Privacy
Store privacy notice
Launch draft: add the final data controller identity, postal address, support email, retention periods, lawful bases, subprocessors, and data subject request workflow before live sales.
What the store processes
- Checkout and billing details handled by Stripe.
- Customer email and Stripe customer/subscription ids.
- License status, plan, site limit, and activation records.
- Normalized site URL/domain and hashed site identifier for activations.
- Plugin version, WordPress version, and PHP version when the plugin checks license or updates.
What the store does not receive
The license API does not receive form submissions, uploaded files, encrypted values, decrypted values, audit logs, encryption keys, search keys, WordPress user passwords, or customer site cookies.
Why the data is used
Data is used to process payment, issue licenses, enforce site limits, provide private update downloads, support customers, prevent fraud, and maintain accounting and security records.
Processors
Stripe processes checkout, subscription, tax, billing, and receipt data. Cloudflare hosts the store, Pages Functions, D1, KV, and R2 release storage.
See the data processing page for the current subprocessor overview, plugin data boundary, and DPA request notes.
Public website analytics
Google Analytics measures visits to public information pages automatically unless you stop it using Analytics preferences in the footer. This does not measure checkout, billing, account or API pages. The page-view events we add omit form contents, URL queries, fragments and referrers. Google Analytics may use cookies; your preference is stored in your browser. Independent hosting logs and Cloudflare analytics are not controlled by this choice. See the cookie notice.
Customer rights
The final production notice should explain how customers can request access, correction, deletion, restriction, portability, objection, and complaint handling where those rights apply.