WPNoti
Back to siteSign up
PrivacyTermsAccount deletionData processing

WPNoti Privacy Policy

Last updated 24 September 202614 min read
Who we areOur role and the store operator’s roleInformation processed through WPNotiWhy we process data and our legal basesWho receives informationInternational transfersRetention and deletionYour rightsSecurityChildrenPolicy updates
In short
MB DEVELOPERIS operates WPNoti and is the contact for account, billing, and support data.
Store customer details are read for the shop you connect. Full form messages stay on that shop.
You can ask for access, correction, or deletion. Account deletion is described on its own page.
01

Who we are

WPNoti is operated by MB DEVELOPERIS, a Lithuanian legal entity, company code 305652066, VAT number LT100015358510, registered address Daukšių g. 2, Daukšių k., LT-18102 Švenčionių r., Lietuva (Lithuania). In this policy, “WPNoti”, “we”, “us” and “our” mean MB DEVELOPERIS.

Contact us about privacy or your personal data at [email protected], by telephone at +370 603 20205, or by post at the address above.

This policy explains personal-data processing connected with wpnoti.com, our iOS and Android applications, the WPNoti WordPress plugin, accounts, subscriptions and support. WPNoti connects to WooCommerce stores to provide store information, management tools, monitoring and notifications.

02

Our role and the store operator’s role

We act as a controller when we determine why and how to process information for our own account administration, subscriptions, billing, service communications, security and business administration. This includes information about individual subscribers, business representatives, invited team members and people who contact us.

For personal data supplied by a connected store and processed to provide its requested features, the store operator normally acts as the controller and we act as its processor. This includes customer and order information, form submissions and previews, store staff information, visitor information and personal data within store alerts. Data can remain personal data even when it contains only an order identifier or a pseudonymous visitor identifier. Processing data temporarily, without saving it in a database, is still processing.

The distinction depends on the purpose, not just the database containing the information. For example, a push token is used to administer delivery, while customer information in the notification is processed for the store operator. Support correspondence about our service is generally controller data; customer records included for troubleshooting are processed on the operator’s behalf where applicable.

Our Data Processing Addendum governs processing on behalf of store operators. If an agency uses WPNoti as a processor for a shop, we act as its subprocessor for that processing.

If you are a customer, visitor or employee of a connected store, consult that store’s privacy notice and normally direct requests about its records to the store operator. If you contact us, we will help identify the appropriate route and assist the operator where required. This does not restrict your rights against us for processing for which we are a controller.

03

Information processed through WPNoti

Accounts, invitations and authentication

We process your email address, authentication identifiers and authentication information, workspace name, membership role, preferences and account status. Supabase provides authentication. If you choose Google or Apple sign-in, we receive the identifier and profile information that provider makes available for sign-in, which may include your name and email address or Apple relay email address. We do not receive your Google or Apple password.

Optional authenticator-app verification involves authentication-factor information needed to verify codes. Workspace administrators provide the email addresses of invitees; we use these to send and administer invitations. Invitation links contain access tokens, with hashed tokens stored in the relevant invitation records.

Store connections

We process the connected store’s URL, display name, connection credential, WordPress, WooCommerce, PHP and WPNoti plugin versions, currency, timezone, connection status and event/check times. Store connection credentials are encrypted before storage.

Orders, notifications and form messages

For order lists and alerts, we store order identifiers and numbers, status, total, currency, item count, payment method and dates. This order-summary record does not contain dedicated fields for the customer’s name, email, postal address or phone number. Customer information can nevertheless be processed through other features described below.

We store notification titles and bodies. They can contain order information, form names and short submission previews, error descriptions, store-administrator or shop-manager activity, and uptime or vulnerability findings. Free-text previews and error messages may contain personal data supplied by a store or its users.

Full form submissions remain on the connected WordPress site and are retrieved when requested. A short preview may also be stored in our notification history and sent through push delivery. Store operators should avoid sending sensitive or unnecessary information in previews, error messages or support requests.

Information retrieved on demand

When an authorised workspace member opens the relevant feature, WPNoti may retrieve and transmit full order details, customer names and contact details, delivery and billing addresses, order notes, purchase history, customer search results, products, coupons and full form submissions.

