1. Overview
At PluginShift (“PluginShift”, “we”, “us”, or “our”), we prioritize your privacy while delivering premium WordPress and WooCommerce plugins. This Privacy Policy outlines how we collect, use, and share your information in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Bangladesh Digital Security Act 2018, and other applicable laws. Our goal is to be transparent and cooperative while limiting our liability to the fullest extent permitted by law.
This policy applies solely to data processed by PluginShift through our website (https://pluginshift.com) and related subdomains. It does not cover third-party sites, services, or actions beyond our direct control. By using our services, you agree to this policy and our Terms & Conditions, subject to your legal rights.
For general inquiries or for any privacy request or complaint, contact our team at admin@pluginshift.com. We are committed to cooperating fully within legal requirements.
2. Who we are
PluginShift, founded in 2024, is a software company headquartered at Sector 10, Road 10, House 23, 1230 Uttara, Dhaka, Bangladesh. We specialize in WordPress and WooCommerce plugins — including Wholesale Engine and Product Recommendations — released under the GNU General Public License (GPLv3). Our services include product sales, downloads, support, and newsletters. We act as the data controller for personal data collected directly.
Third-party processors (for example, Paddle for payments) handle data under strict agreements. PluginShift is not liable for a processor’s actions taken beyond our instructions.
3. Information we collect
We collect only the minimal data necessary for our services, divided into personal data (which identifies an individual) and non-personal data (anonymized or aggregated). No sensitive data is stored in our proprietary tools.
Personal data
We collect personal data only with your explicit consent or to fulfil our services:
- Account & purchase data: name, email address, country (for tax and geolocation), and billing details. “Purchase information” includes transaction IDs, licence keys, and order history used for licensing and support.
- Newsletter data: name and email address for product updates and offers. You can unsubscribe at any time via the links in our emails.
- Support data: your name, email, and the contents of messages you send us by email or through our contact form.
- Usage data: anonymized licence-key usage (such as activation counts) to prevent abuse, collected only with opt-in consent via your account dashboard.
Non-personal data
We also collect data that does not directly identify you:
- IP address (masked), device type, browser, operating system, and city-level location.
- Site usage: pages visited, time spent, referral sources, and activity such as clicks.
- Aggregated analytics: trends used for marketing and product improvement.
4. Children’s privacy
We do not knowingly collect data from individuals under 18 (or under 16 where the GDPR applies). Our services are not intended for children. If such data is inadvertently collected, we delete it promptly upon notification to our team at admin@pluginshift.com. We comply with the Children’s Online Privacy Protection Act (COPPA) but are not liable for unintentional collection that occurs without our knowledge.
5. How we collect information
- Directly: via forms, account creation, purchases, or subscriptions, with clear consent prompts.
- Automatically: using cookies, server logs, web beacons, and analytics, subject to your consent settings.
- From third parties: from Paddle (transaction confirmations) or from social media if you interact with us there (for example on LinkedIn, GitHub, or YouTube). PluginShift is not responsible for third-party practices outside its scope of operations or jurisdiction.
We provide a cookie consent banner so you can accept, reject, or customize non-essential cookies. Rejecting cookies may limit personalization but not core functionality. You are responsible for managing your own browser settings.
6. How we use your information
We use data for defined purposes, based on legal grounds (consent, contract, or legitimate interests):
- Service delivery: process purchases, deliver products, manage accounts, and issue invoices (contract basis).
- Communication: send updates, newsletters, and offers (consent basis; opt-out available).
- Support & security: respond to inquiries, monitor fraud and spam, and improve services (legitimate interests).
- Marketing: personalize offers with your consent (opt-out via your settings).
- Compliance: fulfil legal obligations, such as tax reporting under Bangladeshi law.
We limit use to these purposes and are not liable for misuse by users or third parties beyond our control.
