Privacy Policy

Last updated: April 2, 2026

1. Introduction

Code Cure Lab ("CCL," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your personal information when you visit our website at codecurelab.com (the "Platform") and use our Services.

By using our Platform, you consent to the data practices described in this policy. If you do not agree with the practices described herein, please do not use the Platform.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: When you register, we collect your name, email address, and password (stored in hashed form). If you sign in via third-party providers (Google, X/Twitter, LinkedIn), we receive your name, email and profile picture from those services.
  • Profile Information: Information you voluntarily add to your profile, such as a bio, avatar image and country.
  • Order and Project Data: Details related to orders you place, including project requirements, files uploaded via project chat, communications with our team and feedback. After a project is completed or cancelled, the Platform may offer you the option to delete associated project data; when you delete content or exercise those options, we remove that data from our systems as described in Section 6.
  • Payment Information: Payment transactions are processed by Paddle.com Market Limited ("Paddle"), our Merchant of Record. We do not directly collect, store, or process your credit card numbers or bank account details. Paddle handles all payment data in accordance with PCI DSS standards. Please refer to Paddle's Privacy Policy for details on how they handle your payment information.
  • Communications: Messages, files and attachments exchanged through order chat, support inquiries and any other direct communications with us. If you delete a chat message or similar content in the Platform, it is removed from our systems; we do not retain a separate copy for ordinary purposes.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the Platform, referral source, and interaction patterns.
  • Device and Browser Information: Browser type and version, operating system, device type, screen resolution and language preferences.
  • IP Address and Location: Your IP address is collected to determine your approximate geographic location (country and city level) for service availability, language preferences, and compliance with geographic restrictions. IP addresses are stored only in hashed (anonymized) form in our database; we do not store raw IP addresses.
  • Cookies: We use essential cookies to maintain your session, remember preferences (language, theme) and support core Platform functionality. See Section 8 for details.

2.3 Information from Third Parties

  • OAuth Providers: If you sign in using Google, X/Twitter, or LinkedIn, we receive limited profile information as authorized by you during the authentication flow.
  • Payment Processor: Paddle may share transaction confirmations, subscription status, and billing country information with us to fulfill your orders and manage subscriptions.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To create and manage your account, process orders, deliver software development services and facilitate communication through project chats.
  • Payment Processing: To facilitate payment transactions through Paddle, manage subscription billing and issue invoices.
  • Communication: To send order updates, milestone notifications, delivery confirmations and respond to your inquiries.
  • Platform Improvement: To analyze usage patterns, identify technical issues, improve performance and enhance user experience.
  • Security: To detect and prevent fraud, abuse and unauthorized access to the Platform.
  • Compliance: To enforce geographic restrictions, comply with applicable laws and regulations and fulfill legal obligations.
  • Marketing: With your consent, to send newsletters and promotional communications about our services. You can opt out at any time.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or similar jurisdictions, we process your personal data based on:

  • Contract Performance: Processing necessary to fulfill our contractual obligations to you (account management, order delivery, payment processing).
  • Legitimate Interests: Processing for our legitimate business interests, such as improving our services, ensuring security and analyzing usage, where your rights do not override these interests.
  • Consent: Where you have given explicit consent, such as for marketing communications or optional cookies.
  • Legal Obligation: Processing required to comply with applicable laws and regulations.

5. How We Share Your Information

We do not sell your personal information. We may share your data with:

  • Payment Processor (Paddle): Paddle processes all payments as Merchant of Record and receives necessary transaction and billing information. Paddle is PCI DSS compliant and operates under its own privacy policy.
  • Authentication Providers: Google, X/Twitter and LinkedIn receive authentication requests when you use social sign-in.
  • Hosting and Infrastructure: Our Platform is hosted on cloud infrastructure providers that process data on our behalf under strict data processing agreements.
  • Analytics: We may use privacy-respecting analytics tools to understand how users interact with the Platform. Data is aggregated and anonymized where possible.
  • Legal Requirements: We may disclose your information if required by law, court order, or governmental request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

6. Data Retention

We keep personal information only for as long as needed to operate the Platform, deliver your orders, and meet applicable legal obligations. We do not keep data longer than necessary for those purposes.

