Privacy Policy
1. Who We Are and What This Covers
1.1 Codicen LLC ("we," "us," "our") operates Codicen, a subscription service that identifies recurring regulatory, licensing, tax, and insurance obligations applicable to businesses in the trades in California and sends deadline reminders (the "Service").
1.2 This Privacy Policy explains what personal information we collect, why, who we share it with, how long we keep it, and what rights you have. It applies to our website, the Service, and our email and text-message communications. This Policy also serves as our notice at collection under California Civil Code § 1798.100: the categories we collect, the purposes for collection, and our retention periods are set out in Sections 2, 3, and 7, and we do not sell or share personal information (Section 5).
1.3 It does not apply to any third-party website or service we link to, including government filing portals and Stripe. Those have their own policies.
1.4 The Service is for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
2. Personal Information We Collect
The categories below use the terms defined in the California Consumer Privacy Act.
| CCPA category | What we actually collect | Where it comes from | Why we collect it |
|---|---|---|---|
| Identifiers | Name, business name, business mailing address, email address, mobile telephone number, account username, IP address, device and browser identifiers | You, during signup and in your profile; automatically from your device | To create and secure your account, to identify which obligations apply, to send reminders, to provide support |
| Commercial information | Subscription plan, billing history, payment status, cancellation date, support tickets | You; Stripe | To bill you, to provide the Service, to keep records |
| Professional or employment-related information | Trade and license classification, CSLB licence number and status, bond and insurance carrier and expiry, entity type, Secretary of State entity number, city and county of operation, whether you have employees, other licences and registrations you hold | You, during onboarding; public records from the California Secretary of State, the Contractors State License Board, and other public sources | This is the core input. Your obligations calendar is generated from it |
| Internet or network activity | Pages viewed, features used, links clicked, session timestamps, referring URL, email opens and clicks, text-message delivery status | Automatically, through our own logs and our email and messaging providers | To operate and secure the Service, to diagnose problems, to understand which reminders work |
| Geolocation data | Approximate location inferred from IP address; the business city and county you tell us | Automatically; you | To identify city and county obligations, and for security |
| Inferences | The set of obligations and deadlines we determine apply to you | Derived by us from the above | To provide the Service |
2.1 What we do NOT collect. We do not ask for and do not want your Social Security number, driver's licence number, date of birth, bank account number, or full payment card number. Payment card details go directly to Stripe and never touch our systems. If you send us any of these, we will delete them.
2.2 Sensitive personal information. We do not collect "sensitive personal information" as defined by the California Privacy Rights Act, and we do not use or disclose any information for the purpose of inferring characteristics about you. Note that a sole proprietor's Employer Identification Number or business address may also be personal information; where that is so, we treat it under this policy the same as any other identifier.
2.3 Public records. Much of what the Service pre-fills — licence status, entity registration, expiry dates — comes from records the State of California publishes. Information lawfully made available from federal, state, or local government records is excluded from the CCPA definition of personal information. We still handle it carefully, but you should understand that this information is public regardless of anything we do.
3. How We Use Personal Information
To create, authenticate, and secure your account;
To determine which obligations apply to your business and generate your deadline calendar;
To send you reminder emails at approximately 60, 30, and 7 days before a deadline and reminder text messages at approximately 7 days;
To send transactional messages: receipts, subscription acknowledgements, renewal and price-change notices, cancellation confirmations, security alerts, and service announcements;
To process payments through Stripe and to manage your subscription;
To provide customer support and respond to your questions;
To operate, maintain, debug, monitor, and improve the Service, including analyzing which reminders are opened and acted on;
To detect, investigate, and prevent fraud, abuse, scraping, and security incidents;
To create aggregated and de-identified statistics that do not identify you or your business;
To send marketing emails about our own services, where you have not opted out; and
To comply with law and to establish, exercise, or defend legal claims.
3.1 New purposes. We will not use your personal information for a materially different purpose than those disclosed above without giving you notice and, where required, obtaining your consent.
