Privacy
What we collect, and what never leaves your server
WPNeedleFlow runs on your own WordPress site. Your clients’ names, phone numbers, dates of birth, consent forms and photo IDs stay in your database and are never sent to us.
The short version
There are two entirely separate things here, and it matters which is which.
- This website and store. If you buy a license, we hold the information needed to sell you software and support it: your name, email, billing details and order history.
- The plugin, running on your site. Your studio’s data — clients, appointments, consent forms, photo IDs, sales — lives in your WordPress database on your hosting. We have no access to it and it is never transmitted to us.
What the plugin sends to us
The plugin contacts wpneedleflow.com for two reasons only: to check your license and to check for updates. Those requests carry the following and nothing else:
| When | What is sent |
|---|---|
| Activating a license | Your license key, your site’s address, and the product name. |
| Daily license check | An activation token and your site’s address, so one paid license cannot silently run on twenty sites. |
| Deactivating | The activation token and your site’s address, to free the activation. |
| Update check | The product name, the version you have installed, and the activation token. |
No client record, appointment, consent form, photo ID, message log or sale is included in any of those requests. As with any web request, our server also records the originating IP address in its logs.
What the store collects
- Account and order data — name, email, billing address, purchase history, license keys and the sites they are activated on.
- Payment data — handled by our payment processor. Full card numbers never reach our server and we never store them.
- Support tickets — whatever you write to us, kept so we can follow up.
- Standard web logs and cookies — needed for login sessions, the cart and checkout. WooCommerce sets these; without them the store cannot work.
Services the plugin connects to on your behalf
You can connect your own accounts for card payments and text messaging. When you do, data goes directly from your site to that provider under your agreement with them, not through us:
- Square or Stripe — payment details, for deposits and register sales.
- Twilio — phone numbers and message text, for reminders and replies.
These are optional. The plugin works without them, and we never take a share of a sale.
What we do not do
- We do not sell or rent your information, or your clients’ information.
- We do not use your data to train anything, or share it with advertisers.
- We do not have a copy of your client list. There is nothing for us to hand over, lose or be breached of.
How long we keep things
Order and license records are kept while your license is active and afterwards for as long as tax and accounting rules require. Support tickets are kept so we can see the history of a problem. Ask us to delete your account data and we will, except where we are required to keep a record of a sale.
Inside the plugin, photo IDs are deleted automatically a set number of days after the appointment — you choose how many. That happens on your server, on your schedule.
Your rights
You can ask us what we hold about you, ask for it to be corrected, ask for a copy, or ask for it to be deleted. Write to us and we will answer. Depending on where you live, you may have additional rights under local law, and we will honour those.
If you are a studio owner: for your own clients’ data you are the one responsible for it. It sits on your hosting under your control. The plugin gives you the tools — consent records, ID auto-erase, an export — but the obligations are yours, not ours.
Children
The store is not intended for anyone under 18. The plugin handles bookings for minors on behalf of studios, but that data never reaches us.
Changes
If this policy changes materially we will update the date at the top and, where the change affects existing customers, tell you by email.
Contact
Questions about this policy, or a request about your data: privacy@wpneedleflow.com. You can also open a ticket from your account, which reaches the same people and keeps a record of the conversation.
XtraNet is the company behind WPNeedleFlow and is responsible for this policy.
