Legal
Privacy Policy
How WP Chest and this website handle personal data. Last updated August 27, 2026.
This policy explains what SquidSpark Inc. ("we") does with personal data in connection with WP Chest, a bundle of self-hosted WordPress plugins, and this website. It is written to be read, not to be survived.
The short version
- The plugins run on your own server, against your own database. No visitor data ever reaches us.
- Analytics are cookieless and stay in your WordPress database; geolocation runs offline.
- For your site’s visitors, you are the data controller — not us.
- Every plugin ships an uninstall.php, so removing one leaves no tables or options behind.
Who controls what
WP Chest is software you install on your own WordPress site. Once it is running, the personal data it touches is your visitors' data, held in your database, on your server. For that data you are the controller and we are not a processor — we have no access to it and no way to reach it.
This policy therefore covers two separate things: what the plugins do on your site, so you can describe them accurately in your own privacy notice, and what we collect on this website.
What leaves your server
Two things reach SquidSpark, and nothing else does.
- The licence check. Activating your licence contacts our licence server, and the plugins revalidate it periodically. The request carries your licence key, the site address the licence is being used on, and the network metadata inherent to any web request, including your IP address. That is how a single-site licence can be told apart from an unlimited one. The licence server runs on our own hardware, in a colocation facility in Canada.
- SocialFeed. Routes its calls to Meta through our broker, described below. It runs only if you configure a feed.
Apart from those two, nothing is transmitted anywhere you have not configured yourself. There is no usage telemetry, no third-party analytics embedded in any plugin, and none of your visitor data, form submissions, consent records or analytics ever reaches us.
What the plugins process on your site
- Statistics. Cookieless by design — no cookies and no localStorage. The visitor identifier is a daily-rotating salted SHA-256 hash, which cannot be linked across days. Geolocation is resolved offline from bundled datasets, so no visitor IP is sent to a lookup service. All of it stays in your database, with a 365-day default retention you can change.
- Consent. Stores a consent audit log recording the consent version, model, region and an anonymised IP address, so you can evidence a consent later. It is your record, in your database.
- Forms. Stores submissions in your database and sends them onward only to the CRM and email connectors you configure. The Consent field governs CRM opt-in.
- SSO. Links identities by issuer and subject so logins survive an email change at the identity provider. Client secrets can be defined in wp-config.php and kept out of the database entirely.
- Cache, SEO, Security. Operate on your own content and configuration and do not process visitor personal data beyond what WordPress already handles.
SocialFeed and the broker
SocialFeed is the one component that involves a service outside your server. Your Meta app credentials are held by a broker API rather than by WordPress, and the plugin talks only to that broker, which brokers the OAuth and Graph calls on its behalf. That design keeps your app secret out of the WordPress database.
SquidSpark operates the broker, on our own hardware in Canada. It holds the Meta app credentials and access tokens you give it, and caches the posts it fetches so your site is not calling the Graph API on every page view. Credentials and tokens are kept for as long as the connection is configured and are deleted when you disconnect the account; cached posts hold only what Meta has already published publicly. We process this to provide the feed you asked us to provide — our legal basis is performing our contract with you — and for no other purpose. The broker never receives your visitor data, and is not used to profile anyone.
What we can see
Nothing about your site. We do not receive your visitor data, your form submissions, your consent log or your analytics. If you send us a database export or a screenshot for support, redact personal data first — we would rather work from a redacted example.
What this website collects
This site is a product website with a public roadmap. Most of it can be read without an account and without being tracked. The processing below happens only when you choose to take part.
Your account
Voting on the roadmap and posting a suggestion both require an account, so that one person counts once. Creating one stores your username, your email address and a hashed version of your password. We do not ask for a real name, a company or a telephone number, and there is no profile for other visitors to see.
Suggestions you post
When you submit a suggestion we store the one-line summary, the description of the problem, the area and type you selected, and the email address on the form. Suggestions are reviewed before they appear publicly.
