GaiaWP logo GaiaWP

GaiaWP Studio · Data protection and privacy

Privacy Policy

How GaiaWP collects, uses, and protects your information — including OAuth data for Google Drive, Dropbox, Box, OneDrive, and pCloud. Last updated: 5 September 2026.

Short version

  • Simple use of free GaiaWP plugins does not require an account and sends us no personal data.
  • We never sell your Personally Identifiable Information (PII).
  • Card data is handled by Stripe / PayPal — never stored on our servers.
  • Cloud OAuth tokens (access token & refresh token) for Google Drive, Dropbox, Box, OneDrive, and pCloud are never stored on GaiaWP servers. They are stored only on your own WordPress site.

1. General & consent

GaiaWP plugins and services are operated by GaiaWP Studio. This policy applies only to our online activities and is valid for visitors to our website with regards to the information they share and/or we collect. It does not apply to information collected offline or via other channels. PII is information that can be used on its own or with other information to identify, contact, or locate a single person.

By using our website, you hereby consent to this Privacy Policy and agree to its terms. If you have additional questions, contact us.

2. Information we collect

The personal information you are asked to provide, and why, will be made clear at the point of collection. When ordering, you may be asked for name, email address, billing address, phone number, payment details or other details.

If you contact us directly, we may receive your name, email address, phone number, message contents and attachments, and any other information you choose to provide. When you register for an account — including automatically via a contact or checkout form — we may ask for contact information such as name, company name, address, email, and telephone number.

When do we collect information?

We collect information when you place an order, register an account, subscribe to a newsletter, submit a support form, or enter information on our site.

How do we use your information?

  • To provide, operate, and maintain our website and plugins.
  • To improve, personalize, and expand our website and develop new features.
  • To understand and analyze how you use our website.
  • To process transactions and send licence keys, update and expiry notices.
  • To communicate with you for customer service, updates, and marketing.
  • To send you emails and prevent fraud.

3. How do we protect your information?

Your personal information is contained behind secured networks, accessible only by a limited number of persons with special access rights who are required to keep it confidential. All information you supply is encrypted in transit via TLS. We implement security measures when a user places an order, enters, submits, or accesses information.

Credit card information

We do not directly store credit card information. Payment handling is performed by a 3rd party processor (Stripe and/or PayPal). No card details or card tokens are stored on our servers. We do store other billing, order and contact information.

4. Log files, cookies & web beacons

Log files: we follow standard log-file procedures. As with any hosting service, requests log IP address, browser type, ISP, date/time stamp, referring/exit pages, and possibly clicks. This is not linked to PII and is used for analyzing trends, administering the site, tracking movement, and gathering demographic information. Under our retention policy these logs rotate automatically after 6 months.

Cookies & web beacons: like any website, we use cookies to store preferences and pages visited, to remember cart items, and to optimize experience (including aggregate traffic analytics). You can disable cookies in your browser; some features may then not function properly.

5. Third-party disclosure, accounts & links

We do not sell, trade, or transfer your PII to outside parties, except to trusted partners working on our behalf or with us under confidentiality agreements (hosting, payment processing, email delivery). Partners have no independent right to share this information, and marketing offers include an unsubscribe link.

Our policy does not apply to other advertisers or websites — consult their respective privacy policies. Third-party sites linked from ours have separate policies; we have no responsibility for their content, and links do not imply endorsement. Site owners and content may change without notice.

6. Email newsletter

Promo emails go only to addresses you gave us (purchases, contact forms, or opt-ins) and comply with applicable spam laws. Delivery runs through Zoho Mail under contract; no personal details pass to other third parties. Every mail ends with a one-click unsubscribe link, and unsubscribed addresses are never mailed again. Mails contain a 1px open-tracking image and per-recipient tracked links, used only in aggregate to refine content — open and click counts are approximate because mailbox apps may block or prefetch content. Unsubscribe and tracking links carry opaque signed tokens, never your profile.

7. Cloud storage OAuth disclosures — GaiaWP plugins

Covers Google Drive, Dropbox, Box, Microsoft OneDrive, and pCloud when you connect any GaiaWP plugin using our built-in OAuth app. If you configure the plugin with your own app / OAuth client for any provider, this section does not apply — in that case no data comes to any of our servers.

7.1 What happens during authentication (all providers)

Connecting to any provider visits our authentication helper as part of the standard OAuth 2.0 flow. No backup data, media files, or other site content goes to our servers — data travels directly between your site and the storage provider.

7.2 Token storage — tokens stay on YOUR site, not our server (all providers)

Access tokens and refresh tokens from Google Drive, Dropbox, Box, OneDrive, or pCloud are NOT stored on GaiaWP servers. They are transmitted securely to, and stored only on, the user's own WordPress site (in its local database), under the site owner's control. GaiaWP servers never persist, log, or cache token values. Disconnecting the plugin or revoking access deletes the locally stored tokens from your site.

