Skip to content
Last updated: September 18, 2026

Privacy Policy

How Coodes collects, uses, shares and protects personal data, and the rights you have under GDPR, CCPA/CPRA and Egyptian Law No. 151 of 2020.

13 min read ·

Contents

This Privacy Policy explains how Coodes collects, uses, shares, stores and protects personal data when you visit coodes.org, buy our premium Web2 and Web3 website and mobile app themes, subscribe to our newsletter, contact us or engage us for custom development services. It also explains the rights you have over your personal data and how to exercise them. Effective date and last updated: September 18, 2026.

1. Who We Are and Scope of This Policy

Coodes ("Coodes", "we", "us" or "our") operates the website coodes.org (the "Site"), a digital marketplace offering downloadable themes and templates (including Next.js website templates, Solidity smart contract templates and Flutter mobile app templates) under Regular and Extended licenses, together with custom development services such as custom theme development, Web3 and smart contract integration, Flutter mobile app development, theme customization and installation, and performance, SEO and maintenance work (together, the "Services").

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, the Egyptian Personal Data Protection Law No. 151 of 2020 and similar laws, Coodes is the controller of the personal data described in this policy. You can reach us at:

This policy applies to personal data we process through the Site, through purchases and downloads, through our communications with you and in the course of delivering custom development projects. It does not apply to websites, applications or smart contracts that you build or deploy using our products; if you operate such a product, you are the controller of the data it processes and are responsible for your own privacy notices.

This policy should be read together with our Terms of Service, our Cookie Policy and our License Terms.

2. Personal Data We Collect

The categories we process depend on how you interact with us.

2.1 Data you provide directly

  • Contact form data: your name, email address, the subject of your enquiry and the content of your message, plus anything else you choose to include (for example, project details, links or attachments shared by email).
  • Newsletter data: your email address and a record of your subscription consent (date, time and the form used).
  • Purchase and billing data: your name, email address, billing country and, where required for tax purposes, billing address or tax identification details, the items purchased, license type, price, currency and order reference.
  • Custom services data: business contact details, project briefs, specifications, credentials or access you grant us to your hosting, repositories or staging environments, milestone approvals, invoices and correspondence.
  • Support data: the content of support requests, the item and license concerned, screenshots, logs and other technical information you send us.

2.2 Data collected automatically

  • Technical and log data: IP address, browser type and version, operating system, referring page, pages requested, date and time of requests and error logs generated by our hosting infrastructure for security and reliability purposes.
  • Local storage preferences: your theme preference (dark or light), your wishlist and your cookie consent choice, stored in your browser's localStorage. These are strictly necessary for the features you request and are described in our Cookie Policy.
  • Optional analytics data: only if you give consent, aggregated or pseudonymous usage information such as pages visited, approximate location derived from IP address, device type and session duration.

2.3 Payment and blockchain data

Card and other payment transactions are handled by third-party payment processors. Coodes does not receive or store your full card number or security code. We receive limited information from the processor, such as a transaction identifier, payment status, the last digits of the card, card brand, and the amount and currency. If you pay with cryptocurrency through a third-party gateway, we may receive your wallet address, the transaction hash, the network used and the amount transferred.

3. Sources of Personal Data

We obtain personal data from the following sources:

  • Directly from you when you fill in forms, purchase products, request support, subscribe to the newsletter or communicate with us.
  • From your device and browser when you use the Site, through server logs and localStorage, and through analytics tools if you have consented.
  • From payment processors and crypto payment gateways, which confirm the outcome of transactions and may share fraud-screening signals.
  • From public blockchains, where transaction data related to a crypto payment or a smart contract deployment we carry out for you is publicly visible.
  • From your organization or representatives, when a colleague or agency engages us on your behalf for a custom project.

Under Article 6 of the GDPR and the UK GDPR, we must have a legal basis for each processing activity. The table below summarizes our purposes and the legal bases we rely on.