These responses pass through our infrastructure to provide the requested screen. They are not intentionally saved as full customer or order-detail records in our application database. This does not mean that no data is processed, that devices have no cache, or that operational systems cannot retain technical information. Notification previews, support copies and local caches have their own retention rules below.

Notifications and devices

We process the Expo push token, platform, device name, last-seen time and notification preferences for registered devices. Push delivery uses Expo and the relevant Apple or Google delivery infrastructure. Notification content may appear on a lock screen or be visible to someone with access to the device. You can change notification preferences in WPNoti and notification permissions or preview visibility in your device settings.

Monitoring and vulnerability findings

We process store availability, response status, response time, error information and downtime/recovery incidents. Vulnerability reports match the store’s reported software inventory against Wordfence’s public vulnerability feed and are encrypted before storage. Retrieving the public feed does not involve sending your customer list to Wordfence.

Live visitors

The plugin can maintain short-lived visitor information in the store’s own database, including a hashed identifier and page path. The live view concerns recent visits, including the preceding two minutes; this display window is not itself a statement of database retention. WPNoti retrieves live visitor information and counts when that feature is opened. We do not maintain a separate visitor-profile database for this feature.

A hashed identifier may still be personal data. Counting depends on the store’s configuration and integration with supported consent tools. The store operator must determine whether consent is required, provide the necessary notice and ensure tracking does not start before any required consent. Installing WPNoti alone does not establish that a store’s tracking is compliant.

Payments and subscriptions

For website subscriptions we process billing name, email, business or individual status, VAT number where applicable, billing address, country, and Stripe customer and subscription identifiers. Stripe processes payment details; our application database does not store full payment-card numbers.

For Apple or Google subscriptions we process the billing platform, product and transaction identifiers, a hash of the purchase token and subscription status or expiry. Purchase evidence is transmitted for validation. Apple and Google also process purchases under their own terms and privacy notices.

Support and local storage

Support records include sender details, store URL, subject, message content and replies, together with information you choose to provide. Please omit passwords, complete payment-card details and unnecessary customer information.

The mobile application uses secure device storage for session information and a local database for product fields such as name, SKU, price, stock and status. The current app’s sign-out and in-app account-deletion routines remove its local database. Account deletion through another device or the website does not necessarily immediately erase an offline device’s cache. Remove local app data or the app from devices you no longer use.

Website cookies and similar storage

The website uses these cookies. Sign-in and the record of your cookie choice are necessary. Statistics and marketing cookies are off until you accept them in the cookie banner.

Until you accept statistics cookies, Google Analytics (measurement ID G-G18Q749643) runs in consent mode without an analytics cookie. It can receive a page measurement that is not stored as an identifier on your device. If you accept statistics cookies, Google Analytics stores its usual identifiers so visits can be recognised across pages. Advertising storage stays off unless you accept marketing cookies. Rejecting or withdrawing a category deletes the matching analytics cookies.

CookiePurposeLifetime
platform-localeRemembers the signed-in language, en or lt1 year
platform-timezoneRemembers the time zone used to show dates1 year
platform-time-formatRemembers a 12-hour or 24-hour clock1 year
wpnoti_nativeMarks a page opened inside the mobile app. Value 1. Not used for tracking.1 hour
Session cookies whose names start with sb-Keep the signed-in Supabase sessionFor the auth session. The exact expiry is set by Supabase.
cookieyes-consentStores the choice made in the cookie banner. Necessary.Set by CookieYes, typically 1 year
wp_consent_statistics, wp_consent_preferences, wp_consent_marketingStores that choice for the site consent API. Necessary.180 days
wp_consent_service_google-analyticsStores whether Google Analytics is allowed. Necessary.180 days
_ga, _ga_*Google Analytics identifiers. Set only after statistics cookies are accepted.Up to 2 years

Browser controls can remove or block cookies. Blocking the session cookies prevents sign-in. The preference cookies are set when a signed-in person loads or saves account preferences.

