Privacy Policy – DeskCodes
Legal

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, how we use it, and the rights you have over your personal information.

Last updated: 24 June 2025
Jurisdiction: New York, United States
Controller: DeskCodes LLC

1. Who We Are

DeskCodes LLC ("DeskCodes", "we", "our", "us") operates the website deskcodes.com and is the data controller responsible for your personal data.

Our principal address is 182-21 150th Avenue, Springfield Gardens, NY 11413, United States. We are subject to applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act (CCPA) where applicable.

If you have any questions about this policy or about how we handle your data, contact our team at contact@deskcodes.com.

2. Data We Collect

We collect personal data in the following ways:

CategoryExamplesSource
IdentityFirst name, last name, usernameYou provide it
ContactEmail address, phone number, billing/shipping addressYou provide it
TransactionOrder details, payment method type, purchase historyGenerated when you shop
TechnicalIP address, browser type, device info, pages visitedAutomatically via cookies
CommunicationsMessages sent via contact form, email exchangesYou provide it
MarketingEmail preferences, communication opt-insYou provide it / inferred
We never store full payment card details. All payment processing is handled by PCI-DSS-compliant providers (Stripe, PayPal). We only receive a transaction confirmation and last-4-digits reference.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Order fulfilment — processing your orders, arranging delivery, managing returns and refunds, sending order confirmations and shipping updates.
  • Business operations — preventing fraud, maintaining website security, improving our services, and understanding customer behaviour through analytics.
  • Marketing communications — sending you promotional emails or messages where you have opted in. You can unsubscribe at any time via the link in any email.
  • Legal compliance — retaining records for tax, accounting, and regulatory requirements (e.g., IRS reporting obligations).
  • Customer support — responding to queries and complaints submitted via our contact form or email.

We will never use your data for automated decision-making that produces significant legal effects without your explicit consent.

4. Data Sharing & Third Parties

We do not sell your personal data. We share data only where necessary with trusted third-party service providers who process data on our behalf:

  • Payment processors — Stripe Inc., PayPal, Klarna (secure payment handling).
  • Shipping partners — USPS, UPS, FedEx (order fulfilment and delivery).
  • E-commerce platform — WooCommerce / WordPress (our website and order management).
  • Email marketing — Mailchimp or Klaviyo (only if you have opted in to marketing communications).
  • Analytics — Google Analytics (anonymised usage data to improve our website).
  • Customer support — Help desk tools used to manage and respond to support tickets.

We may also disclose your data to law enforcement or regulatory authorities if required by applicable law, or to protect the rights and safety of our customers.

5. Cookies & Tracking

We use cookies and similar tracking technologies on our website. Cookies are small text files placed on your device that help us provide a better experience.

Cookie TypePurposeCan Opt Out?
EssentialShopping cart, login sessions, security tokensNo — required for site function
AnalyticsPage views, traffic sources, user behaviour (anonymised)Yes — via cookie banner
MarketingRemarketing ads, conversion tracking (Google, Meta)Yes — via cookie banner
PreferencesLanguage, currency, display settingsYes — via browser settings

You can manage cookie preferences through our cookie banner (shown on first visit) or via your browser settings. Disabling essential cookies may affect your ability to shop on our site.

6. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or alteration, including:

  • SSL/TLS encryption for all data transmitted between your browser and our servers.
  • Access controls ensuring only authorised personnel can access personal data.
  • Regular security assessments and software updates.
  • PCI-DSS-compliant payment processing — we never handle raw card data.
In the event of a data breach that poses a risk to your personal information, we will notify affected individuals and the relevant state authorities in accordance with applicable U.S. data breach notification laws.

7. Data Retention

We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.

Data TypeRetention Period
Order & transaction records7 years (IRS and federal tax compliance)
Account informationDuration of account + 2 years after last activity
Support / contact enquiries2 years from last communication
Marketing preferencesUntil you withdraw consent or unsubscribe
Analytics / technical data26 months (Google Analytics default)

When data is no longer required, it is securely deleted or anonymised so it can no longer be associated with you.

8. Your Rights

Under applicable U.S. privacy laws (including the CCPA for California residents), you have the following rights regarding your personal data. You can exercise these rights at any time by contacting us:

Right to KnowRequest disclosure of the personal data we have collected about you and how it is used and shared.
Right to CorrectAsk us to correct inaccurate or incomplete personal data we hold about you.
Right to DeleteRequest deletion of your personal data, subject to certain legal exceptions.
Right to Opt OutOpt out of the sale or sharing of your personal data for cross-context behavioural advertising.
Right to PortabilityReceive a copy of your data in a portable, machine-readable format where technically feasible.
Right to Non-DiscriminationWe will not discriminate against you for exercising any of your privacy rights.

We will respond to all verifiable requests within 45 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Federal Trade Commission (FTC) at ftc.gov or your state's Attorney General office.

9. International Data Transfers

Some of our third-party service providers may be based outside the United States. Where we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Transfers to countries or entities that provide adequate data protection standards.
  • Use of Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms with service providers.
  • Binding corporate rules or other legally recognised transfer mechanisms where applicable.

You can request details of the specific safeguards in place by contacting us at contact@deskcodes.com.

10. Children's Privacy

Our website and services are not directed at children under the age of 13. We do not knowingly collect personal data from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at contact@deskcodes.com and we will delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make significant changes, we will notify you by email (if you have an account) and update the "Last updated" date at the top of this page. Continued use of our website after changes are posted constitutes your acceptance of the revised policy.

12. Contact & Data Requests

For any privacy-related questions, data access requests, or complaints, please reach out through any of the following:

We aim to acknowledge all privacy requests within 48 hours and provide a full response within 45 calendar days as required by applicable U.S. privacy law.