PurposeData usedLegal basis (GDPR Art. 6)
Processing orders, delivering downloads and issuing licensesPurchase, billing and payment dataPerformance of a contract (Art. 6(1)(b))
Providing included and extended product supportSupport data, purchase dataPerformance of a contract (Art. 6(1)(b))
Quoting, delivering and invoicing custom development servicesCustom services data, contact detailsSteps prior to entering a contract and performance of a contract (Art. 6(1)(b))
Responding to contact form enquiriesContact form dataLegitimate interests in answering enquiries (Art. 6(1)(f)), or pre-contractual steps where you ask about a purchase or project
Sending the newsletterEmail address, consent recordConsent (Art. 6(1)(a))
Remembering theme, wishlist and consent choiceslocalStorage valuesLegitimate interests in providing requested functionality (Art. 6(1)(f)); strictly necessary storage
Optional analyticsUsage and device dataConsent (Art. 6(1)(a))
Security, fraud prevention and abuse detectionTechnical and log data, payment signalsLegitimate interests (Art. 6(1)(f))
Accounting, tax and record-keepingPurchase, billing and invoice dataLegal obligation (Art. 6(1)(c))
Handling refunds, chargebacks and legal claimsPurchase, payment and correspondence dataPerformance of a contract, legal obligation and legitimate interests in defending claims

Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Data Retention

We keep personal data only for as long as necessary for the purposes described above, and then delete or anonymize it. Typical retention periods are shown below. Longer periods may apply where required by law or where data is needed to establish, exercise or defend legal claims.

CategoryRetention period
Contact form enquiries (no resulting contract)Up to 24 months from the last communication
Newsletter subscriptionUntil you unsubscribe; a suppression record of your email may be kept to honor the opt-out
Orders, invoices and license recordsFor the life of the license and as required by applicable tax and accounting laws (generally up to 10 years)
Support tickets and correspondenceUp to 36 months after the ticket is closed
Custom project files and communicationsFor the duration of the project plus up to 5 years for warranty, dispute and record-keeping purposes
Access credentials provided for projectsDeleted or revoked promptly after project completion; we ask you to rotate them
Server and security logsTypically up to 90 days, longer if needed to investigate an incident
localStorage preferencesStored on your device until you clear them (see the Cookie Policy)
Optional analytics dataNo longer than 14 months, or as configured in a shorter period

6. Sharing and Processors

We do not sell your personal data. We share personal data only with the categories of recipients below, and only to the extent needed:

  • Hosting and infrastructure providers that host the Site, file downloads and backups.
  • Payment processors and crypto payment gateways that process transactions, detect fraud and handle refunds and chargebacks. These providers often act as independent controllers under their own privacy terms.
  • Email and newsletter service providers that deliver transactional emails and, with your consent, newsletters.
  • Analytics providers, only if you have consented to analytics.
  • Support, communication and project management tools used to manage tickets and custom projects.
  • Professional advisers, such as accountants, auditors and lawyers, under duties of confidentiality.
  • Public authorities, courts or regulators where required by law or to protect our rights, users or the public.
  • A successor entity in the event of a merger, acquisition or sale of all or part of our business, subject to this policy's protections.

Service providers that act as our processors are bound by written agreements requiring them to process personal data only on our instructions, to keep it confidential and to implement appropriate security measures.

7. International Data Transfers

Coodes is based in Egypt, and some of our service providers may be located in other countries. As a result, your personal data may be transferred to, and processed in, countries outside your own, including countries that may not offer the same level of data protection as the European Economic Area (EEA), the United Kingdom or Egypt.

Where we transfer personal data from the EEA or the UK to a country that has not been recognized as providing adequate protection, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum, together with supplementary measures where appropriate. For transfers out of Egypt, we comply with the transfer requirements of Law No. 151 of 2020 and its executive regulations as applicable. You may request further information about these safeguards by contacting us.

8. How We Protect Your Data

We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These include encryption in transit (HTTPS), access controls based on least privilege, secure credential handling for client projects, regular updates and dependency reviews, and backups.

No method of transmission or storage is completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable law.

Note: Please never send us private keys, seed phrases or wallet recovery phrases. Coodes will never ask for them, including during smart contract deployment or Web3 integration work. Where a project requires deployment, we will agree a secure process in which you retain control of your keys.