04

Why we process data and our legal bases

The following applies where we act as a controller under the General Data Protection Regulation (GDPR):

PurposeLegal basis
Set up and administer an individual’s subscription, provide requested account functions, billing and supportPerformance of our contract with that individual, or steps they request before contracting — Article 6(1)(b)
Provide access for a business’s staff or representatives; administer invitations and business contactsOur legitimate interests and those of the subscribing organisation in administering and securely providing its service — Article 6(1)(f). An employer’s contract is not automatically a contract with its employee.
Authenticate users, prevent unauthorised access and misuse, maintain proportionate security/audit records and investigate faultsLegitimate interests in a secure, reliable service and protecting users — Article 6(1)(f); legal obligation where a specific duty applies — Article 6(1)(c)
Issue and retain required accounting/tax records; comply with lawful mandatory requestsLegal obligation — Article 6(1)(c)
Handle complaints, preserve necessary evidence and establish or defend legal claimsLegal obligation where applicable; otherwise legitimate interests in resolving disputes and protecting legal rights — Articles 6(1)(c) and 6(1)(f)
Statistics and marketing cookies, and Google Analytics identifiers tied to the browserConsent — Article 6(1)(a), with the consent required by electronic-communications law. Cookieless consent-mode measurement is limited to what that mode sends while analytics storage is denied.

We assess whether legitimate interests are outweighed by your interests and fundamental rights. You may object as explained below.

Push delivery supports the service and preferences you request, under the relevant contract or legitimate-interest basis above; device permission is an additional delivery control and is not automatically our GDPR legal basis for every related operation. Customer information inside alerts is processed on the store operator’s instructions and legal basis.

Where we act as a processor, the store operator determines the purpose and lawful basis. Our contract with that operator does not independently supply a lawful basis for every use of its customers’ information.

You must provide the account and connection details necessary for the features you request; without them we cannot provide those features. Required billing information may also be needed by law. Optional features and optional information are identified when requested.

05

Who receives information

Authorised workspace members receive the store information their access permits. Grant access only to appropriate people. Our personnel and service providers receive access as needed for their duties, subject to suitable confidentiality and access safeguards.

Recipient/servicePurpose and relevant information
HostingerWebsite and platform hosting on a server in Lithuania. File backups of that hosting are stored in France. Service email is sent through Hostinger.
SupabaseAuthentication and database services. The project region is Frankfurt, Germany. The current project is on Supabase’s free plan, which does not include database backups. Database backups will start when the project moves to Supabase Pro, and this policy will then state that backup period.
Expo, with Apple/Google push infrastructureDeliver device notifications using tokens and notification payloads.
StripeProcess website billing, payments and subscriptions. It may act as a processor for some activities and an independent controller for others.
Apple and GoogleOptional sign-in, app-store purchases, validation, account/store administration and relevant push delivery. Their independent activities are governed by their own privacy notices.
Connected store and its hosting providerReceive feature requests and authorised store changes; retain the underlying WooCommerce records. The store operator chooses its host.
Professional advisers and public authoritiesNecessary accounting, legal advice, dispute handling or compliance with binding legal requirements.

We may disclose necessary information to a prospective acquirer or successor in a genuine business transaction, with appropriate confidentiality and data-protection safeguards and any legally required notice. We do not treat a business transfer as permission to use information for incompatible purposes.

The current processing-provider details, locations and safeguards are set out in the provider schedule to the Data Processing Addendum.

06

International transfers

Our confirmed primary hosting locations are Lithuania for the platform and Frankfurt, Germany for Supabase. A European hosting region does not establish that all support, authentication, email, push or payment processing stays within the European Economic Area (EEA).

Where data is transferred outside the EEA, we must use a lawful transfer mechanism, such as an applicable European Commission adequacy decision or appropriate contractual safeguards, with additional measures where needed. An EU–US Data Privacy Framework adequacy decision can be relied on only for a covered transfer to an appropriately certified recipient. Consent to this privacy policy is not a substitute for transfer safeguards. You may ask us for information about the safeguards relevant to your data and a copy of applicable safeguards, with necessary confidential information redacted.

07

Retention and deletion

We retain personal data for the purposes described above, applying the following schedule. Shorter retention applies when a valid deletion instruction or request requires it; specific legal retention exceptions are described below.

