native codeLas Vegas, NV · available for work

Privacy Policy

What personal information we handle and why. How long we keep it, who else sees it, and how you get it back or deleted.

Version
1.0
Effective
20 August 2026
Applies to
Native Code LLC

Section 1Who we are and what this covers

Native Code LLC is a limited liability company registered in the State of Nevada, United States, working out of Las Vegas, Nevada. In this policy, "we", "us" and "our" mean Native Code LLC.

This policy covers:

  • this website at nativecodeapps.com and anything served from it;
  • every mobile application we publish under our own name on the App Store or Google Play;
  • every application we publish on the Shopify App Store;
  • any software we host and operate as a subscription service.

Individual applications sometimes handle types of information this general policy does not describe. Where that is true, the application has its own supplement, the store listing links to it directly, and the supplement controls where the two differ.

Section 2The two roles we play

Which privacy rules apply to a piece of information depends on why we are holding it. We hold information in two different roles, and it matters which one you are dealing with.

We are the controller of our own users' information
When you visit this website, send us a message, create an account with us, or subscribe to something we sell directly, we decide what is collected and why. We are the controller. This policy is our disclosure to you, and you exercise your rights directly with us.
We are a processor of our customers' information
When a business hires us to build or run software, and when a merchant installs one of our applications on their store, the information that flows through that software belongs to them. They decide what is collected and why. We only act on their instructions. We are the processor, and they are the controller.
If you are a customer of one of our clients

If you bought something from a store running one of our applications, or used software we built for another company, we are almost certainly holding your information as a processor and not as a controller. Your rights run against that business first. Contact them, and they will instruct us. If you contact us directly we will tell you who the controller is, and we will forward your request to them without delay.

Our obligations as a processor are set out in the Data Processing Addendum, which forms part of our agreement with every business customer and merchant.

Section 3Information we collect

Information you give us

  • When you use a form on this site. Your name, your email address, the company you are writing about if you tell us, and the message itself. Nothing on this site requires you to give us a phone number or a postal address.
  • When you create an account in one of our applications. Typically an email address and a password, or a sign in through Apple, Google or Shopify. Some applications need more, and the application’s own supplement says what.
  • When you pay us. Our payment processor collects and holds your card details. We never see or store a full card number. We receive the last four digits, the card type, the expiry, the billing country, and whether the payment succeeded.
  • When you send us support or a bug report. Whatever you choose to include, which sometimes includes screenshots or files. Please do not send us more than the problem requires.

Information collected automatically

  • Server logs. Our hosting provider records the request path, the time, the response status, the browser’s user agent and the IP address that made the request. These logs exist to keep the service running and to spot abuse.
  • Website analytics. We do not run any at the moment, so nothing on this website counts or records your visit beyond the server logs above. If we add analytics we will use a service that sets no cookies and builds no profile of you across sites, and we will say so here before it goes live.
  • Application diagnostics. When one of our applications crashes or errors, we may record the device model, the operating system version, the application version and a technical description of what failed.

Information we receive from someone else

  • App stores. Apple and Google tell us that a purchase, a renewal, a refund or a cancellation happened, and give us an anonymous identifier for the transaction. They do not give us your name, your email address or your payment details.
  • Shopify. When a merchant installs one of our applications, Shopify gives us the store details and the specific data the application asked permission for. We ask for the minimum the application needs to work.
  • Sign in providers. If you sign in with Apple or Google, they tell us an identifier and, depending on your own choices with them, an email address. Apple’s private relay addresses work normally with our applications.

Section 4Why we use it, and our legal basis

If you are in the United Kingdom, the European Economic Area or another place with similar law, we need a lawful basis for every use. Here is ours.

What we doWhyLegal basis
Run your account and provide the software you signed up forWithout it there is no servicePerformance of a contract
Take payment, handle renewals and refundsYou bought somethingPerformance of a contract
Answer a message you sent usYou asked us a questionLegitimate interests, and consent where you gave it
Keep the service up, fix faults, investigate abuseThe service has to work and stay safeLegitimate interests
Count page views and understand which pages are usefulTo improve the site without tracking anyoneLegitimate interests
Send service email such as a receipt or a security noticeYou need to knowPerformance of a contract, and legal obligation
Send an email you asked to receiveYou opted inConsent, which you can withdraw at any time
Keep tax and accounting recordsThe law requires itLegal obligation
Establish, defend or exercise a legal claimRare, but it happensLegitimate interests, and legal obligation

Where we rely on legitimate interests, we have weighed our interest against your privacy and concluded the use is one you would reasonably expect. You can object, and we will stop unless we have a compelling reason not to. See Your rights.

Section 5Who else sees it

We use a small number of service providers to run the business. Each one only receives what it needs to do its job, each is bound by a contract that limits what it may do with the information, and none of them may use it for their own purposes.

The current list, with what each one does and where it runs, is published at Subprocessors. That page is the authoritative list and we keep it current.

