Privacy Policy

Last updated: 29 July 2026

Code N Rob (“we”, “us”, “our”) runs the website at codenrob.com, where we publish articles about AI tools, developer productivity, side hustles and tech life in Singapore. This policy explains what personal data we collect when you visit or subscribe, why we collect it, who we share it with, and the choices you have.

Code N Rob is operated from Singapore, and this site is written primarily for readers in Singapore and the wider Asia-Pacific region. We handle personal data in line with the Singapore Personal Data Protection Act 2012 (PDPA), and this policy is governed by Singapore law. If you visit us from elsewhere, your information will be handled under the PDPA and the practices set out here.

1. Information you give us

Newsletter subscriptions

When you subscribe through the newsletter form in our footer or in the pop-up, we collect your email address and, if you provide it, your name. We use these only to send you new articles and occasional updates from Code N Rob. We do not sell or rent your email address to anyone.

Your subscription is stored in two places: our email marketing provider, MailerLite, and a submissions record inside our own WordPress site. Every email we send includes a one-click unsubscribe link, and you can also ask us to remove you at any time using the contact details in section 10.

Contact form

When you write to us through the contact form, we collect the name, email address and message you enter. We use this solely to reply to you and to keep a record of the conversation. Submissions are emailed to us and stored in our WordPress site.

Comments

If commenting is enabled on an article and you leave a comment, we collect the data shown in the comment form, plus your IP address and browser user-agent string, which help us detect spam. An anonymised string derived from your email address (a “hash”) may be sent to the Gravatar service to check whether you have a profile picture; Gravatar’s privacy policy is available at automattic.com/privacy. Your profile picture is publicly visible next to your comment once it is approved.

2. Information collected automatically

Analytics

We use Google Analytics, delivered through Google Tag Manager and the Site Kit by Google plugin, to understand which articles people read and how they found us. This collects information such as the pages you view, how long you stay, your approximate location (derived from your IP address), your device type, browser and screen size, and the site or search that referred you. We use it in aggregate to improve what we publish — we do not use it to identify you personally.

Cookies

Cookies are small text files stored by your browser. This site uses them for:

  • Analytics — Google Analytics cookies that measure visits and traffic sources, as described above.
  • Functionality — remembering that you have already dismissed our newsletter pop-up, so we do not show it to you again.
  • Comments — if you leave a comment, saving your name, email and website so you do not have to retype them. These last for one year.
  • Security and administration — session cookies used when an administrator logs in to the site.

You can block or delete cookies in your browser settings at any time. If you block analytics cookies, the site will still work normally. To opt out of Google Analytics across all websites, you can install Google’s opt-out browser add-on.

Server logs and security

Our hosting provider keeps standard server logs, which include IP addresses and requested URLs. We also run software that limits repeated failed login attempts and records the IP addresses involved, and we use Google reCAPTCHA to protect our forms and login page from automated abuse. reCAPTCHA collects hardware and software information and behavioural signals from your browser and sends them to Google for analysis; its use is subject to Google’s Privacy Policy and Terms of Service. All of this is used only to keep the site secure and available.

Media and embedded content

If you upload images to the site, avoid uploading images with embedded location data (EXIF GPS), because other visitors can extract it.

Articles on this site may include embedded content — for example YouTube videos or social media posts. Embedded content from other websites behaves exactly as if you had visited that website directly. Those sites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including if you have an account and are logged in to them.

3. The basis on which we collect it

Under the PDPA we rely on the following:

  • Your consent — you give it when you subscribe to the newsletter or submit a form, having been notified here of the purposes. You can withdraw it at any time.
  • Deemed consent — where you voluntarily provide your details for an obvious purpose, such as sending us a message and expecting a reply.
  • Legitimate interests — as permitted by the PDPA, for keeping the site secure, preventing abuse and understanding our audience in aggregate.
  • Legal requirements — where we are required to retain or disclose information by Singapore law.

Withdrawing consent is straightforward: unsubscribe from any email, or write to us. Once you withdraw it we will stop collecting, using and disclosing your personal data for that purpose. We will let you know if withdrawing has any consequence — for example, we can no longer send you new articles.

4. Who we share your data with

We do not sell your personal data. We share it only with the service providers who help us run this site, and only to the extent they need it:

  • MailerLite — stores our newsletter list and sends our emails. See the MailerLite privacy policy.
  • Google — Analytics, Tag Manager, Search Console and reCAPTCHA. See the Google privacy policy.
  • Our email delivery provider — transmits the notification emails generated by our forms, and keeps a short-term log of delivery status.
  • Our web host — stores the site and its database, including form submissions and comments.

We may also disclose information if we are legally required to, or where it is necessary to protect our rights, safety, or the integrity of the site.

5. International transfers

Some of the providers above operate servers outside Singapore. The PDPA’s Transfer Limitation Obligation requires us to satisfy ourselves that data sent overseas is protected to a standard comparable to the PDPA, and we rely on the contractual data-protection terms these providers commit to in order to meet it.

6. How long we keep it

  • Newsletter subscribers — until you unsubscribe or ask us to delete you, after which we remove you from MailerLite and from our stored submissions.
  • Contact form messages — kept while they are useful for the conversation and our records, and deleted on request.
  • Comments — retained indefinitely so that follow-up replies make sense, unless you ask us to remove them.
  • Analytics data — retained according to our Google Analytics retention setting, in aggregated form.
  • Server and security logs — kept for a short period on a rolling basis.

7. Your rights and choices

You can ask us to:

  • Access — tell you what personal data we hold about you, and how it has been used or disclosed in the year before your request;
  • Correction — fix anything that is inaccurate or out of date;
  • Withdrawal of consent — stop using your data for a purpose you previously agreed to, including marketing emails. You can do this yourself with the unsubscribe link in any email;
  • Deletion — remove you from our mailing list and delete your form submissions and comments. We will do this on request, and in any case we stop retaining personal data once it no longer serves the purpose it was collected for.

Write to us using the details in section 10 and we will respond as soon as we reasonably can, within the timeframes set by the PDPA. We may need to confirm your identity before acting on a request. If you are not satisfied with how we have handled your personal data, you may raise the matter with Singapore’s Personal Data Protection Commission.

8. How we protect your data

The site is served over HTTPS, administrator access is protected by strong credentials and login-attempt limiting, and access to subscriber data is restricted to the people who run Code N Rob. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take reasonable steps to protect your information and to address any incident promptly.

9. Children

This site is intended for a general professional audience and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has given us their information, please contact us and we will delete it.

10. Contact us

For any question about this policy, or to exercise any of the rights above, reach us through our contact page or by email at privacy@codenrob.com.

11. Changes to this policy

We may update this policy as the site changes or as the law requires. When we do, we will revise the “last updated” date at the top of this page. If we make a change that materially affects how we use your personal data, we will take reasonable steps to tell you — for example, by a notice on the site or a message to subscribers.