Effective date: June 2, 2026 · Last updated: June 2, 2026
W3 EDGE, LLC d/b/a Auctollo ("Auctollo," "we," "us," or "our") operates the Indexation WordPress plugin and the cloud platform at app.auctollo.com (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what rights you have.
The Indexation Plugin operates entirely on your server by default. We collect personal information from the Plugin only when you explicitly opt in to cloud services or beta features via the consent banner or onboarding wizard. When you opt in, we collect:
| Data | Why we collect it |
|---|---|
| Email address | Account creation, waitlist communications, transactional email |
| Website domain / URL | Associate your WordPress site with your Auctollo account |
| WordPress version | Compatibility monitoring and support |
| PHP version | Compatibility monitoring and support |
| Plugin version | Feature eligibility and update notices |
| WordPress display name | Welcome messaging |
| Consent timestamp and status | GDPR record-keeping, compliance audit trail |
| UTM parameters | Understanding acquisition channels |
Until you interact with the consent banner or account-creation step, no personal data is transmitted to our servers.
Account data: email address (required); display name and avatar URL (from your OAuth provider if you sign in via Google, Microsoft, or GitHub); timestamps.
Subscription and billing: Stripe customer ID and subscription ID; subscription tier, status, and billing period; monthly credit balance and reset date. We do not store payment card numbers — Stripe handles all payment processing and is PCI DSS compliant.
Connected sites: WordPress site URL and name; WordPress version, PHP version, plugin version; site status and last-seen timestamp.
API keys: key prefix (first 8 characters — safe for display and logging); label, creation time, last-used, expiration, and revocation timestamps. The full API key is SHA-256 hashed at creation and never stored in plaintext.
Usage / audit log: feature slug, credits consumed, timestamp, third-party AI provider used, provider cost in USD, request ID, and optional context data (JSON, capped at 2,048 bytes). This log is immutable.
OAuth tokens: token hashes (SHA-256 only; full tokens are never stored), prefixes, scopes, expiration, revocation, and rotation metadata.
We collect standard server logs including IP addresses and user-agent strings for security, fraud prevention, and operational debugging. IP addresses are not linked to user profiles for marketing purposes.
| Purpose | Legal basis (EU / UK GDPR) |
|---|---|
| Providing, operating, and improving the Service | Contract performance |
| Processing payments and managing subscriptions | Contract performance |
| Sending transactional emails (sign-in links, receipts, renewal notices) | Contract performance |
| Sending product and marketing emails | Legitimate interest (opt-out any time) |
| Security monitoring, fraud prevention, rate limiting | Legitimate interest |
| Analytics to improve the Service | Legitimate interest |
| Complying with legal obligations | Legal obligation |
| Enforcing our Terms of Service and AUP | Legitimate interest |
We do not sell your personal information. We do not use your content or site data to train AI models.
We share personal data only with the processors listed below, each contractually required to protect your data and use it only to provide services to us.
| Sub-processor | Role | Data shared | Privacy policy |
|---|---|---|---|
| Supabase (AWS US-East-1) | Database, authentication, edge functions | All platform data listed in Section 1.2 | supabase.com/privacy |
| Stripe | Payment processing and subscription management | Email, billing amounts, Stripe customer and subscription IDs | stripe.com/privacy |
| Mailchimp (Intuit) | Transactional and marketing email | Email, name, domain, version metadata, subscription tags | mailchimp.com/legal/privacy |
| Vercel | Web application hosting and CDN | Server logs, session cookies, IP addresses | vercel.com/legal/privacy-policy |
| Inngest | Background job queue for AI features, credit events, and sitemap triggers | Job payloads — feature identifiers, credit amounts, and context data | inngest.com/privacy |
| Anthropic | AI feature processing | Content submitted to AI features (URLs, titles, meta descriptions) | anthropic.com/privacy |
| OpenAI | AI feature processing (fallback) | Content submitted to AI features | openai.com/privacy |
| Google (Vertex AI / Gemini API) | AI feature processing (fallback) | Content submitted to AI features | policies.google.com/privacy |
| Google Tag Manager / GA4 | Website analytics | Anonymized usage events, anonymized IP — loaded only with your explicit consent in Plugin settings | policies.google.com/privacy |
| AWS Route 53 | DNS routing for auctollo.com and app.auctollo.com | Domain-resolution queries only — no personal data | aws.amazon.com/privacy |
We do not use advertising networks, data brokers, cross-site behavioral tracking, or sell data to any third party for their independent marketing purposes.
When you use AI-powered features (Indexation Troubleshooter, AI redirect suggestions, schema audit, meta-tag scan), relevant data — such as URLs, page titles, and meta descriptions — is transmitted to a third-party AI provider to generate the requested output. We use providers whose standard API terms state that customer data is not used to train their models. You can review which provider processed each request in your usage audit log on the Auctollo dashboard.
See our Cookie Policy for full details. In summary: we use strictly necessary session cookies for authentication, and optional analytics cookies (Google Tag Manager / GA4) only with your explicit consent in the Plugin settings. We do not use advertising or cross-site tracking cookies.
We implement industry-standard security measures: TLS/HTTPS for all data in transit; SHA-256 hashing of API keys and OAuth tokens; Supabase Row-Level Security (RLS) policies for per-user data isolation; Stripe PCI DSS Level 1 compliance for payment data; and access restricted to authorized Auctollo personnel. If you discover a security vulnerability, please disclose it responsibly to legal@auctollo.com.
| Data type | Retention period |
|---|---|
| Account profile | Until account deletion |
| Subscription records | 7 years (tax and legal obligation) |
| Usage / audit log | 24 months, then anonymized |
| Revoked API keys | 90 days after revocation, then deleted |
| Expired / revoked OAuth tokens | 30 days after expiry or revocation, then deleted |
| Waitlist entries | Until erasure request |
| Server logs | 90 days rolling |
| Database backups | 30 days rolling |
In addition to the above rights:
WordPress plugin users: Use WordPress's built-in privacy tools at Tools → Export Personal Data and Tools → Erase Personal Data. The Plugin registers its data categories with WordPress's privacy framework.
Platform users: Email privacy@auctollo.com with the subject "Privacy Request — [Action]" (e.g., "Privacy Request — Data Deletion"). We will acknowledge within 5 business days and respond within 30 days.
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact privacy@auctollo.com.
Auctollo is based in the United States, and data is stored and processed primarily on Supabase / AWS US-East-1 infrastructure. For EU/UK residents, we rely on Standard Contractual Clauses (SCCs) and Supabase's EU data transfer mechanisms to safeguard cross-border transfers.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will be sent to the email address on your account and will describe the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the measures taken or proposed.
EU and UK residents: We will also notify the relevant supervisory authority within 72 hours where required by GDPR Article 33.
To report a suspected security issue: legal@auctollo.com
We will post changes to this page and update the "Last updated" date. For material changes, we will notify you by email or via a dashboard notice at least 30 days before the change takes effect.
Privacy inquiries: privacy@auctollo.com
W3 EDGE, LLC d/b/a Auctollo
9450 SW Gemini Drive PMB 22185, Beaverton, OR 97008-7105, US