  • IP addresses may appear in web-server logs for any HTTPS request. Kept for operational/security purposes only, max 6 months, then auto-deleted. Never shared or used for marketing.
  • On success we may transiently process the provider account identifier solely to complete the handshake. No further processing, no sharing.
  • No other data is sent to or gathered by our servers for any provider above.

7.3 Google Drive app privacy policy

Applies only if you use our built-in app for Google Drive authentication. If you use your own Google Cloud project / OAuth client, it does not apply. Note Google's own terms (consumer Drive accounts are not intended for certain commercial uses — use Workspace where appropriate).

Use of Google Drive involves visiting our authentication server as part of the OAuth flow. No backup/media data goes to our servers. The procedure causes only: (a) IP logged per §7.2; (b) on success, your Google account identifier may be held transiently to hand the token to your site if it re-requests it — no further processing, no sharing.

Scopes:https://www.googleapis.com/auth/drive.file (create/read/manage only files created by GaiaWP) + openid email profile (identify consenting account). The plugin on your server is what exercises these permissions. What you see on the Google consent screen describes the plugin's abilities, not GaiaWP Studio's.

7.4 Dropbox, Box, OneDrive & pCloud

  • Dropbox: app-folder files/content read+write for offloaded media/backups, plus account identification to complete linking.
  • Box: read/write for files and folders you authorize for offload, plus account identification.
  • Microsoft OneDrive (personal & Business): files read/write for offloaded content under the signed-in account, plus sign-in/profile to identify the consenting account.
  • pCloud: file read/write for offloaded media/backups, plus account identification.

Same guarantees as §7.1–7.2: content goes directly between your site and the provider; tokens live only on your site; our servers keep only short-lived security logs.

7.5 Google API Services User Data Policy & Limited Use (Google-specific, required for verification)

Our use of Google user data adheres to the Google API Services User Data Policy, including Limited Use:

  • Access, use, store, and share Google user data only to provide the offload/backup feature you explicitly enabled.
  • Never for advertising, profiling, or any prohibited purpose.
  • Never transferred to third parties except to Google itself at your direction, to comply with law, or in a merger with continued adherence.
  • No human reads Google user data except with your consent, for security, legal compliance, or explicitly requested support.

7.6 Revoke & delete (all providers)

Disconnect inside the plugin and/or revoke in the provider account: Google → Third-party access · Dropbox → Connected apps · Microsoft → Privacy · Box (Account → Authorized apps) · pCloud (Settings → Authorized apps). See §9 for data-deletion requests.

8. Data collection when using GaiaWP plugins

General plugin operation: in the general case there is no communication with our servers — no data is gathered by us. There is no telemetry observing how you use the plugin, and nothing is reported back. Exception: features that require an OAuth flow via our helper (§7, built-in app only) necessarily pass an authentication token through the handshake; no PII is stored or processed by us as part of that procedure.

Licence / update check (paid): connected site stored to answer update requests, expiry notices, and prevent abuse. Requests include WP/PHP/plugin versions, language, multisite flag, memory limit — used only to serve the correct update and aggregate anonymised stats.

News feed: headlines fetched from our blog feed; we receive and process no data.

9. Accounts, rights & deletion (GDPR / CCPA)

Using a plugin does not create an account — only checkout / manual sign-up does. Your GaiaWP password cannot access your WordPress site or PayPal. Users can visit anonymously, will be notified of policy changes on this page, can update personal info by logging in, and we do not allow third-party behavioural tracking beyond aggregate analytics.

You may request access, correction, or deletion/erasure (GDPR “right to be forgotten”, CCPA right to delete/know, right to equal service and price). Contact support from your account email; we verify identity to prevent fraud. Support entries auto-purge after 6 months; forum posts, licence rows, and newsletter entries are deleted on verified request. We do not sell personal information.

Limitations: purchase records retained up to 10 years for tax/audit; server logs 6 months; encrypted backups rotate out and deletions are re-run on restore. Payment-vendor records follow their own policies.

10. Disclaimers

All content on this website is published in good faith for general information only. We make no warranty about completeness, reliability, or accuracy; any action you take is strictly at your own risk. We accept no liability for user-created content or user activities, which do not represent our opinion, nor for losses from use of our website.

11. Contact & changes

For data-protection questions — including OAuth data, access, or deletion — contact GaiaWP Studio support from your account email.

We may periodically update this policy without prior notice; you are responsible for reviewing it regularly. Continued use after changes constitutes acceptance. Future changes (including §7) will be published on this page.