Legal

Privacy Policy

Last updated: June 14, 2026. Learn how we collect, use, and protect your data.

Preamble & Definitions

1. Preamble and Relationship Definitions

This Privacy Policy is a binding agreement detailing the data processing methodologies, collection protocols, storage paradigms, and security procedures implemented by Mega Plugin Hub ("we," "our," or "us"). This policy governs all interactions with our website, our software licensing APIs, our remote dashboard synchronization interfaces, and all WordPress plugin files developed and distributed under our marketplace environment.

By continuing to interact with our platform, you acknowledge that you have read, understood, and consented to the data practices described herein. This agreement governs both the direct collection of information on our centralized Hub and the transactional data flows processed through our developer nodes.

We value user transparency above all. This agreement serves to document our legal compliance structure under current frameworks including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Our data processing operations are governed exclusively by these documented parameters. In the event of updates, notifications are issued in accordance with our policy amendment schedules.

Specifically, this document outlines our relationship with you as a User (either a Vendor who builds extensions, or a Customer who deploys license activations on local server nodes). It is designed to explain, in plain English, what data we capture, where it is routed, and who has access to it. We do not engage in silent tracking or back-channel scraping. Every single byte of data transferred between your self-hosted WordPress site and the Mega Plugin Hub network is documented inside these articles.

Please note that if you are installing our plugins on client websites, you act as the data controller for those sites. You must ensure that your clients are aware of how their non-personal server statistics are processed under our support optimization logs.

Furthermore, the platform interfaces directly with payment APIs and licensing check pipelines. This connection ensures that active keys are validated in compliance with the purchase agreements you execute on our checkout portal.

If you do not agree to the data collection and processing methods described inside this policy, you must stop using our marketplace services, delete your active license codes, and deactivate our plugins from your WordPress websites immediately.

2. Platform Definitions

In this policy: "Data Subject" refers to any visitor, Buyer, or Author using our platform; "Processor" refers to Mega Plugin Hub; "Telemetry" refers to diagnostic logs and connection statistics; and "Cookies" refers to identifiers stored on your device to maintain sessions.

Additional definitions: "Services" refers collectively to all APIs, synchronization channels, support resources, and dashboard panels; "Third-Party Tools" refers to payment gateways, search networks, and content delivery nodes integrated into our workflow. All other capitalized terms not defined herein shall hold the meaning defined in our Terms of Service.

We define "Connected Site" as any self-hosted WordPress database node that has activated a valid license key generated by our licensing portal. "Option Array" refers specifically to the serialization of options configurations stored inside the default wp_options table.

Definitions are key to avoiding billing or compliance ambiguities. When we refer to "Vault Data," we mean local backup snapshots stored under the Safety Vault system. This data remains completely under your local server control and is never transmitted to us.

For clarity, "Webhook Endpoint" refers to the specific REST API route registered on your self-hosted server to handle Settings Sync signals. "Licensing Token" describes the unique key hash used to authenticate downloads from our update servers.

Additionally, "Author Wallet" refers to the ledger balance tracking system used by extension developers to monitor store credits before bank payouts.

Data Collection

1. Information Collection: Account Credentials

During registration, onboarding, and profile creation, we collect direct identifiers including your name, email address, password hash, and profile image. If you authenticate via third-party providers, we process the tokens and basic identifier details authorized by that provider.

We maintain secure logs of login activities, device identifiers, and IP locations to monitor account access profiles. If you register as an Author or Vendor, we collect additional verification files, including company registration logs, verification IDs, and developer credentials.

Password records are hashed using bcrypt mechanisms before being stored. No plain text password data is ever read or processed by our administrative teams.

Profile images are stored securely on our content delivery networks. Users retain the right to delete or update these assets at any point from their accounts.

OAuth tokens received from platforms like Google or GitHub are stored using vault encryption. We limit token usage strictly to authentication operations.

