Privacy Policy
Your privacy is fundamental to how we engineer trust. At The CodeRocket, we build with transparency, security, and respect for your data.
Privacy Built Into Engineering
Privacy at The CodeRocket isn't a policy bolted on after launch. It's a requirement in every architecture review, every pull request, and every production deployment.
Architecture
Data minimization and privacy-by-design reviewed at every system design stage.
Infrastructure
Segmented, hardened cloud environments with isolated production data stores.
Backend & Frontend
Encryption enforced end-to-end across services, APIs, and client applications.
Secure SDLC
Threat modeling, code review, and dependency scanning gate every release.
CI/CD
Automated security and privacy checks run on every build before deployment.
Monitoring
24/7 observability with automated anomaly detection across production systems.
Access Control
Least-privilege permissions with role-based access and full audit logging.
Encryption
AES-256 at rest and TLS 1.3 in transit, applied uniformly across all data stores.
Incident Response
Documented playbooks, defined SLAs, and rehearsed escalation paths.
Production Operations
Change management and rollback procedures protect data integrity in production.
Business Continuity
Disaster recovery and backup strategies validated on a recurring schedule.
Continuous Testing
Ongoing vulnerability management and penetration testing across the stack.
The CodeRocket (“we,” “our,” or “us”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our engineering platform, website, and related services (collectively, the “Services”).
We believe that privacy is not just a legal obligation but a fundamental engineering principle. Just as we build reliable, scalable systems, we build trust through transparent data practices. This policy applies to all users of The CodeRocket platform, including enterprise customers, individual developers, and visitors to our website.
We collect only the data necessary to deliver and improve our Services. Our engineering-first approach means we minimize data collection by default and apply strict access controls.
- Account Information: Name, email address, company name, job title, and authentication credentials.
- Usage Data: Telemetry, performance metrics, feature interactions, and system logs — all anonymized where possible.
- Billing Information: Payment details processed through our PCI-compliant payment processors (we never store full payment data).
- Communications: Support tickets, feedback, and correspondence with our team.
- Device & Browser Data: IP address, user agent, browser type, and operating system for security and analytics.
We do not collect sensitive personal data (e.g., health, racial, or biometric information) unless explicitly provided by you for a specific purpose with your consent.
We process your data to deliver, improve, and secure our Services. Every use case is evaluated against our privacy-first engineering principles.
- Service Delivery: To provide and maintain the platform, authenticate users, and process transactions.
- Improvement: To analyze usage patterns, fix bugs, and enhance performance and features.
- Security: To detect, prevent, and respond to security incidents, fraud, and abuse.
- Communication: To send service updates, security alerts, and respond to support requests.
- Compliance: To meet legal obligations and enforce our terms of service.
We never sell your personal data to third parties. We never use your data for advertising or marketing without your explicit consent.
We process your personal data under the following lawful bases, in compliance with the GDPR and applicable privacy regulations:
- Contractual Necessity: To perform our contract with you and deliver the Services you request.
- Legitimate Interests: To improve our Services, ensure security, and prevent fraud — always balanced against your rights.
- Legal Obligation: To comply with applicable laws, regulations, and court orders.
- Consent: For optional processing activities where you have given clear, affirmative consent.
You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
We use cookies and similar tracking technologies to enhance your experience, analyze usage, and secure our platform. We are transparent about our use of cookies and give you control over them.
- Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
- Preference Cookies: Remember your settings and preferences (e.g., dark mode, language).
- Analytics Cookies: Help us understand how you use our platform to improve performance.
You can manage your cookie preferences at any time. We do not use cookies for advertising or cross-site tracking.
We use privacy-preserving analytics to understand how our platform is used and to identify areas for improvement. All analytics data is aggregated and anonymized where possible.
- We use Plausible and PostHog for product analytics — both are GDPR-compliant and privacy-first.
- We do not use Google Analytics or other tracking tools that rely on cross-site tracking.
- IP addresses are anonymized before storage, and we do not create persistent user profiles.
You can opt out of analytics collection via your account settings at any time.
We partner with trusted third-party service providers to deliver our Services. All partners are vetted for security, privacy, and compliance.
- Infrastructure: AWS (Amazon Web Services) — all data is stored in secure, encrypted data centers.
- Payments: Stripe — PCI Level 1 certified, no payment data stored on our servers.
- Support: Zendesk — for managing support tickets and communications.
- Email: SendGrid — for transactional email and service notifications.
We require all third-party processors to comply with applicable data protection laws and to implement appropriate technical and organizational measures. We conduct regular audits to ensure ongoing compliance.
Security is embedded in our engineering culture. We implement industry-leading measures to protect your data against unauthorized access, alteration, disclosure, or destruction.
We are ISO 27001 certified and undergo annual SOC 2 Type II audits. Our security team works around the clock to ensure the integrity and confidentiality of your data.
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law.
- Account Data: Retained while your account is active and for a limited period thereafter for legal and security purposes.
- Usage Data: Aggregated and anonymized for analytics; raw logs are retained for up to 90 days.
- Support Data: Retained for the duration of your relationship with us and for a reasonable period after.
- Billing Data: Retained as required for tax and accounting purposes (typically 7 years).
When data is no longer needed, we securely delete or anonymize it. You may request deletion of your personal data at any time (subject to legal obligations).
The CodeRocket is a global company with engineering teams and infrastructure in multiple regions. We transfer data in accordance with applicable data protection laws.
- Data is stored in AWS data centers located in the US, EU, and APAC regions.
- For transfers from the EEA to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
- We implement supplementary measures to ensure an equivalent level of protection.
- All data transfers are subject to our Data Processing Agreement (DPA), which incorporates the SCCs.
If you are located in the EEA, UK, or Switzerland, you have the right to request a copy of the safeguards we use for international transfers.
We respect your privacy rights and make it easy for you to exercise them. Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your data (subject to legal exceptions).
- Restriction: Limit how we process your data.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Withdraw consent at any time.
To exercise your rights, please contact our Privacy Team at privacy@thecoderocket.com. We will respond within 30 days.
The CodeRocket is not intended for children under the age of 16. We do not knowingly collect personal data from children.
If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data promptly. If you believe we have collected data from a child, please contact us at privacy@thecoderocket.com.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of significant changes via email or through a prominent notice on our platform.
The “Last Updated” date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically to stay informed about how we protect your privacy.
If we make material changes that affect your rights, we will seek your consent where required by applicable law.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to our dedicated Privacy Team. We take every inquiry seriously and will respond promptly.
Frequently Asked Questions
You can request data deletion by emailing privacy@thecoderocket.com with the subject line "Data Deletion Request." We will verify your identity and process your request within 30 days. In some cases, we may need to retain certain data for legal or security purposes.
We respond to all privacy requests within 30 calendar days of verification. If we need more time due to complexity, we will notify you and provide an estimated timeline.
No. We never sell your personal data to advertising partners. We do not use your data for ad targeting or any marketing purposes without your explicit consent. Our business model is based on delivering exceptional engineering tools, not on monetizing user data.
Yes. All data is encrypted at rest using AES-256 and in transit using TLS 1.3. We use industry-standard encryption protocols and regularly rotate keys to maintain the highest level of security.