Legal
Unreviewed draftPrivacy policy
What data a Subset licence check sends, what this site stores, which subprocessors see it, and the several places where the answer is nothing.
Last changed . This is a draft, so that date says when the wording moved, not when anything came into force.
Who is responsible for this data
[legal entity name] — blank; to be supplied by the business, of [registered postal address] — blank; to be supplied by the business, is the controller of the personal data described here. Privacy requests go to [address for privacy requests] — blank; to be supplied by the business.
What this website collects
Nothing, as you read it.
That is not a figure of speech. The marketing site sets no cookie, writes nothing to local storage, and makes no third-party request. There is no analytics vendor in the dependency tree. If analytics is ever switched on it will be a cookieless, no-cross-site-identifier product — the kind that needs no consent banner — and this section will say which one by name.
The reason is not purity. One of the four plugins is a consent manager, and a consent manager whose own marketing site needs a cookie banner is not a product we could sell with a straight face.
“As you read it” is doing real work in that first sentence, and the one exception is the next section: if you type an address into the waitlist form and submit it, that is something you have chosen to give us, and we store it.
The waitlist
The form on the home page, the pricing page and each plugin page stores three things, and only these three:
| Data | Why |
|---|---|
| The email address you type | So there is somewhere to send the one message you asked for |
| Which plugin you are waiting for | So you are told about that one rather than about all of them |
| Which page you submitted from | So we know which pages people actually want to hear about |
No IP address, no browser, no referrer, no identifier of any kind is stored with it. We considered keeping the IP address as evidence that the sign-up was genuine, which is a common and defensible thing to do, and decided against it on the grounds that we have no dispute to settle and no customers yet.
It is double opt-in, which means the address is not on the list until you confirm it. Submitting the form creates a request to be emailed a confirmation link. Until that link is clicked, the record is a pending request and nothing is ever sent to it; if the link is never clicked, the request simply goes stale and is deleted. That is what stops anybody putting your address on a mailing list you never asked to join.
Unsubscribing takes one click, needs no account and asks you nothing. Every message carries a link that removes your address from the list on the first click. The link identifies the record by a random token rather than by your address, so it cannot be used to find out whether anybody else is on the list — and neither can the form, which gives the same answer to an address it has never seen as it does to one it already holds.
The list is stored in the same database as everything else here, readable only by server code — not by the key that this website’s own pages carry, and not by anybody signed in. There is no newsletter tool connected to it. When one is chosen it will be named in the subprocessor table below before any address reaches it.
What an account holds
When you buy a licence, or sign in, we store:
| Data | Why | Where it comes from |
|---|---|---|
| Email address | Signing in, licence keys, transactional email | You |
| Account name | Distinguishing accounts; agency and team use | You |
| Licence keys, in encrypted form | Verifying a site’s activation | Generated by us |
| Subscription and plan state | Knowing what you are entitled to | Stripe, by webhook |
| Billing identifiers | Linking your account to your Stripe customer | Stripe |
We do not store card numbers. We never see them: payment details go to Stripe directly and we hold an identifier that points at their record of you.
A licence key is stored encrypted and is never shown back to you in full after it is issued — not in the dashboard, not in support tooling. The internal admin can see a prefix and the last four characters and holds no key to decrypt the rest.
What a licence check sends
This is the part that matters most, because it happens on your site without you watching it. When a Subset Pro plugin checks its licence or looks for an update, it sends:
- the licence key, so we know which licence is asking;
- the site’s URL, normalised — scheme and
www.stripped, lowercased — because the site limit is counted in sites and a site has to be identifiable; - the plugin slug and its installed version, so the API can answer whether there is a newer one;
- the WordPress and PHP versions, so an update can be withheld from an environment it would break.
That is the whole list. It does not send your content, your users, your database, your other plugins, your traffic or your admin email.
Checks are cached. A plugin does not call us on page loads; a visitor to your site causes no request to us at all.
Hosted AI credits
Content you send to a hosted AI feature is its own question and gets its own page: hosted AI credits data handling. The summary is that the request is proxied, nothing about its content is stored or logged once it has been answered, and that service has not been built.
Subprocessors
These are the third parties that process data on our behalf. The list is short on purpose and every entry is load-bearing.
| Subprocessor | What it does | What it sees |
|---|---|---|
| Stripe | Payments, subscriptions, tax, invoices | Your name, email, billing address, card details |
| Supabase | Database, authentication, file storage | Everything in the account table above |
| Vercel | Hosting for the site, the dashboard and the API | Request metadata, including IP addresses |
| [AI provider] — blank; to be supplied by the business | Generating output for hosted AI features | The content of a generation request, while it runs |
Account data rests in [data region] — blank; to be supplied by the business. Where a subprocessor moves data out of your region, the transfer relies on their standard contractual terms; the review that replaces this draft has to confirm that rather than take our word for it.
We do not sell data, and we run no advertising, so there is no fifth row of this table and no category of recipient hidden behind the phrase “our partners”.
How long we keep things
- Account and licence records last as long as the account, plus whatever a tax authority requires of invoices — a period [governing law and venue] — blank; to be supplied by the lawyer decides rather than we do.
- Hosted AI request content is not retained at all. See its own page.
- Waitlist addresses last until you unsubscribe, which you can do from any message we send. An unconfirmed request is kept only while its confirmation link is valid — two days — and is then deleted.
- Server logs are kept briefly for debugging and abuse handling, and are not used to build a profile of anybody.
Deleting your account deletes the account, its memberships and its licences. Invoices survive it, because they have to.
Your rights
You can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to processing, or ask us to stop. You can do the common ones yourself: the dashboard changes your email and deletes your account without asking anybody.
If a request needs a human, it goes to [address for privacy requests] — blank; to be supplied by the business. If we get it wrong, you can complain to the supervisory authority where you live.
Children
Nothing here is for children, and we do not knowingly hold data about anybody under sixteen. This is a developer tool sold to people who run websites.
Changes
The date at the top of this page says when it last changed. A change that materially affects what we collect or who sees it will be announced to account holders rather than quietly deployed.