Privacy
Privacy policy
Last updated: 18 August 2026
Information collected
CodeKits.shop collects information you provide for purchases, service inquiries and optional email subscriptions. A subscription records the email address, consent version and subscription time. A subscription notice is sent to the site administrator at [email protected]. Purchase records include the checkout email, product, price, Stripe order identifiers, accepted terms version and delivery status. A download request records its time, usage count and a broad regional aggregate for fulfilment statistics. When a public page is viewed, a restricted traffic-security record may include the page path, IP address, browser and device header, approximate country code, referring site, language header, request identifier and time of access. Private file-sharing transfers also create a restricted security record used to protect the link and diagnose transfer problems.
Why it is used
Subscription information is used to send the product and service updates you requested, maintain evidence of consent, prevent abuse and diagnose delivery or security problems. Subscription is optional and is not required to browse or purchase. Purchase information is used to verify payment, issue receipts, deliver the licensed product, provide support, enforce download and licence limits, handle disputes and meet accounting or legal duties. Private file-transfer audit information is used to confirm delivery, investigate unauthorised access, diagnose failed transfers and protect time-limited customer files from abuse. Traffic-security information is used to understand site activity, distinguish repeat traffic, diagnose technical problems and identify suspicious or abusive requests. It is not used for advertising or sold to third parties.
How it is protected
Sensitive subscription, purchase, download-customer, private file-transfer, traffic-security and service inquiry fields are encrypted in the application before MySQL storage using authenticated AES-256-GCM encryption. Purpose-separated keyed hashes and pseudonyms are used where records need to be associated without exposing readable identifiers. Raw payment-card details are handled by Stripe and are not stored in the CodeKits.shop database. Secure transport, restricted server access and protected environment secrets are also required in production. The normal subscriber dashboard shows a pseudonymous record fingerprint rather than the readable email address. Active addresses are decrypted by the protected server mailing process only when preparing consented email delivery through the configured provider.
Email consent and withdrawal
Marketing email is sent only after an affirmative opt-in. Every new subscriber receives a private unsubscribe link. Unsubscribing changes the record to a suppressed status so further marketing is not sent accidentally. You can also request access, correction or deletion by emailing [email protected].
Retention and sharing
Subscription records are retained while the subscription is active and a limited suppression record may be kept after withdrawal to honour the opt-out. Information is shared only with providers needed to operate the website, payments, database hosting and email delivery, or where disclosure is legally required. Purchase and consent records are retained only for the period needed for fulfilment, licence evidence, support, disputes and applicable accounting or legal obligations, then deleted or anonymised under a documented retention process. Detailed traffic-security records are automatically deleted after 30 days; aggregate page totals may be retained without the readable IP address or browser/device header.
Contact
Privacy questions and data requests can be sent to [email protected].
