Code and Sea Code and Sea
Code and Sea
Toggle sidebar
Privacy policy

Privacy Policy: Code and Sea Ltd

Last Updated: May 18, 2026

Our Privacy Philosophy

Why this policy is intentionally minimal

At Code and Sea Ltd, we believe that software should serve you, not track you. Our business model is built on providing value through craftsmanship, not by monetizing your personal information. We collect the absolute minimum amount of data required to run our business and communicate with you. We never sell, share, or trade your data with third parties for marketing purposes.

1. Legal Compliance & Data Controller

Code and Sea Ltd is a private limited company registered in England and Wales.

  • Company Number: 17178938
  • Registered Office: 66 Paul Street, London, England, EC2A 4NA
  • Data Controller: Code and Sea Ltd
  • Contact: privacy@codeandsea.com

We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

Purpose Legal Basis (UK GDPR Art. 6)
Website Analytics Legitimate Interest (Improving user experience)
Email Marketing Consent (Opt-in to our newsletter)
Customer Support Legitimate Interest (Responding to your inquiries)
Security/Spam Prevention Legitimate Interest (Protecting our website)

2. Information We Collect

What we collect directly and automatically

A. Information You Provide

  • Newsletter Subscription: If you choose to follow our journey, we collect your email address. This is processed via our partner, Brevo.
  • Contact Inquiries: If you email us or use a contact form, we collect your name (if provided), email address, and the contents of your message to provide the requested support.

B. Automatically Collected Information

  • Technical Metadata: Like most websites, we receive basic technical information such as your IP address and browser type to ensure the site displays correctly and remains secure.
  • Usage Analytics: We use PostHog to understand how visitors interact with our site (e.g., which pages are popular) to improve our content.

3. Cookies & LocalStorage

Cookie usage and client-side storage

We avoid intrusive tracking by design. Our website uses a no-cookie approach for analytics.

  • Essential Cookies Only: We set two technical cookies required for security and functionality:
    1. codeandsea-session: A temporary session cookie.
    2. XSRF-TOKEN: A security token to prevent Cross-Site Request Forgery (CSRF) on forms.
  • No Analytics Cookies: We do not use cookies for analytics. Instead, PostHog uses a randomly generated identifier stored in your browser's localStorage. This is anonymous, does not track you across other websites, and is not linked to your personal identity.

4. Our Third-Party Partners

The trusted services that help us run the site

We use a small number of trusted partners to help run our outpost:

  • Brevo (Marketing & Transactional Email): Used to manage our "Logbook" newsletter. When you sign up, your email is stored securely on their servers. You can unsubscribe at any time using the link in any email.
  • PostHog (Analytics): We use PostHog in a privacy-first configuration. All data is processed and stored on EU-based servers (eu.i.posthog.com). We do not send any Personally Identifiable Information (PII) to PostHog. We capture the following custom events: contact_form_submitted (when you send a contact enquiry) and newsletter_subscribed (when you sign up to the Logbook). These events contain no PII.

5. What We DON'T Do

Boundaries we keep on purpose

  • We don't use "tracking pixels" (like Facebook or Google pixels).
  • We don't sell your data to brokers or advertisers.
  • We don't use your data to "profile" you or make automated decisions.
  • We don't collect data from our software products (like Transcendence) through this website.

6. Data Retention & Security

How long we keep data and how we protect it

We only keep your data for as long as necessary.

  • Newsletter emails are kept until you unsubscribe.
  • Support emails are kept for up to two years to ensure we can provide consistent service.
  • Security: All data is transmitted via encrypted SSL (HTTPS) connections and stored in secure facilities with restricted access.

7. Your Rights (UK GDPR)

Your rights over the data we hold

Under the UK GDPR, you have the following rights regarding your data:

  • Access: Request a copy of the data we hold about you.
  • Correction: Ask us to fix inaccurate information.
  • Deletion: Ask us to delete your data (the "Right to be Forgotten").
  • Object/Withdraw: Withdraw your consent for our newsletter at any time.

To exercise these rights, please email us at privacy@codeandsea.com. We will respond to all valid requests within one month.

8. Age Requirements

Who this site is intended for

Our services are intended for users aged 13 and over. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with data, please contact us and we will delete it immediately.

9. Complaints

How to raise a concern

If you are unhappy with how we handle your data, we hope you'll talk to us first. However, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

"Your journey is your own. Your privacy should be too."

— Brent, Founder of Code and Sea