7. Sharing your information
We do not sell personal data. We share data only as necessary, with your consent or where legally required:
- Service providers: Paddle (payments) and our analytics provider process data under strict agreements, with Standard Contractual Clauses (SCCs) for GDPR compliance. PluginShift is not liable for their actions taken beyond our instructions.
- Social media: interaction data may be used for advertising with your consent. You can opt out via each platform’s settings. PluginShift is not responsible for platform policies.
- Legal compliance: we disclose data to comply with laws (such as the Bangladesh Digital Security Act 2018) or to protect rights (for example, under a court order). We cooperate fully but are not liable for legally required disclosures.
- Business transfers: data may be transferred in a merger or acquisition, with prior notice. We are not liable for a successor’s actions.
- Aggregated data: anonymized insights may be shared for research, without identifying information.
For CCPA users: we have not “sold” or “shared” personal data in the past 12 months. International transfers use SCCs or equivalent safeguards. PluginShift is not liable for third-party breaches.
8. Payments
All purchases are processed by Paddle.com Market Limited, who act as the merchant of record and data controller for payment information. Your card details are handled by Paddle under PCI-DSS standards and are never stored on our servers. Please review Paddle’s own privacy policy for how they process payment data.
9. Your rights & choices
You have rights under the GDPR, CCPA, and Bangladeshi law, which we fully support:
- Access: view the data we hold about you.
- Rectification: correct inaccuracies.
- Erasure: request deletion, subject to legal retention.
- Objection / restriction: limit how we process your data.
- Portability: receive your data in a machine-readable format.
- Withdraw consent: at any time, without affecting prior processing.
- CCPA-specific: opt out of “sales/sharing” (not applicable to us), limit sensitive data, and non-discrimination for exercising your rights.
To exercise any of these rights, email admin@pluginshift.com. For cookies, manage your choices via our consent tool or your browser settings. You may opt out of Google Analytics at tools.google.com/dlpage/gaoptout. We honor Do Not Track (DNT) and Global Privacy Control (GPC) signals but are not liable for browser compatibility issues. You also have the right to complain to your local data-protection authority.
10. Data retention & security
Retention: personal data is retained only as long as needed — for example, account data until you request deletion, and invoices for 7 years per Bangladeshi tax law. Non-personal data is kept for up to 26 months. Refunds under our 14-day money-back guarantee (see our Refund Policy) trigger deletion of related purchase data unless we are legally required to keep it. We are not liable for data retained to meet legal obligations.
Security: we use encryption (SSL/TLS), access controls, least-privilege practices, and regular audits. Paddle ensures PCI-DSS compliance. We take reasonable measures but are not liable for breaches beyond our control. In the event of a breach, we notify affected users and authorities within 72 hours (as required by the GDPR) and cooperate fully; liability is limited to direct negligence.
11. Cookies & tracking technologies
We use cookies for essential (e.g. login), functional (e.g. preferences), and analytics/marketing purposes. See our Cookie Policy for details. Essential cookies are always active; others require your consent via our banner. We are not liable for a user’s failure to manage cookie settings, or for third-party tracking beyond our instructions.
12. Changes to this policy
We may update this policy to reflect legal or operational changes. Significant updates will be posted on this page with a new “last updated” date. Continued use of our services implies acceptance. We are not liable for a user’s failure to review updates.
13. Governing law
This policy is governed by the laws of Bangladesh, without regard to conflict-of-law principles. Disputes will be resolved exclusively in the courts of Dhaka, Bangladesh. We cooperate with legal processes but are not liable for outcomes beyond our control.
14. Contact us
For any privacy questions or requests, contact us at admin@pluginshift.com, or write to us at Sector 10, Road 10, House 23, 1230 Uttara, Dhaka, Bangladesh. We respond to all legitimate requests within the timeframes required by applicable law.
Questions about this document? Contact us at admin@pluginshift.com or by post at PluginShift, Sector 10, Road 10, House 23, Dhaka, Dhaka 1230, Bangladesh.