If a suggestion is approved, its summary and description become public on the roadmap board. Your email address and account name are not shown there. Please do not put confidential information into a suggestion — the board is public, and we cannot un-publish something you have already told other readers.
Votes
A vote records your account against the item you voted for, so the board can show a total and so you can take your vote back. Votes are not shown per person.
Automatic collection
- Server logs. Our web server records requests in the ordinary way, including IP address, timestamp, the page requested and your browser’s user-agent string. These are kept for 90 days, then deleted or aggregated, and are used to keep the site running and to investigate abuse.
- Rate limiting. After you post a suggestion we keep a short-lived marker against your account for a few minutes, to stop the form being submitted repeatedly.
- Web fonts. This site loads its typefaces from Google Fonts. That means your IP address and browser details reach Google’s servers when a page loads. If that is not acceptable for your deployment, the fonts can be self-hosted instead.
What we do not do
There is no analytics, no advertising network and no third-party tracking script on this website. We do not sell personal data, and we do not profile you or make automated decisions about you.
No cookies are set for visitors who are not signed in. Signing in sets the standard WordPress session cookies, which keep you signed in and are removed when you sign out.
Legal bases for processing
- Contract. Running your account, and supplying and supporting WP Chest if you are a customer.
- Legitimate interests. Keeping the site available and secure, preventing abuse of the suggestion form, and understanding what customers are asking us to build.
- Consent. Anything you volunteer, such as posting a suggestion. You can withdraw it by asking us to remove the suggestion.
- Legal obligation. Keeping records we are required to keep, such as those relating to a purchase.
How long we keep things
- Account records: until you ask us to delete the account.
- Suggestions and votes: for as long as the roadmap item is relevant. A published suggestion may remain on the board after an account is deleted, with no account attached to it.
- Server logs: 90 days, then deleted or aggregated.
- Purchase and tax records: 7 years from the end of the relevant tax year, as Canadian law requires.
- Support requests, and any files attached to them: 24 months from the last message in the thread.
Who else is involved
We share personal data only with the suppliers needed to run this site and our business, and only as far as they need it:
- SquidSpark’s own servers — this website, the SquidSpark Store and the licence server run on hardware we own, housed in a colocation facility in Canada. The facility provides space, power and connectivity; it does not administer our systems or use the data on them.
- SendGrid, a Twilio company — sending all account, licence and notification email.
- Stripe — taking payment through the SquidSpark Store. Card details go straight to Stripe; we never see or store them.
- Twilio — sending SMS verification codes when you sign in, and SMS notifications, where you have given us a mobile number.
- Microsoft Azure Storage — holding product downloads and release packages, and any files you attach to a support request.
- Google — serving the web fonts described above.
We do not sell personal data or share it for anyone else’s marketing.
International transfers
Our suppliers may process data outside your country. Where information leaves Canada or the European Economic Area, we use providers who commit to comparable protection by contract, including the European Commission’s Standard Contractual Clauses where they apply. You can ask us for more detail at privacy@squidspark.com.
Your rights
Depending on where you live, you may have the right to see the data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, to receive a portable copy, and to withdraw consent.
To exercise any of these, write to privacy@squidspark.com. We will respond within the period the law allows. If you are unhappy with our answer you may complain to your data protection authority — in the UK the Information Commissioner’s Office, in the EU your national supervisory authority.
Children
This site and WP Chest are business tools and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to privacy@squidspark.com and we will delete it.
Security
We take reasonable technical and organisational measures to protect the data described above, including encrypted transport for this website and hashed password storage. No system is perfectly secure, and we cannot guarantee absolute security.
Changes to this policy
If we change how we handle personal data we will update this page and change the date at the top. Where the change is significant we will say so on the site.
Contact
SquidSpark Inc.
7030 Woodbine Ave, Suite 500, Markham, Ontario, L3R 6G2, Canada
privacy@squidspark.com