TE Plugins Sign in
TE Plugins

Privacy

This describes exactly what we hold about you, why, and for how long. It is written from the actual database, not from a template, so where it says we do not collect something, we genuinely do not have a column for it.

In it, "we" and "us" mean [TO CONFIRM: trading name and legal entity].


The short version

We hold your email address, an optional name and company, your orders, your licence keys, and a record of which domains those keys activated on. We use it to sell you software and support it. We do not sell it, share it for advertising, or profile you. There is no analytics on this site and no advertising or tracking cookies at all.


What we collect

When you create an account

Your email address, which is required — it is how we send you a licence key and how you sign in. Optionally a name and a company, both of which you can leave blank.

Your password is never stored. What we keep is a one-way hash of it, which cannot be turned back into your password. If you forget it, we can only help you set a new one; we cannot tell you the old one.

We also record when your account was created and when you last signed in.

When you buy

Your order, what was on it, what it cost, and a reference from the payment provider confirming the payment.

We never see or store your card details. They go directly to the payment provider and never touch this server. What comes back to us is a transaction reference and confirmation that money moved.

When a plugin checks its licence

This is the part most people want to know about, so it is set out in full.

Each plugin activates once and then checks in about once a week. Each check records three things: the licence key it belongs to, the domain it is running on, and the IP address the check came from, with a timestamp.

That is the entire contents of a licence check. It does not send us your database, your member list, your traffic figures, your settings, your source code, or anything else about your exchange or its members. We have no column to put any of it in.

We use it for one purpose: to know how many live domains a licence is running on, because a licence covers one.

When you download

The download and the IP address it came from. Download links are single use and short lived, and the record is how we know a link has been spent.

When you sign in, or fail to

A short-lived record of the email address tried and the IP it came from. This exists only to rate-limit password guessing. These records are deleted automatically after about two hours.

Administrative actions

When we change something significant in the admin panel — issuing a licence, refunding an order — we log what changed, who did it, and the IP address it came from. This is our own audit trail.

What we do not collect

  • No analytics, of any kind, first or third party.
  • No advertising cookies, no tracking pixels, no fingerprinting.
  • No browser or device profile. There is no user-agent column anywhere in the database.
  • No data about your members. We have no relationship with the people who surf your exchange and hold nothing about them.

Cookies

One cookie, named psm_session.

It holds your sign-in session, expires when you close the browser, cannot be read by JavaScript, and is sent only over HTTPS. It carries no identifier that means anything outside this site.

There is no cookie banner because there is nothing to consent to: a strictly necessary sign-in cookie is the only one we set.

Who else sees anything

The payment provider, at checkout, because they take the payment. What you give them is governed by their own privacy policy, not this one.

Google Fonts. This site currently loads its typefaces from fonts.googleapis.com and fonts.gstatic.com, which means your browser makes a request to Google and Google therefore sees your IP address. We do not send them anything else, and we get nothing back about you. We are aware this is avoidable by self-hosting the fonts and intend to do so.

Our host, who runs the server the site sits on and keeps standard web server logs.

That is the complete list. We do not sell your data, rent it, trade it, or hand it to advertisers. We would disclose something if we were legally required to, and we would tell you unless we were forbidden from doing so.

How long we keep it

Your account and your orders we keep for as long as you have an account, and afterwards for as long as we are required to retain business and tax records.

Licence keys and the domains they activated on we keep for the life of the licence, because the licence is perpetual — it is what proves you own what you bought.

Licence check and download records are currently kept indefinitely. We have no operational need for old ones and intend to start pruning them; until we do, this page tells you the truth rather than a policy we are not yet following.

Failed sign-in records are deleted after about two hours, automatically.

Keeping it safe

The site is HTTPS only. Passwords are hashed, never stored. Database credentials and the licence signing secret live in a file outside the web root that is not readable by anyone but the application. Every paid download is streamed through the application behind a single-use token, so nothing is sitting at a guessable URL. Every form is protected against cross-site request forgery, and every database query is parameterised.

No one can promise perfect security. If we ever suffer a breach that affects you, we will tell you what happened, what was taken, and what to do about it.

Your rights

Whatever jurisdiction you are in, you can ask us to:

  • Tell you what we hold about you.
  • Correct anything wrong.
  • Delete your account and personal data. We will keep the minimum needed for tax and accounting records, and we will tell you exactly what that is. Note that deleting your account does not switch off plugins you have installed — they will carry on running, because they do not depend on us.
  • Send you a copy of your data in a portable format.
  • Object to a use you disagree with.

Ask and we will do it. We will not require a reason, charge a fee, or make it difficult. If you are in a jurisdiction with a data protection regulator and you think we have handled this badly, you are entitled to complain to them.

Children

This is software sold to people who run websites. It is not intended for children and we do not knowingly collect anything from them.

Changes

If we change how we handle your data we will update this page and change the date below. If a change is significant we will say so on the site rather than quietly editing the text.

Contact

[TO CONFIRM: contact address for privacy enquiries and data requests.]

Last updated 12 September 2026.