Legal

Privacy policy

What this website and this company collect, why, how long it is kept, and what the plugin does with data on your own site — which is a different question, and the more important one.

Before you rely on this

This document has not been reviewed by a lawyer. Have qualified legal counsel check it against the jurisdictions you sell into before the site goes live.

Who we are

RuleFence (“we”, “us”) publishes the RuleFence plugin and this website. The data controller is WiselyHub LLC, 412 N Main St, Suite 100, Buffalo, Wyoming 82834, USA.

For any privacy question, write to [email protected].

The plugin does not send us your data

This deserves to come before everything else, because it is the question most operators are actually asking.

RuleFence is local-first. Agent identities, permission decisions, approvals, sessions, activity, and the audit trail are stored in your own WordPress database, on your own hosting. We have no access to them, and the plugin does not transmit them to us.

The plugin makes exactly one category of outbound request, and only when you have chosen to make it:

  • Licence activation for a paid edition. Your licence key, the site URL it is being activated for, and the plugin version are sent to the licence endpoint you have configured. Nothing about your agents, permissions, or audit records is included. The free edition does not activate a licence.

There is no telemetry, no usage analytics, and no phone-home in the plugin. Where a licence server cannot be reached, an unreachable server is never treated as a verdict — the plugin does not silently disable itself.

You remain the controller of your site’s data

If your agents process personal data belonging to your users, that processing is yours to govern. The plugin’s job is to make each decision explicit and recorded, including the redaction of sensitive input in the audit trail.

What this website collects

DataWhyBasisRetention
Messages you send us — name, email address, and the content of your messageTo answer you and keep a support historyLegitimate interest; contract where you are a customer3 years from last contact
Purchase records — billing name, address, email, licence key, order and invoice detailsTo supply the licence and meet accounting obligationsContract; legal obligationAs required by law, typically 7 years
Licence activations — licence key, activated site URL, plugin version, activation timestampTo enforce licence scope and support youContractLife of the licence, plus 12 months
Server logs — IP address, user agent, requested URL, timestampSecurity, abuse prevention, and diagnosing faultsLegitimate interest30 days
Mailing list — email address, if you subscribeRelease and security announcementsConsentUntil you unsubscribe

We do not sell personal data, we do not share it with advertisers, and we do not add you to a mailing list because you asked a support question.

Payments

We do not receive or store your full card details. Payments are processed by Stripe, who acts as an independent controller for the payment data you give them. We receive the billing details and the outcome needed to issue a licence and an invoice.

Who processes data for us

We use a small number of service providers under written agreements that permit them to process data only on our instructions:

  • Hosting for this website and the licence endpoint — Hetzner, Germany.
  • Email for support and transactional messages — Amazon SES.
  • Payment processing — Stripe.

Where a provider processes data outside your region, transfers rely on the safeguards described in their own terms, including standard contractual clauses where applicable.

Cookies

This site uses a small number of cookies, none of them for advertising. What each one is for, and how to refuse the non-essential ones, is set out in the cookie policy.

Your rights

Depending on where you live, you may have the right to:

  • Ask what personal data we hold about you, and receive a copy.
  • Have inaccurate data corrected.
  • Have data erased, where we have no overriding obligation to keep it.
  • Object to, or ask us to restrict, a particular use.
  • Receive data you gave us in a portable format.
  • Withdraw consent at any time, where consent is the basis.
  • Complain to your data protection authority.

Write to [email protected]. We answer within 30 days and we do not charge for a reasonable request.

How we protect it

Access to customer data is limited to the people who need it, protected by multi-factor authentication, and reviewed periodically. Data in transit is encrypted. We keep as little as the job requires, for as long as it is genuinely needed.

If a breach affects your personal data and presents a risk to you, we will notify you and the relevant authority within the time limits that apply to us.

To report a suspected vulnerability, follow the responsible disclosure process.

Children

This is a product for site operators. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

Changes to this policy

We update this page when what we do changes. The effective date at the top always reflects the current version, and material changes are announced on the site before they take effect.

Questions

Ask us anything about your data.

We would rather answer a privacy question than have you guess at the answer.