Privacy Policy — Cover My Order
Legal · Part A & B

Privacy Policy

How Cover My Order collects, uses and protects information — on our website, and inside the plugin running on your own WooCommerce store.

Effective 16 Jul 2026 Last updated 16 Jul 2026

Cover My Order ("Cover My Order," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit covermyorder.com (the "Site"), purchase or use a Cover My Order software licence, or install and use the Cover My Order plugin on your own WordPress and WooCommerce store.

This policy is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU GDPR and the Privacy and Electronic Communications Regulations (PECR). If you do not agree with the terms of this policy, please do not access the Site or use our products.

01

Who We Are

For the purposes of UK GDPR, Cover My Order is the data controller of personal information collected through the Site and in connection with your licence purchase, as described in Part A. Where you install our plugin on your own WooCommerce store, you (the store owner) act as the data controller of your customers' data — Cover My Order acts, at most, as a data processor for narrowly defined functions described in Part B.

Data controller Cover My Order
support@covermyorder.com
51 Cardiff Road, Cardiff, CF5 2DQ
United Kingdom
PART A

The Cover My Order Website and Your Account

02

Personal Information We Collect

Information you give us directly

  • Contact form and support submissions — name, email address, message content, and any attachments you choose to include.
  • Newsletter sign-up — email address, and optionally name.
  • Account and purchase information — name, billing email, company name (if provided), country, and licence/subscription details, collected when you purchase a licence through our payment processor, Freemius.
  • Correspondence — records of any emails, support tickets, or other communications you send us.

We do not collect or store full payment card numbers, CVV codes, or bank account numbers ourselves — these are handled directly by Freemius (Section 5).

Information collected automatically

  • Device and technical data — IP address, browser type and version, operating system, device type, screen resolution, referring/exit pages.
  • Usage data — pages visited, time on page, links clicked, navigation patterns.
  • Approximate location — derived from IP address, typically city/country level.
  • Cookies and similar technologies — see Section 8.

Information from third parties

  • Freemius provides purchase confirmation, licence status, and subscription/renewal data.
  • Freemius SDK (plugin usage data) — if you separately opt in from within the plugin, Freemius may collect limited diagnostic data (site URL, PHP/WordPress version, feature usage) and share aggregate insights with us. Off by default; you can decline without affecting plugin functionality.
  • WordPress.org provides aggregate, non-personal install and update statistics for the free plugin.
03

Legal Basis for Processing UK GDPR Art. 6

We only process your personal information where we have a valid legal basis to do so.

BasisWhen we rely on it
ContractProcessing your licence purchase, delivering the software, and providing support you've requested.
Legitimate interestsOperating, securing and improving the Site and business; responding to enquiries; preventing fraud — balanced against your rights.
ConsentNewsletter marketing emails, non-essential cookies, and optional plugin usage-data sharing. Withdrawable at any time.
Legal obligationRetaining financial and tax records as required by UK law.
04

How We Use Your Information

  • Create and manage your licence and account.
  • Process payments, renewals, and refunds (via Freemius).
  • Deliver software updates and licence validation.
  • Provide customer support and respond to enquiries.
  • Send service communications (licence expiry, security notices) — sent regardless of newsletter opt-in, as they're necessary to the contract.
  • Send product updates and marketing content, only if you've opted in to the newsletter.
  • Monitor and improve Site performance, security and experience.
  • Detect and prevent fraud, abuse, or Terms of Service violations.
  • Comply with legal, tax and accounting obligations.

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.

05

Who We Share Your Information With

We do not sell, rent, or trade your personal information. We share it only with the recipients below, each under contractual data protection obligations.

RecipientRolePurposeData shared
Freemius, Inc.
Wilmington, DE, USA
Payment processor & merchant of record Licence sales, payments, subscriptions, EU/UK VAT, optional usage tracking Name, email, billing details, purchase history, country, site URL
Website hosting providerProcessorHosting covermyorder.comServer logs, IP address
Analytics providerProcessorSite traffic and usage analysisUsage data, approx. location, device data
Email/newsletter providerProcessorOpted-in marketing communicationsEmail, name, engagement data
Professional advisorsIndependent controllerLegal, accounting, audit servicesLimited to engagement
Regulators/authoritiesAs required by lawLegal complianceAs legally required
Freemius states in its own privacy policy that it does not sell personal data or use it for its own direct marketing. It is GDPR-compliant by its own commitment despite not being a European entity, governed by its published Data Processing Addendum. Reviewable directly at freemius.com/privacy.
06

International Data Transfers

Freemius, our payment and licensing processor, is a US entity (Wilmington, Delaware), meaning your purchase and billing data is transferred to and processed in the United States. Freemius states it complies with GDPR and, where applicable, the Brazilian LGPD, and never sells personal data. Other processors may also store data outside the UK.

