Privacy Policy
Last updated
Written from how the product actually works, and not yet reviewed by a lawyer. If anything here is wrong or unclear, tell us at help@pressypress.com and we will fix it.
This describes what we hold about you, why, and what you can do about it. It covers your account with us — the dashboard, billing and support. What your own WordPress site collects from its visitors is yours to decide and yours to declare; §8 explains the split.
Written to be read. If a sentence here needs a lawyer to understand, that is our failure rather than yours.
1. Who is responsible
Jaime Lourenço Jacob (an individual operating pressypress.com) decides what happens to the data described here, which under the GDPR makes us the controller. Write to help@pressypress.com about anything on this page — it reaches the people who built the product, not a queue.
Post reaches us at Rua Padre António Vieira 38 6DTR, 4710-412 Braga, Portugal.
We have not appointed a Data Protection Officer. At our size the GDPR does not require one, and naming a role nobody fills would be worse than saying so.
2. What we hold, and why
Everything below exists because something in the product needs it. There is no row here we collect “in case it is useful later”.
- Why
- Signing in, and every message we have to send you — receipts, a failed payment, a site that went down
- Lawful basis
- Contract
- Why
- Addressing you as a person in the dashboard and in email. We ask for a first name at signup and a last name only if you have one
- Lawful basis
- Consent
- Why
- Stored only as a one-way hash. We cannot read it, and nor can anyone who obtains the database
- Lawful basis
- Contract
- Why
- Checking your six-digit codes. Encrypted at rest with a key held outside the database
- Lawful basis
- Contract
- Why
- Signing in with Google. We receive your email address and your name, first and last where Google holds both, and nothing else. Google does not tell us where you are, which is why we ask
- Lawful basis
- Contract
- Why
- Showing every date and time in your clock rather than a server's. Read from your browser at signup
- Lawful basis
- Legitimate interests
- Why
- It sets the tax on your invoice, and it tells us which countries to put servers in next. Asked once at signup, and filled in from your billing address if you were with us before we asked
- Lawful basis
- Legitimate interests
- Why
- Held by Stripe, not by us — we keep only their customer reference. We never see or store a card number
- Lawful basis
- Contract
- Why
- Running them: subdomain, plan, resources, chosen theme and plugins, domains, backups
- Lawful basis
- Contract
- Why
- Showing you what a site is using, and knowing when it needs more
- Lawful basis
- Contract
- Why
- Knowing whether a message we sent you arrived, so a bounced address can be fixed rather than silently ignored
- Lawful basis
- Legitimate interests
- Why
- An append-only record of who changed what, so a compromised account can be reconstructed. See §5 — this one is never deleted
- Lawful basis
- Legitimate interests
- Why
- Rate limiting. Discarded on a short rolling window
- Lawful basis
- Legitimate interests
- Why
- Answering you, and having the history to hand next time. If you use the form on /support while signed in, it also sends your account address, whether it is confirmed, and a list of your Pressies — so you do not have to type them out
- Lawful basis
- Contract
Email address
Your name
Password
Two-factor secret, if you enable it
Google account link, if you use it
Time zone
Country
Billing details
Your sites' configuration
Resource usage
Email delivery records
IP address and browser, on security-relevant actions
Failed sign-in counts, keyed by IP or email
What you write to support, and our replies
| What | Why | Lawful basis |
|---|---|---|
| Email address | Signing in, and every message we have to send you — receipts, a failed payment, a site that went down | Contract |
| Your name | Addressing you as a person in the dashboard and in email. We ask for a first name at signup and a last name only if you have one | Consent |
| Password | Stored only as a one-way hash. We cannot read it, and nor can anyone who obtains the database | Contract |
| Two-factor secret, if you enable it | Checking your six-digit codes. Encrypted at rest with a key held outside the database | Contract |
| Google account link, if you use it | Signing in with Google. We receive your email address and your name, first and last where Google holds both, and nothing else. Google does not tell us where you are, which is why we ask | Contract |
| Time zone | Showing every date and time in your clock rather than a server's. Read from your browser at signup | Legitimate interests |
| Country | It sets the tax on your invoice, and it tells us which countries to put servers in next. Asked once at signup, and filled in from your billing address if you were with us before we asked | Legitimate interests |
| Billing details | Held by Stripe, not by us — we keep only their customer reference. We never see or store a card number | Contract |
| Your sites' configuration | Running them: subdomain, plan, resources, chosen theme and plugins, domains, backups | Contract |
| Resource usage | Showing you what a site is using, and knowing when it needs more | Contract |
| Email delivery records | Knowing whether a message we sent you arrived, so a bounced address can be fixed rather than silently ignored | Legitimate interests |
| IP address and browser, on security-relevant actions | An append-only record of who changed what, so a compromised account can be reconstructed. See §5 — this one is never deleted | Legitimate interests |
| Failed sign-in counts, keyed by IP or email | Rate limiting. Discarded on a short rolling window | Legitimate interests |
| What you write to support, and our replies | Answering you, and having the history to hand next time. If you use the form on /support while signed in, it also sends your account address, whether it is confirmed, and a list of your Pressies — so you do not have to type them out | Contract |
3. Who processes it
These companies handle parts of the job for us. Each is bound by a data processing agreement, or by terms that impose the same duties: they act only on our instructions, and none of them may use your data for their own purposes.