Vendor credentials are subject to manual audits by compliance leads. These documents are stored under high-grade encryption systems to block unauthorized reads.

Additional metadata including timezone selections, preferred language vectors, and notification choices are processed to custom-tailor your portal.

We audit metadata access logs weekly. This monitoring ensures that only authorized platform developers have visibility into system verification logs.

If you create a developer account, we also collect your publicly visible username, website URL, and portfolio descriptions. This information is displayed in our marketplace directory to allow Customers to verify vendor authority and check plugin developer profiles before purchasing licenses.

We log system interaction history, such as when you modify your payout options or cycle your developer API keys. These actions create a permanent log entry in your dashboard audit section to prevent social engineering hijackings.

Furthermore, if you submit support tickets, our agents link your account ID to the conversation records. This tracking allows our engineering team to check if a specific bug relates directly to a past purchase or custom license tier.

Lastly, we run automatic verification scripts to filter out fake or dummy emails. This check keeps our email communication channels clean and prevents system resources being wasted on dead mailbox bounces.

For premium vendor accounts, we also record external payout coordinates (such as bank branch codes, Stripe account details, or Razorpay wallet references) to process monthly sales splits.

We track login attempt history (specifically log files containing timestamps, login failures, and user-agent strings) to secure user dashboards from force-attacks.

2. Information Collection: Invoicing & Billing

To comply with tax laws and generate correct invoices, we collect physical billing addresses, company names, and tax registration identifiers (VAT/GSTIN). We do NOT store card details; payments are handled directly by PCI-DSS compliant sub-processors (Stripe/Razorpay).

All billing records are archived in secure, access-controlled databases to comply with global auditing standards. We also collect historical transaction hashes and invoice numbers to assist in order verification and checkout inquiries.

Billing addresses are verified using automated lookup databases. If a country mismatch occurs, transaction processing might be temporarily flagged.

Archived invoice objects are held in cold storage systems to protect records from modification. Invoices are accessible via the portal billing menu.

For transactions originating from India, we specifically record state codes to compute correct SGST, CGST, or IGST calculations. This matches GST law guidelines and generates tax-compliant documentation.

For EU customers, our system automatically runs real-time queries against the VIES (VAT Information Exchange System) database to validate VAT codes before applying tax exclusions.

We also record payment attempt status histories (such as card declines or 3D-Secure failures). This telemetry helps our checkout team debug cart drops and resolve checkout errors.

We retain invoice archives for up to 7 years in compliance with national tax auditing regulations. Access to invoice files is restricted to senior billing officers and tax auditors.

In addition, we trace order refunds, disputes, and payment chargebacks. These records are vital to protecting Authors from fraudulent buyers.

Tax registration documents uploaded by business accounts are stored in private cloud buckets. These files are excluded from standard web access.

3. Information Collection: Connected Sites

When you activate a license on a WordPress site, the plugin transmits metadata to map the activation to your Hub account. This includes domain names, site URLs, active license keys, and connection hashes generated to secure requests.

This metadata communication occurs periodically (e.g. daily) to verify key validity and check for updates. The platform does not collect admin passwords, private database content, or visitor analytics from your connected WordPress site.

Connection hashes are cycled weekly to maintain transfer security. If a connection validation fails, the plugin retries automatically.

We log domain metadata to track usage allocations against active license limits. Domain logs are deleted within 30 days of deactivation requests.

Additionally, the server connection API logs the external IP address of the hosting server where the site is running. This logging is necessary to protect our update mirrors from high-velocity automated scraping loops.

We also track the active SSL status of the connected domain. If a site runs on insecure HTTP, we display security recommendations in your dashboard.

When you link a client site, our plugin sets a unique local option constant `MEGA_HUB_CONNECTED` in the database. This local flag blocks duplicate connection requests from other accounts.

We process this domain data strictly for system maintenance. We do not sell, rent, or distribute domain listings or client site URLs to third-party tracking databases.

