CodeStellar Privacy Policy
Effective date: 3 October 2026.
This Privacy Policy explains how Code Stellar LLC, doing business as CodeStellar, a Wyoming limited liability company ("CodeStellar," "we," "us," or "our"), handles personal information in connection with our company website at codestellar.co and our business inquiries and client relationships. Contact us at info@codestellar.co.
1. Scope and our role
This policy covers our corporate website and the information we handle for our own business purposes, such as responding to inquiries, managing projects and protecting our services. For those activities, we determine the purposes and means of processing and act as the controller where that term applies.
Our mobile apps have their own privacy policies, and individual SaaS products may also have separate policies. The policy presented in the relevant product governs that product's data practices; this website policy does not replace it. If we process personal information solely on a business client's documented instructions, the client controls that processing and the applicable services agreement and data processing agreement govern our role. Contact that client first about information it controls; we will assist as required by our agreement and applicable law.
2. Information we receive
- Information you provide: your name, email address, company, role, contact details, project requirements, attachments and the contents of messages you choose to send. Please provide only what is needed for the inquiry.
- Business relationship information: proposals, contracts, approvals, project correspondence, billing contacts, invoice and payment-status records, and information needed to deliver agreed services. Do not send full payment-card numbers, passwords, private keys or identity documents through ordinary email or a website inquiry.
- Technical information: when you access the website, the infrastructure serving and protecting it may process your IP address, browser and device information, requested URLs, referring page, request time, response status and security-related events. This supports delivery, troubleshooting and abuse prevention.
- Information from others: a colleague, business partner or referring contact may provide professional contact details and project context. We use this information to address the relevant business request, rather than treating a referral as permission for unrelated marketing.
Providing inquiry information is voluntary. Without the details needed to understand or respond to a request, we may be unable to help or enter into a contract. We do not need sensitive personal information to assess an ordinary project inquiry; please do not include it.
3. Purposes and legal bases
We use personal information for the following purposes. Where European or UK data protection law applies, the corresponding legal bases are:
- Responding to a request and preparing an engagement: taking steps at your request before entering a contract, or our legitimate interest in communicating with business representatives where the contracting party is a company.
- Delivering and administering services: performance of a contract with you, or our legitimate interest in fulfilling business-client engagements and maintaining professional relationships.
- Operating and protecting the website: our legitimate interests in reliable delivery, troubleshooting, preventing fraud and abuse, and protecting systems, subject to your rights and reasonable expectations.
- Accounting, compliance and disputes: compliance with applicable legal obligations and, where appropriate, our legitimate interests in maintaining necessary business records and establishing, exercising or defending legal claims.
- Business follow-up: responding to the project or business matter you raise, based on the applicable basis above. Submitting an inquiry does not subscribe you to a marketing mailing list. If we later offer optional marketing, we will provide the required notice and obtain consent where required; you may object to direct marketing at any time.
We do not use the corporate website to make solely automated decisions that produce legal or similarly significant effects about you.
4. Cookies, website tracking and external links
The company website does not use audience analytics, advertising pixels or cross-site behavioral advertising. Its font and images are served with the website. Interactive design demonstrations run locally in your browser and do not submit their selections to us. Infrastructure providers may use strictly necessary security mechanisms, including cookies where needed to protect and deliver the site.
The contact form uses Cloudflare Turnstile to detect automated abuse. The security check loads when you interact with the form and processes technical browser, network and device signals and a verification token. It is used for security, not audience analytics or advertising. See Cloudflare’s Turnstile Privacy Notice for its processing details. You can contact us by email instead of using the form.
If we introduce optional analytics, advertising technology or other non-essential storage, we will update the relevant notices and obtain consent or offer required choices before activating that technology where the law requires it. Offering paid-media services to clients does not mean that this company website itself uses advertising trackers.
External links take you to independently operated websites. Those operators' policies apply when you visit them. We do not control their privacy practices.
5. Who may receive information
We disclose information only as relevant to the purposes described here:
- Service providers and authorized personnel: providers of hosting, delivery and security, business email and communications, and, where used for an engagement, project administration, billing and secure collaboration. Access is limited to what is needed for their work, under the confidentiality and data-protection terms applicable to the service or engagement.
- Professional advisers: legal, accounting, insurance and other advisers where necessary for business administration or a specific matter, subject to applicable confidentiality duties.
- Legal and security needs: when required by law or valid legal process, or when reasonably necessary and lawful to investigate misuse, address a security incident, or protect rights, property or safety. We assess requests and disclose only what is appropriate.
- Business transactions: relevant information may be reviewed or transferred in a merger, acquisition, financing, restructuring, insolvency or sale of all or part of the business, with appropriate safeguards and notices where required. Such a transaction is not permission for incompatible use without a lawful basis.
- At your direction: when you ask or validly authorize us to share information with a particular recipient.
