Store privacy notice

What the store processes

  • Checkout and billing details handled by Stripe.
  • Customer email and Stripe customer/subscription ids.
  • License status, plan, site limit, and activation records.
  • Normalized site URL/domain and hashed site identifier for activations.
  • Plugin version, WordPress version, and PHP version when the plugin checks license or updates.

What the store does not receive

The license API does not receive form submissions, uploaded files, encrypted values, decrypted values, audit logs, encryption keys, search keys, WordPress user passwords, or customer site cookies.

Why the data is used

Data is used to process payment, issue licenses, enforce site limits, provide private update downloads, support customers, prevent fraud, and maintain accounting and security records.

Processors

Stripe processes checkout, subscription, tax, billing, and receipt data. Cloudflare hosts the store, Pages Functions, D1, KV, and R2 release storage.

See the data processing page for the current subprocessor overview, plugin data boundary, and DPA request notes.

Customer rights

The final production notice should explain how customers can request access, correction, deletion, restriction, portability, objection, and complaint handling where those rights apply.