PRIVACY
What we hold about you.
Written to be read, not to be survived. If anything below is unclear, ask us and we will explain it in plain words.
Last updated 13 August 2026
Who we are
CodiVibes provides software that lets small and mid-sized businesses across Europe build and run their own business systems, and a launch service where we build the first version with you. We operate from Bulgaria and serve customers throughout the European Union.
For anything in this policy — a question, a request, a complaint — use the contact form. It reaches us directly and we answer it ourselves.
What we collect, and why
If you only read the site
We count page views, language switches, clicks on the main buttons and which template pages get opened, so we know which parts of the site are worth keeping. Each browser is given a random identifier that we store in your browser's own storage. It is not linked to a name, and we never send it anywhere else.
We do not set any cookies, and we run no third-party analytics. No Google Analytics, no advertising pixel, no session recorder. We also do not store your IP address alongside these counts.
If you arrive from a campaign or a partner link, we keep the campaign tags from the address for as long as your browser holds them, so that if you later become a customer we can tell which channel or partner brought you. You can clear all of this at any time by clearing site data for codivibes.com in your browser.
If you ask us to get in touch
The enquiry form asks for your name, email, phone if you give one, your company, what your business does and what you need. We use it to reply to you and to prepare a proposal. We do not add you to a newsletter and we do not pass it to anyone else.
If you open an account
To run your account we hold your email address, your name if you give one, the country and language you chose, when you registered, and — if you were referred — the partner who referred you. If you sign in with a password we store it hashed, never in readable form. If you sign in with Google we store the account identifier Google gives us instead, and no password at all.
If you buy credits or a plan
We hold what you bought, what you paid, and the state of your subscription. For a company invoice we hold the billing details you enter: company name, EIK, VAT number, address, city, country and the person representing the company. Where you give a VAT number we check it against the EU VIES register and keep the result and the date, so we can show why an invoice was charged the way it was.
Your card details never reach us. Payment happens on Stripe's own pages; we receive only a reference, the amount and whether it succeeded.
What you build
The systems you build, and the data you put into them, are yours. We do not read them, mine them, or use them to train anything. We can reach them only when you ask us to — for support, or during a launch-service build — and only for as long as that takes.
Why we are allowed to hold it
- To give you what you asked for — running your account, your projects and your payments. Without this data there is no service.
- Because the law requires it — invoices and the accounting record behind them.
- Because we have a legitimate interest — the site counts above, keeping accounts secure, and answering an enquiry you sent us. This is the one ground you can object to, and you can object using the contact form.
Who else touches it
These are the only companies involved in running the service. Each one gets the minimum it needs, and none of them may use it for their own purposes.
| Who | What they do | What they see |
|---|---|---|
| OpenKBS | Runs the studio you build in, and the hosting behind it | Your account on the platform and the projects you create |
| Stripe | Takes the payment | Your card details and email — held by Stripe, not by us |
| Signs you in, if you choose the Google button; also serves the fonts this site uses | That you signed in here, and your email and name from your Google account | |
| Amazon Web Services | Hosts the site, the platform and the database | Stores the data described above, in the EU (Frankfurt) |
We do not sell data, and we do not share it for advertising. Where a provider processes data outside the EU, that transfer runs on the European Commission's standard contractual clauses.
How long we keep it
- Your account — while it is open, and up to 90 days after you close it, in case you come back.
- Invoices and payment records — 10 years, because Bulgarian accounting law says so.
- Enquiries — 24 months from your last message, then deleted.
- Site counts — 24 months, then deleted.
Your rights
Under the GDPR you can ask us to show you what we hold, correct it, delete it, restrict what we do with it, hand it to you in a portable form, or object to the processing we do on legitimate interest. Ask through the contact form. We answer within 30 days, and it costs nothing.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to the Bulgarian Commission for Personal Data Protection (cpdp.bg), or to the supervisory authority in the country where you live.
Security
Everything runs over HTTPS. Passwords are stored hashed and salted, never readable. Access to the customer database is limited to the people who need it to run the service. No system is perfect; if something goes wrong that puts your data at risk, we will tell you and the regulator within the time the law allows.
Changes
If we change this policy in a way that matters, we will say so on this page and date it. The date at the top is always the date of the current version.