New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Legal

Privacy Policy

Last updated: 23 August 2026

BugShield Ltd (“BugShield”, “we”, “us”, or “our”) provides WordPress bug fixing, maintenance, monitoring, and secure credential storage services. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our website and platform.

1. Who we are

BugShield Ltd is the data controller responsible for your personal data. If you have questions about this policy or how we handle your information, contact us at [email protected] or via our contact page.

2. Information we collect

We may collect the following categories of information:

  • Account information: name, email address, password (stored as a secure hash), and account preferences.
  • Newsletter information: your email address and consent when you choose to join our marketing mailing list.
  • Site information: WordPress domain names, site metadata, and details you provide about your websites.
  • Fix request data: descriptions of issues, screenshots, chat messages with developers, and status history.
  • Vault credentials: login details, FTP credentials, and other access information you choose to store in the Vault. These are encrypted and tied to your site, not your user account.
  • Billing information: payment method details processed by our payment provider. We do not store full card numbers on our servers.
  • Usage and technical data: IP address, browser type, device information, log files, and how you interact with our platform.
  • Monitoring and activity data: for maintenance plan subscribers, we log site activity such as plugin updates, WordPress updates, backup events, and vault redemptions.

3. How we use your information

We use personal data to:

  • Provide bug fixing, maintenance, monitoring, and backup services you request.
  • Assign developers to your fix requests and enable communication during active work.
  • Process payments for one-off fixes and subscription plans.
  • Send service notifications, fix updates, and account-related communications.
  • Send optional WordPress and BugShield marketing emails you have asked to receive.
  • Maintain platform security, prevent fraud, and troubleshoot technical issues.
  • Improve our services and develop new features.
  • Comply with legal obligations and enforce our Terms of Use.

4. Vault and site credentials

Credentials stored in the Vault are encrypted when stored. Access is restricted to authorised BugShield developers working on your site, and every redemption is logged. Vault items belong to the site they are stored for, not to individual user accounts. We will never ask you to send passwords by email.

You are responsible for ensuring you have the right to share site credentials with us and for keeping your Vault entries up to date. You can delete vault items at any time through your account.

5. Legal basis for processing

Under UK GDPR, we process personal data on the following bases:

  • Contract: to deliver the services you have signed up for.
  • Legitimate interests: to operate and improve our platform, maintain security, and communicate with you about your account.
  • Legal obligation: where we are required to retain or disclose information by law.
  • Consent: where you have given explicit consent, such as for optional marketing communications.

6. Sharing your information

We do not sell your personal data. We may share information with:

  • Service providers: payment processors, cloud hosting, backup storage partners, and EmailOctopus, which stores mailing-list details and sends optional marketing emails on our behalf.
  • Developers: assigned BugShield developers who need access to fix your site and communicate with you during an active request.
  • Legal authorities: when required by law, court order, or to protect our rights and the safety of users.

All third-party processors are required to handle your data securely and only for the purposes we specify.

7. Data retention

We retain personal data for as long as your account is active or as needed to provide services. Fix request history and chat logs are kept so you have a record of completed work. Vault credentials are deleted when you remove them or when a site is removed from your account. Billing records are retained as required for tax and accounting purposes. Newsletter details are retained until you unsubscribe or withdraw consent. You may request deletion of your account data subject to legal retention requirements.

8. Your rights

Under UK data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data in certain circumstances.
  • Object to or restrict processing in certain circumstances.
  • Request portability of data you have provided to us.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

To exercise any of these rights, email [email protected]. We will respond within one month.

9. Cookies

We use essential cookies to keep you signed in and maintain session security on the BugShield platform. On our marketing website we also load a small set of third-party tools, as described below.

Plausible Analytics. We use a self-hosted Plausible instance to understand aggregate traffic to our marketing site. Plausible is designed to be privacy-friendly and does not use cookies for analytics.

PostHog (session replay). We use PostHog's EU Cloud solely for session replay on our marketing site, so we can review how visitors interact with pages (clicks, scrolling, and navigation). Form inputs are masked by default. We do not use PostHog as our primary analytics product.

Crisp. We use Crisp to provide live chat support on the marketing site. Crisp may set cookies or use local storage so the chat widget can function.

Google Ads. We use the Google Ads tag to measure advertising campaign performance and conversions. Google may set cookies related to advertising measurement.

Meta (Facebook) Pixel. We use the Meta Pixel to measure advertising campaign performance and conversions from Meta ads. Meta may set cookies related to advertising measurement.

Google reCAPTCHA. On our contact form we use Google reCAPTCHA to help prevent spam. Google may set cookies as part of that service.

You can also control cookies through your browser settings. Blocking essential cookies may prevent you from using parts of the platform.

10. Security

We implement technical and organisational measures to protect your data, including encryption, access controls, secure development practices, and staff training. No method of transmission over the internet is completely secure, but we work continuously to safeguard your information. Learn more on our Security page.

11. International transfers

Your data is primarily processed within the United Kingdom and European Economic Area. If we transfer data outside the UK or EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

12. Children

BugShield is a business service and is not directed at children under 18. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we will notify you by email or through the platform where appropriate.

14. Contact us

For privacy-related enquiries, contact us at [email protected] or visit our contact page.

See also our Terms of Use.

Privacy FAQs

Questions about your data

Quick answers about the information we collect, how we protect it, and your privacy rights.

What personal information does BugShield collect?

Depending on how you use BugShield, we may collect account, website, fix request, Vault, billing, technical, monitoring, and newsletter information.

Does BugShield store my full card number?

No. Payments are handled by our payment provider, and BugShield does not store full card numbers on its servers.

How are credentials in the Password Vault protected?

Vault credentials are encrypted when stored. Access is limited to authorised developers working on your site, and every redemption is logged.

Does BugShield sell personal data?

No. We do not sell personal data. We only share information where needed with service providers, assigned developers, or legal authorities as described in this policy.

How long does BugShield keep my information?

We keep personal data while your account is active or for as long as it is needed to provide services and meet legal obligations. Retention periods vary by the type of information.

What data protection rights do I have?

Depending on the circumstances, you may ask to access, correct, delete, restrict, or transfer your data, object to certain processing, withdraw consent, or complain to the ICO.