The licensing agent monitors if a site has deactivated our Settings Sync system. Unlinked sites are flagged as disconnected.

We track the specific version of the plugin running on each connected site. This enables us to notify you if a security patch is missing.

4. Information Collection: Environment Profiling

To resolve configuration conflicts, we trace software environment baselines of connected sites. This telemetry aggregates active PHP versions, WordPress core versions, active plugins, themes, database engines, and memory limit details.

This environmental data is parsed by our support systems to narrow down hosting compatibility bugs. It helps our Authors identify if a theme conflict, a low memory limit, or a deprecated PHP version is causing the plugin to fail.

Environmental statistics are aggregated anonymously. We use this data to publish global host charts and version distribution matrices.

Database engine version tracking ensures optimization scripts run only on supported setups. Unsupported system nodes block script execution.

PHP limits tracing includes memory settings, execution time caps, and file upload parameters. These limits help diagnose script termination issues.

Active plugin logs register directory slugs and current versions. We do not inspect plugin options or internal developer settings arrays.

Theme identifiers are restricted to author names, slugs, and child theme structures. Custom style files or code structures are never inspected.

Environment logs are retained for a maximum of 180 days before being automatically purged by database cleanup crons.

We track the PHP execution mode (such as FPM/FastCGI or Apache Mod_PHP) to understand thread handling issues. This detail is key for database locks diagnostics.

We trace whether object caching tools like Redis or Memcached are enabled on the host. This details whether the plugin should run persistent caching operations.

If you run on a multisite network setup, the telemetry records the network type and sub-site counts. This allows us to display correct multisite network dashboards.

Our system monitors environment profile updates asynchronously. The script consumes minimal resources and terminates execution within 15 milliseconds.

Environmental diagnostic logs include table storage sizes, column fragmentations indices, and transient allocations metrics.

We analyze server operating system types (such as Linux, Windows, or FreeBSD) to optimize local backup archiving scripts.

Web server software profiles (NGINX, Apache, LiteSpeed) are monitored to supply correct rewrite rule configurations for cache layers.

Lastly, timezone settings of the hosting server are recorded to align remote scheduled cleanup events with low-traffic periods.

5. Information Collection: Diagnostic Telemetry

Our performance plugins report diagnostic metrics to render health graphs on the Hub dashboard. This includes database size calculations, overhead values, transient row counts, spam comment counts, and cached page speeds.

Telemetry records are stored in aggregated form, meaning they cannot be linked back to individual site visitors. Authors use this data to calculate average optimization rates and detect database bloat patterns.

Database optimization suggestions are calculated on our servers using the scanned telemetry. These recommendations are purely advisory.

Page speed performance scans use public APIs. Scraping algorithms check only public pages - no backend pages are queried.

We track table-specific overhead metrics, identifying exactly which custom database tables contain fragmented indices. This allows the plugin to target only bloated tables.

Spam comment statistics log the total count of comments flagged in the wp_comments table. We do not download or process comment author names or emails.

Transient telemetry logs the count of expired option transients. Cleaning transients keeps the options table fast and prevents memory exhaustion.

All diagnostic metrics are sent via secure POST payloads. We encrypt telemetry databases separately to prevent data interception.

The dashboard displays database health charts comparing historical scan records. This visual tracking maps table optimization progress.

We log cache directory space metrics to detect if local disk sizes are approaching critical caps.

6. Information Collection: Infrastructure Logs

When you access our portal, our servers record standard internet logs. This includes originating IP addresses, browser headers, user-agent vectors, referral links, entries and exits timestamps, and clickstream data.

We use server logs to diagnose infrastructure issues, balance network traffic across server nodes, and track average loading latency. These logs are automatically rotated and purged after 90 days.

IP logs help our security team pinpoint geo-locations associated with brute-force attacks. We use this data to configure cloud firewall rules.

Browser user-agent statistics help our frontend engineering team optimize dashboard CSS layouts for popular devices and browsers.

