1. Overview
At Addonry ("we", "us", or "our"), protecting the security and privacy of our customers and visitors is fundamental to our platform design. This Privacy Notice describes the personal information we collect through addonry.com, our API endpoints, and the Addonry WordPress Manager plugin, how we utilize that information, and your legal rights under applicable data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect & How We Use It
2.1 Account & Identity Data
When you create an account or authenticate on our platform, we collect:
- Email Address & Name: Used as your primary account identifier, for billing notices, security notifications, and critical update alerts.
- Password: Securely hashed using cryptographic PBKDF2 with unique salts. We never store or have access to plaintext passwords.
- Session & Security Telemetry: Login timestamps, IP addresses, and user-agent strings stored in an immutable security audit log to detect brute-force attacks and unauthorized account access.
2.2 Payment & Transaction Data
All payment transactions on Addonry are handled directly by our PCI-DSS Level 1 certified payment processor, Stripe, Inc.
- No Raw Card Storage: We never collect, process, or store raw credit or debit card numbers, CVC codes, or banking PINs on our servers.
- Tokenized References: Stripe returns a secure tokenized reference (Stripe Customer ID, Payment Method ID, last 4 digits of the card, card brand, and expiration date) which we retain to manage your active subscription and order invoices.
2.3 Download Activity & Quota Tracking
When you request a download grant or consume membership quota, our systems record:
- The product ID, version string, and cryptographic grant hash.
- Timestamp and IP address of the download request.
- Daily unique-product counters to calculate quota compliance under rule
BR-MEM-003.
2.4 Connected WordPress Sites (Addonry Manager Plugin)
When you link a WordPress installation via the Addonry Manager plugin using our device authorization flow:
- Data Transmitted: Site URL, WordPress version, active PHP version, and the list of Addonry-managed plugin/theme slugs. This information is strictly required to determine compatible updates.
- Data Explicitly Excluded: The plugin never reads, harvests, or transmits your WordPress post content, media library, customer orders, user credentials, comments, or MySQL database tables.
3. Authorized Subprocessors
We partner with vetted third-party service providers ("Subprocessors") to deliver hosting, edge security, email, and payment infrastructure:
| Subprocessor | Purpose | Location | Data Transferred |
|---|---|---|---|
| Stripe, Inc. | Payment gateway & subscription billing | United States / Ireland | Billing details, email, card tokens |
| Cloudflare, Inc. | DNS, DDoS defense, WAF, R2 file storage & CDN | Global Edge | IP address, request headers, download traffic |
| Transactional Email Provider | Email verification & receipts | EU / US | Recipient email, order confirmation data |
| Hosting Provider (Cloud VPS) | Application containers & PostgreSQL database | European Union (Germany) | Encrypted database records, server logs |
4. Cookies & Edge Technologies
Addonry adheres to a strict "privacy-first" cookie model. We do not use third-party advertising cookies, cross-site trackers, or data-broker pixels.
- Strictly Necessary Cookies:
gpl_session: A secure, HttpOnly, SameSite=Lax cookie essential for session authentication and account navigation.__Host-anti-forgery tokens: Used to defend against Cross-Site Request Forgery (CSRF) attacks during form submission.
- Preference Cookies: Local storage flags to remember theme preferences or collapsed sidebar states.
5. Data Retention & Erasure
We retain personal data only for as long as your account remains active or as required by statutory accounting, tax, and fraud prevention regulations:
- Financial transaction records are retained for statutory accounting periods (typically 7 to 10 years depending on jurisdiction).
- Download grant logs and transient IP addresses are rotated and aggregated after 90 days.
- Upon account deletion, all active session tokens and connected WordPress site tokens are immediately revoked and permanently deleted from our primary database.
6. Your Data Rights (GDPR & CCPA)
Depending on your jurisdiction, you possess specific rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Rectification: You may update inaccurate or incomplete profile information through your Account Security panel.
- Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your account and associated personal data, subject to legal record retention requirements.
- Right to Data Portability: You may request your transaction history and library entitlements in a machine-readable format.
- Right to Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service if you exercise your privacy rights.
To exercise any of these rights, please email our Data Protection desk at [email protected]. We respond to all verified requests within thirty (30) days.
7. Contacting Our Data Protection Officer
If you have questions, concerns, or complaints regarding this Privacy Notice or our data protection practices, please contact:
Addonry Privacy & Data Protection Desk
Email: [email protected]
Security Reports: Security & Vulnerability Desk