GoodCode
HomeServicesPortfolioBlogAbout
Start a project
HomeServicesPortfolioBlogAboutStart a project
Legal / privacy

Privacy policy

What this site collects, who it goes to, and how to turn the optional parts off. Written to be read, not to be survived.

Effective 14 August 2026

Contents01 · Who we are02 · The short version03 · What we collect04 · Cookies and similar technologies05 · Why we use it, and our legal basis06 · Who we share it with07 · Where your data goes08 · How long we keep it09 · Your privacy choices10 · Your rights11 · How we protect it12 · Children13 · Changes to this policy14 · Contact us
01 · Who we are

Who we are

GoodCode is a product design and engineering studio based in the United States. This policy covers goodcode.us and the forms on it. It is the whole of our public website, and it does not cover work we do inside a client’s own product, which is governed by our contract with that client.

GoodCode is the controller of the personal data described here. You can reach us about anything on this page at [email protected]. Ask and we will give you our postal address for written notices.

02 · The short version

The short version

  • We sell nothing on this site, and we do not run ads. There is no account to create and nothing to buy.
  • The only personal data you hand us directly is what you type into the contact form.
  • We use three tracking tools to understand which work brings people here: PostHog, Google Analytics, and RB2B. None of them load until your privacy choice allows it.
  • If you are in the EEA, the UK, Switzerland or Quebec, we ask before any of them run. In the rest of the world they run unless you turn them off, which you can do at any time from the footer of every page.
  • We do not sell your personal data for money.
03 · What we collect

What we collect

What you give us

The contact form asks for your name, your email address and your message. The puzzle on our 404 page and the hidden object game on our homepage each ask for an email address only if you choose to claim something; the 404 scores stay in your own browser and never reach us. We also receive your IP address with any form you submit, because that is how the anti-spam check works.

What we collect automatically

When our analytics tools are allowed to run, they collect the pages you view, the links you click, the approximate location derived from your IP address, and technical details about your browser and device. PostHog also records a replay of your session: a reconstruction of what you saw and where you clicked. It masks the text you type into form fields.

Business visitor identification

RB2B is different from the other two, and we would rather say so plainly than bury it. When it is allowed to run, it tries to match a visit from a business network to a company and, where it holds a match, to a named person and their work email address. It does this without you filling anything in. It is how a small studio finds out that a company it would like to work with has been reading its case studies. You can turn it off with the same control that turns off analytics, and in the EEA, the UK, Switzerland and Quebec it never runs unless you accept.

What we do not collect

We do not ask for, and have no use for, financial details, government identifiers, health data, or any other special category of personal data. Please do not put any of it in the contact form.

04 · Cookies and similar technologies

Cookies and similar technologies

Cookies and browser storage are the mechanism behind most of the above. Essential entries are the ones the site cannot work correctly without, including the one that remembers your privacy choice; they are set either way. Everything else is set only when your choice allows it, and turning analytics off deletes them from this browser.

NameSet byWhat it doesKept forCategory
gc-consentGoodCode (this site)Remembers your privacy choice so we do not ask againUntil you clear your browser storageEssential
gc-regionGoodCode (this site)Caches the country your request came from, so the privacy rules that apply to you are worked out once per visitUntil you close the tabEssential
__cf_bm, cf_chl_*Cloudflare TurnstileBot detection on the contact form. Loads on the contact page onlySet by Cloudflare, typically 30 minutesEssential
gc404-runsGoodCode (this site)Your own scores in the puzzle on our 404 page. Stays on your device and is never sent to usUntil you clear your browser storageEssential
ph_*_posthogPostHogProduct analytics and session replay: a random visitor id and session state12 monthsAnalytics
_ga, _ga_*Google AnalyticsAudience measurement: a random client id and session state24 monthsAnalytics
RB2B identifiersRB2BMatching a business visitor to a company and, where RB2B holds a match, a named contactSet by RB2BIdentification

Your browser can block or delete cookies on its own, and every major browser has a setting for it. Blocking essential ones means we will ask for your privacy choice again on every visit, because the record of it is the thing you deleted.

05 · Why we use it, and our legal basis

Why we use it, and our legal basis

  • To answer you. We use what you send through the contact form to reply and, if it goes somewhere, to scope a project. Legal basis: steps taken at your request before entering a contract, and our legitimate interest in running a studio.
  • To keep the forms usable. The anti-spam check processes your IP address and some signals about your browser. Legal basis: our legitimate interest in not being buried in automated submissions.
  • To understand the site. Analytics and session replay tell us which work people read and where the site confuses them. Legal basis: your consent.
  • To find the companies we can help. Business visitor identification. Legal basis: your consent where consent is required, and our legitimate interest in business development elsewhere. You can object at any time.