4. Text Messages — Specific Terms
This section must stay, and must stay worded roughly like this Mobile carriers, through the A2P 10DLC registration process, require that a brand sending application-to-person text messages publish a privacy policy containing an explicit statement that mobile opt-in data and consent are not shared with third parties. Campaign registrations are routinely rejected for its absence. If your developer or a copy editor deletes Section 4.4 because it looks redundant, your SMS reminders stop working. |
4.1 Consent. If you provide your mobile number and opt in, you consent to receive recurring automated text messages about your account and your deadlines. Consent is not a condition of purchase; the Service works with email reminders only.
4.2 Frequency and cost. Frequency varies with the number of deadlines on your calendar. Message and data rates may apply from your carrier. We do not charge for messages.
4.3 Opting out. Reply STOP to any message to stop text messages. Reply HELP for assistance. Opting out of text messages does not cancel your subscription and does not stop email reminders.
4.4 We do not share your mobile opt-in data. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the exceptions in Section 5 relating to service providers apply — text-message originator and aggregator services with whom we share information solely to deliver your messages — but under no circumstances will your mobile opt-in consent or telephone number be sold, rented, or shared for anyone else's marketing.
5. How We Share Personal Information
5.1 We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. We do not sell or share the personal information of any person we know to be under 16.
5.2 Service providers. We disclose personal information to vendors who process it on our behalf, under written contracts that limit them to processing it only for our purposes and prohibit them from selling it or using it for their own ends:
| Category of provider | What they receive | Purpose |
|---|---|---|
| Payment processing (Stripe, Inc.) | Name, email, billing address, payment method, subscription and transaction data | To process payments and manage subscriptions |
| Application hosting and database | All account and profile data | To host and operate the Service |
| Transactional and marketing email | Name, email address, message content, open and click data | To send reminders and account emails |
| Text messaging (originator/aggregator) | Mobile number, message content, delivery status | To send text reminders |
| Error monitoring and analytics | IP address, device and usage data, error diagnostics | To keep the Service working and secure |
| Customer support tooling | Name, email, ticket content | To answer your questions |
| Professional advisers (attorney, CPA) | Only what is necessary | To obtain professional advice |
5.3 Legal and safety. We may disclose personal information where we believe in good faith it is necessary to comply with law, a subpoena, or legal process; to enforce our Terms of Service; to protect the rights, property, or safety of any person; or to investigate fraud or a security incident.
5.4 Business transfer. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you and, where required, give you a choice.
5.5 With your direction. We will share your calendar or profile with a third party — your attorney, CPA, or broker, for instance — when you ask us to.
5.6 Aggregated and de-identified information. We may create and disclose aggregated or de-identified information that cannot reasonably be used to identify you. We will maintain it in de-identified form and will not attempt to re-identify it.
5.7 We are not a data broker. We collect personal information directly from you and from public records in the course of providing you a service you subscribe to; we do not collect and sell the personal information of people with whom we have no direct relationship, and we are not required to register under California's Delete Act (Civ. Code § 1798.99.80 et seq.). If our practices ever change in a way that makes that law apply, we will register and update this Policy first.
6. Cookies and Tracking
6.1 We use cookies and similar technologies that are strictly necessary to operate the site and keep you logged in, and we may use a privacy-respecting analytics tool to understand aggregate usage.
6.2 We do not use third-party advertising cookies and we do not participate in cross-context behavioral advertising.
6.3 Global Privacy Control. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request under California law. Because we do not sell or share personal information, a GPC signal does not change how we handle your information — but we recognize and process it regardless.
6.4 Do Not Track. Browsers vary in how they implement Do Not Track signals and there is no common standard, so we do not respond to DNT headers separately from GPC.