We track API request execution speeds to discover bottlenecks. Slow database requests generate optimization alerts for database leads.

Infrastructure logs are archived on separate log servers. These servers have no direct routes to customer payment systems.

7. Information Collection: Support Logs

We log support ticket conversations, bug reports, and emails sent to us. This history is maintained to troubleshoot technical issues, monitor customer service quality, and verify billing claim disputes.

Support logs are retained indefinitely to build a searchable knowledge base of common solutions. Any attachments uploaded to tickets, such as system reports or log files, are stored on secure cloud storage and deleted upon ticket resolution.

We do not request administrative passwords inside support tickets. If you provide staging logins, they are stored inside encrypted secure notes fields.

Support agents review chats to monitor response qualities. Chats are used for training purposes to improve client resolution standards.

Ticket updates are broadcasted to client profiles in real-time. Automated mail notifications are dispatched when tickets close.

If a ticket references an active plugin bug, the issue is logged in our development database to track patching timelines.

Safety Vault Backups

1. Local Safety Vault Storage Exclusions

Our plugins include local database backups (Safety Vault). We explicitly state that database snapshots and vaulted data rows are stored entirely on your hosting server. We do not download, sync, or store your database content on our Hub servers.

By choosing to use our backup features, you acknowledge that all database clones and table exports remain inside your hosting server boundaries. Mega Plugin Hub has no physical or electronic access to these backups.

Encryption keys used for local backup security are stored inside your WordPress wp-config file. We cannot restore backups if keys are lost.

Backup cleanup actions run on local WP-Cron loops. The frequency of cleanup operations is defined by the site administrator.

We provide optional integrations to push backups to your personal AWS or Dropbox accounts. API keys for these connections are stored in your local DB.

All safety vault logs are stored in a custom database table using default WordPress prefixes. Access is limited to administrator accounts.

We run verification loops on local tables to check snapshot integrity. Corrupted rows are highlighted in the local admin panel.

No visitor metadata is backed up separately by the plugin. Backups mirror only the tables explicitly selected by the site administrator.

If you delete the plugin, all vault data tables are dropped immediately to keep your database clean. We do not maintain any recovery vectors.

You are responsible for ensuring that backup directories are protected from public HTTP execution. We set local .htaccess protection files automatically.

Staging site clones are stored separately under temporary configurations. These folders are excluded from standard production scans.

Backup security is controlled entirely by your server firewall permissions. We recommend utilizing strong directory protection filters.

If you execute manual backup restorations, the process runs completely on your PHP memory stack. Our servers do not receive confirmation tokens.

We do not store file structures or attachment directories in our databases. The backup engine packs only database schemas.

We trace the execution speed of backup scripts to provide optimization tips inside your local administrative layout.

Lastly, custom table backup configurations are recorded locally. Excluded tables (such as cache tables) are skipped dynamically during loops.

2. Safety Vault Database Limits

Local backups stored in custom tables on your database are subject to your hosting storage limits. Deactivating the plugin pauses the vault logs. Deleting the plugin drops these custom tables and permanently erases the safety snapshots.

We recommend periodically exporting your backup files to external cloud accounts or deleting old archives to prevent database bloat. The plugin displays diagnostic warnings if safety tables exceed 500MB.

Vault configurations are stored inside the local options array. No license parameters are synced with vault tables.

If database queries block due to server limits, we recommend scaling hosting packages or reducing backup retention lengths.

We restrict the maximum number of backup snapshots stored on your local disk to prevent filling up hosting space partitions.

Backup log execution histories are automatically truncated when table row counts exceed 1000 items to limit database load.

Processing Purposes

1. Legal Processing Bases: Contractual Fulfillment

We process profile, licensing, and transaction details under the Contractual Fulfillment basis. This data is required to validate license activations, issue license tokens, and execute billing charges.

If you decline to provide this essential information, we will be unable to generate licensing keys, deliver updates, or provide customer dashboard access.

