CaeliCode collects the information needed to receive a message, manage an optional subscription, protect its forms from abuse, and understand aggregate site traffic.
Summary
- Contact-form details are sent to the CaeliCode support inbox.
- Newsletter addresses remain pending until the subscriber explicitly confirms by POST, and every delivery must include an unsubscribe route.
- Contact handling includes the request IP in its administrative record; newsletter storage keeps only a keyed IP hash while confirmation is pending.
- Plausible is used for aggregate website analytics.
- CaeliCode does not sell personal information or run advertising trackers on this site.
Information collected
The contact form collects the fields you submit, which may include your name, email address, phone number, company or team, inquiry type, timing, team context, message, and newsletter preference. The newsletter form collects your email address. The server also receives normal request information such as your IP address and browser headers.
Form endpoints use a short-lived security token, a hidden spam field, and rate limiting. Newsletter rate-limiting records contain a keyed one-way hash derived from the requesting IP address and submission timestamps; the raw IP is not written to the newsletter store. Timestamps older than the 24-hour limit window stop counting and are removed the next time subscription rate state is updated.
How the information is used
Contact details are used to read and respond to your inquiry. If you explicitly select the newsletter option, the address is stored as pending and receives a link to a read-only confirmation page; it becomes active only after the confirmation form is submitted. Confirmation links expire after 48 hours. Pending records older than 30 days become eligible for removal during the next newsletter state-maintenance operation. The newsletter application record stores confirmation and unsubscribe bearer tokens only as cryptographic hashes. The pending IP hash is cleared on confirmation.
Service providers
The site necessarily relies on its web-hosting and email-delivery infrastructure to serve pages and deliver form messages. The current public code does not identify those vendors, so this policy does not name or imply a specific provider.
Plausible Analytics is loaded for aggregate traffic measurement. Plausible is designed to operate without tracking cookies or cross-site advertising profiles. Its own privacy and data-handling terms apply to that service.
Retention and security
Contact messages may remain in the receiving mailbox while they are useful for the conversation and normal recordkeeping. An active newsletter record retains the delivery address until unsubscribe or a deletion request. Unsubscribe immediately removes the clear address and request identifier from that record. Unless a later re-opt-in is explicitly confirmed, a keyed email suppression identifier, bounded unexpired unsubscribe-token hashes, and timestamps are retained for the 180-day suppression window, then removed during the next newsletter state-maintenance operation. A confirmed re-opt-in atomically replaces the suppression record with the newly active consent record. Maintenance is triggered by newsletter state changes rather than an exact-time deletion scheduler.
Reasonable technical controls are used, including HTTPS, form tokens, atomic rate limiting, input validation, and a private newsletter store located outside the public website and deployment directory. No internet service can guarantee absolute security.
Your choices
You may avoid the forms and email directly. You may decline the optional newsletter checkbox. Every newsletter delivery must include a token-based unsubscribe link and standards-style one-click unsubscribe support. To request access, correction, or deletion of information you submitted, email support@caelicode.com. Requests will be handled subject to applicable law and any legitimate need to retain limited records.
Contact
Privacy questions and deletion requests: support@caelicode.com.