CategoryRetention rule
Account/authentication information, membership, user preferences and push registrationsWhile required for your account; removed on account deletion, subject to the limited exceptions below. Inactive push registrations are also removed after 90 days without being seen.
Store connections, encrypted credentials, current vulnerability reports and workspace configurationWhile the workspace uses the connection; removed when the workspace is deleted.
Mirrored order summaries90 days from the order’s creation date, or earlier workspace deletion.
Individual uptime checks90 days from the check, or earlier workspace deletion.
Uptime incidents90 days from the incident start, or earlier when the workspace is deleted. The daily cleanup removes incidents older than that.
Notification titles, bodies and short form previewsKept until the workspace is deleted. WPNoti does store these. The full form submission stays on the store and is kept for as long as that store keeps it.
Unaccepted invitations, pairing and other short-lived access recordsRemoved after expiry by scheduled cleanup. Accepted invitation records are deleted 3 days after acceptance by the same cleanup.
Internal operator audit eventsUp to 730 days from the event, unless an earlier erasure is required or a specific legal hold applies. Retention must remain necessary and proportionate.
Workspace support threads and repliesUntil workspace deletion, or earlier deletion when no longer needed.
Support mailbox copiesKept in the Hostinger mailbox until MB DEVELOPERIS deletes that message. There is no automatic expiry.
Workspace billing settings and subscription-validation recordsWhile needed for the subscription/workspace, then deleted, except the minimum records required for accounting, a refund or a specific dispute.
Lithuanian VAT invoices and information required to preserve their authenticity/integrity10 years from invoice issue. Other accounting records follow the applicable legal schedule; this is not a ten-year retention rule for all account information.
BackupsHostinger keeps file backups of the website in France, for the retention period included in the Hostinger plan. The Supabase project does not have database backups while it remains on the free plan. When it moves to Supabase Pro, database backups will follow that plan and this row will state the period. Restored data is not used for ordinary operations, and a deletion instruction is applied again after a restore.
Phone product cacheUntil cleared by the app’s sign-out/deletion routine or local removal of app data; an offline device may require separate local removal.

Scheduled cleanup must be operational for these limits to apply.

Specific records may be retained longer where a law requires it or where reasonably necessary for a concrete dispute or legal claim. We restrict such records to that purpose, review the need and delete them when it ends. We do not retain an entire account merely because one invoice or record must be kept.

Deleting one member’s account does not automatically delete a workspace still used by others. Necessary shared business records may remain for that workspace; we assess removal or de-identification of the departing person’s information where applicable. Remaining membership does not justify keeping all of that person’s data indefinitely.

Deletion of the last member’s account closes the workspace. The procedure, subscription effects and exceptions are explained on our Account Deletion page. Deleting WPNoti records does not delete orders, customers or other records in the connected WooCommerce store. Independent controllers such as payment providers may retain records under their own legal obligations.

08

Your rights

Subject to the applicable conditions, you may request access to your data, correction, erasure, restriction of processing, and a portable copy of data you provided where processing is automated and based on consent or contract. You may object to processing based on legitimate interests on grounds relating to your situation. If personal data is used for direct marketing, you may object to that use at any time. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

Contact [email protected]. We may request proportionate information to verify identity or authority, but do not routinely require an identity document. Requests are ordinarily free. We respond without undue delay and within one month of receipt. Where legally permitted because of complexity or the number of requests, we may extend by up to two further months and will explain the extension within the first month. If we refuse a request or charge a legally permitted fee, we will explain the grounds and your complaint rights.

You may complain to the State Data Protection Inspectorate of Lithuania or, where applicable, the supervisory authority in your habitual residence, workplace or place of the alleged infringement. You do not have to contact us first. Judicial remedies also remain available.

09

Security

We use safeguards appropriate to the nature and risks of processing. The product includes encrypted store credentials and vulnerability reports, hashed purchase-token records, workspace access controls and secure device storage for mobile sessions. Optional two-factor authentication helps protect accounts. These features do not mean that all data is end-to-end encrypted or that a system is immune from compromise.

Protect your credentials, manage team access, secure your devices, and keep your WordPress installation and plugins updated. If you suspect unauthorised access, contact us promptly.

10

Children

WPNoti accounts are intended for adults aged 18 or over. The service is not directed at children. A store operator may nevertheless hold information about children in its own records and remains responsible for the legal conditions applying to that processing. If you believe a child has created a WPNoti account, contact us so we can assess and address it.

11

Policy updates

We will post changes here and update the effective date. For material changes, we will provide a prominent notice and, where appropriate, an account email before the change takes effect. Where consent or another legal step is required, updating this policy alone will not replace it.

Questions about this document?
Write to us and a person will answer.
[email protected]
© 2026 WPNoti. WooCommerce and WordPress are trademarks of their respective owners.PrivacyTermsAccount deletionData processing