Setyenv™ Privacy Policy
Last updated: 9 July 2026 · Version 1.0
This Privacy Policy explains what personal data setyenv.com (the "Site") collects, why, and your rights over it. It concerns the Site and our commercial relationship with you — not the data inside your own installations of our Products.
1. Self-hosted first — what we do NOT receive
Setyenv™ Products run inside your own WordPress server. Your operational data (your records, tickets, workflows, customer data) stays in your database. The Products do not send that data to us. The only outbound communication from the commercial Products to us is license validation (a license key and the domain it runs on). There is no product telemetry or analytics phone-home.
2. Data we process about you (Site + account)
- Account data: the email and profile details you provide when registering, and authentication data (including for mandatory multi-factor authentication).
- Purchase data: what you bought, license keys, domains, invoices and order history. Payments are handled by our payment provider; we do not store full card numbers.
- Support / contact data: the content of messages you send us via the Contact page or email.
- Technical data: standard server access logs (e.g. IP address, browser/user-agent, timestamps, pages requested) generated by our hosting for security and reliability.
3. Cookies
We use only strictly necessary cookies. The complete inventory:
- `PHPSESSID` — a first-party session cookie, technical, deleted when your browser session ends.
- `wordpress_test_cookie` — set by the sign-in form to check that your browser accepts cookies.
- `wordpress_*` sign-in cookies — set only after you sign in, to keep you signed in. They are the service you requested.
- Cookie-notice acknowledgement — a value in your browser's local storage remembering that you dismissed our cookie notice, so we do not show it on every page.
We do not use third-party, advertising, analytics or behavioural-tracking cookies, and the Site makes no third-party requests while you browse. If you purchase, payment happens on Stripe's own hosted page under Stripe's domain and privacy terms — their cookies never touch our pages.
Because every cookie above is strictly necessary to operate the Site, the cookie notice is informative (there is nothing optional to accept or reject). If that ever changes, the notice will be upgraded to a real consent choice and shown again.
4. Why we process it
- To create and secure your account and provide the Site and Products.
- To process purchases, issue licenses and validate them.
- To provide support and respond to your enquiries.
- To keep the Site secure and prevent abuse.
- To meet legal and accounting obligations.
Where required, our legal bases are performance of our contract with you, our legitimate interests in running and securing the service, compliance with legal obligations, and consent where applicable.
5. Who we share it with
We share personal data only with service providers strictly necessary to run the service, under appropriate safeguards:
- Payment provider — to process payments and refunds.
- Hosting and email provider — to host the Site and send transactional email (account, MFA, licenses, refunds).
- Search-engine verification (e.g. Bing Webmaster Tools) — site verification only.
We do not sell your personal data, and we do not share it for third-party advertising.
6. International transfers
Where data is processed outside your country, we rely on appropriate legal safeguards for such transfers.
7. Retention
We keep account, license and invoice data for as long as your account is active and as required for legal, tax and accounting purposes; support and log data for a limited period appropriate to their purpose.
8. Your rights
Subject to applicable law, you may request to access, correct, delete, export or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, contact us (Section 10). You may also complain to your local data protection authority.
9. Security
We protect your data with measures appropriate to the risk, including mandatory multi-factor authentication on accounts and encrypted transport (HTTPS). No method is perfectly secure, but we work to safeguard your information.
10. Contact
For any privacy request or question, use the Contact page on setyenv.com.
11. Changes
We may update this Privacy Policy; the "Last updated" date above reflects the current version.