Privacy policy
Last updated: 4 October 2026
1. Who is responsible for your data
Themo WP is the controller of the data described here. For any question about your data: our support team (Help in your account).
This policy covers the themo-wp.com website, your account, your orders and the license server the plugin connects to. What your own customers type on your site stays on your site: we don't process it, and you are responsible for it.
2. The data we process
- Account: name, email address, password (stored only as an irreversible hash), language, phone number, and your photo if you add one.
- Billing: the name, company, address, country and tax ID shown on your invoices.
- Orders and payments: plan, amounts, the account chosen for the transfer, order reference, the receipts you send, the amount received and the approval date.
- Licenses: the key (encrypted), the domains of the sites where it is activated, the installed plugin version and the date of the last check.
- The plugin's calls to our server: to check your license or look for an update, the plugin sends the key, the site's domain, the product and its version; our server also sees the IP address of the server that hosts your site.
- Security: your sign-in sessions (browser, system, IP address, last activity), the sign-in, confirmation or reset links sent by email, anti-abuse counters, and a log of important actions on your account (orders, payments, password or email changes).
- Emails: the list of service emails sent to you.
- Support: the messages you send us and our replies.
We never receive card details: payment is by transfer, through your bank or payment service.
3. Why we process it, and on what basis
- To perform our contract with you: creating and running your account, processing your orders, delivering, updating and checking your licenses, sending you service emails (address confirmation, order, payment reminder, delivery, invoice) and answering your support requests.
- To meet our legal obligations: issuing and keeping invoices and accounting records.
- For our legitimate interest: securing the service and your accounts, preventing fraud and abuse, and fixing incidents. You can object to this processing on grounds relating to your situation.
We don't send newsletters or advertising without your consent, we don't use your data for targeted advertising, and we don't sell it.
4. Who can see it
- The members of our team who need it for their work, with administrator access protected by two-factor authentication.
- Our service providers, who act only on our instructions:
- Contabo GmbH (Germany): server and database hosting, and file storage (Contabo Object Storage: profile photos, receipts, invoices, plugin releases and encrypted backups);
- Cloudflare (United States, global network): routing and protecting the site;
- Resend (United States): sending emails.
- If you write to us on WhatsApp or by email, WhatsApp (Meta) and the email service behind our support address process those messages.
- The payment services you choose, such as Wise, Payoneer or your bank, process your transfer under their own terms and privacy policies.
- Authorities, when the law requires us to.
5. Transfers outside Morocco
We are a company established in the United States, and your data is hosted in Germany, in the European Union; some providers also process it in the United States. It is therefore processed outside Morocco. Moroccan law No. 09-08 makes these transfers subject, depending on the destination country, to a declaration to or an authorisation from the CNDP; they are made within that framework and, where it applies, the GDPR's, through the contractual data protection commitments these providers offer.
6. How long we keep it
- Account, licenses and activations: as long as your account exists.
- Unpaid orders: as long as your account exists.
- Invoices, paid orders and payment records: 10 years, as the law requires for accounting records.
- Sign-in sessions, including the IP address: deleted 90 days after they end (sign-out or expiry; a session lasts 30 days at most).
- Links sent by email: valid for 15 minutes to 48 hours, then deleted 30 days after they were used or expired.
- Anti-abuse counters: erased automatically after one hour at most.
- The log of important actions and the list of emails sent: as long as your account exists; the IP address recorded with an action is erased after 90 days.
- Support messages: up to 3 years after our last exchange.
- Encrypted database backups: 12 months at most, then erased.
When you ask us to delete your account, we delete or anonymise your data, except what the law requires us to keep.
7. Security
Traffic with the site is encrypted (HTTPS). Passwords are stored as hashes (scrypt) and license keys are encrypted. Administrator access requires two-factor authentication, and backups are encrypted. No system is infallible: if a breach affecting your data happened, we would tell you, and tell the competent authorities where the law requires it.
8. Your rights
Under Moroccan law No. 09-08 on the protection of individuals with regard to the processing of personal data and, if you live in the European Union, the GDPR, you can:
- access your data and get a copy of it;
- have it corrected or completed (you can change most of it yourself in your account, under Profile);
- object to its processing on legitimate grounds;
- ask for it to be deleted;
- under the GDPR, also ask for processing to be restricted and for your data to be ported.
To use these rights, write to our support team (Help in your account) from your account's address. We may ask you to confirm your identity. We make corrections within the 10 clear days Moroccan law No. 09-08 allows, and answer other requests within one month at most.
You can also complain to Morocco's data protection authority, the CNDP (Commission nationale de contrôle de la protection des données à caractère personnel, www.cndp.ma) or, in the European Union, to your country's data protection authority.
9. Cookies and browser storage
We only use what the site needs to work, with no advertising and no audience measurement:
- NEXT_LOCALE (cookie): the site's language, for your visit.
- tw_s (cookie scripts can't read): your customer session, 30 days at most.
- tw_admin and tw_admin_sidebar (cookies): for our team only, the admin session (12 hours at most) and how the menu is shown.
- tw-theme (local storage): your choice of light or dark theme.
- A copy of the order form (local storage): if you need to sign in during an order, your browser keeps what you typed for one hour at most so you don't have to type it again. It is erased as soon as the order is placed, when you sign out, and in any case after one hour.
Cloudflare may also set technical security cookies. Because these are essential to the service, they don't require your consent.
10. Minors
Our services are meant for professionals and adults; they are not intended for anyone under 18.
11. Changes
We may update this policy; the date of the last update is shown at the top of the page. If an important change affects you, we tell you by email.