Beyond those providers, we disclose information in only three situations:

  • When you tell us to. For example, connecting one of our applications to another service you use.
  • When the law requires it. A valid subpoena, court order or lawful request. We check that a request is valid, we give it the narrowest reading we reasonably can, and we tell you it happened unless we are legally prohibited from doing so.
  • If the business is sold. If Native Code LLC or one of its products is acquired, information transfers to the buyer, who remains bound by this policy until you are told otherwise. You will be told before anything about your information changes.

Section 6What we never do

These are commitments, not aspirations. If any of them ever changes, we will say so plainly and in advance.

  • We do not sell personal information, and we never have.
  • We do not share personal information for cross context behavioral advertising, which is the specific thing California, Colorado, Connecticut, Virginia, Texas and other states give you the right to opt out of. There is nothing here for you to opt out of.
  • We do not put advertising networks or advertising SDKs in our applications.
  • We do not sell or supply information to data brokers.
  • We do not use your information to train machine learning models for anyone else.
  • We do not read a business customer’s data for our own purposes. We look at it only to fix a fault they reported, or where they instruct us to.
  • We do not make decisions about you by automated means that produce legal or similarly significant effects.
  • We do not track you. Our applications do not ask for the advertising identifier your phone provides, do not use it, and do not link what you do in one of our apps to anything you do in another company’s app or website. That is what Apple’s App Tracking Transparency prompt exists to ask about, which is why you will never see it in one of our apps: there would be nothing to consent to.

Section 7Categories, in the words the law uses

California and several other states require this stated using their own category names, so here it is in their words rather than ours. This covers the last twelve months.

Statutory categoryDo we collect itWhy, and who receives it
Identifiers
name, email, IP address, account ID
YesTo run your account and answer you. Shared with our hosting, database and email providers only
Customer records
as defined by Cal. Civ. Code 1798.80
YesName and contact details for billing. Shared with our payment processor
Commercial information
purchases, subscriptions
YesTo take payment, handle renewals and keep tax records
Internet activity
pages viewed, referrer, diagnostics
YesTo keep the service running and see which pages are useful. Not linked to you and never used across other websites
GeolocationCountry onlyDerived from the IP address for aggregate counts, then discarded. We never collect precise location
Sensitive personal information
government ID, financial account, precise location, race, religion, health, biometrics, contents of your mail
NoWe do not collect any of it, so there is nothing for you to limit
Biometric, sensory, education, professional dataNoNot collected
Inferences and profilesNoWe do not build a profile of you or infer anything about you

We have not sold or shared any category of personal information in the last twelve months, and we have not disclosed any of it for a business purpose beyond the providers listed on the Subprocessors page.

Section 8What you have to give us, and what happens if you do not

None of this is a legal requirement. It is only ever what the thing you asked for needs in order to work.

  • To use this website: nothing. There is no sign in, no cookie and no tracker on it.
  • To send us a message: a name, an email address and the message. Without an address we have no way to reply.
  • To hold an account: an email address, which is how we identify you and how we send security notices. Without it we cannot give you an account.
  • To buy something: payment details, which go to our payment processor rather than to us, and the billing country, which we are required to record for tax. Without them we cannot take payment.

Nothing beyond that is required, and declining to give us anything optional never changes the service you get.

Section 9How long we keep it

We keep information for as long as it is doing a job, then we delete it. Where the law sets a minimum, we keep it that long and no longer.

WhatHow longWhy
Your account and the content in itUntil you delete it, then 30 daysThe 30 days is a grace period in case the deletion was a mistake
Backups containing deleted dataUp to 35 days after deletionBackups roll over on a schedule and cannot be edited in place
Messages you send through a form on this site, held in our email inbox24 monthsSo we can pick up a conversation you started. The inbox is hosted by Google, which is listed as a subprocessor
Invoices, receipts and tax records7 yearsRequired by tax law. These survive account deletion
Server access logs30 daysOperations and abuse investigation
Crash and error diagnostics90 daysLong enough to find a pattern, short enough not to accumulate
Aggregate analytics with no personal information in itIndefinitelyCounts of page views cannot identify anyone
A record that a deletion request was made and honouredKeptPrivacy law requires us to be able to show we complied

Section 10Deleting your account and your data

Every application we publish that lets you create an account also lets you delete it from inside the application, without asking us and without contacting support. You can also do it from the web, on any device, whether or not the application is still installed.

Delete your account from the web.

When you delete an account we remove your profile, your settings, the content you created in the application, and your email address from our active systems within 30 days. What survives, and why:

  • Financial records we are legally required to keep, as set out above. These are not linked back to an active account.
  • Backups, until they age out on their normal schedule within 35 days. Backups are not used to restore a deleted account.
  • A minimal record that the deletion happened, so we can prove we honoured it.
  • Anything a court order or an active legal hold requires us to preserve. If this applies to you we will tell you.

Deleting an account you created through Apple, Google or Shopify does not cancel a subscription you bought through them. See Billing and Refunds for how to cancel in each place.

