Skip to main content
MalixCode
Back to site

privacy

Privacy Policy

This page explains what information MalixCode may process when someone browses the site, submits the contact form or gets in touch about a project.

Last updated: July 11, 2026

privacy

Privacy Policy

1. Overview

MalixCode is a portfolio and client-acquisition site for web design and development. This page describes the current technical handling of data when someone browses the site, submits a project or referral form, or contacts MalixCode directly.

2. Data processed

  • Basic technical data that may appear in hosting and security logs, including IP address, browser and device type, date, time, and requested URL.
  • Project-form data: name, project state, optional existing-site URL, preferred contact method, email, phone or Telegram, project goal, and consent confirmation.
  • Allowlisted attribution data: UTM parameters, GCLID, FBCLID, MSCLKID, page path, and referrer without query or hash values.
  • Referral-registration data: the referrer's own name and contact details, the generated personal code, and the technical link between that code and a project request submitted directly by the potential client.

After a form is submitted, the request is stored in protected server-side storage and is available through the private admin area.

3. How data is used

  • To review a request and reply through the selected contact method.
  • To create a personal referral link, contact the referrer about the program, and match the code to a project request submitted directly by the potential client.
  • To operate the site, prevent spam, and troubleshoot technical problems.
  • To measure privacy-safe funnel steps and traffic sources only after separate analytics consent.

4. Browser storage and attribution

  • The privacy choice is stored in localStorage under a site-specific technical key until the visitor changes it or clears browser data.
  • First-touch and last-touch attribution is stored in sessionStorage for the browser session and is submitted with a form. Arbitrary query parameters, referrer query/hash values, and obvious email or token values are discarded.
  • Language is determined by the URL (/ or /ru) and is not stored separately in browser storage.
  • If GA4 is actually configured and consent is accepted, Google Analytics may set _ga cookies. On rejection or Global Privacy Control, the script is not loaded and GA cookies accessible to the site are removed.

5. Technical providers

  • Vercel provides hosting, site delivery, and technical logs.
  • Neon provides the protected lead database when the production database is connected.
  • Resend sends new-lead notifications to the configured service inbox.
  • Google Analytics 4 is used only when a valid measurement ID is configured, analytics is not disabled by configuration, and the visitor has consented.

Google Ads and Meta Pixel are not currently connected. Fonts are bundled through Next.js and served by the site without a runtime request to Google Fonts. MalixCode does not sell form data for money.

6. Referral submissions

The referrer enters only their own contact details and receives a personal link with a code. The potential client opens that link and submits the project form directly; the code is stored with their request so the referral can be verified. The referral form does not ask the referrer to provide another person's contact details.

7. Retention

No fixed automatic deletion period is currently configured for leads. Requests are kept while needed to review the inquiry, continue the conversation, manage a project, or maintain the administrative record, and can be archived or deleted from the private admin area. Technical-log retention follows each provider's settings. Session attribution ends with the browser session; the privacy choice remains until changed or cleared.

8. Privacy choices and GPC

Optional analytics is denied by default. Visitors can accept, reject, or manage analytics and reopen the choice from the footer. A Global Privacy Control signal is always treated as rejection of optional analytics.

9. Security

The site uses HTTPS, private admin sessions, server-side validation, form honeypot and rate limits, protected storage, and security headers. No system can guarantee absolute security, so collection is limited to data needed for the purposes described here.

10. Data requests and updates

To request access, correction, or deletion, email contact@malixcode.com. This policy is updated when forms, providers, analytics, or actual data handling changes.

MalixCode

Privacy, contact and website data information for MalixCode.

Back to contact