Privacy policy
What this site collects, who it goes to, and how to turn the optional parts off. Written to be read, not to be survived.
Effective 14 August 2026
Who we are
GoodCode is a product design and engineering studio based in the United States. This policy covers goodcode.us and the forms on it. It is the whole of our public website, and it does not cover work we do inside a client’s own product, which is governed by our contract with that client.
GoodCode is the controller of the personal data described here. You can reach us about anything on this page at [email protected]. Ask and we will give you our postal address for written notices.
The short version
- We sell nothing on this site, and we do not run ads. There is no account to create and nothing to buy.
- The only personal data you hand us directly is what you type into the contact form.
- We use three tracking tools to understand which work brings people here: PostHog, Google Analytics, and RB2B. None of them load until your privacy choice allows it.
- If you are in the EEA, the UK, Switzerland or Quebec, we ask before any of them run. In the rest of the world they run unless you turn them off, which you can do at any time from the footer of every page.
- We do not sell your personal data for money.
What we collect
What you give us
The contact form asks for your name, your email address and your message. The puzzle on our 404 page and the hidden object game on our homepage each ask for an email address only if you choose to claim something; the 404 scores stay in your own browser and never reach us. We also receive your IP address with any form you submit, because that is how the anti-spam check works.
What we collect automatically
When our analytics tools are allowed to run, they collect the pages you view, the links you click, the approximate location derived from your IP address, and technical details about your browser and device. PostHog also records a replay of your session: a reconstruction of what you saw and where you clicked. It masks the text you type into form fields.
Business visitor identification
RB2B is different from the other two, and we would rather say so plainly than bury it. When it is allowed to run, it tries to match a visit from a business network to a company and, where it holds a match, to a named person and their work email address. It does this without you filling anything in. It is how a small studio finds out that a company it would like to work with has been reading its case studies. You can turn it off with the same control that turns off analytics, and in the EEA, the UK, Switzerland and Quebec it never runs unless you accept.
What we do not collect
We do not ask for, and have no use for, financial details, government identifiers, health data, or any other special category of personal data. Please do not put any of it in the contact form.
Why we use it, and our legal basis
- To answer you. We use what you send through the contact form to reply and, if it goes somewhere, to scope a project. Legal basis: steps taken at your request before entering a contract, and our legitimate interest in running a studio.
- To keep the forms usable. The anti-spam check processes your IP address and some signals about your browser. Legal basis: our legitimate interest in not being buried in automated submissions.
- To understand the site. Analytics and session replay tell us which work people read and where the site confuses them. Legal basis: your consent.
- To find the companies we can help. Business visitor identification. Legal basis: your consent where consent is required, and our legitimate interest in business development elsewhere. You can object at any time.
We do not use any of this to make automated decisions that produce legal effects for you.
Where your data goes
We are based in the United States and so are all of our providers, so personal data collected through this site is processed in the United States. If you are in the EEA, the UK or Switzerland, that is a transfer out of your region. We rely on the European Commission and UK adequacy decisions for the EU-US Data Privacy Framework where a provider is certified under it, and on Standard Contractual Clauses otherwise. Ask us at [email protected] and we will tell you which applies to a given provider.
How long we keep it
- Contact form messages. Up to 24 months after our last exchange with you.
- Analytics and session replay. Up to 12 months in PostHog and 14 months in Google Analytics.
- Business visitor identification. Up to 24 months in RB2B.
- Server and security logs. Up to 30 days in Cloudflare.
Your privacy choices
One control covers analytics, session replay and business visitor identification. It works from anywhere on the site, it takes effect immediately, and turning things off also deletes the cookies those tools set in this browser.
- Global Privacy Control. If your browser or an extension sends the GPC signal, we treat it as an instruction to keep analytics and identification off, in every region, without asking you anything.
- Do Not Sell or Share My Personal Information. The same control is that opt out. You do not need an account and we will not ask you to verify your identity to use it.
- Google Analytics. Google publishes a browser add-on that opts you out of it across every site, at tools.google.com/dlpage/gaoptout.
- Email. We send no newsletters and run no drip sequences from this site. If a person here has emailed you, reply and say stop, and we will.
Your rights
Depending on where you live, you may have some or all of the following rights over your personal data: to know what we hold, to get a copy of it, to correct it, to delete it, to restrict or object to how we use it, to take it elsewhere in a portable form, and to withdraw consent you have given. Withdrawing consent does not undo what was lawful before you withdrew it.
To use any of them, email [email protected] and tell us what you want. We will not charge you, and we will not treat you differently for asking. We answer within 30 days, or within 45 days under the US state laws that allow it. We may ask for enough information to be sure the request is really yours. If you use an authorised agent, we will ask for proof of their authority.
If you are in the EEA, the UK or Switzerland, you can also complain to your data protection authority. We would rather you told us first so we can put it right.
How we protect it
The site is served over HTTPS with a strict content security policy, it sets no cookies of its own beyond the ones listed above, and the form endpoints run at the edge with bot protection. Messages reach us through Slack and email, both on accounts protected by multi-factor authentication. No method of transmission over the internet is perfectly secure, so please do not send anything confidential through a web form. If you need to, email us and we will sign a mutual non-disclosure agreement first.
Children
This site is for people doing business with us. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us something, email [email protected] and we will delete it.
Changes to this policy
When we change what we collect or who we share it with, we update this page and move the effective date at the top. If a change means we need your consent for something new, we will ask again rather than assume the old answer still applies.
Contact us
Questions, requests and complaints about privacy all go to [email protected]. A person reads it, not a ticket queue.