Privacy Policy

How Codalyn collects, uses, and protects personal information.

Last updated: 2026-07-11

This Privacy Policy describes how Codalyn ("Codalyn," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Tower application, related APIs, the Beacon extension (when connected to Tower), and our websites at https://tower.codalyn.app and https://codalyn.app (collectively, the "Service").

This Policy applies to visitors, account holders, workspace members, and billing contacts. It does not apply to third-party websites or services that we do not control.

1. Information we collect

We collect information in three broad categories:

Information you provide

  • Account data: name, email address, password (stored in hashed form), profile details, and authentication session data.
  • Workspace data: workspace names, membership, roles, invitations, and settings you configure.
  • Billing data: subscription plan, billing status, and payment-related identifiers processed by Stripe (we do not store full payment card numbers).
  • Support and communications: messages you send to us, including email to support@codalyn.app.
  • Content you submit: files, images, CMS-related data, and other Customer Content processed to provide the Service.

Information collected automatically

  • Usage and device data: pages viewed, features used, API usage counts, IP address, browser type, operating system, referral URLs, and timestamps.
  • Log and diagnostic data: server logs, error reports, and performance data collected through Sentry and similar tools.
  • Analytics data: product analytics events collected through PostHog when enabled, used to understand feature adoption and improve the Service.
  • Cookies and similar technologies: session cookies required for authentication and security, and optional analytics cookies as described below.

Information from third parties

  • Webflow: when you connect a Webflow account, we receive OAuth tokens and Webflow site, CMS, asset, and related metadata needed to operate integrations.
  • Stripe: payment status, customer identifiers, and subscription metadata.
  • Identity providers: if we offer social or SSO sign-in in the future, profile information from those providers.

2. How we use information

We use personal information to:

  • create and manage accounts and workspaces;
  • authenticate users and maintain security;
  • provide, operate, and improve the Service;
  • process subscriptions and enforce usage limits;
  • send transactional email (verification, invitations, billing notices) via providers such as Resend;
  • respond to support requests;
  • monitor performance, debug errors, and prevent abuse;
  • comply with legal obligations; and
  • with your consent where required, send product updates or marketing communications (you may opt out).

We do not sell your personal information.

3. Legal bases for processing (EEA, UK, and Switzerland)

Where applicable, we rely on:

  • Contract: to provide the Service you request.
  • Legitimate interests: to secure and improve the Service, prevent fraud, and understand usage, balanced against your rights.
  • Consent: for optional analytics or marketing where required.
  • Legal obligation: to comply with applicable law.

4. How we share information

We share personal information only as needed:

RecipientPurpose
Service providersHosting (e.g., Vercel), database (e.g., Neon), email (Resend), payments (Stripe), analytics (PostHog), error monitoring (Sentry), and file storage (Vercel Blob) — each processes data on our behalf under contractual safeguards.
WebflowWhen you authorize a connection, as required by your use of Webflow integrations.
Workspace membersInformation visible within a shared workspace according to your role and settings.
Legal and safetyWhen required by law, to protect rights and safety, or in connection with a merger or acquisition with notice where required.

We require processors to handle personal information only for authorized purposes and in accordance with applicable data protection law.

5. Cookies and analytics

We use:

  • Strictly necessary cookies for authentication, session management, and security. These cannot be disabled while using the signed-in Service.
  • Analytics cookies (PostHog) to understand aggregate product usage. These load only after you grant consent to the "measurement" category through our consent banner.

Consent management

Our websites show a consent banner (powered by c15t) before any non-essential cookies or analytics scripts run:

  • Analytics does not load, set cookies, or transmit data until you accept the "measurement" category.
  • Your choice is stored locally on your device (browser storage and a consent cookie); we do not maintain server-side consent records.
  • You can review, change, or withdraw your consent at any time using the "Cookies" link in the site footer. Withdrawing consent stops analytics collection for subsequent activity.

You can also control cookies through browser settings. Disabling necessary cookies may limit Service functionality.

6. Data retention

We retain personal information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type:

  • Account and workspace data: retained while your account exists and for a reasonable period after deletion for backup and legal purposes.
  • Billing records: retained as required for tax, accounting, and fraud prevention.
  • Logs and analytics: retained for limited periods according to provider settings and operational needs.

When you delete your account or workspace, we delete or anonymize personal information within a reasonable timeframe, except where retention is required by law.

7. Security

We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and secure credential handling. No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials.

8. International transfers

We may process and store information in the United States and other countries where we or our service providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for cross-border transfers.

9. Your rights and choices

Depending on your location, you may have rights to:

  • access, correct, or delete personal information;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is consent-based; and
  • lodge a complaint with a supervisory authority.

To exercise these rights, contact support@codalyn.app. We may verify your identity before responding. Some requests may be limited by law or legitimate business needs (for example, retaining billing records).

Marketing: you may opt out of promotional email using the unsubscribe link in those messages.

Account deletion: account holders may request deletion through account settings or by contacting us.

10. California privacy notice (CCPA/CPRA)

If you are a California resident, you have additional rights including knowing categories of personal information collected, requesting deletion, and opting out of "sale" or "sharing" as defined by California law. We do not sell personal information. To submit a request, email support@codalyn.app. We will not discriminate against you for exercising privacy rights.

11. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated Policy and revise the "Last updated" date. Material changes will be communicated through the Service or by email where appropriate. Continued use after changes become effective constitutes acceptance.

13. Contact us

Codalyn
Privacy inquiries: support@codalyn.app

For questions about these Terms, see our Terms of Service.

Effective date: 2026-07-11