We use Cloudflare to host and protect the company website. Business correspondence addressed to info@codestellar.co is handled through Google/Gmail. These providers process information needed to perform their respective services. An inquiry is used to respond to the relevant request; it is not permission to add you to advertising audiences. When you submit the contact form, Cloudflare processes the request and Resend delivers your email address, selected project category and message to our company mailbox. We use your address as the reply-to address. The form does not subscribe you to marketing, accept attachments or create a customer account. Our form handler does not save submissions in a website database or deliberately write message contents to application logs; email copies and provider delivery records are still processed and retained by the email services.
For the company website, we do not sell personal information or disclose it for cross-context behavioral advertising. This statement concerns the website and business communications covered here, not the separate practices of an app, client or independently operated platform.
6. Client materials and AI-enabled work
A general inquiry is not an instruction to upload your confidential materials or personal information to an AI service. Any use of personal information in client-specific AI integrations, development, analytics or advertising must be addressed in the agreed scope, documented instructions, applicable privacy notices and data-protection arrangements. This policy does not give us unrestricted rights to use client data for model training or unrelated purposes.
Where we act for a client, the relevant agreement should identify the processing purpose, permitted recipients, security requirements, retention and deletion arrangements, and any required international-transfer safeguards. Please arrange a suitable secure channel before providing production datasets or other restricted material.
7. International processing
CodeStellar is based in the United States. Your communications and service-provider processing may take place in the United States and other countries where authorized providers operate. Those countries may have different data-protection laws.
Transfers restricted by applicable law require a valid transfer mechanism and safeguards. Depending on the recipient and circumstances, these may include an applicable adequacy decision or appropriate contractual protections, such as standard contractual clauses. We must establish the applicable safeguards before undertaking a restricted transfer; this policy does not itself create a transfer agreement or establish a provider’s certification. Contact info@codestellar.co to ask about the safeguards relevant to your information and how to obtain a copy, subject to lawful redactions. We do not claim certification under a transfer framework merely by mentioning international processing.
8. Retention
We keep personal information only for as long as reasonably needed for its stated purpose and applicable obligations. The criteria differ by record:
- Inquiry records are retained while addressing the inquiry and any reasonably anticipated follow-up; an ongoing project or dispute may justify retaining relevant correspondence longer.
- Client contracts, approvals and financial records are retained for the relationship and the applicable accounting, tax, contractual and legal-claim periods.
- Resend processes message and delivery records under its service retention settings; its published standard retention for email and log data is 30 days. This does not delete the correspondence already delivered to our Gmail mailbox, which follows the inquiry and business-record criteria above.
- Technical and security records are retained for operational troubleshooting and investigation needs, according to the applicable infrastructure configuration; relevant records may be preserved for a specific incident.
- Information processed for a client follows the agreed return/deletion instructions, subject to legal obligations and defined backup arrangements.
When the relevant need ends, we delete or de-identify information, subject to lawful retention requirements. Backup copies may persist through their normal replacement cycle with restricted use. A legal hold may postpone deletion of the records it covers. You may ask us about the retention criteria applicable to a particular record.
9. Security
We use reasonable technical and organizational safeguards appropriate to the information and risks, including access controls and measures to protect transmission and operation. No website, communication channel or storage system is completely secure. If a personal-data breach requires notification, we will provide the notifications required by applicable law. Please report suspected security problems to info@codestellar.co without including unnecessary sensitive information.
10. Your rights and choices
Depending on where you live and which laws apply, you may have rights to access information, receive a copy, correct inaccuracies, request deletion, restrict processing, receive portable information, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. You may object to direct marketing at any time.
Residents of US states with applicable privacy laws may also have rights to opt out of covered sales, targeted advertising or certain profiling, and to appeal a denied request. The company website does not engage in those covered advertising activities. Where legally required, we honor recognized opt-out preference signals, including Global Privacy Control. We do not use the older browser Do Not Track setting as an independent consent mechanism.
Send requests to info@codestellar.co with the subject "Privacy request." We may request proportionate information to verify your identity and, for an authorized agent, authority to act. Do not send identity documents unless we request a suitable verification method. We respond within the period required by applicable law, explain any permitted extension or refusal, and provide appeal instructions where required. We do not discriminate against you for exercising legally protected rights.
You can complain to the data-protection authority or other regulator with jurisdiction over you. If European or UK law applies, this includes the relevant supervisory authority in your place of residence or work, or where an alleged infringement occurred. You do not have to contact us before using that right. Rights may be subject to lawful exceptions, including necessary recordkeeping, legal claims and the rights of others.
11. Children
The company website and business inquiry process are intended for a general professional audience, not children under 13. We do not knowingly collect children's personal information through this website. If you believe a child has provided it, contact us so we can investigate and take appropriate action. This statement does not replace a separate app's age requirements or children's privacy disclosures.
12. Changes and contact
We will publish the effective date of this policy when the new company website launches. Until activation, this prepared version does not replace any currently effective product-specific policy. For later material changes, we will update that date and provide additional notice or obtain consent where required before a new use begins. A policy update does not retrospectively authorize incompatible processing.
Privacy contact: Code Stellar LLC, Wyoming, United States.
info@codestellar.co
Website and Business Services Terms