Privacy Policy.
How Coded By RT collects, utilizes, safeguards, and respects your personal and project information.
1. Information We Collect
We collect information necessary to scope, architect, deliver, and support software engineering engagements:
2. How We Use Your Information
We process collected data exclusively for valid commercial and engineering purposes:
- Service Delivery: To architect, engineer, test, and deploy bespoke web applications and AI workflows.
- Project Communications: To transmit sprint updates, review deliverables, schedule consultations, and maintain ongoing correspondence.
- Payment Processing: To generate invoices, process retainer disbursements, and manage billing accounts securely.
- Platform Optimization: To analyze latency, locate runtime anomalies, and improve website response speed.
- Security & Compliance: To prevent fraudulent requests, enforce Turnstile bot verification, and fulfill statutory legal obligations.
3. Data Storage & Security Standards
Your information is stored in encrypted, access-restricted databases hosted in enterprise-grade multi-region cloud data centers. We enforce rigorous security protocols:
- Encryption in Transit: Strict TLS 1.3 cryptographic protocols with HSTS preloading for all web and API traffic.
- Encryption at Rest: Industry-standard AES-256 database encryption for sensitive project and contact records.
- Access Control: Zero-trust role-based access control (RBAC) and multi-factor authentication for studio engineers.
- Audits & Backups: Automated daily backups with continuous vulnerability scanning and dependency audits.
4. Data Sharing & Third-Party Disclosure
We do not sell, rent, monetize, or trade your personal information with third parties. Disclosures occur strictly under the following circumstances:
- Authorized Service Providers: Trusted cloud infrastructure processors that facilitate our operations under strict data privacy terms (such as Supabase for database storage, Clerk for user authentication, Razorpay for payment processing, and Cloudflare for CDN & DDoS mitigation).
- Legal Obligations: When mandated by enforceable court orders, applicable law, or regulatory compliance inquiries.
- Rights & Safety Protection: When necessary to enforce service agreements or defend the security of our platforms and clients.
- Explicit Consent: With your prior written authorization for specific third-party integrations.
5. Your Global Privacy Rights
In accordance with GDPR, CCPA, and international data protection standards, you have the right to:
6. Contact & Data Protection Officer
To exercise your data privacy rights, request data export or deletion, or ask questions regarding this Privacy Policy:
Direct Email: [email protected]
Operating Model: Global Remote Software Engineering Studio
This Privacy Policy was last updated in January 2026.