. If you block or delete strictly necessary items, parts of the platform may not function correctly — for example, you may be signed out or asked to re-authenticate. Blocking or clearing preference items will cause us to forget choices such as your selected language.
Guidance for managing storage is available in the help pages of common browsers, including Chrome, Firefox, Safari, and Edge.
9. Changes to this policy
We may update this Cookie Policy to reflect changes to the platform, to the technologies we use, or to applicable law. When we make a material change — in particular, if we ever introduce any storage that is not strictly necessary — we will update the effective date at the top of this policy and, where the law requires it, seek your consent before that storage is set. We encourage you to review this policy periodically.
Contact
If you have questions about this Cookie Policy or about how Coded handles personal data, contact us:
- Email: privacy@coded.eu
- Legal / data protection: legal@coded.eu
- Postal: Coded B.V., De Taling 15, 2761 SL Zevenhuizen, The Netherlands
Coded B.V. is registered with the Netherlands Chamber of Commerce (KvK) under number 42027097, VAT number NL869368795B01. This policy takes effect on 11 June 2026.
This Cookie Policy is governed by the laws of the Netherlands, and disputes are subject to the competent courts of Amsterdam, without prejudice to any mandatory consumer or data protection law of your country or region of residence that also applies to you.
<!-- OPEN ITEMS FOR COUNSEL: 1. Confirm contact domain: coded.eu (legal/privacy) · coded.co (ops) for privacy@/legal@ addresses. 2. Fill placeholders: 42027097, NL869368795B01, De Taling 15, 2761 SL Zevenhuizen, The Netherlands, 11 June 2026, and the "Last updated" date. 3. Verify the §3 tables against actual implementation — confirm exact cookie/storage names, mechanism (HTTP cookie vs localStorage/sessionStorage), domains, first/third-party status, and real lifetimes. Replace "typical" lifetimes with concrete values or commit to keeping the table current. 4. Confirm the cookieless analytics claim is technically accurate (no persistent device identifier set; nothing written to the device for identification) before publishing it as fact; align wording with the actual analytics implementation. 5. Validate the no-consent-banner legal conclusion under Dutch Telecommunications Act art. 11.7a (ePrivacy art. 5(3)) and confirm it holds in the other launch jurisdictions; reassess the "load balancing / routing" cookie's strictly-necessary classification. 6. Confirm whether Coded sets any consent/preference record cookie in practice (§3.1 last row) — remove if not used. 7. Merchant storefronts (§5): confirm the platform actually permits merchant-added third-party tags and that the controller/processor allocation matches the DPA and merchant terms; align responsibility wording. 8. Payments (§6): confirm Stripe and Mollie cookie behaviour during checkout and that the "strictly necessary, provider-controlled" framing is accurate; ensure provider notices are linked from the Privacy Policy. 9. EU/Frankfurt hosting statement (§7): confirm accuracy and the international-transfer safeguards referenced in the Privacy Policy (e.g. SCCs) actually exist. 10. Confirm consistency with the Privacy Policy on rights, transfers, retention, and the "no selling/sharing for cross-context behavioural advertising" representation (US CCPA/CPRA wording). 11. Confirm no certifications (SOC 2 / ISO 27001 / PCI-DSS level) are implied anywhere; none are claimed in this draft — keep it that way. -->