Privacy Policy
Last updated: 30 July 2026 · Effective: 30 July 2026
This policy explains what personal data wpcodify.com collects, why we collect it, who we share it with, and the choices you have. It covers our website, customer dashboard, documentation site, support desk, licence server and marketing emails.
Data controller: wpCodify, Bangladesh. Contact: support@wpcodify.com.
1. Summary
| We collect | Why | Kept for |
|---|---|---|
| Name, email, account details | To create your account, deliver orders, and support you | While your account is active |
| Order and billing records | To fulfil the order and meet tax/accounting obligations | 7 years (tax and accounting) |
| Licence keys and activated domains | To enforce activation limits and deliver updates | Life of the licence + 3 years |
| Support tickets and attachments | To answer your questions and keep a service history | 3 years after the ticket closes |
| IP address and approximate location | Security, abuse prevention, and support context | 12 months |
| Email opens and link clicks | To measure whether our emails are useful | 12 months |
| Site usage analytics | To improve the site and our products | 12 months |
We do not sell your personal data. We do not use it to build advertising profiles.
2. Information we collect
2.1 Information you give us
- Account and checkout: name, email address, and any billing details required by the payment method.
- Support requests: your name, email, the content of your message, attachments and screenshots you upload, and the product or purchase code you reference.
- Reviews and comments: the display name and content you submit.
- Email subscriptions: the email address and any name or preferences you provide.
- Correspondence: anything you send us by email or live chat.
2.2 Information collected automatically
- Licence activations. When a Product is activated, our licence server records the website domain, the licence key used, the activation and deactivation times, and the last time the site checked for updates. This is how activation limits and update delivery work.
- Security logs. Requests to our licence and support APIs are logged with the IP address, the endpoint called and whether the request succeeded. We use these logs to detect brute-force attempts, key sharing and abuse, and to block offending addresses.
- Support context. When you open a ticket we may record the IP address the ticket came from and resolve it to an approximate country/region, to help us route requests, prevent spam and understand your environment.
- Email tracking. Our newsletters and campaign emails may include a tracking pixel and signed redirect links so we can see whether a message was opened and which links were clicked. You can stop this by disabling remote images in your email client or unsubscribing.
- Website analytics. We collect standard usage data such as pages visited, referring URL, browser and device type, and general location derived from IP.
- Cookies. See section 7.
2.3 Information from third parties
- Payment providers. Card and online payments are processed by Paddle, which acts as merchant of record. Paddle collects your payment and billing details directly on its own checkout and shares with us only what we need to fulfil the order — the transaction outcome, your email address, country and the amount. We never receive your card number.
- Envato. When you verify an Envato/ThemeForest purchase code for support, we send the code to Envato’s API and receive back the item purchased, the buyer’s username, the licence type and the supported-until date, which we store with your ticket.
We never receive or store your full payment card details.
3. Why we use your data, and our legal basis
Where the GDPR or similar law applies, we rely on the following bases.
| Purpose | Legal basis |
|---|---|
| Deliver your order, licence key and downloads | Performance of a contract |
| Provide support and updates | Performance of a contract |
| Enforce licence terms and activation limits | Legitimate interests (protecting our products) |
| Detect fraud, spam and abuse; block malicious traffic | Legitimate interests (security) |
| Keep tax, accounting and transaction records | Legal obligation |
| Send product updates, offers and newsletters | Consent (you can withdraw at any time) |
| Improve our site and products through analytics | Legitimate interests or consent, depending on your region |
4. Marketing emails
4.1 We only add you to marketing lists where you have opted in, or where you are an existing customer and local law permits product-related messages. Transactional emails — receipts, licence keys, support replies, security notices — are sent regardless, because they are part of the service.
4.2 Every marketing email includes an unsubscribe link. Unsubscribing takes effect immediately and does not affect transactional emails.
4.3 We record whether a campaign email was opened and which links were clicked, at the level of an individual subscriber, so we can stop sending content that isn’t useful.
5. Who we share data with
We share personal data only with providers who need it to run our service, and only for that purpose:
- Payment processing — Paddle (merchant of record for card and online payments), and any bank used for manual transfers.
- Hosting and infrastructure — our web host, licence server host, and CDN.
- Email delivery — our transactional and marketing email providers.
- Purchase verification — Envato, when a purchase code is checked.
- Analytics — our website analytics provider.
- Professional advisers and authorities — accountants, lawyers, or authorities where we are legally required to disclose.
We may also transfer data as part of a merger, acquisition or sale of assets, in which case we will notify you.
We do not sell personal data, and we do not share it with advertising networks for cross-site profiling.
6. International transfers
We are based in Bangladesh and our providers may process data in other countries, including the EU, UK and US. Where data leaves the EEA or UK, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision. You may request details of the safeguards used.
7. Cookies and similar technologies
| Cookie / storage | Purpose | Type |
|---|---|---|
ftp_cart_key |
Identifies your shopping cart so items persist between pages. Contains a random key only — no prices or personal data. | Essential |
| WordPress login/session cookies | Keep you signed in to your account | Essential |
| Analytics cookies | Measure traffic and how the site is used | Optional |
| Preference storage | Remember interface choices such as dismissed notices | Functional |
Essential cookies are required for the site to work. You can control optional cookies through our cookie banner where shown, and all cookies through your browser settings — though blocking essential cookies will break checkout and login.
8. Data retention
We keep personal data only as long as we need it:
- Account data — while your account exists, then deleted or anonymised within 6 months of closure.
- Orders and invoices — for the period required by tax and accounting law in our jurisdiction, typically 7 years.
- Licence and activation records — for the life of the licence plus 3 years, so we can resolve later disputes about entitlement.
- Support tickets — 3 years after closure.
- Security and API logs — 12 months.
- Marketing lists — until you unsubscribe, or after 24 months of no engagement.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (“right to be forgotten”), subject to records we must keep by law.
- Restrict or object to certain processing, including direct marketing.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Complain to your local data protection authority.
If you are in California, you additionally have the right to know what personal information is collected, to request deletion, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
To exercise any right, email support@wpcodify.com. We will respond within 30 days and may ask you to verify your identity — usually by replying from the email address on your account.
10. Security
We protect your data with HTTPS across the site, hashed passwords, signed API requests between our store and licence server, rate limiting and automated blocking of abusive addresses, and restricted staff access on a need-to-know basis. No system is perfectly secure, so we cannot guarantee absolute security, but we will notify you and the relevant authority without undue delay if a breach affects your personal data.
11. Children
Our products and services are intended for business and professional use and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
12. Third-party sites
Our site, documentation and emails may link to third-party websites. This policy does not cover them; please read their own privacy notices.
13. Changes to this policy
We will update this policy as our services and legal obligations change. The “last updated” date will change, and we will notify you of material changes by email or a notice on the site.
14. Contact
wpCodify Bangladesh Privacy enquiries: support@wpcodify.com General support: https://wpcodify.com/support