License token generation occurs upon receipt of payment status. Verification logs map the token to the account ID.

Contractual data fields are locked after transaction checks. Access is limited to billing systems and support queues.

Specifically, our contractual obligations include maintaining a secure dashboard where you can check your orders, download codebase archives, download invoicing history, and manage domain allowances.

If a payment gets flagged as fraudulent, the contractual base allows us to suspend related licenses immediately to prevent credit card chargeback damage.

We also verify license allocations to support Author splits. Contractual parameters require calculating commissions accurately.

If a customer cancels auto-renewals, subscription records reflect the updated billing cycles to stop future transaction charges.

2. Legal Processing Bases: Explicit Consent

We process data under Explicit Consent for newsletters, promotional communications, and optional beta updates. You can withdraw your consent at any time via your settings panel.

Consent options can be adjusted inside your user profile. Opting out of promotional mailings will not affect transactional emails, such as order receipts and update alerts.

We collect consent for beta updates processing separately. Beta testing versions are deployed only on domains opting in.

If you write product reviews on our directory, you consent to displaying your username and purchase history alongside ratings.

3. Legal Processing Bases: Legitimate Interests

We process data under Legitimate Interests. This is required to secure the Platform, trace API usage, and protect the marketplace from license key piracy.

We perform balancing tests to ensure that our legitimate interest actions do not override your privacy rights. These security checks are designed to keep the platform free from spam and abuse.

Legitimate interests include tracing license activation velocity to flag bots. Scalping patterns block key execution instantly.

We trace login attempts to block brute-force vectors. Repeated failures blacklist IP ranges for a 24-hour period.

Support metrics are analyzed to optimize ticketing priorities. This tracking improves delivery speeds without sharing profile fields.

We run automated scans to flag nulled versions loading our scripts. Tracking piracy keeps our codebase clean and developers secure.

Additionally, tracking average server response rates helps our DevOps team scale VPS clusters before resources bottlenecks occur.

We inspect API requests metadata to trace script compatibility patterns. These metrics help block malicious file injection vectors.

If an account displays patterns of voucher abuse, our billing teams audit related profiles to maintain fair marketplace pricing.

We compile anonymous sales performance statistics to update marketplace category recommendations for dashboard users.

4. Data Processing Purposes: License Checks

Active domain checkings prevent license key fraud and trace current domain allowances. Keys displaying patterns of public distribution are deactivated.

License verification queries return simple true/false statuses along with activation counts. If a key activation count exceeds its allowance, subsequent activation requests are blocked.

License pings log the date, domain, and server IP. IPs are checked against known proxy lists to identify masked origins.

Key deactivations are updated in the vendor dashboard in real-time. Authors can audit deactivation reasons.

Expired keys run local deactivation queries. Option syncing is suspended immediately upon license expiration.

We track deactivation patterns to block keys linked to domain flipping. Key transfers must stay within normal guidelines.

Active domain arrays are refreshed automatically when options sync. Deleted sites clear slots within 15 minutes.

If a site is deactivated, our system issues a final options sync webhook to clean up validation settings tables.

License check pings use compressed JSON envelopes. This keeps HTTP payload sizes below 1.2KB to prevent server overhead.

We run key audits against known piracy platforms. Keys shared on leak databases are locked instantly by cron loops.

5. Data Processing Purposes: Automatic Updates

When new releases are uploaded by Authors, our servers process site updates. Connected sites authenticate their keys to pull new plugin ZIP files from our servers.

The updates API traces the current version of the plugin installed on your server to deliver the correct delta update files. Update downloads are logged for debugging deployment bugs.

Update distributions utilize Cloudflare edge caching. Download speeds are tracked to monitor delivery node metrics.

If an update fails due to zip extraction limits, our telemetry maps the error to display help tips in client panels.

6. Data Processing Purposes: Remote Option Sync

When options are edited on the Hub, a sync webhook writes options arrays directly to your site database. Webhooks do not read private tables - they only write plugin options.

