Privacy Policy
Last updated: February 18, 2026
1. Introduction
FluxCode Studio LLC (“FluxCode,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you visit fluxcode.studio or use our services. This policy applies to visitors worldwide and addresses requirements under GDPR (EU/EEA), CCPA (California), PIPEDA (Canada), LGPD (Brazil), and POPIA (South Africa).
2. Information We Collect
We may collect the following types of information:
- Contact Information: Name, email address, and company name when you submit our contact form or subscribe to our newsletter.
- Usage Data: Information about how you interact with our website, including pages visited, time spent, and referring URLs. We do not use third-party analytics or tracking tools.
- Technical Data: Browser type, device type, and operating system collected automatically. IP addresses are processed by our hosting provider (Vercel) for CDN routing but are not stored by FluxCode.
3. Legal Basis for Processing (GDPR)
For EU/EEA residents, we process your data under the following legal bases:
- Consent: When you submit our contact form with the consent checkbox, or subscribe to our newsletter.
- Legitimate Interest: To improve our website and ensure security.
- Contract Necessity: To respond to project inquiries and fulfill service agreements.
4. How We Use Your Information
- To respond to your inquiries and project requests
- To send newsletter updates you've subscribed to
- To improve our website and services
- To comply with legal obligations
5. Data Sharing & Third-Party Processors
We do not sell, trade, or rent your personal information to third parties. We share data only with trusted service providers who process data on our behalf, subject to data processing agreements:
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Vercel | Hosting & CDN | Request logs (minimal) | Global CDN |
| Neon | Database hosting | Contact & newsletter data | AWS US-East-1 |
| Resend | Email delivery | Name, email address | US |
| Wasabi | Media file storage | Uploaded files only | US-East-1 |
For EU residents: data transfers to US-based services are protected by Standard Contractual Clauses (SCCs) where applicable.
6. Data Retention
- Contact submissions: Retained for 12 months or until resolved, then deleted.
- Newsletter subscribers: Retained until you unsubscribe. Unsubscribe records are kept for compliance purposes.
- Authentication sessions: Admin sessions expire after 30 days.
- Media files: Retained until deleted by an administrator.
- Access logs: Retained by Vercel for up to 30 days.
You may request deletion of your data at any time by contacting us at hello@fluxcode.studio.
7. Cookies & Consent
Our website uses only essential cookies required for site functionality. We do not use tracking cookies, third-party advertising cookies, or analytics scripts.
- Cookie consent preference: Stored in your browser's localStorage to remember your choice.
- Authentication cookies: Used for admin dashboard access only (NextAuth session).
You can manage or clear cookies at any time through your browser settings. Our cookie consent banner appears on your first visit and respects your choice.
8. Your Rights
Depending on your location, you may have the following rights:
GDPR (EU/EEA Residents)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
We will respond to GDPR requests within 30 days.
CCPA (California Residents)
- Right to know what personal information we collect
- Right to delete your personal information
- Right to opt-out of the sale or sharing of personal information
- Right to non-discrimination for exercising your rights
We do not sell or share your personal information with third parties for their direct marketing purposes.
Other Jurisdictions
Residents of Canada (PIPEDA), Brazil (LGPD), and South Africa (POPIA) may exercise equivalent rights by contacting us. We will process all requests in accordance with applicable local law.
9. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Hashed authentication credentials (bcrypt)
- Input sanitization to prevent injection attacks
- Security headers (HSTS, CSP, X-Frame-Options)
- File upload validation and size limits
However, no method of transmission over the internet is 100% secure.
10. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected individuals via email within 72 hours of becoming aware of the breach, as required by GDPR. We will also notify relevant supervisory authorities where applicable.
11. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
12. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. We will notify newsletter subscribers of material changes via email. Continued use of our website constitutes acceptance of any changes.
14. Contact Us
If you have questions about this privacy policy, wish to exercise your data rights, or need to submit a data request, contact us at hello@fluxcode.studio.
FluxCode Studio LLC
Email: hello@fluxcode.studio
Data Controller: Jon Rezin