Where this occurs, we rely on appropriate safeguards:

  • The UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses; or
  • Transfers to countries with UK adequacy regulations in place; or
  • Other recognised mechanisms, including a processor's own contractual GDPR commitments (as with Freemius's DPA).
07

Data Retention

  • Account and licence data — for the duration of your active licence, plus up to 7 years afterward for UK tax/accounting (HMRC).
  • Support correspondence — up to 3 years from the last interaction.
  • Newsletter data — until you unsubscribe or request deletion.
  • Website analytics — aggregated/pseudonymised beyond 26 months; raw identifiable data kept no longer than 26 months.
  • Marketing consent records — retained as evidence of past consent status, even after unsubscribing.
08

Cookies and Tracking Technologies

  • Strictly necessary — core Site functionality. Cannot be disabled; no consent required under PECR.
  • Functional — remember preferences such as pricing display settings.
  • Analytics — aggregate traffic patterns. Requires consent.
  • Marketing — measures marketing effectiveness, where used. Requires consent.

We manage consent through a floating cookie preference widget, available at any time from the corner of the screen, where you can view, accept, reject, or update your choices per category. Strictly necessary cookies are excluded, as they don't require consent.

09

Your Rights Under UK GDPR

  • Right of access — a copy of the personal information we hold about you.
  • Right to rectification — correction of inaccurate or incomplete information.
  • Right to erasure — deletion, subject to legal retention obligations.
  • Right to restrict processing — limit how we use your information in certain circumstances.
  • Right to data portability — a structured, machine-readable copy, where based on consent or contract.
  • Right to object — to legitimate-interest processing or direct marketing, any time.
  • Right to withdraw consent — without affecting prior lawful processing.
  • Rights on automated decision-making — not applicable; we don't currently engage in this.

We respond within one calendar month, extendable by two further months for complex requests. We may verify your identity first.

10

Your Right to Complain

If you believe we've mishandled your personal information under UK GDPR, you may lodge a complaint with:

Supervisory authority Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF, UK
ico.org.uk · 0303 123 1113

We'd appreciate the chance to address concerns directly first — please contact us before approaching the ICO if possible.

11

Data Security

  • Encrypted connections (HTTPS/TLS) across the Site.
  • Access controls limiting internal access on a need-to-know basis.
  • Reputable, contractually bound third-party processors.
  • Regular review of security practices.

No method of transmission or storage is completely secure. In the event of a breach posing risk to your rights, we notify the ICO within 72 hours where required, and affected individuals without undue delay where high risk is likely.

12

Children's Privacy

The Site and our products are intended for business use by store owners, administrators and professionals. We do not knowingly collect personal information from children under 16. If we become aware we have, we take steps to delete it promptly.

PART B

How the Plugin Handles Data on Your Store

13

Self-Hosted Architecture

  • Your customers' data stays on your infrastructure. Premiums, claims, evidence uploads, and ledger entries live in your own WordPress/WooCommerce database. We do not receive, transmit, or store this data ourselves.
  • You are the data controller for personal information your customers submit through the plugin. Your own privacy policy and data-subject obligations are separate from, and not fulfilled by, this document.
  • Licence validation — the plugin periodically contacts Freemius with your site URL, plugin version, and licence key. Never your customers' order, claim, or ledger data.
  • Optional usage-data sharing — Freemius's own opt-in screen may ask to share diagnostic data (PHP/WP version, feature usage). Off by default; togglable in wp-admin.
  • Optional integrations — SMS (Twilio), webhooks (Slack/Zapier/custom), or carrier tracking (AfterShip) only transmit data when you actively enable them.
  • Uninstalling — deactivation doesn't erase data. If offered, a "remove all data on uninstall" toggle will delete it.

Because we don't have access to Part B data, requests about your customers' claims or order data must go to you, the store owner.

14

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in practices, technology, or legal requirements. We'll revise the "Last updated" date above, and for material changes, give reasonable advance notice — a Site notice or an email to registered customers — before changes take effect. We encourage periodic review.

15

Contact Us

Questions, concerns, or requests about this policy or your personal information:

Cover My Order support@covermyorder.com
51 Cardiff Road, Cardiff, CF5 2DQ
United Kingdom