Privacy Policy
Last updated 2 October 2026. Written to be read rather than skimmed past.
The short version. We collect what we need to run your account and your sites, and nothing else. We do not sell data and do not share it for others' marketing. You can ask us to export or delete your data at any time.
1. Who controls your data
WPCentrify is operated by ROLYXHUB (SMC-PRIVATE) LIMITED, a company registered in Pakistan, with its registered office at PVT CENTER CHAKLALA, RAWALPINDI, Pakistan. WPCentrify is the data controller for account and marketing data, and the data processor for data contained within the WordPress sites you connect. Processor obligations are set out in the Data Processing Agreement.
Privacy contact: privacy@wpcentrify.com
2. What we collect and why
Account data
Name, email address, company name, billing details and authentication data. We collect this to create and secure your account, bill you, and provide support. Lawful basis: performance of a contract.
Site operational data
Metadata about the WordPress sites you connect: URLs, WordPress version, installed plugin and theme versions, uptime and performance measurements, update history and error logs. We collect this to provide the service. Lawful basis: performance of a contract.
Backup data
Where you enable backups, we store encrypted copies of your site files and database. These may contain personal data belonging to your own users or customers. We act as processor for this data and process it only to provide backup and restore functions. We do not inspect, index or analyze backup contents.
Usage data
How you interact with the dashboard, which features you use, and diagnostic information. We use this to improve the product and diagnose faults. Lawful basis: legitimate interests.
Marketing data
Where you opt in, your email address and engagement with our emails. Lawful basis: consent, withdrawable at any time via the unsubscribe link in every email.
3. What we do not do
- We do not sell personal data. There is no circumstance in which we would.
- We do not share your data with third parties for their own marketing purposes.
- We do not run advertising trackers or third-party advertising pixels on this website.
- We do not inspect the contents of your backups.
4. Cookies, analytics and advertising
We use strictly necessary cookies for authentication and security. These are required for the service to function and do not require consent.
For website analytics we use Google Analytics 4, loaded through Google Tag Manager, to understand aggregate usage and improve the site. It sets two cookies, _ga and _ga_G-RJ7B287QHN, which expire after two years.
Whether these are set before you choose depends on where you are. If you are in the EEA, the UK or Switzerland, analytics and advertising storage are denied by default using Google Consent Mode, nothing non-essential is written on your first visit, and you are asked before anything is stored. Elsewhere they are enabled by default and no banner is shown.
Either way you can change or withdraw your choice at any time through Cookie settings in the footer of any page, and a decision to decline is remembered so you are not asked repeatedly. You can also block or delete cookies for this site in your browser. None of this affects your use of the site.
Google Signals and ad personalization are switched off on our analytics property, so your visit is not used to build advertising audiences. We do not use cross-site behavioral profiling.
Analytics data is processed by Google and may be transferred outside the EEA. We rely on Standard Contractual Clauses for those transfers. Google describes its own handling in its privacy documentation for businesses.
5. Where your data is stored
Operational data and backups are stored in the United States on OVHcloud servers. You may supply your own storage bucket, in which case backup data never enters our infrastructure.
Where personal data is transferred internationally, we rely on adequacy decisions where they exist and otherwise on Standard Contractual Clauses, available on request.
6. How long we keep it
- Account data: for the life of the account, then 12 months for legal and accounting purposes.
- Site operational data and activity logs: per your plan's retention setting, 12 months by default.
- Backups: per your configured retention policy.
- After cancellation: exportable for 30 days, deleted from active systems within 30 days thereafter and from backup systems within 90 days.
- Marketing data: until you unsubscribe, then suppressed rather than deleted so we do not contact you again.
7. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. You also have the right to complain to your local supervisory authority.
To exercise any of these, email privacy@wpcentrify.com. We respond within 30 days and do not charge for reasonable requests. Much of this is also self-service: export and deletion are available directly in the dashboard.
If you are a California resident, you have the right to know what personal information is collected, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA.
8. Subprocessors
We use a small number of subprocessors: OVHcloud for hosting and encrypted backup storage, and Hostinger for email. Both are listed in the Data Processing Agreement with their function and location. AI features run on a model hosted on our own servers; where an external AI model is used, no personal data is sent to it. We notify customers in advance of any new subprocessor and provide an opportunity to object. Separately from the product, this website uses Google Analytics and Google Tag Manager, as described in section 4.
9. Security
We encrypt data in transit with TLS 1.3 and at rest with AES-256, enforce least-privilege access internally, log administrative access, and operate a documented incident response process. Full detail is on the security page, and our GDPR compliance summary sets out data subject rights and how to exercise them.
In the event of a personal data breach affecting you, we notify you without undue delay and in any case within 72 hours of confirmation, with the facts as known and the actions taken.
10. Children
WPCentrify is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy. Material changes are notified by email at least 30 days before they take effect, and the last updated date at the top of this page always reflects the current version.