1. Overview
At Addonry ("we", "us", or "our"), protecting the security and privacy of our customers and visitors is fundamental to our platform design. This Privacy Notice describes the personal information we collect through addonry.com, our API endpoints, and the Addonry WordPress Manager plugin, how we utilize that information, and your legal rights under applicable data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect & How We Use It
2.1 Account & Identity Data
When you create an account or authenticate on our platform, we collect:
- Email Address & Name: Used as your primary account identifier, for billing notices, security notifications, and critical update alerts.
- Password: Securely hashed using cryptographic PBKDF2 with unique salts. We never store or have access to plaintext passwords.
- Session & Security Telemetry: Login timestamps, IP addresses, and user-agent strings stored in an immutable security audit log to detect brute-force attacks and unauthorized account access.
2.2 Payment & Transaction Data
All payment transactions on Addonry are handled directly by our PCI-DSS Level 1 certified payment processor, Stripe, Inc.
- No Raw Card Storage: We never collect, process, or store raw credit or debit card numbers, CVC codes, or banking PINs on our servers.
- Tokenized References: Stripe returns a secure tokenized reference (Stripe Customer ID, Payment Method ID, last 4 digits of the card, card brand, and expiration date) which we retain to manage your active subscription and order invoices.
2.3 Download Activity & Quota Tracking
When you request a download grant or consume membership quota, our systems record:
- The product ID, version string, and cryptographic grant hash.
- Timestamp and IP address of the download request.
- Daily unique-product counters to calculate quota compliance under rule
BR-MEM-003.
2.4 Connected WordPress Sites (Addonry Manager Plugin)
When you link a WordPress installation via the Addonry Manager plugin using our device authorization flow:
- Data Transmitted: Site URL, WordPress version, active PHP version, and the list of Addonry-managed plugin/theme slugs. This information is strictly required to determine compatible updates.
- Data Explicitly Excluded: The plugin never reads, harvests, or transmits your WordPress post content, media library, customer orders, user credentials, comments, or MySQL database tables.
2.5 Website Analytics (Google Analytics 4)
We use Google Analytics 4 to understand how visitors find and use our public pages so we can improve the catalog and checkout experience.
- What is measured: Pages viewed on public pages, products viewed, items added to the cart, checkout started, sign-ups and sign-ins, and completed purchases (order value, currency and products).
- Identifiers: A random pseudonymous identifier stored in the
_gacookie. Completed purchases are reported from our servers after Stripe confirms the payment, using that identifier and a hashed transaction reference. - Never sent to Google: Your name, email address, password, raw order or account numbers, download or login tokens, connected WordPress site URLs, or search terms. Account, admin and WordPress-linking pages are not measured.
- Legal basis: Your consent in the European Economic Area, the United Kingdom and Switzerland; our legitimate interest in improving the service elsewhere. You can object or withdraw at any time via Cookie settings in the site footer.
3. Authorized Subprocessors
We partner with vetted third-party service providers ("Subprocessors") to deliver hosting, edge security, email, and payment infrastructure:
| Subprocessor | Purpose | Location | Data Transferred |
|---|---|---|---|
| Stripe, Inc. | Payment gateway & subscription billing | United States / Ireland | Billing details, email, card tokens |
| Cloudflare, Inc. | DNS, DDoS defense, WAF, R2 file storage & CDN | Global Edge | IP address, request headers, download traffic |
| Transactional Email Provider | Email verification & receipts | EU / US | Recipient email, order confirmation data |
| Google Ireland Ltd. / Google LLC | Website analytics (Google Analytics 4) | European Union / United States | Pseudonymous cookie ID, pages viewed, device and approximate location, purchase value and products |
| Hosting Provider (Cloud VPS) | Application containers & PostgreSQL database | European Union (Germany) | Encrypted database records, server logs |
4. Cookies & Edge Technologies
We keep cookies to a minimum. We do not use data-broker pixels or sell personal information.
- Strictly Necessary Cookies (always on):
gpl_session: A secure, HttpOnly, SameSite=Lax cookie essential for session authentication and account navigation.__Host-anti-forgery tokens: Used to defend against Cross-Site Request Forgery (CSRF) attacks during form submission.
- Preference Cookies:
addonry_consent: Remembers your cookie choice for 6 months.- Local storage flags to remember your cart, language, theme preferences or collapsed sidebar states.
- Analytics Cookies (Google Analytics 4, set by
googletagmanager.com):_ga: Distinguishes visitors with a random identifier. Expires after 2 years._ga_<ID>: Keeps the state of the current visit. Expires after 2 years.
Your choice: In the European Economic Area, the United Kingdom and Switzerland, analytics cookies are only set after you click Accept. In other regions they are set by default and you can switch them off with Reject. Either way you can change your decision at any time via Cookie settings in the footer; rejecting stops new analytics cookies and measurement on this browser.
5. Data Retention & Erasure
We retain personal data only for as long as your account remains active or as required by statutory accounting, tax, and fraud prevention regulations:
- Financial transaction records are retained for statutory accounting periods (typically 7 to 10 years depending on jurisdiction).
- Download grant logs and transient IP addresses are rotated and aggregated after 90 days.
- Upon account deletion, all active session tokens and connected WordPress site tokens are immediately revoked and permanently deleted from our primary database.
6. Your Data Rights (GDPR & CCPA)
Depending on your jurisdiction, you possess specific rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Rectification: You may update inaccurate or incomplete profile information through your Account Security panel.
- Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your account and associated personal data, subject to legal record retention requirements.
- Right to Data Portability: You may request your transaction history and library entitlements in a machine-readable format.
- Right to Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service if you exercise your privacy rights.
To exercise any of these rights, please email us at [email protected]. We respond to all verified requests within thirty (30) days.
7. Contact
If you have questions, concerns, or complaints regarding this Privacy Notice or our data protection practices, please contact:
Addonry Privacy
Email: [email protected]
Security Reports: Security & Vulnerability Desk