// legal

Privacy policy

What data we collect when you buy CreditKit Pro and visit creditkit.store. Written in plain English. Last updated 24 May 2026.

Who we are

CreditKit (“we”, “us”, “our”) operates the website https://creditkit.store and sells the CreditKit Pro WordPress plugin. We’re based in the Netherlands. For questions about this policy email privacy@creditkit.store.

What we collect, and why

When you visit creditkit.store

  • Server access logs — standard web server logs (IP address, request URL, timestamp, user agent). Used for security and to prevent abuse. Retained 30 days, then deleted.
  • Privacy-friendly analytics — we use Plausible Analytics, which does not use cookies and does not store personally identifiable information. We see aggregated visit counts and referrers only.
  • No tracking cookies, no ad networks, no Facebook Pixel, no Google Tag Manager.

When you buy CreditKit Pro

Lemon Squeezy is our merchant of record. They handle the entire checkout, payment processing, VAT calculation, and invoice generation. We never see your card details. Lemon Squeezy shares with us:

  • Your email address — for the welcome email and customer portal access
  • Your country — for tier eligibility checks
  • Order amount and tier — for license creation
  • A unique order ID — for support correspondence

Lemon Squeezy’s own privacy policy applies to their checkout: lemonsqueezy.com/privacy.

When you activate the plugin

The CreditKit Pro plugin contacts our license server (creditkit.store) once per activation and once every 12 hours after that to verify your license is still active. The activation request sends:

  • Your license key
  • The URL of the WordPress site activating the license
  • The plugin version
  • The PHP, WordPress, and WooCommerce versions on the site

We store this on our license server to enforce the per-tier site limit and to know which versions our customers run (for backwards-compat decisions). We never see, send, or store your customers’ data — the plugin’s ledger runs entirely on YOUR WordPress database.

Your customers’ data

The CreditKit Pro plugin stores all credit balances, transactions, audit logs, and webhook subscriptions in eleven tables on YOUR WordPress database (prefixed wp_pcs_*). None of this data flows to creditkit.store. You are the data controller for your customers. We are not a sub-processor of their data.

Email

We send transactional emails (welcome message, password-less login links, payment receipts) via Lemon Squeezy and via SendGrid. We don’t send marketing emails unless you explicitly opted in. We don’t share your email with third parties.

Your rights (GDPR)

If you’re in the EU or UK, you have the right to:

  • Access — a copy of the data we hold on you. Email privacy@creditkit.store and we’ll send it within 30 days.
  • Correction — fix any incorrect data.
  • Deletion — request removal. We’ll delete unless legally required to retain (e.g. invoice records for 7 years per Dutch law).
  • Portability — export in machine-readable form.

Retention

  • Server access logs: 30 days
  • License activation records: while the license is active, plus 1 year after expiry
  • Customer email + order ID: 7 years (Dutch tax law)
  • Support email threads: 2 years

Changes

When we update this policy, we’ll bump the “Last updated” date at the top and email all active license holders.