Skip to content

Privacy Policy

How we collect, use, and protect your information, and what happens to your site's data when we provide WordPress care.

Last updated: July 22, 2026. This is a general-purpose privacy policy for WebFixit (webfixit.io). It is a reasonable working draft, not a substitute for advice from a qualified privacy attorney in your jurisdiction, especially if you process EU/UK personal data at scale or handle regulated data (health, financial, children's data).

1. Who we are

WebFixit ("WebFixit", "we", "us", or "our") operates webfixit.io and provides WordPress maintenance, updates, backups, security, staging, and related services (the "Services").WebFixit is the trading name used for these services; the underlying legal entity operating webfixit.io is referred to in this policy as "WebFixit". Replace with your registered company name and address before relying on this policy in production.

This policy applies to visitors of our marketing site, prospects who contact us, and clients enrolled in a care plan. It does not apply to third-party sites we link to.

2. Information we collect

We collect information in three broad categories:

  • Contact & account information: name, email, phone, company, website URL, and anything you submit through our contact, signup, or calculator forms.
  • Billing information: plan selection and billing details processed by our payment processor. We do not store full card numbers ourselves.
  • Site access & operational data: for active care plan clients, this includes WordPress admin credentials or equivalent access tokens, hosting details, backup snapshots, and change logs needed to perform maintenance work.
  • Technical & analytics data: IP address, browser/device type, pages viewed, referring URL, and standard server logs collected automatically when you use our site.

4. How we use your information

  • Responding to inquiries and delivering the Services you request.
  • Performing maintenance work on enrolled sites: updates, backups, security monitoring, and staging verification.
  • Billing, invoicing, and fraud prevention.
  • Sending service communications (maintenance reports, incident alerts, billing notices) and, where you've opted in, product updates.
  • Improving our site, support, and Services based on aggregated usage patterns.

We do not sell personal information, and we never will.

5. Cookies and similar technologies

We use essential cookies to operate the site (session state, theme preference) and, where enabled, privacy-conscious analytics to understand aggregate traffic patterns. We do not use cookies for cross-site advertising profiling. You can control cookies through your browser settings; disabling essential cookies may affect site functionality.

6. Sharing & sub-processors

We share information only with service providers who help us run webfixit.io and deliver care plans, under contractual confidentiality and data-protection terms. Categories of sub-processors include:

  • Hosting & infrastructure: the provider hosting our application, our clients' backups, and staging environments.
  • Email & communications: the provider we use to deliver transactional email (contact replies, billing, incident alerts).
  • Analytics: an aggregate, privacy-respecting analytics tool used to understand site traffic.
  • Payment processing: a PCI-compliant payment processor that handles card details directly; we never see full card numbers.

A current, named list of sub-processors is available on request at [email protected]. We do not share personal information with third parties for their own marketing purposes. We may disclose information where required by law, to enforce our terms, or to protect the rights, property, or safety of WebFixit, our clients, or others.

7. International data transfers

Our infrastructure and sub-processors may be located outside your country of residence, including in the United States. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised under applicable data-protection law.

8. Data retention

We retain contact and billing records for as long as needed to provide the Services and to meet legal, accounting, or reporting obligations, typically for the duration of your relationship with us plus a limited period afterward. Site backups and access credentials for a care plan are retained for the plan's stated backup window and are deleted or revoked within a reasonable period after a client cancels, unless a longer period is required by law.

9. Security & breach notification

We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data we hold, including access controls on site credentials, encrypted off-site backup storage, and restricted internal access to client environments. No system is completely secure, and we cannot guarantee absolute security.

If we become aware of a security incident that compromises your personal information or a client's site backups/credentials, we will notify affected clients without undue delay after becoming aware of the incident, and in line with applicable breach-notification law (including GDPR's 72-hour supervisory authority notification requirement, where applicable), describing the nature of the incident and the steps we're taking in response.

10. Your rights (GDPR)

If GDPR applies to you, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request erasure of your data, subject to legal retention requirements;
  • Restrict or object to certain processing;
  • Receive your data in a portable format; and
  • Lodge a complaint with your local data-protection supervisory authority.

To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law.

11. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, request deletion of your personal information, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising. You will not be discriminated against for exercising any of these rights. Submit requests to [email protected].

12. Children's privacy

Our Services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Data Processing Agreements for agencies & clients

If you are an agency or business that needs a signed Data Processing Agreement (DPA), for example because you process EU/UK personal data on behalf of your own clients through a white-label WebFixit plan, we're happy to put one in place. Email [email protected] and we'll send our standard DPA template for review.

14. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above; where required by law, we will provide additional notice.

15. Contact us

Questions about this policy or your data: [email protected]