BugShield Ltd (“BugShield”, “we”, “us”, or “our”) provides WordPress bug fixing, maintenance, monitoring, and secure credential storage services. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our website and platform.
1. Who we are
BugShield Ltd is the data controller responsible for your personal data. If you have questions about this policy or how we handle your information, contact us at [email protected] or via our contact page.
2. Information we collect
We may collect the following categories of information:
- Account information: name, email address, password (stored as a secure hash), and account preferences.
- Site information: WordPress domain names, site metadata, and details you provide about your websites.
- Fix request data: descriptions of issues, screenshots, chat messages with developers, and status history.
- Vault credentials: login details, FTP credentials, and other access information you choose to store in the Vault. These are encrypted and tied to your site, not your user account.
- Billing information: payment method details processed by our payment provider. We do not store full card numbers on our servers.
- Usage and technical data: IP address, browser type, device information, log files, and how you interact with our platform.
- Monitoring and activity data: for maintenance plan subscribers, we log site activity such as plugin updates, WordPress updates, backup events, and vault redemptions.
3. How we use your information
We use personal data to:
- Provide bug fixing, maintenance, monitoring, and backup services you request.
- Assign developers to your fix requests and enable communication during active work.
- Process payments for one-off fixes and subscription plans.
- Send service notifications, fix updates, and account-related communications.
- Maintain platform security, prevent fraud, and troubleshoot technical issues.
- Improve our services and develop new features.
- Comply with legal obligations and enforce our Terms of Use.
4. Vault and site credentials
Credentials stored in the Vault are encrypted when stored. Access is restricted to authorised BugShield developers working on your site, and every redemption is logged. Vault items belong to the site they are stored for, not to individual user accounts. We will never ask you to send passwords by email.
You are responsible for ensuring you have the right to share site credentials with us and for keeping your Vault entries up to date. You can delete vault items at any time through your account.
5. Legal basis for processing
Under UK GDPR, we process personal data on the following bases:
- Contract: to deliver the services you have signed up for.
- Legitimate interests: to operate and improve our platform, maintain security, and communicate with you about your account.
- Legal obligation: where we are required to retain or disclose information by law.
- Consent: where you have given explicit consent, such as for optional marketing communications.
6. Sharing your information
We do not sell your personal data. We may share information with:
- Service providers: payment processors, cloud hosting, email delivery, and backup storage partners who process data on our behalf under contract.
- Developers: assigned BugShield developers who need access to fix your site and communicate with you during an active request.
- Legal authorities: when required by law, court order, or to protect our rights and the safety of users.
All third-party processors are required to handle your data securely and only for the purposes we specify.
7. Data retention
We retain personal data for as long as your account is active or as needed to provide services. Fix request history and chat logs are kept so you have a record of completed work. Vault credentials are deleted when you remove them or when a site is removed from your account. Billing records are retained as required for tax and accounting purposes. You may request deletion of your account data subject to legal retention requirements.
8. Your rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data in certain circumstances.
- Object to or restrict processing in certain circumstances.
- Request portability of data you have provided to us.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise any of these rights, email [email protected]. We will respond within one month.
9. Cookies
We use essential cookies to keep you signed in and maintain session security on the BugShield platform. On our marketing website, we only use non-essential cookies if you accept them through our cookie banner.
Google Analytics. If you accept analytics cookies, we use Google Analytics
to collect anonymous usage data such as pages visited, time on site, and general traffic sources. Google Analytics
sets cookies including _ga and
_ga_*. We do not load Google Analytics unless you
click Accept on the cookie banner. You can reject analytics cookies and still use our website.
Your cookie preference is stored in a cookie called
bugshield_cookie_consent so we do not ask you on
every visit. You can also control cookies through your browser settings. Blocking essential cookies may prevent
you from using parts of the platform.
10. Security
We implement technical and organisational measures to protect your data, including encryption, access controls, secure development practices, and staff training. No method of transmission over the internet is completely secure, but we work continuously to safeguard your information. Learn more on our Security page.
11. International transfers
Your data is primarily processed within the United Kingdom and European Economic Area. If we transfer data outside the UK or EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
12. Children
BugShield is a business service and is not directed at children under 18. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we will notify you by email or through the platform where appropriate.
14. Contact us
For privacy-related enquiries, contact us at [email protected] or visit our contact page.
See also our Terms of Use.