Privacy Policy
Last updated: May 2026
This Privacy Policy explains how PrismSearch (“we”, “us”, “our”) collects, uses and protects personal data when you visit prismasearch.io, purchase a license, or use our plugin on your WordPress site.
We are committed to protecting your privacy and handling your data transparently and in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Who we are
PrismSearch is developed and sold by WTeam. For any privacy-related questions, contact us at:
Email: privacy@prismasearch.io
Website: prismasearch.io
2. What data we collect and why
2.1 When you purchase a license
We collect the following data through WooCommerce to process your order:
- Name and email address
- Billing address (required for invoicing)
- Payment information — processed securely by our payment provider (Stripe). We do not store full card numbers.
- License key and domain URL you register the Pro license on
- Order history and subscription status
Legal basis: Contract performance (Article 6(1)(b) GDPR) — necessary to deliver your license and provide support.
2.2 When you create an account (My Account)
If you register on our site, we store your username, email address and encrypted password. You can update or delete your account data at any time from the My Account page.
Legal basis: Contract performance and legitimate interest (Article 6(1)(b) and (f) GDPR).
2.3 When you visit our website
We may collect standard server log data including your IP address, browser type, pages visited and referrer URL. This data is used solely for security monitoring and is not shared with third parties.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) — maintaining site security.
2.4 License validation (Pro plugin)
When you activate or validate a Pro license, the plugin sends your license key, site URL, installed PrismSearch plugin version and WordPress version to our license validation server. This data is used to verify your subscription status, manage license activations and help diagnose version-specific compatibility or support issues. No site content, indexed data, post content, meta field values or search queries are transmitted. This request is made periodically to confirm the license status.
Legal basis: Contract performance (Article 6(1)(b) GDPR).
3. Cookies
Our website uses only essential cookies necessary for the shop to function. These include:
| Cookie | Purpose | Duration |
|---|---|---|
woocommerce_cart_hash | Tracks cart contents | Session |
woocommerce_items_in_cart | Indicates items in cart | Session |
wp_woocommerce_session_* | Session data for checkout | 2 days |
wordpress_logged_in_* | Authentication — keeps you logged in | Session / 14 days |
We do not use tracking cookies, advertising cookies or analytics cookies. We do not use Google Analytics or similar third-party tracking services.
4. How we use your data
- To process and deliver your license purchase
- To manage your subscription and send renewal reminders
- To provide customer support
- To send transactional emails (order confirmation, license key, invoice)
- To validate Pro licenses via the plugin’s license check
- To comply with legal obligations (e.g. invoicing requirements)
We do not sell, rent or share your personal data with third parties for marketing purposes.
5. Who we share data with
We use a limited number of trusted third-party services to operate our shop:
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Name, email, billing address, payment data |
| Hosting provider | Website hosting | Server logs, uploaded files |
| Email service (SMTP) | Transactional emails | Name, email address |
All processors are contractually bound to handle your data in accordance with GDPR.
6. Data retention
We retain your personal data only as long as necessary:
- Order and billing data — 7 years (legal accounting obligation)
- Account data — until you delete your account or request erasure
- License records — duration of your license + 2 years for support purposes
- Server logs — 30 days
7. Your rights under GDPR
If you are located in the EU or EEA, you have the following rights:
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your data (“right to be forgotten”) — subject to legal retention obligations |
| Restriction | Request that we limit how we process your data |
| Portability | Receive your data in a machine-readable format |
| Objection | Object to processing based on legitimate interest |
| Withdraw consent | Where processing is based on consent, withdraw it at any time |
To exercise any of these rights, email us at privacy@prismasearch.io. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include:
- HTTPS encryption on all pages
- Encrypted password storage (bcrypt)
- Payment data handled entirely by our PCI-compliant payment processor — we never see or store full card numbers
- Regular software updates and security monitoring
- Access to order data limited to authorised personnel only
9. PrismSearch plugin — data processing on your site
When you install the PrismSearch plugin on your own WordPress site, the plugin processes your site’s content (post titles, content, meta fields) to build a local search index. This index is stored entirely on your own server — no content from your WordPress site is sent to our servers.
The only data transmitted to our servers for Pro license validation is the license key, site URL, installed PrismSearch plugin version and WordPress version (see section 2.4). These technical details are used for license verification, activation management and support diagnostics. You are the data controller for any personal data on your own WordPress site; we act only as a data processor for license validation purposes.
10. Children’s privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make significant changes, we will update the “Last updated” date at the top of this page. Continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact
For any questions, requests or complaints regarding this Privacy Policy:
Response time: Within 30 days
Language: English or Hungarian
Questions about this policy? We’re happy to help.