Privacy policy
Last updated: June 12, 2026
At EAN CODA we take privacy seriously. This policy explains what personal data we process when you use the eancoda.com website or buy our EAN barcodes, for what purpose, and what rights you have. Processing is governed by the General Data Protection Regulation (GDPR) and other applicable law.
1. Data controller
The controller is Digisini LLC, a company incorporated in the United States that operates the EAN CODA brand. For any privacy matter you can reach us at info@eancoda.com or through the website's contact form.
2. What data we process
- Purchase data: email address (essential to send you the codes) and, if you provide them, name, company details and billing details (tax ID, address).
- Contact data: name, email address and the message you send us through the form.
- Payment data: you enter these directly into the secure payment gateway (Stripe). EAN CODA does not store your full card details; we only receive the payment confirmation.
- Technical data: we use privacy-friendly web analytics (Plausible), without cookies and with aggregated metrics; we do not build profiles or identify you.
3. Purposes and legal basis
- Processing your order (generating and sending the codes, managing your account and support) — basis: performance of the contract.
- Invoicing and accounting/tax obligations — basis: compliance with a legal obligation.
- Handling your enquiries from the contact form — basis: your consent / pre-contractual steps.
- Security and abuse/fraud prevention and aggregated site analytics — basis: legitimate interest.
4. Retention
We keep your data for as long as the contractual relationship lasts and, afterwards, for the periods required by law (especially tax and commercial ones). Contact enquiry data is kept for as long as needed to assist you and, where applicable, to evidence the handling.
5. Recipients and processors
We do not sell or share your data with third parties for commercial purposes. We share strictly necessary data with providers acting as our data processors: payment gateways (Stripe), our email and hosting provider, and the cookieless analytics tool (Plausible). Each one processes data under its own safeguards and only on our instructions.
6. International transfers
As the controller (Digisini LLC) is located in the United States and some providers may process data outside the European Economic Area, such transfers are carried out with the appropriate safeguards provided for by the GDPR (for example, standard contractual clauses or recognised transfer frameworks).
7. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given. To do so, write to info@eancoda.com stating the right you wish to exercise. If you believe we have not handled your request properly, you may lodge a complaint with the competent supervisory authority (in Spain, the Spanish Data Protection Agency, www.aepd.es).
8. Security
We apply reasonable technical and organisational measures to protect your data. The site runs over encrypted connections (SSL/TLS) and payment is handled through certified gateways.
9. Changes to this policy
We may update this policy to reflect legal or service changes. We will always publish the current version on this page with its update date.