Option synchronization runs asynchronously to prevent blocking WordPress admin pages. Sync payloads are cryptographically signed to ensure option integrity.

Sync logs record only the configuration timestamp and status code. Values of options arrays are not saved in API histories.

If option write operations fail due to database lockouts, the system queues subsequent updates for retry attempts.

7. Data Processing Purposes: Renewals & Orders

Transaction details process renewals, generate PDF invoices, and trace order statuses. GSTIN/VAT details are snapshotted in order tables to comply with local tax rules.

Renewals are scheduled using billing tokens provided by card networks. Order history records are locked after generation to prevent retro-active changes for tax security.

We match billing cycles with transaction histories to generate year-end tax folders for compliance teams.

Renewal fail events trigger email alerts. We attempt card transactions up to 3 times before pausing premium check features.

8. Data Processing Purposes: Security & Piracy

IP access logs and request headers are analyzed to mitigate DDoS vulnerabilities, prevent SQL injections, and trace unauthorized API requests.

We employ firewall rules to block IPs showing suspicious scraping activity. This protection is necessary to maintain fast response speeds for valid developers and users.

Security scan actions inspect core theme file directories on target nodes. Discovered vulnerabilities are logged locally.

We trace server resource utilization metrics during code scans to prevent script timeouts on budget hosting nodes.

Sub-Processors

1. Sub-Processors: Payment Gateways

Stripe and Razorpay process customer payments. These sub-processors receive emails, billing addresses, tax registration metrics, and tokenized payment details. We do not store card credentials on our servers.

Payment gateways process transactional details according to their own privacy standards. By initiating checkout, you authorize direct billing data sharing with these gateway services.

We review gateway compliance certifications annually. If a sub-processor fails security standards, integrations are suspended.

Refund requests communicate billing IDs directly with gateways. Transaction logs trace settlement balances.

Payment split setups route vendor payouts directly. Authors must link valid gateway profiles to request earnings transfers.

Gateway API endpoints use secure TLS structures. No billing fields are passed in clear text formats.

Stripe radar tools screen transactions for credit card fraud. Payment reviews delay checkout status codes momentarily.

Payment gateways record geo-IP parameters during card checks to run billing address matches.

2. Sub-Processors: CDN Services

We use Cloudflare to secure requests and purge site caches. Cloudflare processes access logs, IP details, and referral links to optimize API speeds.

Cloudflare caches asset files on edge nodes globally. CDN logs store visitor IP addresses to verify cache hit rates and block server scraping loops.

Cloudflare Web Application Firewall (WAF) screens API pings. Malicious request payloads are blocked at DNS levels.

CDN nodes distribute plugin zip files to minimize downloading latency. Download metrics optimize mirror selections.

3. Sub-Processors: Mail Delivery Systems

Transactional mailers (e.g. Mailgun) distribute verification links, invoices, and renewal alerts. Mailers receive customer names, emails, and invoice meta values.

Mail sub-processors track email delivery statistics, bounce rates, and link clicks. This telemetry is monitored to maintain optimal email delivery servers.

We sign email structures using SPF and DKIM tags. Verified headers prevent mail clients placing invoices in spam.

Mail logs store recipient strings and delivery response codes. Logs purge automatically after 30 days.

Cookies & Encryption

1. Regulatory and Legal Disclosures

We may disclose data under subpoena, court order, or to cooperate with law enforcement, in compliance with governing laws.

If we are legally required to disclose your personal information, we will make reasonable efforts to notify you in advance, unless restricted by law or court orders.

Legal review boards verify disclosures legitimacy prior to databases access. Invalid tickets are rejected.

We compile annual transparency index summaries documenting the volume of official request records processed.

2. Cookie Usage Policies

We store technical cookies on your device to maintain sessions, track preferences, and secure page routes. Disabling cookies will break portal dashboard features.

