Privacy Policy
Last updated: July 29, 2026privacy-policy.md
01 Data Controller
The data controller for this website and for the plugins sold through it is:
InTouchDesign
Via IV Novembre 140
09070 Zeddiani (OR), Sardegna, Italy
P.IVA: 01205960956
Email: info@intouchdesign.it
Website: www.intouchdesign.it
02 What Data We Collect
We may collect and process the following categories of personal data:
- Identity data: first name, last name, username or similar identifier.
- Contact data: email address, billing address.
- Financial data: payment information processed securely by our payment processors (Freemius / Stripe). We do not store card details on our servers.
- Technical data: IP address, browser type and version, time zone, browser plug-in types and versions, operating system.
- Usage data: information about how you use our website and plugins.
- Plugin telemetry (opt-in): if you opt in inside the plugin dashboard, anonymous usage statistics (WordPress version, PHP version, active theme) may be collected via the Freemius SDK to help us improve our products.
03 How We Collect Your Data
We collect data through:
- Direct interactions: when you purchase a plugin, create an account, contact us by email, or fill in a form on this website (e.g. the "Notify Me" waitlist for upcoming plugins).
- Automated technologies: cookies and similar tracking technologies as you interact with our website (see Section 7).
- Third parties: our payment processor Freemius/Stripe may share transaction data with us.
04 How We Use Your Data
We use your personal data for the following purposes:
- To process and manage your plugin purchase and license.
- To deliver software updates and technical support.
- To communicate with you about your order, license, or support request.
- To send product-related notifications (new versions, security notices). You can unsubscribe at any time.
- To comply with legal obligations (e.g., tax records, invoicing).
- To improve our products and website based on aggregated, anonymised usage data.
05 Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:
- Contract performance: processing your purchase and delivering the licensed software.
- Legal obligation: keeping accounting records as required by Italian tax law.
- Legitimate interests: website security, fraud prevention, and improving our products.
- Consent: for optional plugin telemetry and marketing emails (you can withdraw consent at any time).
06 Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy or as required by law. Purchase records and invoices are kept for 10 years as required by Italian fiscal regulations. Support-related emails are retained for 3 years after your last interaction. You can request deletion of your account and associated data at any time (subject to legal retention obligations).
07 Cookies
This website uses a minimal set of cookies:
- Strictly necessary cookies: required for the website to function (e.g., session management). Cannot be disabled.
- Analytics cookies: if any third-party analytics are used, they are configured in anonymised mode and require your consent.
You can control cookies through your browser settings. Disabling strictly necessary cookies may affect website functionality.
08 Third-Party Processors
We share your data with the following third-party processors, all operating under appropriate data processing agreements:
- Freemius Inc. — license management, payment processing, and optional plugin telemetry. Privacy Policy.
- Stripe Inc. — payment processing. Privacy Policy.
- Brevo (Sendinblue SA) — email address storage and delivery for the "Notify Me" plugin launch waitlist. You can unsubscribe via the link in any email we send. Privacy Policy.
We do not sell your personal data to any third party.
09 International Transfers
Freemius and Stripe are US-based companies. When your data is transferred to the United States, it is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of protection consistent with GDPR requirements. Brevo is an EU-based company (France) and processes data within the European Economic Area.
10 Your Rights
Under GDPR and Italian privacy law (D.Lgs. 196/2003 as amended), you have the right to:
- Access your personal data we hold.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to legal retention obligations.
- Restrict the processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent at any time for processing based on consent.
To exercise any of these rights, contact us at info@intouchdesign.it. We will respond within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
11 Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful loss, alteration, disclosure, or access. Payments are processed exclusively through PCI-DSS compliant processors; we never handle or store card numbers directly.
12 Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top of this page indicates when it was last revised. We encourage you to review this page periodically. For material changes, we will notify active customers by email.
13 Contact
For any privacy-related question or request, please contact:
info@intouchdesign.it
