Privacy Policy

Last updated: September 20, 2026

1. What we collect

Customers: when you order an audit we collect your email address and the domain you ask us to audit. Reports are addressed by secret link; account holders access them via login. Payment details are handled by Stripe — card numbers never touch our servers. We also collect standard technical data (IP address, browser, pages visited) for security and analytics.

Website owners (prospective customers): we operate a security-scanning service for WordPress sites. To offer it, we collect publicly-available information about websites — the domain name, contact email addresses and contact-form URLs published on the site itself, and the site's WordPress configuration — sourced from public Certificate Transparency logs and from pages the site publishes openly on the internet.

2. Scan data

Audit findings are produced by read-only probes against public-facing surfaces of a domain (HTTP pages, TLS, DNS, well-known paths). We store the results to generate reports, to provide monitoring comparisons over time, and to produce aggregate, anonymized benchmarks. If a domain we have scanned isn't yours and you want its data removed, tell us at info@wpsecaudit.com with proof of control and we'll remove it.

3. Outreach & your choices

If your website publicly lists a contact email address or contact form, we may use it to send a one-time or short-sequence message about security issues our scanner found on your site, with a link to a free summary. Our legal basis is legitimate interest (B2B security notification). Every marketing email includes a working unsubscribe link; you can also opt out of all channels — including contact-form messages — at any time by emailing info@wpsecaudit.com with your domain or address. Opt-outs are honored promptly and permanently.

4. Breach data

Where we check whether site contact emails appear in public breach corpora (XposedOrNot / HaveIBeenPwned), we record breach names and dates only — never passwords or breach contents. This data appears in the affected site's own report.

5. Cookies

We use a session cookie for login and a signed cookie for pricing-experiment consistency. Optional analytics (GA4) fire only when the site operator enables them.

6. Sharing & processors

We don't sell personal data. We share data only with service providers acting on our behalf: Stripe (payments), Resend (transactional email), MailWizz (our self-hosted email platform), hosting providers, and lookup services (DNS resolvers, CVE databases, breach APIs) which receive the domain or email being audited as technically required for the lookup. Reports are shared only via links you create.

7. Retention

Customer accounts and reports are retained while your account is active and for up to 24 months after, for dispute and tax purposes. Prospect (website-owner) records that never convert are retained for up to 12 months, or deleted sooner on request. Backups roll off within 30 days.

8. Your rights (GDPR / CCPA & others)

Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to opt out of any "sale" or "sharing" (we do neither). California residents: we do not sell or share personal information for cross-context behavioral advertising. To exercise any right, email info@wpsecaudit.com; we respond within 30 days. EU/UK residents may also complain to their local supervisory authority.

9. Security & transfers

We use TLS in transit, encrypted credentials, least-privilege access, and rate-limited administrative surfaces. Data is processed in the United States (or where our hosting resides); by using the service you consent to that transfer. No method of storage is 100% secure; if a breach affects your data we will notify you as required by law.

10. Children

The service is not directed at children under 16 and we do not knowingly collect their data.

11. Changes & contact

We may update this policy; the "last updated" date above reflects the current version. Privacy questions or requests: info@wpsecaudit.com.