- What for
- Payments, invoices, tax
- What they see
- Your name, email, billing address and card — the card never touches us
- What for
- Email — both the messages we send you and, if you use the form on /support, delivering yours to the inbox below
- What they see
- Your email address and the message content
- What for
- Sign in with Google, if you choose it
- What they see
- Only that you signed in; they give us your email and name
- What for
- Error reports, so a failure gets fixed rather than noticed by you twice
- What they see
- Technical detail about what broke. Credentials, tokens and email addresses are stripped before an event is sent
- What for
- Running background work — building a site, taking a backup, chasing a failed payment
- What they see
- Job payloads, which reference your site and account by identifier
- What for
- The shared inbox behind help@pressypress.com — where support conversations live
- What they see
- Your email address, everything in the thread, and the account details described in the last row above
Stripe
Postmark
Sentry
Inngest
Zammad
| Who | What for | What they see |
|---|---|---|
| Stripe | Payments, invoices, tax | Your name, email, billing address and card — the card never touches us |
| Postmark | Email — both the messages we send you and, if you use the form on /support, delivering yours to the inbox below | Your email address and the message content |
| Sign in with Google, if you choose it | Only that you signed in; they give us your email and name | |
| Sentry | Error reports, so a failure gets fixed rather than noticed by you twice | Technical detail about what broke. Credentials, tokens and email addresses are stripped before an event is sent |
| Inngest | Running background work — building a site, taking a backup, chasing a failed payment | Job payloads, which reference your site and account by identifier |
| Zammad | The shared inbox behind help@pressypress.com — where support conversations live | Your email address, everything in the thread, and the account details described in the last row above |
Our application, database and the servers your WordPress sites run on are operated by us, on infrastructure we rent. Those providers can technically reach the machines and are bound by the same kind of agreement.
We do not sell your data, and we do not share it with advertisers or data brokers. If that ever changed it would need your consent first, asked for plainly.
4. Where it is
Your account data and your sites are stored on servers in Europe. Our processors above operate in the European Economic Area, the United Kingdom and the United States.
Where data reaches the United States, the transfer relies on the EU–US Data Privacy Framework where the processor is certified under it, and on the European Commission’s Standard Contractual Clauses otherwise.
5. How long we keep it
- How long
- Until you close the account — see §7
- How long
- 30 days, then overwritten. A backup taken before you deleted something is a backup that can restore it, which is the point
- How long
- As long as tax and accounting law requires us to keep them, which is longer than your account lives and is not our choice
- How long
- For as long as the account exists
- How long
- Indefinitely. It is append-only by design: a record of who changed what is worth nothing if the person who changed it can erase the entry
- How long
- Minutes. They exist to count recent attempts and nothing else
Your account and its sites
Backups of your sites
Billing records
Email delivery records
The security log (§2's IP and browser row)
Rate-limit counters
| What | How long |
|---|---|
| Your account and its sites | Until you close the account — see §7 |
| Backups of your sites | 30 days, then overwritten. A backup taken before you deleted something is a backup that can restore it, which is the point |
| Billing records | As long as tax and accounting law requires us to keep them, which is longer than your account lives and is not our choice |
| Email delivery records | For as long as the account exists |
| The security log (§2's IP and browser row) | Indefinitely. It is append-only by design: a record of who changed what is worth nothing if the person who changed it can erase the entry |
| Rate-limit counters | Minutes. They exist to count recent attempts and nothing else |
6. Cookies
We set the smallest number we can, and what is set depends on whether you have agreed to anything beyond the necessary ones. The cookie policy lists every one by name, what it does and how long it lasts — and it is generated from the same configuration that sets them, so it cannot drift from reality.
7. Your rights, and how to use them
Under the GDPR you can ask us to:
- show you everything we hold about you, as a file you can keep
- correct anything that is wrong
- delete your account and everything in it
- hand your data to you, or to another provider, in a portable form
- stop processing that relies on our legitimate interests
- withdraw a consent you gave, at any time, as easily as you gave it
Your name, email, country, time zone and password are editable in your account settings today, and deleting the account is a button on the same page. It takes effect after seven days, during which nothing changes and you can undo it yourself. Cancel any Pressies first — we will not destroy a live site as a side effect of a privacy request.
What “delete” honestly means here. Your email address, name, country, time zone, password, two-factor secrets and any connected Google account are erased, and anything still running is destroyed. Your invoices are kept, because tax law requires it and we are not allowed to choose otherwise — they stay as financial records with no name attached to them. The security log keeps a record that an action happened, with the IP address and browser removed. We would rather set that out than write “we delete everything” and be wrong about it.
We answer within one month, free of charge. If you think we have got this wrong, you can complain to the data protection authority where you live — in Portugal that is the CNPD. We would rather you told us first.
8. Your site's visitors are not our business
This is the part most hosting privacy policies leave vague, so: for the site you run on a Pressy, you are the controller and we are your processor. What your WordPress installation collects, which plugins you add, whether it needs its own cookie banner and what its privacy policy says are all yours to decide. We do not read your site’s database, and nothing your visitors submit is used by us for anything.
The traffic figures we show you are counts, not people: hits, unique hits, bot hits and bytes transferred, per hour and per day. We do not build visitor profiles and we do not store the individual requests behind those numbers.
Our staff can reach the servers your site runs on, because otherwise nobody could fix it when it breaks. Any such access is recorded in the log described in §2.
9. Security
Passwords are hashed and never recoverable. Two-factor secrets are encrypted with a key stored outside the database. Sessions are HTTP-only cookies that expire. Traffic is HTTPS everywhere, on your sites as well as ours. Error reports are scrubbed of credentials and email addresses before they leave.
None of that is a guarantee, and a policy that promised one would be worth less than this sentence. If we ever suffer a breach that puts you at risk, we will tell you and the relevant authority within the 72 hours the law allows, and we will tell you what actually happened.
10. Children
The service is not for under-16s and we do not knowingly hold their data. If you believe a child has an account, tell us and we will delete it.
11. Changes
When this changes, the date at the top changes with it. If a change materially affects you — a new processor, a new purpose, a new category of data — we will email you before it takes effect rather than relying on you to re-read the page.