You can block cookies via browser settings, but doing so will break authentication states. We also use analytics cookies to measure page traffic and UX patterns.

Cookie files expire automatically based on classification. Session tokens purge upon browser termination; configuration values persist.

We do not use tracking pixels or cross-site tracking cookies. Third-party advertising integrations are prohibited on our network.

For absolute control, users can configure cookie parameters from their browser. Setting options block marketing configurations completely.

Cookie logs do not store IP strings. Data maps anonymously to prevent user tracking loops.

We run Cookie audits weekly to confirm that no unauthorized third-party scripts are generating tracking files.

If you select dark theme presets, our UI saves the state inside local browser cookie caches to speed up rendering loops.

3. Local Storage Settings Persistence

Local storage keys save admin settings and theme selections. This data remains on your device and is not synced to our servers.

Local storage values persist until cleared by your browser settings. No personal profile data or license hashes are cached in browser local storage.

Local variables record only configuration parameters (such as collapsed sidebar states or filter checks).

Browser garbage collectors clear temporary storage slots automatically. Disabling cache limits local persistent settings storage.

4. Network Security Protocols (TLS 1.3)

All REST API pings and option transfers use TLS 1.3 encryption. Passwords use secure hashing, and database access is locked under internal firewalls.

We run periodic penetration audits to evaluate database defenses. Internal communications between server databases use separate private networking lines.

TLS validation checks block connections using obsolete configurations. Legacy protocol headers are dropped instantly.

We run real-time file scanner scripts on servers to detect unauthorized modifications. Hacked systems isolate automatically.

5. X-Mega-License Authentication Keys

REST webhooks verify the X-Mega-License header. If the signature is invalid, the request is rejected immediately, protecting your site from configuration injections.

Authentication key validation happens locally on your server during request processing. Keys can be rotated inside the WordPress admin panel if you suspect compromise.

X-Mega-License headers carry signature hashes generated using SHA-256 routines. Shared secrets are stored in DB options.

Validation scripts trace authentication failures. Repeated invalid headers block IP access at local levels.

Retention & Deletion

1. Data Retention Guidelines

Account profile data is retained as long as your account exists. Tax laws require us to store billing details and transaction history for up to 7 years.

Inactive accounts displaying no order history are purged after 2 years of inactivity. Telemetry files and access logs are rotated automatically every 90 days.

Database snapshots and environment profiles are purged automatically when support tickets status switches to archived.

License records remain in database history tables to verify author split commissions during legal audits.

We configure database purging rules to run automatically at midnight. Purged indices are wiped completely from physical disks.

Email lists are cleaned quarterly. Unsubscribed addresses are scrubbed from transactional mailing records to prevent accidental sends.

We verify backups directories are cleared. Staging records delete once developer testing tasks conclude.

We retain support correspondence arrays indefinitely to ensure compliance queries can be checked against order logs.

2. Account Deletion Purging Timelines

Upon request, we delete your account profile within 30 days. Traced logs are anonymized, and site sync connections are terminated.

Once deleted, your account is unrecoverable, and your license keys will stop working. Authors wallet balances must be withdrawn before submitting a deletion request.

Backup archives are cleaned up instantly from edge mirrors. Synced servers process deactivation webhooks within 24 hours.

We send a final confirmation email containing order numbers prior to account deletion executing. This notice is non-optional.

Deletions scrub account tables, user profiles, download history records, and linked site registries from central databases.

We verify that third-party nodes update their datasets. Payment processors receive deletion alerts within 48 hours.

GDPR & CCPA Rights

1. GDPR Right of Access

EEA/UK users can request a copy of all personal data we store. Reports are delivered in a machine-readable JSON/CSV format.

Access reports are provided within 30 days of request receipt. Verification steps are required to ensure the data is delivered to the correct owner.

Subject Access Requests (SAR) can be initiated from the account privacy menu. There are no fees associated with standard requests.

Reports detail login histories, device classifications, licensing profiles, billing databases, and support chats.

