Skip to content
WPApaxon
Pricing
Security
Sign inGet Started

Plugins

Apaxon MenuApaxon CoreBookingsBuildingSecurityEmail DeliveryBackups
Pricing

Industries

Restaurants and cafésSalons and barbersGarages and tradesAgencies
Security

Support

DocumentationHelp centreContact usStatus
Sign inGet Started

Legal

Privacy policy

What we collect, why we collect it, and what you can ask us to do about it. Written to be read rather than to be defensible.

Last updated 17 August 2026

On this page

  1. Who we are
  2. What we collect and why
  3. What the plugin sends
  4. What we do not collect
  5. Where your data is held
  6. Who else processes it
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Changes
  11. Complaints

Who we are

Apaxon builds WordPress plugins and operates the WPApaxon platform at wpapaxon.com. For the purposes of UK data protection law, Apaxon is the data controller for the information described on this page.

Apaxon Limited, registered in England and Wales, company number [COMPANY NUMBER]. Registered address: [REGISTERED ADDRESS].

For anything on this page, write to privacy@apaxon.co.uk.

What we collect and why

Only what the service needs to work. Each item below exists because something would break without it.

WhatWhyLawful basis
Email addressTo identify your account, sign you in, and send service messagesContract
Name, if you give oneTo address you properly in the portal and in supportContract
PasswordStored only as an Argon2id hash. We cannot read it, and cannot tell you what it isContract
Two-factor secret and recovery codesOnly if you enable two-factor authentication. The secret is encrypted at rest; recovery codes are stored hashedContract
Licence keysStored as a SHA-256 hash plus the first few characters, so you can recognise a key in a list. We never hold the full keyContract
Site addresses you activateTo count seats and show you which sites are using a licenceContract
WordPress, PHP and plugin versionsTo warn you about vulnerabilities affecting your setup, and to support you without asking what you are runningLegitimate interests
Hashed IP addressTo rate-limit sign-in and activation attempts. Hashed with a secret pepper, so the original address cannot be recovered from our databaseLegitimate interests — security
Audit recordsSign-ins, licence activations, role changes and similar. So that if something happens to your account, both of us can see whatLegitimate interests — security

Where we rely on legitimate interests, we have considered whether the processing is necessary and whether it is what you would reasonably expect. If you disagree with that assessment for your own data, tell us and we will look at it again.

What the Apaxon Core plugin sends

Nothing, until you enter a licence key. Installed and activated without one, Apaxon Core makes no requests to us at all.

Once a key is entered, the plugin contacts us on a schedule and sends:

  • The licence key, so we can tell whose it is
  • Your site address, so seats can be counted and shown to you
  • WordPress, PHP and installed Apaxon plugin version numbers — and you can turn this off under Apaxon → Settings → Privacy. The cost of turning it off is that we can no longer warn you about vulnerabilities affecting your specific setup

These checks run on a scheduled task, roughly twice a day. They never run on a visitor page load, and no visitor to your website causes a request to us.

What we do not collect

This list matters as much as the one above.

  • Nothing about your website's visitors. No page views, no IP addresses, no behavioural data, no fingerprinting
  • No content from your site. Not your posts, your products, your customers or your orders
  • No analytics on this website. There is no Google Analytics tag, no Facebook pixel and no third-party tracking script on wpapaxon.com
  • No advertising data, ever. We do not sell, rent or share personal data with advertisers, data brokers or anyone else for their own purposes

Where your data is held

Account and licensing data is stored in a PostgreSQL database hosted by Neon in London, United Kingdom (AWS eu-west-2).

The website and its API run on Vercel. Vercel operates globally, so a request may be handled by infrastructure outside the UK, and Vercel may process technical data such as IP addresses to route and secure that request. Where personal data leaves the UK it is transferred under the UK International Data Transfer Addendum or an adequacy decision.

Who else processes it

We use a small number of suppliers to run the service. Each acts on our instructions under a data processing agreement, and none may use your data for their own purposes.

SupplierWhat forWhere
NeonDatabase hostingUnited Kingdom
VercelWebsite and API hostingGlobal, with UK/EU routing
Our email providerService messages — sign-in alerts, licence noticesUnited Kingdom / EU

We do not currently take payments through this website. When we do, payment card details will be handled by the payment provider and will never reach our servers. This page will be updated before that happens.

How long we keep it

  • Account data — for as long as your account exists. Close it and we delete or anonymise your personal data within 30 days
  • Licence and activation records — for the life of the licence, then for six years, because they form part of our accounting records
  • Audit records — 12 months
  • Sessions — 30 days, or until you sign out

Your rights

Under UK GDPR you have the right to:

  • Ask what we hold about you, and get a copy
  • Have inaccurate information corrected
  • Have your data deleted, where we have no overriding reason to keep it
  • Object to processing we carry out under legitimate interests
  • Ask us to restrict processing while a dispute is resolved
  • Receive your data in a portable format

Email privacy@apaxon.co.uk. We will respond within one month. There is no charge, and you do not have to give a reason.

Cookies

We set two cookies, both strictly necessary, and neither used for tracking or advertising:

  • apx_session — keeps you signed in. Expires after 30 days
  • apx_mfa — a short-lived cookie during two-factor sign-in. Expires after five minutes

Because both are strictly necessary for a service you have asked for, no consent banner is required — and we would rather not show you one. Full detail on the cookie policy.

Changes to this policy

If we change anything material — a new supplier, a new category of data, a different purpose — we will update the date at the top and email account holders before it takes effect. We will not quietly broaden what we collect.

Complaints

If you think we have handled your data badly, please tell us first at privacy@apaxon.co.uk — most things are a misunderstanding we can fix quickly.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. You do not have to come to us first.

WPApaxon

Powerful WordPress tools.
One secure foundation.

WPApaxon is the platform. Apaxon Core is the free plugin it runs through.

Plugins

  • Apaxon Menu
  • Apaxon Core
  • Bookings
  • Security
  • All plugins

Industries

  • Restaurants and cafés
  • Salons and barbers
  • Garages and trades
  • Agencies

Support

  • Documentation
  • Help centre
  • Security
  • Status

Company

  • About
  • Pricing
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Cookie policy
  • Licence

© 2026 Apaxon. All rights reserved.

Terms·Privacy

WordPress is a trademark of the WordPress Foundation. Apaxon is not affiliated with it.