Data boundary and subprocessors

Role summary

For store purchases, licensing, update delivery, and support, the seller acts as the store operator for customer account, license, activation, billing, and support records. Customers remain responsible for the personal data they collect in their own WordPress forms.

Plugin data boundary

Cornerstone Forms Encryption runs on the customer's WordPress site. The license API does not receive form submissions, uploaded files, encrypted values, decrypted values, encryption keys, search keys, audit logs, WordPress user passwords, or customer site cookies.

Store data categories

  • Customer email and Stripe customer/subscription identifiers.
  • License status, plan, site limit, and activation records.
  • Normalized site URL/domain and hashed site identifier for activations.
  • Plugin version, WordPress version, and PHP version for license/update checks.
  • Support messages and operational diagnostics that customers choose to send.

Subprocessors and service providers

Provider Purpose Data involved
Stripe Checkout, subscriptions, tax, receipts, fraud prevention, and Customer Portal. Billing identity, email, payment metadata, tax/VAT details, subscription ids.
Cloudflare Hosting, Pages Functions, D1, KV, private R2 release storage, security, and email sending where enabled. Store traffic, license/update API records, release files, operational logs, license email metadata.

DPA and processor terms

For business customers that require a Data Processing Agreement, the final production page should identify the DPA request channel and the seller's approved process. Do not send form submissions, encrypted values, uploads, passwords, encryption keys, or search keys when requesting a DPA.

Subprocessor changes

The final production policy should explain how customers are notified about new subprocessors or material subprocessor changes, and how they can raise reasonable objections where applicable.

Reference points

Review the privacy and security boundaries before launch.

Keep the public privacy notice, support process, DPA contact, and subprocessor list aligned before enabling live checkout.