Skip to main content
InfinitePlugins
TermsPrivacyRefund

Privacy Policy

Effective April 2026

We collect the minimum data needed to run the Service. No ad networks, no data brokers, no cross-site tracking. The only analytics tool we use (Google Analytics) is optional and loads exclusively after you allow it. This policy explains what we keep, why, and how to exercise your rights under the GDPR.

1. What we collect

When you browse

  • Standard web-server logs (IP, user-agent, URL, timestamp) — kept ~30 days at the hosting layer.
  • Essential cookies for session state, security, and checkout (see §3).
  • Only if you click "Allow analytics" in the cookie notice: Google Analytics 4 (page views, approximate region, device type). If you choose "Essential only" — or never answer — no analytics code loads and no analytics cookies are set.

When you create an account

  • Your email address and a salted + hashed password (scrypt; we never see your plaintext password).
  • Your account creation date + last-login timestamps.

When you purchase

  • The plugin you bought, the amount paid, and the billing email — stored so your downloads stay available.
  • Card details are never on our servers. Stripe processes payment and returns an opaque reference we store.

2. What we don't collect

No browsing history across sites. No social-login profiles. No marketing-opt-in demographics. No location data beyond your IP's approximate region (from server logs).

3. Cookies

Essential cookies (no consent required — they only operate the Service):

  • ip_user_session — your signed-in user session. httpOnly.
  • ip_admin_session — signed-in admin session (admin staff only). httpOnly.
  • ip_csrf — cross-site-request-forgery protection token. Deliberately readable by our own page scripts (that's how the double-submit defence works); contains no personal data.
  • ip_checkout_success — short-lived (30 min) proof that your browser started a checkout, so only you can view your own order-confirmation page. httpOnly.

Optional cookies, set only after you click "Allow analytics":

  • _ga / _ga_* — Google Analytics 4 identifiers. Never set unless you opt in.

Your cookie choice itself is stored in your browser's local storage (ip_analytics_consent / ip_cookie_ack), not in a cookie. Session cookies are SameSite=Lax + Secure (on HTTPS).

4. Third parties

We share data only with processors essential to running the Service:

  • Stripe — payment processing. Their privacy policy: stripe.com/privacy.
  • Google Analytics (optional, opt-in only) — aggregate usage statistics. Receives data only if you clicked "Allow analytics". Their privacy policy: policies.google.com/privacy.
  • Transactional email provider — for sending password-reset, verification, and order-receipt emails. They receive only the recipient address and email body.
  • Hosting infrastructure — standard cloud hosting, inside the EU where feasible.

We don't sell or rent your data. We don't allow third parties to use it for their own marketing.

5. Legal basis for processing (GDPR Art 6)

  • Contract — account creation, order processing, download delivery, receipts. Processing is necessary to perform the contract you entered when you signed up or purchased.
  • Legal obligation — retention of invoice/order records (10 years) and VAT records under EU/national tax law.
  • Legitimate interests — rate limiting, abuse detection, security audit logs, per-customer download watermarking (to detect license violations). We balance these against your privacy by minimising what we log and hashing identifiers where feasible.

We do not rely on consent for any core processing — essential cookies are exempt from the consent requirement. The one thing we do ask consent for is optional analytics (GDPR Art 6(1)(a) / ePrivacy Art 5(3)): Google Analytics loads only after you click "Allow analytics", and declining changes nothing about how the shop works. You can clear your browser's site data at any time to be asked again.

6. Your rights (GDPR)

If you're in the EU, EEA, UK, or Switzerland, you have the right to:

  • Access the data we hold about you.
  • Rectify inaccurate data.
  • Erase your account and associated data ("right to be forgotten").
  • Export your data in a portable format.
  • Object to specific uses or restrict processing.
  • Lodge a complaint with your national data protection authority. For the operator of this Service (based in the EU), the lead supervisory authority is Valstybinė duomenų apsaugos inspekcija (VDAI).

Email privacy@infiniteplugins.com from the address on your account. We reply within 30 days. If you've lost access to that email address, contact support — recovery requires manual identity verification.

Automated decision-making: we do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Fraud scoring happens at the Stripe layer for payment authorisation only; see their privacy policy for details.

Data Protection Officer: our processing does not meet the Art 37 thresholds that require appointing a DPO. Your privacy contact is the controller above.

5a. International transfers

We prefer processors based in the EU/EEA. Where a processor operates outside (for example, Stripe processes some data in the US), transfers rely on EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. We review processor safeguards at least annually.

7. Data retention

  • Account data: until you delete your account (self-service in Settings, or by email). Long-inactive accounts may be removed after advance email notice.
  • Order records: 10 years (required for tax/accounting).
  • Web-server logs: ~30 days, rotated at the hosting layer.
  • Audit log of admin actions: 2 years (purged automatically on a scheduled job).
  • Download logs: 90 days (purged automatically).

8. Security

Passwords hashed with scrypt. Sessions rotated on password change. Rate limits + account lockout on authentication. Full HTTPS with HSTS. No plaintext passwords are ever stored or transmitted to us.

9. Changes

We'll email account holders about material changes at least 14 days before they apply. The effective date above is updated when the policy changes.

10. Contact (controller)

Controller: Perfiniti, MB (juridinio asmens kodas 306948787), Kalvarijų g. 135, LT-08248 Vilnius, Lithuania. Operating under the trading name "InfinitePlugins".

Privacy contact: privacy@infiniteplugins.com

© 2026 InfinitePlugins. Made in Europe. Home · Plugins