Section 11Your rights and how to use them

You have rights over your information. Which ones depend on where you live, but we apply the strongest of them to everybody, because running two standards is a good way to get one of them wrong.

  • Know and access. Ask what we hold about you and get a copy.
  • Portability. Get that copy in a format you can take elsewhere.
  • Correct. Fix something that is wrong.
  • Delete. Have it erased, subject to the exceptions in Section 10.
  • Opt out. Of sale, of sharing for advertising, and of profiling. We do none of these, so there is nothing to opt out of, but the right exists and we honor it.
  • Limit use of sensitive information. We do not collect sensitive personal information as those laws define it.
  • Object and restrict. Object to a use based on legitimate interests, or ask us to pause a use while a dispute is resolved.
  • Withdraw consent. Where a use runs on consent, take it back at any time. It does not undo what was lawful before you withdrew.
  • No retaliation. We will never charge you more, give you a worse service, or refuse to serve you because you used a right.

How to make a request. Use the privacy rights request form. We answer within 45 days, and we will tell you if we need an extension the law allows. We may need to verify who you are before we hand over data, and we will only ask for what verification actually requires.

Authorised agents. Someone may make a request for you. We will ask for proof that you gave them permission, and we may still verify you directly.

Appeals. If we refuse a request, we will tell you why, and you can appeal. Reply to our decision or use the same form and mark it as an appeal. We answer appeals within 45 days with a written explanation. If we refuse the appeal we will tell you how to complain to your state’s attorney general or to your data protection authority. Residents of the United Kingdom and the European Economic Area may also complain to their supervisory authority directly, at any time, without appealing to us first.

Global Privacy Control. Our website honours the GPC browser signal. As we do not sell or share personal information, the signal changes nothing in practice, but it is respected.

Nevada residents. Nevada law gives you the right to tell a company not to sell your covered information. We do not sell it. You can still submit the request through the same form and we will record it.

Section 12Children

Our software is built for adults doing work. It is not directed to children, and we do not knowingly collect personal information from anyone under 13, or under 16 where local law sets that age.

On Google Play our applications declare a target audience of adults only. On the App Store they carry an age rating consistent with that.

If you believe a child has given us personal information, tell us through the contact form and we will delete it and the account attached to it.

Section 13Where your information is stored

We are based in the United States and our services run on infrastructure in the United States. If you use our software from outside the United States, your information will be transferred to and processed there.

For information covered by United Kingdom or European law, we rely on the European Commission’s Standard Contractual Clauses, and the United Kingdom Addendum to them, with every provider that receives such information. We have assessed those transfers and apply encryption in transit and at rest as an additional safeguard. Copies of the clauses we use are available on request through the contact form.

Section 14Our representative in Europe and the United Kingdom

Article 27 of the GDPR requires some companies outside Europe to appoint a representative there. It does not apply where the processing is occasional, does not involve large scale handling of special category data, and is unlikely to result in a risk to people’s rights.

We rely on that exemption today. Our processing is occasional, we hold no special category data, and the service is aimed at businesses rather than at consumers in the European Economic Area or the United Kingdom. If that stops being true we will appoint a representative and name them here before we rely on it.

In the meantime, people in the EEA and the UK can reach us directly through the contact form, and can complain to their own supervisory authority at any time without going through us first.

Section 15How we protect it

We encrypt information in transit and at rest, restrict access to the smallest number of people who need it, isolate one customer’s data from another’s at the database level, and keep credentials out of source code.

Our practices, our incident response, and how to report a vulnerability to us are described in full on the Security page.

No system is perfectly secure. If a breach affects your information we will notify you and the relevant regulator within the time the law requires, which is 72 hours of becoming aware for information covered by European law, and without unreasonable delay everywhere else.

Section 16Cookies and similar technologies

This website sets no advertising cookies, no tracking cookies and no third party cookies. There is no consent banner because there is nothing to consent to. The full detail, including the few strictly necessary items our applications use, is on the Cookie Policy page.

Section 17Our mobile and merchant applications

Store reviewers and merchants generally need a specific answer rather than a general one. The App Store Disclosures page answers Apple, Google and Shopify separately, in the terms each of them uses, and links back into the relevant part of this policy.

Every application also has its own supplement covering exactly what that application collects and which device permissions it asks for. The link is in the application’s store listing and inside the application itself.

Section 18Changes to this policy

When we change this policy we publish the new version here with a new version number and effective date, and we record what changed on the legal index.

If a change materially reduces your privacy, we will give you notice before it takes effect, by email where we have your address and in the application where we do not, and we will not apply it retroactively to information already collected.

Section 19How to reach us

The quickest way to reach us is the contact form. It comes straight to us here in Las Vegas, a person reads every message, and we answer within one business day.

For a privacy right, use the privacy rights request form instead, so your request is logged and tracked against the statutory deadline.

We have not appointed a Data Protection Officer, because our processing does not meet the threshold that requires one. Privacy questions are handled by the company’s management directly.