Privacy Policy

Effective March 21, 2026 · Noob Media LLC d/b/a CodeHawke

1. Who We Are

Noob Media LLC d/b/a CodeHawke ("CodeHawke," "we," "us," or "our") operates the codehawke.com website and platform. Our mailing address is PO Box 872, Great Falls, VA 22066, USA. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our services.

For EU/EEA users: CodeHawke is the data controller for information about platform users (sellers and learners). For buyer data collected through seller storefronts, the individual seller is the data controller and CodeHawke is the data processor. See Section 5.

2. What We Collect

CategoryExamplesSource
Account DataName, email address, password (hashed), store name, store slug, support email, website URLYou provide directly on registration or in account settings
Billing DataStripe Customer ID for your CodeHawke subscription, plan tier, subscription statusGenerated when you subscribe to a paid plan; Stripe handles card details directly
Product DataProduct titles, descriptions, prices, cover images, uploaded files (hosted plan), fulfillment URLsYou provide when creating products
Sales & Order DataBuyer email, purchase amount, currency, Stripe payment intent ID, access token, order timestampsGenerated automatically when a buyer completes checkout through your Stripe account
Usage DataPages visited, feature usage, bandwidth consumed, error logs, IP address, browser typeCollected automatically via server logs and session data
Payment Provider CredentialsYour payment provider credentials (AES-256-GCM encrypted at rest), publishable keys, webhook secretsYou provide when connecting your payment account; never exposed in browser

We do not collect credit or debit card numbers. All payment processing is handled by Stripe.

3. How We Use It

  • To provide the Platform: Create and manage your account, process your subscription, host your products, generate checkout sessions, and deliver files to buyers.
  • To verify payments: Use your encrypted Stripe secret key server-side only to verify that a checkout session was completed before releasing access to a buyer.
  • To send transactional emails: Purchase confirmations to buyers, access link delivery, subscription receipts, and service notifications to sellers.
  • To improve the Platform: Analyze aggregated usage patterns, diagnose errors, and develop new features.
  • To enforce our Terms: Detect abuse, investigate fraud, and comply with legal obligations.
  • To communicate with you: Respond to support inquiries and, if you have opted in, send product updates.

We do not use your data for advertising targeting or sell it to third-party data brokers.

4. Data Sharing

We share data only in these circumstances:

  • Stripe: We pass necessary parameters to Stripe to create checkout sessions on your behalf. Stripe's Privacy Policy governs their handling of payment data.
  • Cloud Infrastructure: We use AWS (S3, SES, optionally Rekognition), Cloudflare, and MongoDB Atlas to operate the Platform. These providers process data under contractual data processing agreements.
  • Legal Requirements: We may disclose data when required by law, court order, or governmental authority, or to protect the rights, property, or safety of CodeHawke, its users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, user data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

We do not sell, rent, or trade personally identifiable information to third parties for their marketing purposes.

5. Sellers & Buyer Data

If you are a Seller

When your buyers complete purchases through your storefront, CodeHawke receives their email address and order details in order to generate access tokens and deliver your product. You are the Data Controller for your buyers' personal data. CodeHawke is the Data Processor - we process that data only on your instruction to fulfill orders.

As the data controller, you are responsible for: maintaining a privacy policy on your storefront; obtaining any required buyer consents; and responding to data subject rights requests from your buyers (access, erasure, portability) under GDPR, CCPA, or other applicable law.

Buyer Data Ownership

Because payments flow through your own Stripe account, your customers' payment history remains in your payment provider's system - not ours. If you close your CodeHawke account, your buyer order records are retained for 30 days then deleted, except where we are required by law to retain them longer.

If you are a Buyer

If you purchased a digital product from a seller using CodeHawke, your purchase was made directly from that seller. Your relationship is with the seller, not with CodeHawke. For data requests related to your purchase (access to data, deletion of data), contact the seller directly. For platform-level data requests about your email and access token, contact support@codehawke.com.

6. Stripe & Payment Data

Stripe is an independent data controller for all payment and cardholder data. When you (as a seller) connect your payment account to CodeHawke, you grant CodeHawke permission to create checkout sessions and retrieve session status on your behalf. We store your payment credentials encrypted at rest using AES-256-GCM and never expose it in the browser or in logs.

CodeHawke does not store full credit card numbers, CVV codes, or other payment instrument details at any point. All card data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.

7. Cookies & Tracking

We use cookies and similar technologies for:

  • Authentication: A session/JWT cookie to keep you logged in to your dashboard.
  • Security: CSRF protection tokens.
  • Preferences: Remembering display settings.

We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral advertising networks. We do not use Google Analytics or similar third-party analytics services on authenticated dashboard pages. Basic server-side access logging is used for security and abuse detection.

You can disable cookies in your browser settings, but doing so will prevent you from logging in to the dashboard.

8. Data Retention

Data TypeRetention Period
Account dataFor the life of the account, plus 30 days after deletion
Order records7 years (required for financial record-keeping)
Hosted product files30 days after account closure, then permanently deleted
Server access logs90 days
Encrypted Stripe API keysDeleted immediately upon account closure or key rotation

9. Security

We implement appropriate technical and organizational measures to protect your data, including:

  • AES-256-GCM encryption for sensitive credentials (payment credentials) at rest.
  • TLS encryption for all data in transit.
  • JWT-based authentication with short-lived tokens.
  • Content moderation scanning on uploaded images where infrastructure permits.
  • Role-based access controls limiting which systems and personnel can access production data.

No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Access
Request a copy of the personal data we hold about you.
Correction
Request correction of inaccurate or incomplete data.
Deletion
Request deletion of your personal data, subject to legal retention obligations.
Portability
Request your data in a structured, machine-readable format.
Objection
Object to processing of your data in certain circumstances.
Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at support@codehawke.com. We will respond within 30 days. EU/EEA residents may also lodge a complaint with their local data protection authority.

California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act: the right to know what categories of personal information we collect and how we use them; the right to opt out of the "sale" of personal information (we do not sell personal information); and the right to non-discrimination for exercising CCPA rights. To make a verifiable consumer request, email support@codehawke.com with "CCPA Request" in the subject line.

11. Children

The Platform is not directed to children under 13. We do not knowingly collect personal information from anyone under 13 years of age. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly. If you believe a child has provided us with personal data, contact support@codehawke.com.

12. Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the Platform at least 14 days before the change takes effect. The "Effective Date" at the top of this page indicates when it was last revised. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.

13. Contact

Noob Media LLC d/b/a CodeHawke
PO Box 872, Great Falls, VA 22066

General privacy inquiries: support@codehawke.com
Legal, GDPR, CCPA requests: legal@codehawke.com

See also: Terms · Refund Policy