How Codidge collects, uses, shares and protects personal information across the Codidge platform, the Codidge mobile application, and the websites we build and host for our clients.
This policy explains how Codidge Technology Studio handles personal information in connection with the Codidge platform at admin.codidge.com, the Codidge mobile application, this website, and the client websites and storefronts we operate on behalf of subscribing organizations.
As a controller
We act as a controller for information about the people we deal with directly: the users of our platform (owners, administrators, managers, operators), the people who contact us through this website, and visitors to codidge.com. We decide why and how that information is processed.
As a processor
We act as a processor for the business records an organization puts into the platform — including records about that organization's own customers, bookings, orders and enquiries. There the organization is the controller: it decides what to collect and why, and we process it on its instructions. If you are a customer of a business that uses Codidge, contact that business first; we will route requests we receive to them.
2. Information we collect
Account and profile information
Name, work email address and phone number.
The organizations and locations you belong to, your role, and your permissions.
Language preference and interface settings.
Authentication data held in Amazon Cognito — password hashes (never the password itself), sign-in timestamps, and multi-factor details where enabled.
Your record of accepting these documents: the version accepted and the date and time.
Organization and business information
Business name, branding, addresses, opening hours, contact details and tax configuration.
Catalogue data: products, services, variants, prices, availability and media.
Operational records: orders, bookings, rentals, quotes, invoices and fulfilment status.
Website and channel content the organization creates or generates.
Records about an organization's customers
Organizations use the platform to keep customer records — typically name, email, phone, addresses, order and booking history, and notes. This information is entered or collected by the organization, and we process it only for that organization.
Usage, device and log data
IP address, browser or device type, operating system, and app version.
Pages and modules visited, actions taken, and timestamps.
Error reports and diagnostic logs.
Push notification tokens registered by the mobile app, tied to your membership of an organization.
Communications and support
Messages you send us, support requests, feedback, and any files or screenshots you attach.
Payment information
Subscription payments are handled by Stripe. We receive the subscription status, plan, billing contact and the last digits and brand of the card. We do not receive or store full card numbers.
What we do not want
Please do not put government identifiers, health records, biometric data or full payment card numbers into free-text fields. The platform is not designed to hold them.
3. How we use information
Purpose
Examples
Provide the service
Authenticate you, load your organizations and locations, run the modules your plan includes, publish your channels.
Operate and secure the platform
Detect abuse and fraud, enforce rate limits and permissions, investigate incidents, keep backups.
Communicate
Service notices, security alerts, invitation and password emails, push notifications about your work, and responses to your support requests.
Billing
Manage subscriptions, credits and invoices through our payment provider.
AI features
Send your prompt and the context you select to a model provider so it can generate the draft you asked for.
Improve the product
Understand which features are used, diagnose errors, and plan work — using aggregated or de-identified data wherever it will do.
Comply with law
Meet tax, accounting and record-keeping duties, and respond to lawful requests.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the platform to you and your organization); legitimate interests (securing the service, preventing abuse, improving the product, direct business communications); legal obligation (tax and accounting records, lawful requests); and consent, where we ask for it — for example push notifications, or access to your device's photos or contacts.
You can withdraw consent at any time; doing so does not affect processing already carried out.
5. AI processing
When you use an AI feature — website generation, social content, printable assets, image generation or text assistance — the prompt and the context you selected are sent to a third-party model provider (currently OpenAI and Anthropic) to produce the result. That may include your organization's AI profile, catalogue entries, or an image you chose.
We use these providers under business terms that prohibit training their public models on our API content. Even so, treat AI features as you would any external service: do not paste confidential or personal data into a prompt unless it is necessary for the result you want.
6. Who we share information with
Recipient
Why
Your organization
Administrators can see your profile, role, permissions and the activity carried out under your account.
Amazon Web Services
Hosting, database, storage, content delivery, authentication and email delivery. Primary region: United States.
Stripe
Subscription billing and payment processing.
OpenAI, Anthropic
Processing prompts submitted through AI features.
Expo, Apple (APNs), Google (FCM)
Delivering push notifications to the mobile app.
Integrations you connect
Only the data the integration needs, and only once your organization authorizes it.
Professional advisers, authorities
Where required by law, to establish or defend legal claims, or to protect the rights and safety of users.
A successor entity
In a merger, acquisition or asset sale, subject to this policy.
7. The mobile application
The Codidge mobile app asks for permissions only when a feature needs them, and each one can be refused or revoked in your device settings:
Notifications — to deliver alerts about orders, bookings and other work assigned to you. Requested after you sign in, never on the sign-in screen.
Photos — to attach images when you submit feedback or upload media to your catalogue.
Contacts — only if you choose to import or export CRM records. Contacts are uploaded to your account only with your explicit confirmation.
Refusing a permission disables the feature that needs it; the rest of the app keeps working.
8. Cookies and similar technologies
The platform uses cookies and local browser storage that are strictly necessary: keeping you signed in, remembering your active organization and location, and storing your language and interface preferences. Blocking them will break sign-in.
Client websites we build may use additional cookies — analytics or marketing — chosen by the organization that owns the site. Those sites carry their own notices.
9. How long we keep information
Account and profile data — for as long as your account is active, then deleted or anonymized after the account is closed.
Organization data — for as long as the organization subscribes, plus a limited export window after termination.
Logs and diagnostics — typically a rolling period measured in months.
Billing and tax records — for the period required by law, usually several years.
Backups — deleted on their own rotation schedule after the live record is removed.
10. Security
We encrypt data in transit with TLS and at rest in our cloud storage. Access is controlled by role and permission, authentication runs on Amazon Cognito, and administrative access to production systems is limited to the people who need it. Every request is scoped to the organization and location it belongs to.
No system is completely secure. Use a strong, unique password, keep it to yourself, and tell us at info@codidge.com if you suspect unauthorized access.
11. International transfers
Our infrastructure is hosted in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your information will be transferred outside your country. Where required, we rely on the European Commission's Standard Contractual Clauses and equivalent safeguards with our providers.
12. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to object to or restrict processing, to receive it in a portable format, and to withdraw consent. Residents of California may additionally request disclosure of the categories collected and shared, and may not be discriminated against for exercising a right.
To exercise a right over your own platform account, email info@codidge.com from your account address, or use the account deletion option in your profile in the platform or the mobile app. We respond within the time the applicable law allows.
If your request concerns records held by a business that uses Codidge — for example an order or booking you placed with them — contact that business. We will forward requests we receive to the relevant organization and assist them in responding.
If you are in the EEA or UK you may also complain to your local supervisory authority.
13. Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, write to info@codidge.com and we will delete it.
14. Changes to this policy
We may update this policy. The version and date at the top of the page identify the current text. Material changes are announced to organization administrators by email or in the platform before they take effect.
15. Contact
Privacy questions and requests: info@codidge.com — Codidge Technology Studio, Miami, Florida, United States.