Privacy Policy
Last updated: 24 July 2026
1. Controller
The CodeCave GmbH, Alfred-Nobel-Straße 29, 50226 Frechen, Germany, operates MoveMRR and is responsible for the processing described in this notice. Privacy questions and data-subject requests can be sent to info@thecodecave.de.
2. Information We Process
We collect information you provide directly to us when you create an account, use our services, or communicate with us. This includes:
- Account information (email address, name)
- Stripe API keys (restricted keys only, stored securely)
- Migration project data and configurations
- Communication records when you contact us
Our hosting and security systems also process technical request data such as IP address, timestamp, requested path, browser information, and security events. The public website analytics described below processes anonymous page, device, referral, and interaction data.
3. Purposes and Legal Bases
We use the information we collect to:
- provide the requested account, migration, checkout, and support services and take steps before entering a contract;
- meet legal, accounting, and compliance obligations;
- secure the service, prevent misuse, diagnose errors, and improve product and website performance on the basis of our legitimate interests; and
- act on consent where a particular processing activity requires it.
4. Cookieless Website Analytics
The public MoveMRR website uses a self-hosted Rybbit instance through the
same-origin /analytics/ endpoint. The implementation does
not use analytics cookies, local storage, user identification, or session
replay.
We measure page paths and titles, referral source, browser and device class, coarse location derived from an IP address, scroll milestones, FAQ and resource interactions, and clicks that open the MoveMRR app. Rybbit uses IP address and user-agent information transiently to produce anonymous identifiers and location information; the raw IP address is not retained in the analytics database.
For organic and AI referral attribution, the website records only the classified source, source hostname, landing path, and language for the current browser tab. It deliberately excludes full referrer URLs, search queries, URL fragments, and user-entered AI prompts.
Learn more about the underlying cookieless design in the Rybbit privacy documentation .
5. Stripe Credentials and Security
MoveMRR uses purpose-specific restricted Stripe API keys and validates the permissions required for the selected operation. Stored live keys use Supabase Vault, are not returned to the browser after storage, and expire inside MoveMRR after 30 days. This expiry does not revoke the credential in Stripe; the account owner remains responsible for revoking it after the project.
One-time live keys used only to read catalog information during Sandbox Seeding are passed to the backend operation and are not stored as project credentials. MoveMRR does not handle raw card numbers; eligible payment credentials are copied through Stripe's supported process.
6. Service Providers and Disclosures
We do not sell, trade, or rent your personal information to third parties. Data may be processed by vendors that provide hosting, database and vault infrastructure, payments, transactional services, and security under appropriate contractual safeguards. We may also disclose information:
- when required by law or a valid legal request;
- to investigate fraud, abuse, or a security incident;
- in a corporate transaction subject to applicable safeguards; or
- when you instruct or consent to the disclosure.
7. Retention
We retain personal data only for as long as needed for the relevant service, security, support, accounting, or legal purpose. Retention periods vary by data category and applicable obligations. Migration credentials have the shorter product-specific limits described above; deleting or expiring a stored credential does not delete Stripe's own records.
8. Your Rights
Subject to the applicable law and its conditions, you may request:
- access to and a copy of personal data;
- correction or deletion;
- restriction of or objection to processing;
- data portability; and
- withdrawal of consent without affecting earlier lawful processing.
You may also lodge a complaint with the data-protection supervisory authority responsible for you.
9. Browser Storage and Cookies
The public marketing website does not use advertising or analytics cookies. It uses session storage only to keep anonymous organic or AI referral attribution within the current browser tab. The MoveMRR application may use strictly necessary storage for authentication, security, and session state.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact
If you have questions about this privacy policy, please contact us at info@thecodecave.de.