9. Your Rights Under the GDPR and UK GDPR

If you are in the EEA or the UK, you have the following rights, subject to legal conditions and exceptions:

  • Access: obtain confirmation of whether we process your data and receive a copy of it.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: ask us to delete your data in certain circumstances.
  • Restriction: ask us to limit processing, for example while accuracy is being verified.
  • Portability: receive data you provided in a structured, commonly used, machine-readable format where processing is based on consent or contract and is automated.
  • Objection: object to processing based on legitimate interests, and object at any time to direct marketing.
  • Withdraw consent: at any time, for newsletter or analytics processing.
  • Complaint: lodge a complaint with the supervisory authority in your country of residence, place of work or place of the alleged infringement, or with the UK Information Commissioner's Office if you are in the UK.

To exercise your rights, email [email protected] or use our contact page. We may need to verify your identity before acting on a request. We will respond within one month, which may be extended by up to two further months for complex or numerous requests, in which case we will inform you. Exercising your rights is generally free of charge.

10. Additional Information for California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) may give you additional rights, to the extent the law applies to Coodes:

  • Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of third parties with whom we share it.
  • Right to delete personal information we collected from you, subject to exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information for cross-context behavioral advertising.
  • Right to limit the use of sensitive personal information, where applicable.
  • Right to non-discrimination for exercising your rights.

Do not sell or share: Coodes does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined in the CCPA/CPRA. We have not done so in the preceding 12 months. We also honor Global Privacy Control (GPC) signals as a valid opt-out request, as described in our Cookie Policy. The categories we collect are identifiers, commercial information, internet activity information and, for custom projects, professional information.

You or an authorized agent may submit a request by emailing [email protected]. We will verify requests by matching information you provide against our records.

11. Information for Individuals Under Egyptian Law

Coodes is located in Cairo, Egypt, and processes personal data in accordance with the Egyptian Personal Data Protection Law No. 151 of 2020 and, once in force and applicable, its executive regulations. Under that law, data subjects generally have rights to know about, access and obtain their personal data held by a controller; to withdraw prior consent; to request correction, amendment, erasure or restriction of processing; to be informed of any breach affecting their personal data; and to object to processing that conflicts with their fundamental rights and freedoms.

We process personal data for specified and legitimate purposes, keep it accurate and no longer than necessary, and apply appropriate security measures. You may exercise your rights under Egyptian law by contacting us using the details in this policy. You may also have the right to file a complaint with the competent Egyptian data protection authority.

12. Blockchain and Web3 Data

Some of our products and services involve public blockchains, for example when you pay with cryptocurrency or when we deploy or integrate a smart contract as part of a custom project. Please be aware of the following:

  • Transactions recorded on public blockchains, including wallet addresses, transaction hashes, amounts, timestamps and smart contract interactions, are publicly visible and are replicated across a decentralized network that Coodes does not control.
  • Public on-chain data cannot be altered or erased, by us or by anyone else. As a result, rights such as erasure and rectification cannot be exercised with respect to data recorded on a blockchain. We can, however, delete or restrict copies of such data held in our own off-chain systems, such as order records linking a wallet address to your name, subject to our legal retention obligations.
  • A wallet address may become personal data if it can be linked to you.

Coodes does not custody your digital assets and does not hold your private keys.

13. Children's Privacy

Our Services are intended for businesses, developers and adults. They are not directed to children under 16 years of age (or a higher age where required by local law), and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

14. Automated Decision-Making and Marketing

Coodes does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Our payment processors may use automated fraud-screening tools as part of their own services; if a payment is declined, you may contact us and we will help you raise the issue with the processor or find an alternative payment method.

We send marketing emails only to newsletter subscribers who have consented. Each newsletter contains an unsubscribe link, and you can also unsubscribe by emailing us. Transactional emails about purchases and support will still be sent.

15. Changes, Contact and Complaints

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements or practices. The "last updated" date at the top of this page indicates when it was last revised. If we make material changes, we will provide notice on the Site and, where appropriate, by email before the changes take effect.

If you have questions, requests or complaints about how we handle your personal data, please contact us first so we can try to resolve the matter:

If you are not satisfied with our response, you have the right to complain to the competent data protection supervisory authority in your jurisdiction. See also our FAQs.

Questions about this policy?

Contact us at [email protected] — we reply within 24 hours on business days.

Contact us