๐Ÿ”’ Privacy

Privacy Policy

Last updated:

We don't sell your data and collect only the minimum needed to ship your order and run the service. Tap a section to read the details.

1 What we collect โ–พ
  • Account info โ€” email, name, phone (if provided), and the URL of the site you want upgraded.
  • Payment info โ€” handled entirely by our payment processor. We never see your card number; we receive a token + the last 4 digits.
  • Order data โ€” products purchased, status, delivery notes.
  • Integration data โ€” credentials needed to deliver an upgrade (payments, CRM, email). Encrypted at rest.
  • Site analysis output โ€” for a free plan we fetch the public HTML of your URL and run an automated audit. No passwords/logged-in content.
  • Logs โ€” IP, user-agent, request timing (debug + rate-limit).
  • Anonymous page views โ€” Vercel Web Analytics (URL path only; no cookies, no cross-site tracking, IPs not stored).
2 How we use it โ–พ

To deliver and support what you bought, send the receipts and updates you asked for, prevent abuse, and answer support. That's the whole list โ€” no ad targeting on your data.

3 Third-party processors โ–พ

We share the minimum required data with:

  • Stripe โ€” payments & payment integration (Stripe Connect). Privacy Policy.
  • Resend / Brevo โ€” transactional email (receipts, login links, replies).
  • Vercel โ€” hosting, edge logs, privacy-friendly Web Analytics. Analytics privacy.
  • Turso (libSQL) โ€” database hosting for orders, sessions, outbox.
  • Groq / OpenRouter / HuggingFace / Together / Cerebras / Cloudflare Workers AI โ€” model inference; we don't enable training-on-input where a no-train flag exists.
  • Firebase Auth (optional) โ€” Google / Facebook / Apple sign-in if you choose it.
3A Payment integration & KYC data โ–พ

If you activate payment integration, we use Stripe Connect to create a connected Stripe Express account on your behalf, sharing with Stripe:

  • Identity โ€” name, email, business details for verification (KYC) and compliance.
  • Transaction data โ€” amounts, currency, and customer metadata, used to calculate and collect the platform fee.
  • Account status โ€” onboarding status, whether charges/payouts are enabled, and any restrictions.

Stripe acts as both processor (on our instructions) and independent controller (its own AML/sanctions obligations). See the Stripe Privacy Policy and Connected Account Agreement.

Acquirer disclosure: card transactions are acquired by Wells Fargo Bank, N.A. (or another acquirer Stripe designates). Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. We don't access your Stripe dashboard credentials, bank details, or tax IDs โ€” Stripe collects those directly.

4 Cookies โ–พ

One first-party HTTP-only cookie, pms_sid, keeps you signed in (30-day expiry, never for ads). Paid integrations you enable on your own site (GA, Meta Pixel) add their own cookies โ€” our site itself does not.

5 Data retention โ–พ

Orders: 7 years (tax). Marketing subscribers: until you unsubscribe. Server logs: 90 days. Email outbox: 90 days after delivery. Idempotency keys: 24 hours.

6 Your rights โ–พ

Request a copy, deletion, or correction at plugmysiteaisolutions+privacy@gmail.com โ€” we respond within 30 days. EU/UK/California residents have GDPR / UK GDPR / CCPA rights, including complaining to a supervisory authority.

7 Security โ–พ

HTTPS + HSTS everywhere, scoped database tokens, signed webhooks, hashed passwords, per-user rate limiting, and Idempotency-Key replay protection on every state-changing endpoint.

8 Changes & contact โ–พ

We update this page when practices change and bump the date above; major changes are emailed to active customers. Questions: plugmysiteaisolutions+privacy@gmail.com (postal address on request).

PlugMySite ยท We collect the minimum, encrypt what matters, and never sell your data.