We do not use any of this to make automated decisions that produce legal effects for you.

06 · Who we share it with

Who we share it with

We do not sell your personal data for money. We share it with the service providers below, which process it on our behalf and under contract, and we will disclose it if the law requires it or to protect our rights.

ProviderWhat they do for usWhereTheir policy
CloudflareHosting, content delivery, bot protection on the contact form, and sending the email that form producesUnited States and global edge networkPrivacy policy
PostHogProduct analytics and session replayUnited States (PostHog US Cloud)Privacy policy
GoogleGoogle Analytics 4 audience measurement, and Google Fonts, which receives your IP address when a page loads its typefacesUnited StatesPrivacy policy
RB2BBusiness visitor identificationUnited StatesPrivacy policy
SlackWhere a contact form submission is delivered to our teamUnited StatesPrivacy policy

Some US state privacy laws define “sale” and “sharing” broadly enough that using analytics and visitor identification tools can count, whether or not money changes hands. We treat them that way to be safe: the same control that turns off analytics is our opt out of any sale or sharing, and we honour Global Privacy Control everywhere. See your privacy choices.

07 · Where your data goes

Where your data goes

We are based in the United States and so are all of our providers, so personal data collected through this site is processed in the United States. If you are in the EEA, the UK or Switzerland, that is a transfer out of your region. We rely on the European Commission and UK adequacy decisions for the EU-US Data Privacy Framework where a provider is certified under it, and on Standard Contractual Clauses otherwise. Ask us at [email protected] and we will tell you which applies to a given provider.

08 · How long we keep it

How long we keep it

  • Contact form messages. Up to 24 months after our last exchange with you.
  • Analytics and session replay. Up to 12 months in PostHog and 14 months in Google Analytics.
  • Business visitor identification. Up to 24 months in RB2B.
  • Server and security logs. Up to 30 days in Cloudflare.
09 · Your privacy choices

Your privacy choices

One control covers analytics, session replay and business visitor identification. It works from anywhere on the site, it takes effect immediately, and turning things off also deletes the cookies those tools set in this browser.

  • Global Privacy Control. If your browser or an extension sends the GPC signal, we treat it as an instruction to keep analytics and identification off, in every region, without asking you anything.
  • Do Not Sell or Share My Personal Information. The same control is that opt out. You do not need an account and we will not ask you to verify your identity to use it.
  • Google Analytics. Google publishes a browser add-on that opts you out of it across every site, at tools.google.com/dlpage/gaoptout.
  • Email. We send no newsletters and run no drip sequences from this site. If a person here has emailed you, reply and say stop, and we will.
10 · Your rights

Your rights

Depending on where you live, you may have some or all of the following rights over your personal data: to know what we hold, to get a copy of it, to correct it, to delete it, to restrict or object to how we use it, to take it elsewhere in a portable form, and to withdraw consent you have given. Withdrawing consent does not undo what was lawful before you withdrew it.

To use any of them, email [email protected] and tell us what you want. We will not charge you, and we will not treat you differently for asking. We answer within 30 days, or within 45 days under the US state laws that allow it. We may ask for enough information to be sure the request is really yours. If you use an authorised agent, we will ask for proof of their authority.

If you are in the EEA, the UK or Switzerland, you can also complain to your data protection authority. We would rather you told us first so we can put it right.

11 · How we protect it

How we protect it

The site is served over HTTPS with a strict content security policy, it sets no cookies of its own beyond the ones listed above, and the form endpoints run at the edge with bot protection. Messages reach us through Slack and email, both on accounts protected by multi-factor authentication. No method of transmission over the internet is perfectly secure, so please do not send anything confidential through a web form. If you need to, email us and we will sign a mutual non-disclosure agreement first.

12 · Children

Children

This site is for people doing business with us. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us something, email [email protected] and we will delete it.

13 · Changes to this policy

Changes to this policy

When we change what we collect or who we share it with, we update this page and move the effective date at the top. If a change means we need your consent for something new, we will ask again rather than assume the old answer still applies.

14 · Contact us

Contact us

Questions, requests and complaints about privacy all go to [email protected]. A person reads it, not a ticket queue.

We are the human you want in the loop

Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · Let's collaborate · 
Click to start a project
GoodCode

Designers & engineers for cybersecurity, AI & enterprise

Framer PartnerClaude Partner Network member

Explore

HomeServicesPortfolioAboutBlog

Services

AdvisoryUX Research & DesignEngineeringBrandingWebsites

Connect

[email protected]
LinkedInGitHubDribbble
© 2026 GoodCode · USA · goodcode.us
Privacy policyTerms of service