Skip to content

40% off every licence

See pricing

Privacy policy

Effective [[EFFECTIVE DATE]]

Version 1.0

A translation of this document is not published yet, so the English text is shown. The English version is the one that governs.

This explains what personal data we collect, why, what we do with it, and what you can tell us to do about it.

It covers this website and the licensing service the HUBU plugin talks to. It does not cover what your site does with your members' data — when you run HUBU, that data stays on your server and you are the controller of it. We never receive it.


1. Who is responsible

Who is responsible for your data
Controller[[LEGAL NAME]]
Registered address[[REGISTERED ADDRESS]]
Contact for privacysupport@hubu.pro
Representative in the EUNot applicable — we are established in [[COUNTRY]], so GDPR Article 27 does not apply.
Data protection officerNot appointed. We are below the threshold that requires one; privacy questions go to the address above.

2. What the plugin does NOT send us

This section is first because it is the question a data protection officer reviewing HUBU asks first, and because the answer is short.

Your members' personal data never reaches us. HUBU runs inside your WordPress installation. Member accounts, profile fields, login and session records, uploaded avatars — everything the plugin collects about the people using your site is written to your own database, on your own hosting. We do not receive it, we cannot read it, and the plugin contains no mechanism for sending it to us.

For that data you are the controller and we are not a processor, so there is nothing to agree under Article 28 of the GDPR. If a procurement review needs that confirmed in writing, ask sales@hubu.pro.

What the licence check does send is set out in section 3.2 below: a domain, a licence key, two version numbers and the administrative email address on the licence. That is what identifies a licence and decides which release to offer you.

3.1 When you buy a licence

What: name, email address, billing address, country, VAT number if you give one, the tier you bought, the amount, and the order number.

Why: to sell you the licence, issue the key, send the invoice, meet our tax obligations, and handle a refund if you ask for one.

Legal basis: performance of a contract (GDPR Art. 6(1)(b)) for the sale itself; legal obligation (Art. 6(1)(c)) for the invoice and tax records.

We do not receive or store your card number. Payment is handled by [[PAYMENT PROCESSOR]], who are a separate controller for the payment itself and have their own privacy notice.

3.2 When your site activates a licence key

This is the one people do not expect, so it is stated plainly.

What: the domain the key is being activated on, the IP address the request comes from, the plugin version, and the WordPress and PHP versions.

Why: to check the key is valid, to enforce the number of sites the tier covers, and to deliver the right update to the right site.

Legal basis: performance of a contract (Art. 6(1)(b)) — this is how the service you bought works — and our legitimate interest (Art. 6(1)(f)) in preventing licence keys being shared beyond the tier that was paid for.

What we do not collect: nothing about your members, your content, your database or your traffic. The activation request carries the site's own identifying details and nothing from inside it.

3.3 When you email us

What: your address, whatever you write, and anything you attach — which for a support request is often a screenshot, a log excerpt or a site URL.

Why: to answer you, and to keep enough of a record that a follow-up does not start from nothing.

Legal basis: performance of a contract for a licence holder's support request; legitimate interest (Art. 6(1)(f)) for a pre-sales question.

Please do not send us credentials. We never need your WordPress password or an admin account, and if you send one we will ask you to change it.

3.4 When you visit this website

What: the pages you request, your IP address, your browser and operating system, the referring page, and the date and time. This is standard server logging.

Why: to serve the site, and to investigate errors and abuse.

Legal basis: legitimate interest (Art. 6(1)(f)) in operating a website securely.

Analytics: [[ANALYTICS]].

3.5 Cookies

We set as few as we can.

Cookies this site sets
CookieSet byPurposeLasts
wp_woocommerce_session_*WooCommerceKeeps your cart and checkout progress48 hours
woocommerce_cart_hash, woocommerce_items_in_cartWooCommerceTells the page whether the cart has changedSession
wordpress_logged_in_*WordPressOnly if you have an account with us and are signed inSession, or 14 days if you asked to be remembered

These are strictly necessary for a shop to function, so we do not ask consent for them — there is nothing to consent to, and switching them off would break the checkout. We set no advertising cookies and no third-party tracking cookies. If [[ANALYTICS]] ever changes that, this section changes with it and a consent banner appears with it.

4. Who else sees your data

Who else receives your data, and why
RecipientWhat they getWhy
[[PAYMENT PROCESSOR]]Name, email, billing address, amountTo take the payment
[[HOSTING PROVIDER]]Everything stored on the site, as the hostTo run the site
[[EMAIL PROVIDER]]Email address and message contentTo send order and support email
Accountant / tax authorityInvoice recordsLegal obligation

We do not sell personal data, and we do not share it for anyone else's marketing.

5. Transfers outside your country

Some of the providers above are established outside the EEA and the UK. Where personal data is transferred there, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering that country where one exists. You can ask us which applies to a specific provider and we will tell you.

6. How long we keep it

How long each kind of data is kept
DataKept for
Invoices and order records[[RETENTION — INVOICES]], because tax law requires it
Licence key and activation recordsThe term, plus one year, so a renewal or a dispute can be reconstructed
Support emailThree years from the last message in the thread
Server logsNinety days
Marketing consent, if you gave oneUntil you withdraw it, plus a record of the withdrawal

After that we delete it, or anonymise it so it can no longer identify you.

7. Your rights

Under the GDPR and equivalent law you can ask us to:

  • tell you what we hold about you, and give you a copy (Art. 15);
  • correct anything that is wrong (Art. 16);
  • delete it (Art. 17) — subject to records we are legally required to keep, such as invoices;
  • restrict what we do with it while a question about it is resolved (Art. 18);
  • give it to you, or to someone else, in a portable format (Art. 20);
  • stop processing based on legitimate interest (Art. 21).

Where we rely on consent, you can withdraw it at any time (Art. 7(3)), and withdrawing does not make what we did before unlawful.

Email support@hubu.pro. We will answer within one month, and tell you if we need longer because a request is complex. There is no charge.

If you are not satisfied, you can complain to a data protection supervisory authority — in the EU, the authority where you live, work, or where you think the problem happened; in the UK, the Information Commissioner's Office. You do not have to come to us first, though we would like the chance.

8. Is giving us your data optional?

For a purchase, no: without a name, an email address and a billing country we cannot issue an invoice or a licence key, so we cannot sell you a licence. For everything else — a pre-sales question, a mailing list — it is entirely up to you, and declining costs you nothing but the answer.

9. Automated decisions

We do not make any decision about you by automated means alone, and we do not profile you. Licence-key validation is an automated check of a key against a list; it decides whether a key is valid, not anything about you.

10. Children

HUBU is sold to people running websites, and we do not knowingly collect data from anyone under sixteen. If you think a child has given us personal data, email support@hubu.pro and we will delete it.

11. Security

Order and licence data sits on hosting with encryption in transit, access limited to the people who need it, and no card data at all. That is a description of what we do rather than a guarantee: no system is perfectly secure, and anyone who tells you otherwise is selling something. If we ever suffer a breach that risks your rights, we will notify the supervisory authority within seventy-two hours and tell you where the law requires it.

12. Changes

If we change this policy we publish the new version here with a new effective date. For a change that materially affects you we email the address on your account at least thirty days beforehand.