If a request requires manual developer parsing, we notify the user regarding a possible 15-day processing extension.

Verification requires providing a valid photo identification card matching the profile billing registration.

Digital copies are sent via encrypted email loops. The download link remains active for a 7-day period.

We log SAR execution timestamps to comply with regulatory tracking rules. Content of the report is not cached in logs.

If you detect data fields omitted from reports, you can request manual audit scans. We run full database diagnostics searches.

SAR files are packaged using zip compression with secure password setups. Passwords are sent via separate SMS or secure email.

Additionally, if you hold active subscriptions, the access report details planned automatic renewal dates and linked Stripe cards.

GDPR compliance guarantees access to system configuration hashes. Users can review webhook sync logs directly.

We deliver portability formats in standard structures. Data packages include transaction invoices and keys histories.

Access rights survive profile suspensions. Blacklisted accounts can still request personal data reports via compliance mail.

2. GDPR Right of Rectification

You can correct profile, address, or invoicing details at any time from your account panel.

Corrected address values will propagate to all future order records automatically. Historical order documents cannot be updated once locked for tax submission.

Rectification changes execute instantly in our database. API updates check new profiles values during licenses pings.

Billing names modifications require manual verification checks if linked to active business tax numbers.

3. GDPR Right of Portability

You have the right to request the transfer of your profile and transaction records directly to another platform provider.

Portability requests are processed in standard formatting arrays. We do not charge fees to package or transmit portability files.

We serialize profile files using JSON formats. Transfer scripts connect directly with external platform nodes if requested.

We test file formats compatibility. Custom tax fields are packaged under standardized tags to prevent importing errors.

4. GDPR Right to Erasure

You can request the permanent erasure of your personal data. We comply within 30 days, unless a legal hold or tax audit requirement blocks it.

Erasure requests apply to all platform nodes. Tax billing metadata is retained separately as legally required by local corporate registries.

If a license key is connected to active client sites, erasure requests automatically terminate option sync actions.

We archive de-identified transaction hashes to maintain billing balances. These hashes are completely stripped of personal references.

Erasure validation queries scan cloud storage buckets to ensure all corresponding support attachments are dropped.

If a user holds active vendor wallet balances, erasure blocks until payout balances clear standard bank networks.

We notify sub-processors regarding erasure requests. Stripe and Cloudflare process corresponding deletions within GDPR deadlines.

Once erased, we send a final verification ticket to the parent email. No recovery operations are available.

If a user registers a new account after erasure, historical order records cannot be linked to the new profile.

Erasure procedures are audited by external data protection agencies to confirm compliance with global standards.

5. CCPA Consumer Privacy Rights

California residents can opt-out of data sales (which we do not do), access stored profiles, and request deletion without discrimination.

California users can submit data requests using the contact details below. We verify CCPA request identity via registered email pings.

We do not sell user profiling parameters to marketing agencies. Telemetry is restricted entirely to plugin operations.

CCPA disclosures are updated annually to match compliance standards. The compliance history is logged.

6. Minors Privacy Safeguards

Our services are not intended for children under 13. If we discover we have stored data of a child under 13, we purge it immediately.

Parents can submit verification alerts if they believe their child has registered an account. We investigate and purge such account records within 48 hours.

7. Cross-Border Data Transfers

Personal data may be transferred to and processed in servers located outside your region, secured under standard contractual clauses.

We maintain active data transfer agreements with all sub-processors. These legal nodes guarantee data security levels equal to your home region.

8. Policy Amendments

We update this policy as regulations change. Changes are published on this page, and major updates are sent via email notification.

We log historical versions of our privacy terms. Continued use of our software licenses constitutes acceptance of updated privacy terms.

9. Contact Information

For questions on data protection or to request erasure, email our compliance officer at support@megapluginhub.com.

You can also submit legal compliance queries directly from your dashboard support panel. We reply to all privacy inquiries within 3 business days.