Account deletion: When you request deletion of your account, we delete associated account data at that time. We do not retain your profile or account records on an ongoing basis after your account is deleted, except where the law requires us to keep certain minimal records (for example, tax or accounting information held by our payment processor, Paddle, under its own policies).

Chat and messages: When you delete chat messages or other content you control in the Platform, that content is deleted from our systems. We do not keep duplicate copies of user-deleted chat or messages for routine analytics or marketing.

Orders and projects: After a project is completed or cancelled, you may be offered the option to delete associated project data (including related chat or files, where the feature is available). If you use those deletion options, we remove that data as implemented in the Platform. We do not maintain a parallel archive of project content you have chosen to delete.

Legal requirements: In limited circumstances we may need to retain certain information to comply with law, respond to lawful requests, or resolve disputes. That retention is the minimum necessary and not used to override deletions described above except where legally required.

7. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and sensitive data at rest.
  • Secure password hashing using bcrypt with appropriate salt rounds.
  • IP addresses stored only in SHA-256 hashed form.
  • HTTP-only, secure cookies for sensitive session tokens.
  • Role-based access controls limiting data access to authorized personnel.
  • Regular security reviews and updates.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Cookies and Tracking

8.1 Cookies We Use

  • Session Cookies: Essential for authentication and maintaining your logged-in state.
  • Preference Cookies: Store your language selection, theme preferences and accent color choices.
  • Geo Cookies: Store your detected country for service availability and language suggestions. These are non-personally-identifiable.

8.2 No Third-Party Tracking Cookies

We do not use third-party advertising cookies or cross-site tracking technologies. We do not participate in ad networks or sell data to advertisers.

9. Your Rights and Controls

This section describes what you can do in the Platform and what you can request from us. It reflects how Code Cure Lab actually operates today.

9.1 What you can do in the Platform

  • Profile: You can review and update certain profile information (such as name, avatar, and related settings) in your account where those features are available.
  • Chats and messages: Where the app allows it, you can delete your own chat messages or content. Deleted content is removed as described in Section 6.
  • Files and project data: Where the app allows it, you can delete files or project-related data associated with an order, including after a project is completed or cancelled, as offered in the interface.
  • Account deletion: You can request deletion of your account through the account or profile flows where provided, or by contacting us at privacy@codecurelab.com. Account deletion is handled as described in Section 6.
  • Marketing: If you receive marketing emails from us, you can use the unsubscribe link in those messages where applicable.

9.2 What we do not provide as a standard service

We do not operate a self-service "download everything we know about you" tool. We do not, as a routine offering, provide a full copy of all personal data we hold about you, a comprehensive subject access package, or a bundled machine-readable export of your data (sometimes called data portability). If you need something specific and we can reasonably help without disproportionate burden, you may ask; we are not obligated to build custom exports beyond what applicable law may require in your jurisdiction.

9.3 Contacting us

For account deletion, privacy questions, or requests that your jurisdiction may entitle you to, email privacy@codecurelab.com. We will respond within a reasonable time. Complex requests may take longer; we may need to verify your identity before acting on sensitive requests.

9.4 California Residents (CCPA)

We do not sell personal information. California residents may have rights under the CCPA, such as requesting deletion of personal information or learning about our practices. Because we do not offer a full automated data export, please contact privacy@codecurelab.com to submit requests or questions. We will handle verifiable requests in line with applicable law.

9.5 EEA/UK and other regions

If you are in the EEA, UK, or another region with privacy laws, you may have statutory rights that we cannot contract away. You may contact us at privacy@codecurelab.com; we will consider your request under applicable law. You may also have the right to lodge a complaint with your local data protection authority.

10. International Data Transfers

Your data may be processed and stored in locations outside your country of residence. We ensure that any international transfers of personal data are protected by appropriate safeguards, including standard contractual clauses or equivalent measures approved by relevant data protection authorities.

11. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us.

12. Third-Party Links

The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you visit.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform. The "Last updated" date at the top of this policy indicates when it was last revised. Your continued use of the Platform after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

  • Privacy inquiries: privacy@codecurelab.com
  • General inquiries: support@codecurelab.com
  • Website: codecurelab.com