Skip to content
WPApaxon
PricingBlog
Sign inGet Started

Plugins

By category

Foundation1Business8Commerce4Security4Marketing5Website tools3

Popular

Apaxon CoreApaxon CRMApaxon MenuApaxon Bookings

Platform

How it works

Security standardPricing

Company

About ApaxonBlogContact
Pricing
Blog
Sign inGet Started

Legal

Privacy policy

What we collect, why we collect it, and what you can ask us to do about it. Written to be read rather than to be defensible.

Last updated 27 August 2026

On this page

  1. Who we are
  2. What we collect and why
  3. What the plugin sends
  4. What we do not collect
  5. Where your data is held
  6. Who else processes it
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Changes
  11. Complaints

Who we are

Apaxon builds WordPress plugins and operates the WPApaxon platform at wpapaxon.com. For the purposes of UK data protection law, Apaxon is the data controller for the information described on this page.

Apaxon Limited, registered in England and Wales, company number 09784429. Registered address: Piccadilly Business Centre, Aldow Enterprise Park, Manchester, M12 6AE, Greater Manchester.

For anything on this page, write to privacy@apaxon.co.uk.

What we collect and why

Only what the service needs to work. Each item below exists because something would break without it.

WhatWhyLawful basis
Email addressTo identify your account, sign you in, and send service messagesContract
Name, if you give oneTo address you properly in the portal and in supportContract
PasswordStored only as an Argon2id hash. We cannot read it, and cannot tell you what it isContract
Two-factor secret and recovery codesOnly if you enable two-factor authentication. The secret is encrypted at rest; recovery codes are stored hashedContract
Licence keysStored as a SHA-256 hash plus the first few characters, so you can recognise a key in a list. We never hold the full keyContract
Site addresses you activateTo count seats and show you which sites are using a licenceContract
WordPress, PHP and plugin versionsTo warn you about vulnerabilities affecting your setup, and to support you without asking what you are runningLegitimate interests
Hashed IP addressTo rate-limit sign-in and activation attempts. Hashed with a secret pepper, so the original address cannot be recovered from our databaseLegitimate interests — security
Audit recordsSign-ins, licence activations, role changes and similar. So that if something happens to your account, both of us can see whatLegitimate interests — security

Where we rely on legitimate interests, we have considered whether the processing is necessary and whether it is what you would reasonably expect. If you disagree with that assessment for your own data, tell us and we will look at it again.

What the Apaxon Core plugin sends

Nothing, until you enter a licence key. Installed and activated without one, Apaxon Core makes no requests to us at all.

Once a key is entered, the plugin contacts us on a schedule and sends:

  • The licence key, so we can tell whose it is
  • Your site address, so seats can be counted and shown to you
  • WordPress, PHP and installed Apaxon plugin version numbers — and you can turn this off under Apaxon → Settings → Privacy. The cost of turning it off is that we can no longer warn you about vulnerabilities affecting your specific setup

These checks run on a scheduled task, roughly twice a day. They never run on a visitor page load, and no visitor to your website causes a request to us.

What we do not collect

This list matters as much as the one above.

  • Nothing about your website's visitors. No page views, no IP addresses, no behavioural data, no fingerprinting
  • No content from your site. Not your posts, your products, your customers or your orders
  • Analytics only if you say yes. We use Google Analytics to count which pages people find useful. It is switched off until you accept it, and declining changes nothing about how the site works. There is no Facebook pixel, no advertising tag and no other third-party script
  • No advertising data, ever. We do not sell, rent or share personal data with advertisers, data brokers or anyone else for their own purposes

Where your data is held

Account and licensing data is stored in a PostgreSQL database hosted by Neon in London, United Kingdom (AWS eu-west-2).

The website and its API run on Vercel. Vercel operates globally, so a request may be handled by infrastructure outside the UK, and Vercel may process technical data such as IP addresses to route and secure that request. Where personal data leaves the UK it is transferred under the UK International Data Transfer Addendum or an adequacy decision.

Who else processes it

We use a small number of suppliers to run the service. Each acts on our instructions under a data processing agreement, and none may use your data for their own purposes.

SupplierWhat forWhere
NeonDatabase hostingUnited Kingdom
VercelWebsite and API hostingGlobal, with UK/EU routing
Our email providerService messages — sign-in alerts, licence noticesUnited Kingdom / EU

We do not currently take payments through this website. When we do, payment card details will be handled by the payment provider and will never reach our servers. This page will be updated before that happens.

How long we keep it

  • Account data — for as long as your account exists. Close it and we delete or anonymise your personal data within 30 days
  • Licence and activation records — for the life of the licence, then for six years, because they form part of our accounting records
  • Audit records — 12 months
  • Sessions — 30 days, or until you sign out

Your rights

Under UK GDPR you have the right to:

  • Ask what we hold about you, and get a copy
  • Have inaccurate information corrected
  • Have your data deleted, where we have no overriding reason to keep it
  • Object to processing we carry out under legitimate interests
  • Ask us to restrict processing while a dispute is resolved
  • Receive your data in a portable format

Email privacy@apaxon.co.uk. We will respond within one month. There is no charge, and you do not have to give a reason.

Cookies

Three of ours, and one from Google that only appears if you allow it.

  • apx_session — keeps you signed in. Expires after 30 days. Strictly necessary
  • apx_mfa — a short-lived cookie during two-factor sign-in. Expires after five minutes. Strictly necessary
  • apx_consent — records whether you accepted analytics, so we stop asking. It holds one word and nothing that identifies you. Expires after a year
  • _ga and _ga_* — Google Analytics, and only once you accept. They give a browser an identifier so a second visit is not counted as a second person. Expire after two years

Until you accept, Google Analytics runs without storage — it counts a page view and puts nothing on your device. Accepting turns the cookies on; declining leaves them off, and we do not ask again for a year.

We said for a long time that this site would never show a consent banner, and we meant it. Adding analytics is what changed it: under the UK rules a cookie that is not strictly necessary needs your permission before it is set. So there is now a banner, with two buttons of equal weight. Clearing the apx_consent cookie brings it back if you change your mind.

Changes to this policy

If we change anything material — a new supplier, a new category of data, a different purpose — we will update the date at the top and email account holders before it takes effect. We will not quietly broaden what we collect.

Complaints

If you think we have handled your data badly, please tell us first at privacy@apaxon.co.uk — most things are a misunderstanding we can fix quickly.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. You do not have to come to us first.

WPApaxon

Powerful WordPress tools.
One secure foundation.

WPApaxon is the platform. Apaxon Core is the free plugin it runs through.

Contact

Tell us what you need.

What is it about?

We use this to reply and nothing else. No list, no tracking.

Plugins

  • Apaxon Core
  • Apaxon CRM
  • Apaxon Menu
  • Apaxon CRM Pro
  • All plugins

Platform

  • Pricing
  • Security standard
  • Blog

Company

  • About
  • Contact
  • Sign in
  • Support

Legal

  • Terms of service
  • Privacy policy

© 2026 Apaxon. All rights reserved.

Terms·Privacy

WordPress is a trademark of the WordPress Foundation. Apaxon is not affiliated with it.

We would like to count which pages people find useful, using Google Analytics. It sets a cookie. Nothing here is used for advertising, and declining changes nothing about how the site works. What we store