Privacy policy
Version 2026-10-07.
Who is responsible
WP Provider B.V., the Netherlands, runs WP Provider Translate and is responsible for the personal data described here. Questions and requests: support@wpptranslate.com.
What the plugin sends
Nothing is sent before an administrator clicks Connect in the plugin. After that, the site sends:
- the published text of its pages, with the context needed to translate it (for example which element a text is in), the site's address and the chosen languages;
- which of its languages the plan includes and how much of the plan is used, when asked;
- how many of its pages are translated, how many wait for room in the plan and how many words those need, and its languages: counts only, never page addresses or text, so your account page can say what your plan means for your site;
- when an administrator clicks the plan button in the plugin: which message they saw, the plan and language it was about, and the screen in WordPress to come back to;
- when switching from WPML, the original and translated texts of the imported pages;
- a problem report, when you send one: your message, your contact email, the page and language, and, if you leave that box ticked, the WordPress and PHP versions, the theme, the active plugins and the plugin's state.
The plugin never sends what visitors type, customer names or addresses, order pages, or anything shown only to logged-in users. Values visitors see on their own (such as their name in a greeting) are masked on the site before a text is sent.
What we store, and for how long
- Your account: your email address and name, the accounts and sites you belong to, and a password if you set one (only as an Argon2id hash). Kept until you ask us to delete your account.
- Logging in: a session cookie while you are logged in. With each login email we store when and from which internet address it was requested and how many wrong codes were entered, to stop abuse, for 30 days; of the code and the link only a hash. Failed logins and wrong codes per internet address are kept for one day. While a login email is on its way, a cookie in the browser that asked for it lets the link in that email log in there at once; it lasts 60 minutes. A browser that logged in with a password keeps a cookie for a year that says only that, so the password is asked first there the next time.
- Sites: each site's address and plan, and the page counts the plugin sends. Its site key is stored only as a hash.
- The plan button: each click on the plan button in the plugin: the site, the message shown, the screen to come back to, whether the link was opened, who then logged in, and whether it ended in a payment or a plan change. We use this to see which messages help. Deleted after 90 days.
- Requests to change a plan: when you ask whoever manages a plan to change it: who asked, for which site and which plan. Your email address is included in the email they get, and the page says so before you send it. Deleted after 90 days.
- Who pays: for a paid plan, which person's payment method the account is charged on. Someone who pays for an account without being in its team becomes its billing contact; they see the plan and their own billing details, not the people in the account.
- Texts and translations: the texts sites send and their translations, in a translation memory. Translations of published texts are reused for every site that has the same text. Translations of published text hold no personal data and stay in the shared memory, also after the site or account is gone, without any link to them.
- Translation calls: a record of each call to a translation model (languages, model, size, cost and outcome, not the texts) for checking quality and costs, deleted after 90 days.
- Billing, for paid plans: the billing name, organisation, address, billing email and VAT number you enter, your plan, and the references Mollie gives for your payments and direct debit mandate. We never see card or bank account numbers. Each invoice keeps the billing details it was made with, also when the person who paid is not in the account's team or has left the account. Invoices and their billing details are kept for seven years, as Dutch law requires, and deleted after that.
- Problem reports: stored with the service and filed as an issue in our own private project on GitHub, where we handle them.
- Estimates on our website: when someone asks our website for the size of a site, we read public pages of that site and store its address and the estimate. We store a hash of the visitor's internet address for one day, to limit abuse, and no other data about the visitor.
- Backups: the database is backed up every night; a backup is kept for seven days.
Who processes your data
- Hetzner Online (Germany): hosts the service and its backups, on servers in Helsinki, Finland (EU).
- OpenRouter (United States): passes the texts to be translated to the translation model; at present OpenAI's models (United States). Texts can be processed outside the EU.
- Mollie (the Netherlands): payments, direct debit and invoices for paid plans.
- SMTP2Go: sends login links and other emails from the service.
- GitHub (United States): problem reports, as issues in our private project.
- VIES (European Commission): checks a VAT number you enter.
We do not sell your data, and we do not use it for advertising. The service sets no tracking or advertising cookies.
Your rights
You can ask to see, correct, export or delete your personal data, or object to how we use it, by emailing support@wpptranslate.com. We answer within a month. When we delete your account, we remove your account, its users and sessions, and its sites with their keys; invoices and their billing details are kept for seven years, as the law requires, and deleted after that. You can also complain to the Dutch data protection authority (Autoriteit Persoonsgegevens).
Changes
When this policy changes, the version above changes.