Privacy
Privacy Policy
This page describes every piece of information this site collects, who else sees it, and how to make me delete it. It is deliberately specific, because a privacy policy that could describe any website describes nothing.
Effective 7 August 2026
1. Who is responsible
The Coding Doctor, operated by Brian Pitts, MD, MEHP, at 3575 Arden Way, Unit #2312, Sacramento, CA 95864, United States, is the controller of the information described here. Write to brian@thecodingdoctor.com about anything on this page and a person will answer.
2. The short version
What this site does not do
No advertising networks. No social media pixels. No cross-site tracking. No data broker, ever, for any price. The fonts are served from this domain rather than a font network, so simply reading a page here does not announce you to anyone else.
3. When you just read something
Traffic is measured by Independent Analytics, which runs on this site's own server. Nothing is sent to an analytics company, and it sets no tracking cookie.
It records the page viewed, where you arrived from, any campaign tag in the link, your country, region and city, your device type, browser and operating system, and clicks on outbound or download links. To count returning visits without identifying you, it stores a one-way hash built from a secret that rotates. Your IP address itself is not stored.
4. When you subscribe or fill in a form
Forms are handled by Fluent Forms and the mailing list by FunnelKit Automations, both of which store their data in this site's own database rather than an external service.
I hold your email address, your name if you gave one, your list preferences, which emails you opened or clicked, and whatever you typed into the form. New addresses are checked for validity by Reoon Email Verifier, and form submissions are screened for spam by Akismet, which is operated by Automattic; both receive the submitted data in order to do that.
5. When you buy an Intensive
Your order is recorded by WooCommerce on this site: name, email address, billing address, what you bought, and when. That record is what produces your receipt and your seat.
Card details never reach this site. Payment is handled entirely by Stripe, which receives your card number and billing details directly. I see only the result, the last four digits, and Stripe's reference. Stripe processes that data under its own privacy policy and its own obligations as a payment institution.
6. When you book a call
Bookings run through FluentBooking on this site and hold your name, email address, chosen time zone and slot, and anything you wrote in the booking notes. The call itself takes place on Zoom, which handles the connection and any recording under its own terms.
7. When I email you
Outgoing email is relayed by Twilio SendGrid, which necessarily receives your address and the message in order to deliver it. Delivery logs are kept for ninety days and then discarded.
8. Cookies
- Cart and session cookies set by WooCommerce, so your cart survives the walk to the checkout: woocommerce_items_in_cart, woocommerce_cart_hash and a session cookie.
- A WordPress login cookie, only if you have an account here and sign in.
- A cookie that remembers you have been given a preview link while part of the site is not yet public.
On the checkout page Stripe sets two of its own, __stripe_mid and __stripe_sid, to tell a real card from a stolen one. They are Stripe's, they carry no advertising purpose, and without them the payment field will not run. That is the complete list. There are no advertising or profiling cookies, which is why this site does not greet you with a consent wall.
9. During an Intensive
Sessions are recorded so attendees can revisit any step, and the recording is shared with everyone who attended. Your name, your voice, your camera if it is on, and anything you screen-share may appear in it. If you would rather not, keep your camera off and rename yourself in Zoom; nobody will ask why.
Patient data
Sessions use synthetic data only. Do not bring real patient information into a screen share, a file, or the chat. If it appears, I stop the session until it is gone, and I delete it from any recording before that recording is shared.
10. Why I am allowed to hold it
- To perform our contract, for everything needed to sell you a seat and deliver it.
- With your consent, for marketing email, which you can withdraw at any moment without losing anything you bought.
- For legitimate interests, meaning keeping the site running and secure and understanding in aggregate which pages are read.
- To meet legal obligations, principally keeping tax and payment records.
11. Everyone else who touches it
The complete list of third parties that receive any of your data, and the only reason each one does: Stripe takes payments. Twilio SendGrid delivers email. Zoom carries the sessions. DreamHost hosts the site and therefore its database. Reoon checks that an email address is real. Automattic, through Akismet, screens form spam.
Nobody else. Your data is not sold, rented, or shared for anyone's advertising. If a court or a law compels disclosure I will comply, and I will tell you unless I am forbidden to.
12. Where it lives and how long
Data is stored in the United States. If you are writing from the United Kingdom, the European Economic Area, or anywhere with similar rules, understand that using this site means your information is handled there.
- Mailing list: until you unsubscribe. I then keep a minimal suppression record so I do not accidentally email you again.
- Orders and receipts: seven years, because tax law requires it.
- Email delivery logs: ninety days.
- Traffic records: kept while they are useful, and never attached to your name.
- Session recordings: kept while they are still useful to the people who attended.
13. What you can make me do
You can ask for a copy of what I hold, have it corrected, have it deleted, have it sent to you in a portable form, object to a particular use, or withdraw consent. Ask by email and I answer within thirty days, usually the same week. I do not charge for it and I do not treat you differently for asking.
Two things you can do yourself, without me: change what you receive on the email preferences page, and correct your details on the manage profile page. Both open from the link at the foot of any email I send.
California residents. You have the right to know what is collected, to have it deleted or corrected, and to opt out of the sale or sharing of personal information. There is nothing to opt out of, because none is sold or shared.
UK and EEA residents. Alongside the rights above you may complain to your national data protection authority. I would rather you told me first and gave me the chance to fix it.
14. Children
This site is meant for practising clinicians and is not directed at children. I do not knowingly collect anything from anyone under sixteen. If that has happened, tell me and I will delete it.
15. Security
The site is served over TLS, administrative access is limited and protected, and payment data never touches it. That said, no system is perfectly secure, and I would rather say so than imply a guarantee I cannot make. If a breach ever affects your data I will tell you promptly and plainly.
16. Changes
If this policy changes in a way that matters, I will change the effective date above and say so in an email rather than hoping you re-read the page.
17. Getting hold of me
The Coding Doctor
Brian Pitts, MD, MEHP
3575 Arden Way, Unit #2312, Sacramento, CA 95864, United States

