Codes 'n' Coffee Tech
Legal

Privacy Policy

Last updated: 25 July 2026

Codes 'n' Coffee Tech uses this policy to explain how information submitted through codesncoffee.com is handled. We aim to collect only the context needed to respond to business inquiries, operate the website, and understand content performance with consent.

Information we collect

  • Discovery inquiries: name, work email, phone, company, designation, solution interest, operational challenge, source page, consent time, and available campaign attribution.
  • AI blueprint requests: the selected solution and operational description you submit for scope qualification and an illustrative response. Do not include confidential, personal, patient, financial, regulated, or record-level information.
  • Technical information: ordinary hosting and security logs may contain IP address, browser, device, request time, and requested URL.
  • Consent preferences: stored in your browser so the site can respect your analytics choice.

How inquiry data moves

The website sends a valid inquiry to a server-side endpoint. The endpoint first sends the complete inquiry to configured Codes 'n' Coffee Tech inboxes through the configured transactional SMTP service. When HubSpot is configured, the endpoint also attempts to create or update a contact and add a note containing the phone, operational context, solution, and attribution. A missing or unavailable CRM does not prevent the email-based inquiry from completing. CRM and SMTP credentials stay server-side.

Only after the internal inquiry email is accepted does the website load the configured Google Calendar appointment schedule inside the confirmation screen. At that point your browser connects to Google, whose own privacy terms apply. A separate Google Calendar link remains available when the embedded schedule cannot load. Your submitted name and company are used in on-screen confirmation copy and are not placed in the booking URL by this site.

Analytics and cookies

Google Analytics 4 loads only after you consent to analytics in the cookie controls. We use it to understand page use and events such as discovery-CTA clicks, form outcomes, calendar clicks, article engagement, and AI-to-contact journeys. We do not use advertising storage through this implementation. See the Cookie Policy.

AI processing

The blueprint builder sends the operational description to a constrained Anthropic Claude scope-and-safety classification step. Only an accepted, sanitized operational summary is sent in a separate Claude request to generate the fixed-format blueprint. Contact details are not included in either model prompt, and neither request has tools, browsing, or conversation history.

The generated result uses a fixed structure and remains illustrative. A branded PDF is created in memory, emailed transactionally to the submitted work email and our configured recipients, and returned for an immediate browser download. The website does not create a public blueprint URL or retain the generated PDF in application storage.

If automated qualification or generation is unavailable, the visitor may choose to continue with a direct inquiry. The operational context is then emailed to our team and an accurate acknowledgement is sent to the visitor without claiming that a blueprint or PDF was created.

The normal contact form does not call Anthropic or generate a blueprint.

Spam and abuse protection

Contact and blueprint submissions use Cloudflare Turnstile, server-side token verification, structured validation, and hidden spam fields. Turnstile may process ordinary technical signals needed to distinguish people from automated abuse.

Why we use information

  • To qualify and respond to a requested business conversation.
  • To maintain inquiry history and avoid losing operational context.
  • To secure, diagnose, and improve the website.
  • To measure content and conversion performance when analytics consent is granted.

Sharing and international processing

Information may be processed by our hosting provider, HubSpot, Google Calendar, Google Analytics, Cloudflare Turnstile, Anthropic, and the configured SMTP provider for the purposes described above. These providers may process data in other countries under their own contractual and legal safeguards. We do not sell inquiry data.

Retention and choices

Business inquiry records are retained while they remain relevant to the requested conversation, relationship, legal obligations, or legitimate record-keeping needs. You can ask us to access, correct, or delete information associated with your inquiry by using the contact page. We may need to verify the request and may retain information where required for security, legal, or contractual reasons.

Changes

We will update the date and content of this policy when website processing changes materially.

This operational disclosure is not legal advice. The final policy should be reviewed against the company’s legal entity, contracts, deployment providers, and applicable jurisdictions before launch.