Last updated: August 4, 2026
This Privacy Policy explains what personal data WPZOOM collects when you visit wpzoom.com, buy our products, or contact us — and why we collect it, how long we keep it, who we share it with, and what rights you have over it.
1. Who We Are
The website wpzoom.com (including its subdomains) is owned and operated by WPZOOM B.V., a private limited company registered in the Netherlands under KvK number 70938105, with its registered office at Herengracht 420, 1017 BZ Amsterdam, The Netherlands.
WPZOOM B.V. is the “data controller” of your personal data. For any privacy-related questions or requests, email us at hello@wpzoom.com or use our contact form.
2. What Personal Data We Collect and Why
Purchases and Accounts
When you buy a theme or plugin from our store, we collect the information needed to process your order: your name, email address, billing address and country, VAT number (if you purchase as an EU business), and payment details. We use this data to:
- Process your order, deliver your products, and send you order confirmations, invoices, and important account or service information
- Set up and administer your account, verify your identity, and provide technical and customer support
- Respond to your questions, refund requests, or complaints
- Determine the correct VAT rate for your purchase and retain evidence of your location (billing country and IP address), as required by EU VAT law
- Prevent fraudulent transactions
Your payment details are entered directly with our payment processors — Stripe for card payments and PayPal for PayPal payments — and never touch or get stored on our servers. We only receive confirmation of payment and, for card payments, the last digits of your card for reference.
If you create an account, we also store your username, password (in hashed form, which we cannot read), purchase history, and license keys.
License Activation and Software Updates
When you activate a license key for one of our products, or when your WordPress site checks for product updates, your site sends us your site URL, your license key, and information about the product installed, such as its version. We need this data to deliver updates and support, verify your license, and enforce activation limits. It is processed on the basis of our contract with you.
Support and Other Communications
When you contact us — by email or through our contact form — we keep a record of the correspondence, including your contact details and any information you choose to share, so we can resolve your request and refer back to it if you contact us again. Support conversations are managed in Help Scout, our help desk platform.
Comments
When you leave a comment on our blog, we collect the data shown in the comments form plus your IP address and browser user agent string to help with spam detection. Comments may be checked through Akismet, an automated spam detection service by Automattic.
An anonymized string created from your email address (a hash) may be provided to the Gravatar service to check whether you use it. The Gravatar service’s privacy policy is available at automattic.com/privacy. After approval of your comment, your profile picture is visible to the public in the context of your comment. Anything you include in a public comment can be read and collected by anyone — if you want a comment removed later, contact us.
Newsletter and Marketing Emails
If you subscribe to our newsletter, we use your email address (and name, if provided) to send you news about our products, tutorials, and special offers. You can unsubscribe at any time using the link in every email. If you are an existing customer, we may also email you about products and updates similar to what you’ve already purchased, based on our legitimate interest — you can opt out of these at any time as well.
Transactional emails (order confirmations, license and renewal notices, security notices, and legally required communications) are part of the service itself and are sent to all customers.
Cookies and Consent
We use cookies and similar technologies to make the site work, remember your preferences, and — only with your consent — for analytics and marketing. When you first visit, a consent banner (powered by the Complianz privacy suite) lets you accept or refuse non-essential cookies, and you can change your choice at any time. To record your consent, your IP address is anonymized and stored in our own database; no personal data is shared with Complianz. For the full list of cookies we use and their lifetimes, see our Cookie Policy.
Analytics
We use two analytics services to understand how visitors use our site (pages visited, time on page, approximate location, device and browser type) and to improve our website and products:
- Fathom Analytics — a privacy-first service that works without cookies and does not collect or store personal data (privacy policy).
- Google Analytics — used only with your consent, with IP anonymization. You can refuse or withdraw consent for analytics cookies at any time via the cookie banner settings (Google’s privacy policy).
Technical and Security Data
Like most websites, our servers automatically log technical data such as IP addresses, browser type, operating system, referring pages, and timestamps. We use this data to keep the site secure, detect and block abuse, and diagnose technical problems. Our site is served through Cloudflare, which provides content delivery, DDoS protection, and a web application firewall.
Embedded Content and Media
Articles on this site may include embedded content (e.g. videos, tweets, images). Embedded content from other websites behaves exactly as if you had visited that website directly: those sites may collect data about you, use cookies, and monitor your interaction with the embedded content, especially if you have an account with them and are logged in. If you upload images to our site (for example in support requests or comments), avoid uploading images with embedded location data (EXIF GPS), as visitors can download images and extract that data.
