- Home
- Privacy policy
Privacy policy
Last updated 22 July 2026. This policy explains what we collect, why, and what you can ask us to do about it.
Template notice: this page is a structural starting point supplied with the site build. Have it reviewed by your own legal counsel and updated with your registered entity details before launch.
Who we are
WooSecure (“we”, “us”) provides managed security for WordPress and WooCommerce stores. For the purposes of the UK GDPR and EU GDPR we are the data controller for the account data described below, and a data processor for the site activity data we handle on your behalf.
Registered address and company number: [to be completed]. Data protection contact: privacy@woosecure.com.
What we collect
Account data
- Name and email address of each person you invite to your account
- The domains of the stores you connect
- Billing details, processed by our payment provider — we never store full card numbers
Security telemetry
- IP addresses and user agents of requests to your WordPress admin, used to allow or block access
- Admin activity events such as logins, order changes, price edits and plugin activations
- Error events raised by your site, including file names and stack traces
We do not receive, store or process your customers' payment details, cart contents or storefront browsing activity. WooSecure operates at the administration layer only.
Why we process it
- To provide the service — deciding whether a request to your admin is authorised. Lawful basis: performance of a contract.
- To keep the service secure — identifying attack patterns across the platform. Lawful basis: legitimate interests.
- To bill you — lawful basis: performance of a contract and legal obligation.
- To contact you about the service — incident notifications and material changes. Lawful basis: legitimate interests.
Where data is stored
Account data and security telemetry are stored on servers in the European Union. Where a sub-processor operates outside the EEA, transfers are covered by Standard Contractual Clauses.
How long we keep it
- Activity log events: retained for the life of your subscription, then 30 days after cancellation
- Blocked request telemetry: 90 days in identifiable form, then aggregated
- Account and billing records: as required by applicable tax law, typically seven years
Sub-processors
We use a small number of providers for hosting, payment processing, transactional email and error tracking. A current list is available on request from privacy@woosecure.com, and we will give notice before adding a new sub-processor that handles personal data.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or port your personal data, and to object to processing based on legitimate interests. To exercise any of these, email privacy@woosecure.com. We respond within 30 days.
You also have the right to complain to your local supervisory authority.
Cookies
This marketing site sets no advertising or tracking cookies. The WooSecure panel sets a strictly necessary session cookie so that you stay signed in; it cannot be disabled without breaking authentication.
Changes
If we make a material change we will update the date at the top of this page and notify account owners by email before the change takes effect.
Contact
Questions about this policy: privacy@woosecure.com.