Rotozoom Plugins — Privacy Policy
Last updated: 2026-06-28
This Privacy Policy explains what data the Rotozoom family of WordPress / WooCommerce plugins (each, a "Plugin") transmits to external services, why, and how it is handled. It is published by LEDLIGHTINGS LTD. ("Rotozoom", "we", "us"), str. Stefan Stambolov 1, Zlatograd, Bulgaria, VAT No. BG204173724, contact support@rotozoom.com. It also covers the Rotozoom account you create on rotozoom.com to download plugins and manage your licences and billing (Section 3).
Short version: most Rotozoom plugins run entirely on your own server and send nothing externally. Only the optional cloud features (AI assistant, AI support chat, self-hosted licensing/updates and billing) transmit data — and even then only an anonymous installation ID, your site URL, and the specific content a feature needs. No customer names, emails or order records are sent unless someone types them into a chat themselves.
1. Scope & roles
This policy covers every Plugin distributed under the Rotozoom program. Many of them (for example Rotozoom Product Filter and Rotozoom Conditions in their public builds) operate fully locally and make no external requests at all — for those Plugins this policy is informational only. Where a Plugin offers a cloud feature:
- You, the site owner, are the data controller for any personal data your visitors enter.
- Rotozoom acts as a data processor on your behalf and engages the sub-processors in Section 5.
If you operate in the EU/EEA or serve EU/EEA visitors, reference the relevant Plugin in your own privacy policy and, where required, conclude a Data Processing Agreement (DPA) with us — see Section 9.
2. What data is sent, by feature
Data leaves your site only for the features listed below. A Plugin that does not include one of these features sends the corresponding data never.
| Feature | Data sent | Destination | When |
|---|---|---|---|
| AI Sales Assistant (Rotozoom Sales Assistant) | Chat message text (may contain personal data only if a visitor types it); your product catalogue per item — name, categories, attributes, price, stock status, image URL, derived search text; optional store-profile text you author. | Rotozoom API → Anthropic (reply) & Voyage AI (search index) | On each chat message and during product indexing |
| AI Support Chat (Rotozoom Dashboard / utilities) | The support question text you or your staff type, plus plugin documentation context. | Rotozoom API → Anthropic | On each support question |
| Licensing & updates (self-hosted builds only) | Installation ID and site URL; your Rotozoom account/licence identifier. Not present in the wordpress.org builds, which use the WordPress.org update system. | Rotozoom API | Periodic heartbeat / update checks |
| Billing (PRO plans & credit packs) | Your payment details, handled directly by the payment processor. The Plugin never stores card data. | Stripe | At checkout |
The installation ID is a randomly generated UUID (or, for licensed installs, an identifier derived from your Rotozoom licence). It is not tied to a named individual.
What is NOT sent: no Plugin transmits your customers' account details, email addresses, billing/shipping addresses, or order history. Those are only ever sent if a person voluntarily types them into a chat message.
Anonymous usage statistics (opt-in). Free installs that have not connected a Rotozoom account may — only if you explicitly choose "Allow" when prompted — send an anonymous weekly ping. It contains a separate random telemetry identifier (not linked to your account, licence or installation ID), the plugin version, your WordPress / PHP / WooCommerce versions, your site's language, whether the site is a multisite, and the country derived from your server's network address at our edge — the network address itself is never stored. It includes no site URL, email or personal data. You can decline ("No thanks"), never enable it, or turn it off later in Rotozoom Connect settings.
3. Your Rotozoom account & sign-in (rotozoom.com)
To download plugins and manage your licences and billing, you create a Rotozoom account on rotozoom.com. This part of the policy covers that account, for which we are the data controller.
- Email & password — we store your email address and, optionally, the name and company you provide. Passwords are hashed by our authentication provider (Supabase Auth); we never see them in plaintext.
- Sign in with Google (optional) — instead of a password you may use "Continue with Google". Google returns a signed identity token containing your email address, name, profile picture and Google account ID, which we use only to create and identify your account. We request basic profile and email only — never your Gmail, Drive, contacts or any other Google data — and we never receive your Google password. A one-time nonce is applied for replay protection. Your use of Google sign-in is also governed by Google's Privacy Policy. You can always register with an email and password instead.
- Billing details — if you buy a PRO plan, the name, company, address and VAT number you enter (the VAT number is validated through the EU VIES service) are stored to issue invoices. Card data is handled solely by Stripe; we never store it.
- Download activity — when you download a plugin, we log the event (plugin, time, country, and a salted, non-reversible hash of your IP — never the raw IP) to produce aggregate download statistics, filter bots and prevent abuse.
- Account deletion — request deletion of your account and its data at support@rotozoom.com.
4. Where data is processed
- The Rotozoom API runs on Supabase infrastructure in the EU (West / Ireland) region.
- Sub-processors (Section 5) may process data in the United States. Such transfers rely on the relevant provider's Standard Contractual Clauses and Data Processing Addendum.
5. Sub-processors
We share the minimum necessary data with the following providers, each only for the features that use them:
- Supabase (Rotozoom API host) — stores chat history, usage counters, the product search index, credit balances and settings. supabase.com/privacy
- Anthropic, PBC (Claude AI) — receives chat / support text and the relevant retrieved snippet to generate replies. Anthropic does not train its models on data submitted through its API. anthropic.com/legal/privacy
- Voyage AI — receives product text to compute the numerical embeddings used for semantic product search. voyageai.com/privacy
- Stripe — processes payments if you buy a PRO subscription or credit pack. stripe.com/privacy
- Google LLC — when you choose "Sign in with Google", verifies your identity and returns your basic profile (email, name, picture) so we can create your account. policies.google.com/privacy
6. What is stored, and for how long
- On your own WordPress site: chat projects/messages, the local product index and plugin settings. You control these and can delete them at any time.
- On the Rotozoom API: usage records, the product embedding index, credit/usage counters and settings, kept while the installation is active, to provide the service, enforce limits and prevent abuse.
- Deletion: request deletion of all data tied to your installation ID at support@rotozoom.com. We delete within 30 days, except limited records we must retain by law (e.g. payment records).
7. Why we process data (purposes & legal basis)
- To provide the cloud feature you chose to use (performance of the service).
- To enforce free/PRO limits and the credit system, and to detect and prevent abuse (our legitimate interest in operating securely).
- To create and secure your Rotozoom account and provide licence and billing management (performance of a contract).
- To process payments, where applicable (performance of a contract).
8. Your visitors' rights
Because you are the controller, requests from your visitors (access, deletion, objection, etc.) should be directed to you. We will assist you for any data held on the Rotozoom API in our role as processor.
9. Data Processing Agreement (DPA)
A DPA is available on request for site owners who require one under the GDPR. Contact support@rotozoom.com.
10. Children
The Plugins are business tools and are not directed at children. Do not use them to knowingly collect data from children under the age applicable in your jurisdiction.
11. Changes
We may update this policy as the service evolves. Material changes are reflected by the "Last updated" date above and, where appropriate, announced in the Plugin or on our website.
12. Contact
Questions about this policy or your data: support@rotozoom.com, LEDLIGHTINGS LTD., str. Stefan Stambolov 1, Zlatograd, Bulgaria.