Privacy Policy
Last updated: February 2026
TheCodeDealer ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website at thecodedealer.io (the "Platform"). We are based in the United Kingdom and process your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
TheCodeDealer is a sole trader trading name operated from the United Kingdom. As the data controller, we are responsible for your personal data. If you have any questions about this Privacy Policy or how we handle your data, you can contact us at:
2. Information We Collect
We collect different types of information depending on how you interact with the Platform:
2.1 Information You Provide
- Account registration: Name, email address, and password when you create an account directly, or name and email when you register via Google or GitHub;
- Profile information: Display name, bio, and avatar image that you choose to add to your profile;
- Payment information: Billing details provided during checkout (processed and stored by Stripe — we do not store your card details);
- Newsletter signup: Name and email address when you subscribe to our newsletter;
- Communications: Any information you provide when you contact us via email or our contact form.
2.2 Information Collected Automatically
- Usage data: Pages visited, courses viewed, lectures watched, and course progress;
- Device information: Browser type, operating system, and screen resolution;
- Log data: IP address, access times, and referring URLs;
- Cookies: Authentication cookies required for keeping you logged in (see Section 7 below).
2.3 Information from Third Parties
- OAuth providers: If you register or log in via Google or GitHub, we receive your name, email address, and profile picture from those providers;
- Stripe: Payment confirmation details, transaction IDs, and subscription status.
3. How We Use Your Information
We use your personal data for the following purposes and legal bases:
- To provide and maintain the Platform — including account creation, course access, progress tracking, and subscription management (legal basis: performance of a contract);
- To process payments — handling purchases, subscriptions, and billing through Stripe (legal basis: performance of a contract);
- To communicate with you — responding to enquiries and sending service-related notifications such as purchase confirmations and subscription updates (legal basis: performance of a contract);
- To send marketing communications — newsletters, course announcements, and promotional offers, only where you have opted in (legal basis: consent);
- To improve the Platform — analysing usage patterns to enhance content, features, and user experience (legal basis: legitimate interests);
- To prevent fraud and abuse — detecting unauthorised access and enforcing our Terms of Service (legal basis: legitimate interests);
- To comply with legal obligations — meeting tax, accounting, and regulatory requirements (legal basis: legal obligation).
4. How We Share Your Information
We do not sell your personal data. We share your information only with the following categories of third-party service providers who assist us in operating the Platform:
- Stripe — Payment processing. Stripe receives your payment details and billing information. See Stripe's Privacy Policy;
- Supabase — Authentication services. Supabase processes your email and login credentials. See Supabase's Privacy Policy;
- Mux — Video streaming and delivery. Mux may process usage data related to video playback;
- Cloudinary — Image hosting for profile avatars and course imagery;
- Loops — Email and newsletter delivery. Loops receives your name and email address if you subscribe to our newsletter;
- Vercel — Website hosting and content delivery.
We may also disclose your information if required to do so by law, court order, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Data Retention
We retain your personal data for as long as necessary to:
- Maintain your account and provide our services;
- Comply with legal and regulatory obligations (e.g., tax and accounting records are retained for a minimum of 6 years);
- Resolve disputes and enforce our Terms of Service.
If you delete your account, we will remove your personal data within a reasonable timeframe, except where we are required by law to retain it. Anonymised or aggregated data that can no longer identify you may be retained indefinitely for analytical purposes.
6. Your Rights Under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access — You can request a copy of the personal data we hold about you;
- Right to rectification — You can ask us to correct inaccurate or incomplete data. You can also update your profile information directly through the Platform;
- Right to erasure — You can request that we delete your personal data, subject to legal retention obligations;
- Right to restriction of processing — You can ask us to restrict how we process your data in certain circumstances;
- Right to data portability — You can request your data in a structured, commonly used, machine-readable format;
- Right to object — You can object to processing based on legitimate interests or for direct marketing purposes;
- Right to withdraw consent — Where we rely on your consent (e.g., newsletter), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at thecodedealer24@gmail.com. We will respond to your request within one month, as required by law. If you are not satisfied with our response, you have the right to lodge a complaint with the United Kingdom's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.
7. Cookies
We use cookies that are strictly necessary for the operation of the Platform:
- Authentication cookies — HTTP-only secure cookies that store encrypted authentication tokens to keep you logged in. These are essential for the Platform to function and do not require your consent under UK cookie regulations;
- Session cookies — Temporary cookies that are deleted when you close your browser.
We currently do not use advertising cookies, tracking cookies, or third-party analytics cookies. We do not participate in cross-site tracking or behavioural advertising. If this changes, we will update this policy accordingly.
8. International Data Transfers
Some of our third-party service providers (such as Stripe, Supabase, Mux, Cloudinary, and Vercel) are based in the United States. Where your data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision from the UK Secretary of State;
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to Standard Contractual Clauses (SCCs).
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data in transit;
- HTTP-only, secure cookies to prevent client-side access to authentication tokens;
- Password hashing and secure authentication through Supabase;
- Payment card data handled exclusively by Stripe (PCI DSS compliant) — we never store your card details.
While we take reasonable steps to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
10. Children's Privacy
The Platform is not intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will take steps to delete that information promptly.
11. Third-Party Links
The Platform may contain links to third-party websites, including our social media profiles (YouTube, GitHub, Instagram, Facebook) and community channels (Discord). We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies before providing any personal data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through the Platform. We encourage you to review this page periodically.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
For legal or privacy-related enquiries, please email us at the address above. We monitor this inbox regularly and aim to respond within 5 business days.
You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO):