Privacy Policy

Last updated: June 2025

1. Who we are

Codici is operated by codi.ci. References to "we", "us", or "our" in this policy refer to the operator of this platform.

2. What data we collect

Account data

When you create an account we collect your name and email address. If you belong to an organization account, we also store your role within that account.

Lookup data

We do not store the content of your lookups — not the product description you submit, nor the HS code or classification result we return. We only store usage metadata: which user or API key made the request, the originating IP address, and the timestamp. This is used for billing, rate-limiting, and security purposes only, so there are no compliance or data sovereignty concerns around the content of what you look up.

Payment data

We do not take payments through this platform and never handle your card details. Subscriptions are invoiced separately, and we store only the billing name, address and email you give us for that purpose.

Usage and technical data

We log each lookup against your account (user or API key, originating IP address, timestamp) for billing, rate-limiting and security purposes, together with a record of administrative actions taken on your account. As above, none of this includes the content of your lookups.

3. How we use your data

  • To provide the service: process lookups, apply your plan allowance, and prepare invoices.
  • To communicate with you: account and sign-in emails, plan or allowance notices, and service updates.
  • To improve the service: analyze aggregate usage patterns (never individual lookup content).
  • To comply with legal obligations.

4. Data sharing

We share your product descriptions with our classification technology partner solely to perform the classification you requested. That partner processes this data under its own privacy policy.

We do not sell your data to any third party.

5. Data retention

We retain the usage records described above for as long as your account is active, plus 12 months after account closure. There is no stored history of what you looked up to delete, because we never keep it.

Billing records are retained for 7 years to comply with financial regulations.

6. Your rights

Under GDPR (if applicable to you), you have the right to access, correct, or delete your personal data; to restrict or object to processing; and to data portability. To exercise these rights, contact us via the contact page.

7. Cookies

We use a single session cookie to keep you logged in. We do not use tracking or advertising cookies.

8. Security

Passwords are stored as bcrypt hashes. API keys are stored as SHA-256 hashes; the raw key is shown only once. All traffic is encrypted via HTTPS.

9. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email.

10. Contact

For privacy questions, please use our contact form.