How Cover My Order collects, uses and protects information — on our website, and inside the plugin running on your own WooCommerce store.
Cover My Order ("Cover My Order," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit covermyorder.com (the "Site"), purchase or use a Cover My Order software licence, or install and use the Cover My Order plugin on your own WordPress and WooCommerce store.
This policy is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU GDPR and the Privacy and Electronic Communications Regulations (PECR). If you do not agree with the terms of this policy, please do not access the Site or use our products.
For the purposes of UK GDPR, Cover My Order is the data controller of personal information collected through the Site and in connection with your licence purchase, as described in Part A. Where you install our plugin on your own WooCommerce store, you (the store owner) act as the data controller of your customers' data — Cover My Order acts, at most, as a data processor for narrowly defined functions described in Part B.
We do not collect or store full payment card numbers, CVV codes, or bank account numbers ourselves — these are handled directly by Freemius (Section 5).
We only process your personal information where we have a valid legal basis to do so.
| Basis | When we rely on it |
|---|---|
| Contract | Processing your licence purchase, delivering the software, and providing support you've requested. |
| Legitimate interests | Operating, securing and improving the Site and business; responding to enquiries; preventing fraud — balanced against your rights. |
| Consent | Newsletter marketing emails, non-essential cookies, and optional plugin usage-data sharing. Withdrawable at any time. |
| Legal obligation | Retaining financial and tax records as required by UK law. |
We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.
We do not sell, rent, or trade your personal information. We share it only with the recipients below, each under contractual data protection obligations.
| Recipient | Role | Purpose | Data shared |
|---|---|---|---|
| Freemius, Inc. Wilmington, DE, USA |
Payment processor & merchant of record | Licence sales, payments, subscriptions, EU/UK VAT, optional usage tracking | Name, email, billing details, purchase history, country, site URL |
| Website hosting provider | Processor | Hosting covermyorder.com | Server logs, IP address |
| Analytics provider | Processor | Site traffic and usage analysis | Usage data, approx. location, device data |
| Email/newsletter provider | Processor | Opted-in marketing communications | Email, name, engagement data |
| Professional advisors | Independent controller | Legal, accounting, audit services | Limited to engagement |
| Regulators/authorities | As required by law | Legal compliance | As legally required |
Freemius, our payment and licensing processor, is a US entity (Wilmington, Delaware), meaning your purchase and billing data is transferred to and processed in the United States. Freemius states it complies with GDPR and, where applicable, the Brazilian LGPD, and never sells personal data. Other processors may also store data outside the UK.
Where this occurs, we rely on appropriate safeguards:
We manage consent through a floating cookie preference widget, available at any time from the corner of the screen, where you can view, accept, reject, or update your choices per category. Strictly necessary cookies are excluded, as they don't require consent.
We respond within one calendar month, extendable by two further months for complex requests. We may verify your identity first.
If you believe we've mishandled your personal information under UK GDPR, you may lodge a complaint with:
We'd appreciate the chance to address concerns directly first — please contact us before approaching the ICO if possible.
No method of transmission or storage is completely secure. In the event of a breach posing risk to your rights, we notify the ICO within 72 hours where required, and affected individuals without undue delay where high risk is likely.
The Site and our products are intended for business use by store owners, administrators and professionals. We do not knowingly collect personal information from children under 16. If we become aware we have, we take steps to delete it promptly.
Because we don't have access to Part B data, requests about your customers' claims or order data must go to you, the store owner.
We may update this Privacy Policy periodically to reflect changes in practices, technology, or legal requirements. We'll revise the "Last updated" date above, and for material changes, give reasonable advance notice — a Site notice or an email to registered customers — before changes take effect. We encourage periodic review.
Questions, concerns, or requests about this policy or your personal information: