Privacy Policy

Effective 26 August 2026

This Privacy Policy explains how StoreSuite (“StoreSuite”, “we”, “us”, or “our”) collects, uses, and shares personal information when you visit storesuite.dev (the “Site”) or install and use the StoreSuite plugin (the “Plugin”). StoreSuite is a product of PluginizeLab, an independent software studio founded and run by Md Aminur Islam.

Two things are worth stating up front, because they shape everything below. The Site has no accounts and no checkout, but it does run Google Analytics, which sets cookies and tells Google something about your visit - section 2 describes exactly what. The Plugin runs entirely on your own server, and your store’s data never leaves it; the only thing it reports back to us is environment telemetry, and only if you opt in from its admin notice - section 5 lists exactly what that sends, and the little it sends if you decline.

1. Information We Collect

Information you provide to us. There is no account system and no shopping cart. The contact form sends us what you type into it - name, email, subject, how you found us, and your message - by way of our own WordPress site, which runs Contact Form 7 and delivers it to us by email. Contact Form 7 may also record the submitting IP address and browser string.

The newsletter field in the footer takes your email address and nothing else. It goes to the same WordPress site, which passes it to Brevo, the email service that stores the list and sends the mail; Brevo processes it under its own privacy policy. Subscribing is the only thing that address is used for, and you can unsubscribe from any message we send.

Cloudflare Turnstile protects both forms; see section 2.

Information collected automatically. The Site is a static website hosted on Cloudflare Pages. As with any web host, our host processes standard request data - IP address, browser and device type, requested URL, referring URL, and timestamp - in server logs, in order to deliver pages and protect against abuse. We do not use log data for marketing or build visitor profiles from it. Recognising a returning browser is Google Analytics’ doing, not our host’s, and is covered next.

2. Cookies, Analytics, and Third-Party Scripts

Google Analytics. Every page loads Google Analytics 4 (G-3FXC2H2L90) from Google’s servers, so requesting a page here also contacts Google. It sets _ga and _ga_<id> cookies holding a randomly generated identifier - that is what counts your return visit as the same visitor rather than a new one. It is not your name or email, and we have no account system to link it to.

Google processes your IP address, an approximate location derived from it, your browser and device type, the pages you view, the referring URL, and time on page. We see only the aggregate: page counts, country and city, browser breakdowns, and where visitors arrived from. Our tag is the standard snippet - one config call, no custom events, no identifiers of our own, nothing else uploaded. Event-level retention follows the period configured on the Analytics property.

Opting out. Install Google’s opt-out add-on or block the tag with any content blocker. Nothing here depends on Analytics, so the Site works identically either way. Google’s own terms: Privacy Policy and how Google uses this data.

Cloudflare Turnstile. Both the contact form and the newsletter field are protected by Turnstile, loaded from challenges.cloudflare.com. Cloudflare receives your IP address and browser signals to decide whether you are a person, and may set a short-lived cookie. The widget is not loaded with the page: it appears only once you engage with one of those forms, so simply reading the Site never contacts Cloudflare for it. See its Privacy Policy.

Nothing else runs. No advertising tracker, pixel, session recorder, or A/B script. Fonts are self-hosted, so loading a page does not report your visit to a font vendor. Your appearance choice is saved locally under theme, and documentation search runs in your browser against a pre-built index - neither leaves your device.

3. Account and License Data

There is none. StoreSuite has no user accounts, no licence keys, no activation server, and no login on this Site. Nothing about your installation reaches us unless you opt in to the telemetry described in section 5, and that is not a registration - it grants no licence, unlocks nothing, and declining costs you no functionality.

4. Payments

We take no payments. StoreSuite is free and open source, distributed through WordPress.org, with no paid tier, subscription, or upsell. We operate no payment processor and hold no billing information whatsoever.

5. Plugin Data

Store and customer data. Everything the Plugin touches - products, orders, customers, coupons, and analytics - is read from and written to your own WordPress database, on your own hosting. It is processed locally within your store. We never receive it and have no technical means of accessing it.

Telemetry and usage data. Since version 1.2.3 the Plugin bundles the Appsero SDK, which reports basic environment information that helps us troubleshoot faster and decide what to build next. It is opt-in: nothing is sent until you click Allow on the admin notice StoreSuite shows after activation. Decline or dismiss it and the weekly report never runs, with no difference in how the Plugin behaves.

If you do allow it, a report goes to Appsero on activation and weekly after that, containing:

  • Your site name, site URL, and the site’s language.
  • The administrator email address on the site, and the first administrator account’s first and last name.
  • The IP address the request comes from.
  • Server and WordPress environment details - PHP, MySQL, and WordPress versions, server software, memory limit, max upload size, timezone, whether debug mode and the SOAP, cURL, and fsockopen extensions are available, whether it is a multisite, and the active theme’s slug.
  • Counts only: how many users you have by role, and how many plugins are active and inactive. The names of your other plugins are not sent - StoreSuite does not enable that part of the SDK.
  • The StoreSuite version, and whether the site looks like a local install.

Two smaller cases are worth naming. Declining sends one request too, carrying nothing but an anonymous installation hash and a flag saying tracking was skipped - so that we do not keep asking. And deactivating StoreSuite offers an optional survey; if you pick a reason and submit it, that reason is sent, and skipping the survey sends nothing.

No store or customer data is ever included - no products, orders, customers, coupons, revenue figures, or API keys.

Your choice is stored in the storesuite_allow_tracking WordPress option on your own site. Set it to no, or deactivate the Plugin, and the weekly report stops. Appsero acts as our processor here and handles the data under the Appsero privacy policy; you can also ask us to delete what has already been sent, using the contact address in section 14.

AI generation. Alongside opt-in telemetry, this is the other place data leaves your server, and the only one that can involve your product content, so please read it carefully. StoreSuite’s AI features are built on the WordPress core AI Client and Connectors API, and you bring your own provider and your own API keys. When you use a generate action, the input involved - your hint, product title, selected categories, an existing description, or an image prompt - is sent from your server directly to the AI provider you configured in WordPress, authenticated with your credentials.

Consequently, that data is handled under your provider’s privacy policy and retention terms, not ours; review them before enabling AI on real customer or product data. Your API keys are stored by WordPress on your server, and StoreSuite transmits them only to the provider you selected. No AI request is routed through us, and we see none of it. If no provider is configured, no request is made and the AI controls hide themselves. Generated images are held server-side in a short-lived transient for preview, and are written to your media library only when you choose to insert them.

Access control. Dashboard access is gated on the WordPress manage_woocommerce capability - normally administrators and shop managers. Deciding who holds that capability on your site is your responsibility as the site operator.

6. Communications

If you write to us, we use your address to reply and for nothing else, and we never add it to the mailing list. Subscribing to release updates is a separate, deliberate act: the address you enter in the footer is used only to send those updates, every message carries an unsubscribe link, and unsubscribing removes you from the list. We do not sell or rent addresses from either route.

7. Support Access and Logs

Support happens in public on the WordPress.org support forum. We do not request, and will never ask for, your site credentials. If you voluntarily share screenshots, logs, or error output in a support thread, remove customer data and API keys first - those threads are publicly visible.

8. Sharing Your Information

We do not sell personal data. The third parties involved are Google, which receives the Analytics data described in section 2 on every page view; Cloudflare, both as our host and as the provider of the Turnstile check; Brevo, which stores newsletter subscribers and sends the mail; our own WordPress site and its email delivery, which carry form submissions to us; Appsero, which receives and stores the Plugin telemetry described in section 5, but only from sites that opted in; and legal authorities, where we are legally required to respond. Your AI provider is not on this list, because we never send anything to them - your server does, under your own account.

9. International Data Transfers

Our host, Google, Cloudflare, and Appsero all operate globally, so the data described above may be processed in the United States or elsewhere, under those providers’ own safeguards and transfer mechanisms.

10. Your Rights

Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA/CPRA to access, correct, delete, or object to the processing of your personal data. Because we hold very little, most such requests resolve quickly. Contact us at the address below to exercise them - or, for Analytics specifically, use the opt-out in section 2, and for Plugin telemetry the withdrawal described in section 5, neither of which needs a request to us.

For data inside your own store, you are the data controller and we are not a processor, because that data never reaches us. Requests from your customers are handled through WordPress and WooCommerce’s built-in privacy tools, exactly as they would be without StoreSuite installed.

11. Data Retention

Server logs are retained by our host for a short period under their standard policy. Analytics data is retained by Google for the period configured on the property. Contact-form submissions stay in our email for as long as the conversation is useful, and are deleted on request. Newsletter addresses stay in Brevo until you unsubscribe or ask us to delete them. Telemetry from sites that opted in is retained in Appsero while we still find it useful for support and product decisions, and is deleted on request. Outside those there is nothing further to keep - no profiles, no account records, and nothing at all from a site that never opted in.

12. Minors

StoreSuite is a business tool and is not intended for individuals under the age of 18. We do not knowingly collect their information.

13. Changes to This Policy

We may update this policy from time to time. Material changes are reflected in the effective date at the top of this page.

14. Contact Us

For questions about this policy, please contact us at hello@storesuite.dev. For questions about the Plugin itself, the WordPress.org support forum is usually the better place - the answer there helps everyone.