7. How Long We Keep Information
| Type of information | Retention period |
|---|---|
| Account and profile data (including licence, trade, and location details) | For as long as your account is active, then 30 days after you close it, after which it is deleted or de-identified — unless a longer period is required below |
| Billing and transaction records | Seven (7) years, to meet tax and accounting record-keeping obligations |
| Automatic-renewal consent records, disclosure version shown, and acknowledgement emails | Four (4) years, as evidence of compliance with California's Automatic Renewal Law |
| Text-message consent and opt-out records | Four (4) years, as evidence of consent under the Telephone Consumer Protection Act |
| Reminder delivery logs | Two (2) years |
| Server, security, and access logs | Twelve (12) months |
| Support tickets and correspondence | Three (3) years |
| Aggregated or de-identified data | Indefinitely |
| Anything subject to a legal hold | Until the hold is lifted |
We keep each category only for as long as reasonably necessary for the purpose it was collected for, or as required by law.
8. Your California Privacy Rights
If you are a California resident, you have the following rights. We honor them regardless of whether we are currently a "business" subject to the CCPA thresholds.
Right to know. You may request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collecting it, and the categories of third parties to whom we disclose it.
Right to delete. You may request that we delete personal information we collected from you, subject to exceptions — for example, where we need it to complete a transaction, detect security incidents, or comply with a legal obligation.
Right to correct. You may request that we correct inaccurate personal information. You can correct most of it yourself in your profile, and doing so is faster.
Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. If that ever changes, we will update this policy and provide a "Do Not Sell or Share My Personal Information" link before doing so.
Right to limit use of sensitive personal information. We do not collect sensitive personal information, so this right does not currently apply.
Right to non-discrimination. We will not deny you the Service, charge you a different price, or provide a different quality of service because you exercised any of these rights.
Right to data portability. Where you request the specific pieces of information we hold, we will provide them in a portable and, to the extent technically feasible, readily usable format.
8.1 How to make a request. Email [email protected] with the subject line "Privacy Request," or write to us at the address in Section 12. Tell us which right you are exercising.
8.2 Verification. To protect you, we will verify your identity before acting — typically by confirming that the request comes from the email address on your account, and by asking you to confirm two pieces of information we already hold. We will not ask you to create an account to make a request.
8.3 Timing. We will acknowledge your request within ten (10) business days and respond within forty-five (45) calendar days. If we need more time, we will tell you within that period and may take up to a further forty-five (45) days.
8.4 Authorized agents. You may use an authorized agent, who must provide written permission signed by you, and we may ask you to verify your identity directly.
8.5 Cost. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will tell you why before charging or declining.
8.6 Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We make no such disclosures.
8.7 No financial incentives. We do not offer financial incentives, price differences, or service differences in exchange for the collection, sale, sharing, or retention of personal information. If we ever introduce a program that qualifies as a financial incentive under the CCPA (for example, a referral discount tied to contact information), we will provide the required notice and obtain opt-in consent before it operates.
9. Security
9.1 We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, multi-factor authentication on administrative accounts, access limited to those who need it, secrets held in a managed secret store, and periodic review of access.
9.2 No system is perfectly secure. We cannot and do not guarantee the security of any information, and you provide it at your own risk.
9.3 Breach notification. If a breach of your unencrypted personal information occurs, we will notify you as required by California Civil Code § 1798.82, in the most expedient time possible and without unreasonable delay.
9.4 Your part. Use a strong, unique password. Do not share your credentials. Tell us immediately if you believe your account has been accessed without authorization.
10. Where Information Is Processed
We and our service providers process personal information in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. The Service is intended for California businesses and we do not market it outside the United States.
11. Changes to This Policy
We may update this Privacy Policy. If a change is material, we will notify you by email to the address on your account and post the updated policy with a new "Last updated" date before it takes effect. Continued use after the effective date constitutes acceptance.
12. Contact Us
Codicen LLC
2108 N Street #12501, Sacramento, California 95816
Privacy requests: [email protected] | General: [email protected]
If you have a disability and need this policy in an alternative format, contact us and we will provide one.