Privacy Policy
Effective March 21, 2026 · Noob Media LLC d/b/a CodeHawke
1. Who We Are
Noob Media LLC d/b/a CodeHawke ("CodeHawke," "we," "us," or "our") operates the codehawke.com website and platform. Our mailing address is PO Box 872, Great Falls, VA 22066, USA. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our services.
For EU/EEA users: CodeHawke is the data controller for information about platform users (sellers and learners). For buyer data collected through seller storefronts, the individual seller is the data controller and CodeHawke is the data processor. See Section 5.
2. What We Collect
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, email address, password (hashed), store name, store slug, support email, website URL | You provide directly on registration or in account settings |
| Billing Data | Stripe Customer ID for your CodeHawke subscription, plan tier, subscription status | Generated when you subscribe to a paid plan; Stripe handles card details directly |
| Product Data | Product titles, descriptions, prices, cover images, uploaded files (hosted plan), fulfillment URLs | You provide when creating products |
| Sales & Order Data | Buyer email, purchase amount, currency, Stripe payment intent ID, access token, order timestamps | Generated automatically when a buyer completes checkout through your Stripe account |
| Usage Data | Pages visited, feature usage, bandwidth consumed, error logs, IP address, browser type | Collected automatically via server logs and session data |
| Payment Provider Credentials | Your payment provider credentials (AES-256-GCM encrypted at rest), publishable keys, webhook secrets | You provide when connecting your payment account; never exposed in browser |
We do not collect credit or debit card numbers. All payment processing is handled by Stripe.
3. How We Use It
- To provide the Platform: Create and manage your account, process your subscription, host your products, generate checkout sessions, and deliver files to buyers.
- To verify payments: Use your encrypted Stripe secret key server-side only to verify that a checkout session was completed before releasing access to a buyer.
- To send transactional emails: Purchase confirmations to buyers, access link delivery, subscription receipts, and service notifications to sellers.
- To improve the Platform: Analyze aggregated usage patterns, diagnose errors, and develop new features.
- To enforce our Terms: Detect abuse, investigate fraud, and comply with legal obligations.
- To communicate with you: Respond to support inquiries and, if you have opted in, send product updates.
We do not use your data for advertising targeting or sell it to third-party data brokers.
4. Data Sharing
We share data only in these circumstances:
- Stripe: We pass necessary parameters to Stripe to create checkout sessions on your behalf. Stripe's Privacy Policy governs their handling of payment data.
- Cloud Infrastructure: We use AWS (S3, SES, optionally Rekognition), Cloudflare, and MongoDB Atlas to operate the Platform. These providers process data under contractual data processing agreements.
- Legal Requirements: We may disclose data when required by law, court order, or governmental authority, or to protect the rights, property, or safety of CodeHawke, its users, or the public.
- Business Transfers: In the event of a merger, acquisition, or asset sale, user data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
We do not sell, rent, or trade personally identifiable information to third parties for their marketing purposes.
5. Sellers & Buyer Data
If you are a Seller
When your buyers complete purchases through your storefront, CodeHawke receives their email address and order details in order to generate access tokens and deliver your product. You are the Data Controller for your buyers' personal data. CodeHawke is the Data Processor - we process that data only on your instruction to fulfill orders.
As the data controller, you are responsible for: maintaining a privacy policy on your storefront; obtaining any required buyer consents; and responding to data subject rights requests from your buyers (access, erasure, portability) under GDPR, CCPA, or other applicable law.
Buyer Data Ownership
Because payments flow through your own Stripe account, your customers' payment history remains in your payment provider's system - not ours. If you close your CodeHawke account, your buyer order records are retained for 30 days then deleted, except where we are required by law to retain them longer.
If you are a Buyer
If you purchased a digital product from a seller using CodeHawke, your purchase was made directly from that seller. Your relationship is with the seller, not with CodeHawke. For data requests related to your purchase (access to data, deletion of data), contact the seller directly. For platform-level data requests about your email and access token, contact support@codehawke.com.
6. Stripe & Payment Data
Stripe is an independent data controller for all payment and cardholder data. When you (as a seller) connect your payment account to CodeHawke, you grant CodeHawke permission to create checkout sessions and retrieve session status on your behalf. We store your payment credentials encrypted at rest using AES-256-GCM and never expose it in the browser or in logs.
CodeHawke does not store full credit card numbers, CVV codes, or other payment instrument details at any point. All card data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.
7. Cookies & Tracking
We use cookies and similar technologies for:
- Authentication: A session/JWT cookie to keep you logged in to your dashboard.
- Security: CSRF protection tokens.
- Preferences: Remembering display settings.
We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral advertising networks. We do not use Google Analytics or similar third-party analytics services on authenticated dashboard pages. Basic server-side access logging is used for security and abuse detection.
You can disable cookies in your browser settings, but doing so will prevent you from logging in to the dashboard.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | For the life of the account, plus 30 days after deletion |
| Order records | 7 years (required for financial record-keeping) |
| Hosted product files | 30 days after account closure, then permanently deleted |
| Server access logs | 90 days |
| Encrypted Stripe API keys | Deleted immediately upon account closure or key rotation |
9. Security
We implement appropriate technical and organizational measures to protect your data, including:
- AES-256-GCM encryption for sensitive credentials (payment credentials) at rest.
- TLS encryption for all data in transit.
- JWT-based authentication with short-lived tokens.
- Content moderation scanning on uploaded images where infrastructure permits.
- Role-based access controls limiting which systems and personnel can access production data.
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at support@codehawke.com. We will respond within 30 days. EU/EEA residents may also lodge a complaint with their local data protection authority.
California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act: the right to know what categories of personal information we collect and how we use them; the right to opt out of the "sale" of personal information (we do not sell personal information); and the right to non-discrimination for exercising CCPA rights. To make a verifiable consumer request, email support@codehawke.com with "CCPA Request" in the subject line.
11. Children
The Platform is not directed to children under 13. We do not knowingly collect personal information from anyone under 13 years of age. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly. If you believe a child has provided us with personal data, contact support@codehawke.com.
12. Policy Changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the Platform at least 14 days before the change takes effect. The "Effective Date" at the top of this page indicates when it was last revised. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.
13. Contact
PO Box 872, Great Falls, VA 22066
General privacy inquiries: support@codehawke.com
Legal, GDPR, CCPA requests: legal@codehawke.com
See also: Terms · Refund Policy