Privacy Policy
The short version
We run a licensing and update service for a WordPress plugin. We process the minimum needed to do that: your account details, your billing email, and technical health data your store reports about itself. Your store's products, orders and customers never reach us — no endpoint exists that could receive them. We use no analytics or advertising trackers, so this site needs no cookie banner.
What we process, and why
- Account data — name, email, password (stored as a hash). Basis: performing our contract with you.
- Billing data — billing email, chosen plan, subscription references and invoice records held at our payment providers. Card details go directly to the provider and never touch our systems. Basis: contract and legal (bookkeeping) obligations.
- Site telemetry — for each store you connect: its URL and name, a random installation identifier, plugin/WordPress/WooCommerce/PHP versions, component health status, and check-in timestamps. This is what your store reports about itself; we cannot and do not fetch anything from it. Basis: contract (delivering updates and licensing) and our legitimate interest in fleet health and abuse prevention.
- Support and demo enquiries — what you send us, so we can answer. Basis: legitimate interest / pre-contractual steps.
Installation secrets and any credentials we store are encrypted at rest. Payment-provider webhooks are verified cryptographically and we store only their identifiers, never their payloads.
Who receives data
- Frisbii (EU) and Stripe — payment and subscription processing; for payments they act under their own responsibility as required by financial regulation. Stripe may process data in the US under the EU–US Data Privacy Framework and standard contractual clauses.
- Hosting and email delivery providers acting on our instructions under data processing agreements.
We do not sell personal data, and we do not share it with anyone else unless the law requires it.
How long we keep it
- Site telemetry: for the life of the installation; removed when the installation is deleted.
- Account and licensing records: for the life of the account.
- Billing records: five years after the financial year, as the Danish Bookkeeping Act requires.
- Deleting an account removes its installations and their history.
Cookies
The public website sets no cookies. Signing in to the dashboard sets strictly necessary session and security cookies only — nothing tracks you, which is why there is no consent banner to click.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, restriction of or objection to processing, and a portable copy — write to [email protected] and we will respond within a month. You can also complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk) or your local supervisory authority.
Your customers' data
To be explicit, because it matters in this product category: data about your store's customers — orders, addresses, payment details — is processed by your WordPress installation and never transmitted to us. For that data you are the controller and we are not a processor, because we never receive it.
Changes
If this policy changes materially we will announce it by email to account holders before it takes effect.