Skip to content

Privacy and GDPR in WP Provider Translate

WP Provider Translate sends the published text of your pages to be translated, in the background, and nothing about your visitors. What visitors type, customer names and addresses, order pages and anything only logged-in users see stay on your site. Translations are stored in your own database, so a page view never calls an outside service. This page lists exactly what is sent, when, and what is not, so you can answer GDPR questions about your site.

Nothing is sent before you connect

Installing and activating the plugin sends nothing. Only when an administrator clicks Connect on WP Provider Translate → Settings does your site start talking to the WP Provider Translate service. See install and connect.

When you connect, you log in with your email address. The service stores your email address, your account name and your site’s address.

What is sent to be translated

After you connect, your site sends:

  • The published text of your pages, including product, cart and checkout pages: page content, theme and menu texts, image descriptions and the other text visitors read. See what gets translated for the full list.
  • Texts you saved in settings that visitors see, such as WooCommerce email texts.
  • The address of each page the text comes from, your site’s address and the languages you chose.
  • Text that widgets load after the page opened (a product filter, a “load more” list), when a logged-out visitor’s browser fetched it with an ordinary page request. Only the content texts are sent, not values a script uses, such as names or ids.

This happens in the background: when your content changes, during the site crawl, and after a visitor has seen text that has no translation yet. It never happens during the page view itself. See how translation runs.

Translations of text that other sites share are reused for everyone.

What is never sent

  • Anything a logged-in user sees. Logged-in views can show someone’s own data, so they are never used, and neither are previews.
  • Form posts. The page that answers a submitted form can repeat what was typed, so it is not used.
  • Order pages. WooCommerce’s order received, view order and order pay pages show one customer’s name, address and order, and are left out.
  • Visitor values. A reference number, order number, email address or search term in a page’s address stays out: the sentence around it is translated with a placeholder, and the visitor’s own value goes back in on the page.
  • Customer details in shop data, such as billing and shipping addresses.
  • Text you mark not to translate (an element with class="notranslate" or translate="no").

The browser never calls the translation service

Some text appears after a page has loaded, for example a message after a visitor clicks a button. A small script on translated pages asks your own site for known translations of such text. Your site answers from its own database only. A request from a visitor’s browser never sends text to the translation service and never waits for it. Your visitors’ browsers don’t connect to the service at all.

Requests are signed

Your site’s key is handed over once, when you connect. After that it is never sent again: every request from your site to the translation service is signed instead, and the service refuses a request that is not signed correctly, is sent twice, or carries the wrong time. This is why the server clock matters: if it is off, the settings page tells you.

Other moments something is sent

  • Report a problem. WP Provider Translate → Report a problem sends your message, the page and language, your email address if you leave it filled in, and, if you keep Technical details ticked, versions, theme, plugins and the plugin’s state. Show exactly what is sent shows all of it before you send. No keys, passwords or visitors’ data are included. See settings and your plan.
  • Switching from WPML. When your site is connected, the import sends texts from your published pages and their WPML translations that it could not pair by itself, so the service can match them. See migrate from WPML.
  • Checking your plan. To show how much of your plan a waiting page needs, the site sends that page’s address and texts.

Where translations are stored

  • On your site. Every translation is stored in your WordPress database and served from there.
  • With your account. The service keeps your translations too, so connecting again later brings them back. Deleting the plugin removes everything it stored on your site and disconnects it.

For your privacy policy

Mention that your site uses WP Provider Translate to translate its published content, and that page text, page addresses and the chosen languages are sent to the WP Provider Translate service for that purpose. Visitors’ personal data is not sent. Have your privacy policy checked by someone who knows the rules that apply to you.

Troubleshooting

  • “This server’s clock is … minutes off.” Signed requests need the right time. Ask your host to fix the server time.
  • “The translation service refused this site.” Disconnect and connect again under WP Provider Translate → Settings.
For developers
  • wppt_may_extract (filter): return false for pages that show one visitor’s data, so nothing is sent from them.
  • wppt_visitor_values (filter): add values that belong to one visitor, to mask before anything is sent.
  • Details and signatures: filters and actions.