Privacy Policy

What data we collect, why we collect it, and the rights you have over it.

Last updated: September 19, 2026

WPPres (“we”, “us”, “our”) operates this website and publishes the StorePOS plugin. This policy explains what personal data we collect, why we collect it, and what rights you have over it.

1. Who is responsible for your data

WPPres is the data controller for the personal data described in this policy. You can contact us about anything in it through our contact page.

2. What we collect, and why

When you contact us

Our contact form collects your name, email address, subject and message. We use this solely to answer you and to keep a record of the conversation. The lawful basis is our legitimate interest in responding to enquiries, and the performance of a contract where you are an existing customer.

When you buy a licence

Purchases are processed by Paddle.com Market Ltd, who act as merchant of record. Paddle collects your billing details, including your payment card information, directly. We never see or store your full card number. Paddle passes us the information we need to fulfil and support your order: your name, email address, country, the product purchased, the order reference and the transaction amount. The lawful basis is the performance of our contract with you.

Paddle’s own handling of your data is governed by the Paddle privacy policy.

When you activate the plugin

To validate a licence and deliver updates, the plugin sends us your licence key, the site URL it is activated on, and basic environment information such as the plugin version, WordPress version and PHP version. We use this to enforce activation limits, to deliver the right updates, and to diagnose support requests. The lawful basis is the performance of our contract with you.

The plugin does not transmit your sales data, your products, your customers or your order history to us. That data stays in your own WordPress database, on your own hosting.

When you visit this website

Our web server keeps standard access logs containing the requesting IP address, the page requested, the timestamp and the user agent. These are used for security and troubleshooting and are retained for a limited period. The lawful basis is our legitimate interest in keeping the site secure and available.

3. Cookies

This website does not use advertising or cross-site tracking cookies. WordPress may set functional cookies if you log in or leave a comment. Paddle sets cookies necessary to operate its checkout, described in Paddle’s own policy.

4. Who we share data with

We do not sell your personal data, and we do not share it for advertising. We share it only with the service providers we need to run the business:

  • Paddle.com Market Ltd — payment processing, invoicing, tax compliance and fraud prevention.
  • Our hosting provider — storage and delivery of this website and our support systems.
  • Our email provider — delivery of transactional email such as receipts, licence keys and support replies.

We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.

5. International transfers

Some of our providers operate outside your country of residence. Where personal data is transferred out of the European Economic Area or the United Kingdom, that transfer is covered by an adequacy decision or by Standard Contractual Clauses.

6. How long we keep it

  • Contact enquiries — up to 24 months after the conversation ends.
  • Purchase and licence records — for as long as your licence is active, and afterwards for the period our tax and accounting obligations require (typically 6 to 10 years).
  • Server access logs — a rolling short-term window.

7. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, where we have no overriding obligation to keep it;
  • restrict or object to our processing of it;
  • receive your data in a portable, machine-readable format;
  • withdraw consent, where we relied on consent;
  • complain to your local data protection authority.

To exercise any of these, write to us through the contact page. We respond within one month.

8. Security

This site is served over HTTPS. We restrict access to purchase and support records to the people who need it, and we apply security updates promptly. No system is perfectly secure, but we take the protection of your data seriously and will notify you and the relevant authority of a qualifying breach as the law requires.

9. Children

StorePOS is a business product. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy. The “last updated” date above shows when it last changed; material changes will be notified to licence holders by email.