Who we are
Coding with T Ltd (“we”, “us”) is the data controller for the personal data described here. We are registered in England & Wales, with our registered office at 61 Bridge Street, Kington, HR5 3DJ, United Kingdom. You can reach us at [email protected].
This policy covers codingwitht.com. It does not cover third-party sites we link to, such as YouTube or WhatsApp, which have their own policies.
What we collect, and why
When you send an enquiry or use the estimate planner
Our contact form, estimate planner and lead-magnet forms all submit to the same endpoint, which stores the submission in our database and emails it to us. Depending on which form you use, that record can include:
- Your name, email address and phone or other contact detail — so we can reply to you.
- Your country — for timezone and currency context.
- Project details you choose to give us — enquiry type, your message, the kind of app you want, industry, platforms, features, expected scale, design needs and timeline.
- The estimated price range the planner produced for you, and the currency it was shown in.
- Your browser's user-agent string and the full raw form submission — kept for spam filtering and to diagnose broken submissions.
Lawful basis: our legitimate interest in responding to people who ask us to get in touch, and in keeping our forms free of spam. If the enquiry leads to a project, we then rely on taking steps at your request before entering a contract.
When you buy source code
Payment is taken by Stripe on Stripe's own hosted checkout page. We want to be explicit about what that means: your card number never reaches this website and we never see or store it . What we do record against your order is:
- Your name and email address, as given to Stripe at checkout.
- The Stripe checkout session and payment identifiers, so we can match a payment to an order and handle any dispute.
- The amount paid, the currency, the order status, the products purchased and the time of purchase.
Lawful basis: performance of our contract with you — we cannot deliver a purchase or honour a licence without it. We also keep transaction records to meet our legal accounting obligations.
When we deliver your download
Products are delivered as a link to a file hosted on Google Drive. If you request access to that file, Google shows us the email address of the Google account making the request so we can check it against your purchase and approve it. If that address differs from the one you paid with, we may ask you to confirm which order it belongs to.
When you simply browse the site
Our shop keeps your basket in your own browser's local storage (under the key cwt-cart). It stays on your device, is never transmitted to us
as a profile, and is cleared once an order completes. Our hosting provider
processes technical data such as IP address and user agent to serve pages
and block abuse. We also use privacy-friendly, aggregate site analytics —
see our Cookie Policy for the detail.
Who else processes your data
We keep this list short on purpose. These are the only third parties that receive personal data through this site, and each acts as our processor or as an independent controller for their own service:
| Provider | What they do | What they receive |
|---|---|---|
| Cloudflare | Website hosting, CDN, security, aggregate analytics | Technical request data such as IP address and user agent |
| Supabase | The database storing enquiries and orders | Everything described in the two sections above |
| Stripe | Payment processing | Your name, email, payment details and billing country |
| Brevo / Resend | Sending enquiry alerts and order emails | Your name, email and the content of the message |
| Web fonts, product file delivery via Drive, and site analytics if enabled | Your IP address when fonts load; your Google account email if you request file access |
We do not sell your personal data, and we do not share it with advertisers or data brokers.
International transfers
Some of these providers operate outside the UK, including in the United States. Where your data is transferred outside the UK, we rely on the provider's safeguards for such transfers — typically the UK International Data Transfer Addendum or Standard Contractual Clauses, together with the relevant adequacy regulations. You can ask us which safeguard applies to a specific provider.
How long we keep it
| Record | Retention |
|---|---|
| Enquiries that do not become a project | 24 months from your last contact with us, then deleted |
| Enquiries that become a project | 6 years after the project ends, to cover contractual claims |
| Orders and transaction records | 6 years from the end of the relevant financial year, as UK tax law requires |
| Order emails and support correspondence | 24 months, unless it relates to an ongoing matter |
You can ask us to delete your data sooner — see below. We may need to keep the minimum required for accounting and for defending legal claims.
Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted where we have no overriding reason to keep it.
- Restriction and objection — ask us to pause processing, or object to processing we base on legitimate interests.
- Portability — receive data you gave us in a machine-readable form.
- Withdraw consent — at any time, where we relied on your consent. This does not affect processing carried out before you withdrew it.
Email [email protected] to exercise any of these. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk, or call their helpline on 0303 123 1113. We would appreciate the chance to resolve it with you first.
Security
The site is served over HTTPS. Enquiry and order data is held in an access-controlled database with row-level security, and the credentials that can write to it are held server-side only and never exposed in the browser. Payment card data is handled entirely by Stripe, a PCI-DSS Level 1 service provider. No system is perfectly secure, but we do not collect more than we need, which is the most effective protection available.
Children
This site is aimed at businesses and developers. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change how we handle personal data we will update this page and move the “last updated” date at the top. Significant changes affecting existing customers will be notified by email where we hold an address for you.
Contact
Questions about this policy? Email [email protected], or write to Coding with T Ltd, 61 Bridge Street, Kington, HR5 3DJ, United Kingdom.