Data Protection & Sovereignty
Privacy & Data Processing Policy
Data governance, end-to-end encrypted cloud vault storage, Stripe payment isolation, and operational privacy protocols governing WPSmooth LLC.
Entity: WPSmooth LLC
Effective: September 2026
Scope: PII, Telemetry & Backups
Storage: Encrypted Cloud Vault & Stripe Isolated
đź”’
Zero-Knowledge Storage & Data Isolation
WPSmooth LLC operates on strict zero-knowledge principles. Customer payment credentials never touch our origin servers, and daily automated backup archives are encrypted end-to-end and streamed directly to dedicated cloud object storage under an autonomous 30-day rolling purge cycle.
01
Information Collection & Use
-
•Lead Capture & PII: When you submit your website URL and email address for a vulnerability audit or service inquiry, this personally identifiable information (PII) is securely routed to and stored within Google Workspace and our proprietary, self-hosted client management dashboard.
-
•Scheduling Data: Fit call booking information is processed via our custom website calendar integration and synchronized directly with Google Calendar without third-party data broker exposure.
-
•Website Analytics: We utilize Google Analytics to track visitor interactions, micro-conversions, and overall site performance. This involves standard tracking cookies deployed on frontend interactions to monitor speed and user experience metrics.
-
•B2B Communications & Legitimate Interest: We process publicly available business contact information for B2B outreach under the lawful basis of legitimate interest. You may opt out of our communication sequences at any time via the automated unsubscribe link provided in our routing infrastructure.
02
Payment Processing Infrastructure
-
✓Third-Party Gateway: All financial transactions, recurring monthly retainers, and Custom Remediation Agreements are processed exclusively through Stripe, an accredited PCI-DSS Level 1 service provider.
-
✓Data Isolation: WPSmooth LLC does not process, transmit, or store raw payment data (such as complete credit card numbers or CVV codes) on our own DigitalOcean droplet or database infrastructure. All checkout sessions interface directly via Stripe’s secure API tokens.
03
Managed Service Data Storage & Retention
-
•Backup Cadence: Daily API-triggered backups are streamed directly to isolated off-site cloud object storage infrastructure, preventing local server disk bloat and origin storage exhaustion.
-
•Retention Period: Backup archives are maintained on a strict 30-day rolling retention lifecycle. Upon exceeding the 30-day threshold, older archives are autonomously and permanently purged from the storage bucket.
-
•Internal Client Management & Geographic Region: Our isolated management hub is hosted on secure cloud infrastructure located within the United States, maintaining strict separation from public-facing assets. Client configurations and service statuses are managed in this isolated environment without exposing underlying origin frameworks.
04
Infrastructure & Data Sovereignty
-
•Global Distribution: Dedicated cloud storage repositories are distributed across high-speed Tier-1 enterprise edge data centers within the United States, ensuring high availability, fault tolerance, and geo-resilience without single-point-of-failure constraints.
-
•Zero Egress Footprint: The architecture leverages zero-egress cloud object infrastructure to maintain an ultra-lightweight operational footprint with zero egress penalties during rollback actions.
05
Encryption & Security
-
✓End-to-End Encryption: All backup payloads—including sensitive database contents, WooCommerce customer transactions, and end-user PII—are encrypted end-to-end at rest using AES-256 within our isolated cloud vault.
-
✓Data Obfuscation: Automated Antigravity Python scripts and API connections strictly orchestrate the transit and storage of these encrypted payloads without decrypting, reading, or processing the underlying application data.
06
User Rights & Data Control
-
•Access and Erasure: Users maintain the right to request access to, or deletion of, their personal data stored within our marketing or client management systems.
-
•Asynchronous Requests: In alignment with our operational communication protocols, all data requests must be submitted asynchronously via our official support channels. Requests are verified and processed within statutory timelines.
Questions regarding our privacy framework or compliance?
Our technical team is available to review data isolation and encryption specifications.
If you have questions about this Privacy Policy, you can contact WPSmooth LLC at 30 North Gould St, STE N, Sheridan, WY 82801.