3. Legal Bases for Processing
Under the GDPR, we rely on the following legal bases:
- Performance of a contract — processing orders and payments, delivering products, license activation and updates, managing your account, and providing support.
- Legal obligation — keeping invoices and administration records for tax purposes, retaining VAT location evidence, and responding to lawful requests from authorities.
- Legitimate interests — securing our website and services, preventing fraud and spam, improving our products, and sending product news to existing customers (with the option to opt out).
- Consent — the newsletter, and analytics and marketing cookies. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
4. Who We Share Your Data With
We never sell or rent your personal data. We share it only with service providers (“processors”) who help us run our business, under data processing agreements that limit what they can do with it:
- Stripe — payment processing (privacy policy)
- PayPal — payment processing (privacy policy)
- Cloudways — web hosting
- Cloudflare — content delivery network and security (privacy policy)
- Fathom Analytics — cookieless website analytics (privacy policy)
- Google — website analytics, with your consent (privacy policy)
- Automattic — Gravatar profile images and Akismet spam detection (privacy policy)
- MailerLite — newsletter delivery (privacy policy)
- Help Scout — customer support help desk (privacy policy)
We may also share data with our professional advisers (such as our accountant, for financial administration) where necessary, and we will disclose personal data if we are legally required to do so — for example in response to a valid court order — or where disclosure is necessary to protect our rights, prevent fraud, or protect the safety of any person.
5. Where Your Data Is Sent
Some of the providers listed above are based outside the European Economic Area — for example in the United States — or process data there. When personal data is transferred outside the EEA, we make sure it is protected to EU standards: either the country or provider is covered by a European Commission adequacy decision (such as the EU–U.S. Data Privacy Framework), or the transfer is safeguarded by the European Commission’s Standard Contractual Clauses included in our agreements with them. You can request more details about these safeguards by emailing us.
6. How Long We Retain Your Data
- Orders, invoices, and payment records — 7 years, as required by Dutch tax law.
- Account data — for as long as your account is active. You can request deletion at any time; we will then remove your account data except what we must keep for the legal retention periods above.
- Support correspondence — 3 years after the last contact, so we can refer back to earlier issues.
- Blog comments — retained indefinitely, so we can recognize and approve follow-up comments automatically instead of holding them in a moderation queue.
- Newsletter data — until you unsubscribe. If you opt out, we keep your email address on a suppression list so we don’t contact you again.
- Cookie consent records — 12 months.
- Analytics data — 14 months for Google Analytics; Fathom Analytics stores only aggregated statistics that contain no personal data.
- Server and security logs — 30 days.
7. Your Rights Over Your Data
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your data deleted, except data we are obliged to keep for administrative, legal, or security purposes
- Restriction — limit how we process your data in certain circumstances
- Data portability — receive the data you provided to us in a structured, machine-readable format
- Objection — object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent — for any processing based on consent, at any time
To exercise any of these rights, email hello@wpzoom.com. We may ask you to verify your identity, and we will respond within one month. If you believe we are not handling your data properly, you also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
8. How We Protect Your Data
All traffic to our website is encrypted with TLS. Passwords are stored in hashed form. Payment card details are handled entirely by our payment processors and never stored on our servers. Access to personal data is limited to team members who need it to do their jobs and who are bound by confidentiality obligations. We keep our systems updated, scan them regularly for vulnerabilities, and use a web application firewall to block malicious traffic.
9. Data Breaches
Despite these measures, no system is perfectly secure. If a personal data breach occurs, we will assess it promptly, notify the Autoriteit Persoonsgegevens within 72 hours where required by law, and inform you directly if the breach is likely to pose a high risk to your rights and freedoms.
10. Automated Decision-Making
We do not make decisions about you based solely on automated processing that would produce legal or similarly significant effects. Our payment processors use automated fraud screening on transactions; if your payment is declined and you believe this is an error, contact us and we will look into it personally.
11. Children
Our website and products are intended for adults and businesses. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available on this page, with the “last updated” date at the top. If we make material changes, we will notify you by email or by a notice on our website.
13. Contact
Questions, concerns, or requests about your personal data? Email hello@wpzoom.com or write to WPZOOM B.V., Herengracht 420, 1017 BZ Amsterdam, The Netherlands.