Legal
Privacy Policy
What we collect, why, and what control you have over it.
This document is a starting template prepared for RxCodz. Have it reviewed by a qualified professional in your jurisdiction before relying on it.
1. What we collect
When you create an account: your email address, username, password (stored only as a salted hash — we never see it), and anything you choose to add to your profile.
When you sign in: the time, your IP address, and your browser's user-agent string. This is shown back to you in your profile so you can spot access you do not recognise.
When you contact us: your name, email, optional Discord handle and company, and the content of your message.
Automatically: a session cookie if you are signed in, and a theme preference stored in your browser.
2. Why we collect it
- To operate your account and keep it secure
- To reply to your enquiry and deliver work you have asked for
- To detect and prevent abuse, spam, and unauthorised access
- To keep an audit record of administrative actions
We do not sell your data, and we do not use it for advertising.
3. Cookies
We use a small number of cookies. See the Cookie Policy for the full list. We do not use advertising or cross-site tracking cookies.
4. Retention
| Data | Kept for |
|---|---|
| Account data | Until you delete your account |
| Sessions | Until they expire or you revoke them |
| Login history | 180 days |
| Security logs | 365 days |
| Contact requests | 24 months |
| Audit logs | Retained as a compliance record |
5. Sharing
We share data only with service providers needed to run the site (hosting, and email delivery where configured), and where we are legally required to.
Contact through Discord is subject to Discord's own privacy policy — we do not control it.
6. Your rights
You can access, correct, export, or delete your data. Most of it you can change yourself in your profile. For anything else, ask us on Discord or through the contact form and we will action it within 30 days.
7. Security
Passwords are hashed with scrypt. Session tokens are stored only as hashes, so a database leak cannot be replayed as a login. Access to administrative functions is role-restricted and every privileged action is logged. No system is perfectly secure, but we treat your data as if a breach would matter — because it would.
8. Children
This site is not intended for people under 13, and we do not knowingly collect their data.
9. Changes
Material changes will be noted here with a new effective date.
Questions about this?
