Who the controller is
The data controller is Lasse Feddersen, a sole trader. Contact: email us.
This website
There is no analytics on this site. No Google Analytics, no Plausible, no Facebook pixel, no heatmap, no session recorder, and no advertising tag. We do not set a cookie, and there is no cookie banner because there is nothing to consent to.
The tools on this site, the marquee preview, the speed calculator and the accessibility checker, run entirely in your browser. Whatever you type into them stays in the tab: nothing you put into a tool is uploaded, and the site itself is static files with no server behind it to upload anything to.
One form here does transmit something. If you use the lost-download form, the email address you type into it is sent to our licence service, so that it can email a fresh download link back to you. That happens when you press the button, and not before.
Our hosting provider keeps ordinary server logs, which include IP addresses, for a short period and for the purpose of running and protecting the service. We do not read them for marketing.
If you buy Pro
Checkout is handled by Paddle, who are the merchant of record. Their checkout runs in an overlay on this site and loads their own script when, and only when, you click the button. Paddle receive your name, email address, billing country and payment details, and they process them under their own privacy policy. We never see or store your card details.
We receive from Paddle: your email address, your country, and the fact that a purchase happened. That is what a licence key is issued against and what we use to email you the download link and to email you if something material changes.
The free plugin
The free plugin makes no outbound network requests of any kind. No licence check, no update ping, no usage statistics, no “anonymous telemetry”, no opt-in tracker, no phone home. It cannot report anything about your site to us, because it never contacts us. This is also stated in its listing on WordPress.org, where hiding such a call would be grounds for removal.
Pro, and exactly what it sends
Pro contacts one service of ours. Five calls to it exist, and these are all five. If no key has been entered, or this copy has no service address configured, the licence calls do not happen at all.
| When | What is sent | Why |
|---|---|---|
| Once, when a key is first checked on this site: when you press Activate on the License tab, or the first time a copy that already had a licence inside it is checked in the admin | Your licence key, the product name, the word “wordpress” as a label, and an installation id. The id is a hash of a short random string generated once and kept on your site; it does not contain your domain name, and your domain cannot be worked out from it | To activate the key. Because the random string travels with your database, a staging copy or a move to a new domain keeps the same id and does not use up a second activation |
| At most once every seven days, and only during a WordPress admin request; also when you press Check now | Your licence key and the activation id. Nothing else | To check the licence is still valid and bound to your site |
| Only when you press Remove key from this site | Your licence key and the activation id | To give the seat back, so the licence can be used on another site |
| When WordPress checks for plugin updates. The answer is kept for twelve hours, and an answer that failed for an hour, so it is at most twice a day | In the body of the request: the product name, the installed version number, your licence key, and the same installation id as above | To answer whether a newer version exists and to hand back a download link that only works for a valid licence |
| Only when WordPress installs an update that the check above reported | A signed, expiring token in the download address, and nothing else — no key and no site name | To download the new version |
All five also carry your site’s address, the whole address and not only the hostname, together with the WordPress version, in the standard User-Agent header that WordPress itself sets on every outbound request. It is written down here because it is a real transmission of a real identifier, not because it is hidden anywhere.
None of these calls is made while a visitor is waiting for a page. Your visitors never trigger a request to us, and your marquees, your posts, your products and your visitors’ details never reach us at all. If our service is unreachable, nothing visible happens and your site is not slowed down: a request that does not answer within five seconds is given up.
The Products strip reads WooCommerce on your own server. Nothing about your shop goes anywhere.
How long we keep things
Licence records, meaning email address, key, activations and site addresses, are kept for as long as the licence exists and for six years afterwards, because tax law requires the transaction records to be retained. Support emails are kept for two years and then deleted.
Your rights
If you are in the UK or the EU, you have the right to ask what we hold about you, to have it corrected, to have it deleted, to object to processing and to receive it in a portable form. Email and you will get an answer from a person within thirty days. Purchase records that tax law requires us to keep are the one thing we cannot delete on request, and we will tell you plainly if that applies.
You may also complain to your national data protection authority.