PRIVACY · UPDATED 27 SEPTEMBER 2026

Your data.
Your business.

Store reports stay in your WordPress installation. Our purchase service handles licensing, payments and written requests. We do not use advertising trackers. Optional website measurement starts only after you accept it; you can reject or withdraw at any time.

Who is responsible?

View current operator and privacy details, including without JavaScript.

The company identified below operates OrderWorth and is the controller of personal data collected through this website and its licensing service. Your store operator controls the data processed inside its own WordPress installation.

Legal business name: A.M.E.X. Internet Marketing ltd

Business address: Makariou III, No.9, Larnaca, 7530, Cyprus

Country: Cyprus

Company registration: HE377934

VAT registration: 10377934Z

Privacy contact: [email protected]

Product support: [email protected]

For an email enquiry or privacy request, include “OrderWorth” in the subject.

What we use, and why

Data comes from you, your activated installation, the browser request and payment confirmations from Stripe. We do not buy personal data, sell it, or use it for advertising.

Purpose and information Legal basis
Deliver a purchase: plan, amount, currency, payment references and status, dates, accepted terms version and purchase identifier. Perform a contract with an individual purchaser, or our legitimate interest in supplying a business purchaser.
Provide updates and site slots: license term, purchase-key hash, site URL, installation-token hash, activation date, last authenticated check time and check result. Provide the purchased service; administer business licenses where relevant. Reporting in WordPress does not require update activation.
Written assistance: your request subject, message text, replies and timestamps. Provide requested contractual support, or our legitimate interest in answering business enquiries.
Privacy requests: request type, correspondence, received date, response target, status and any documented retention hold. Meet our data-protection obligations.
Protect the service: request IP address transiently, a keyed IP hash for rate limits, essential browser-recovery identifiers and operational request metadata. Our legitimate interest in preventing abuse and protecting purchases. Essential cookies support a service you request.
Accounting, disputes and refunds: necessary transaction records, dates and payment references. Applicable legal recordkeeping obligations and our legitimate interest in establishing or defending claims.
Optional website measurement: public page name, time/day, approximate country and a short-lived, pseudonymous visit identifier. No IP address is stored in analytics. Your consent, GDPR Article 6(1)(a). Rejecting does not limit browsing or purchases.
Staff workspace: name, email, password hash, role, access status, sessions, last activity, invitations and security activity. Optional authenticator secrets and recovery codes are encrypted. Our legitimate interest in securing and administering business operations. Staff provide these details to use their accounts.

Contract, legal-obligation and legitimate-interest grounds correspond to GDPR Article 6(1)(b), (c) and (f). Our interests are delivering a secure service, handling business enquiries and resolving disputes; you may object to processing based on legitimate interests.

You can browse and download Free without providing a name or email to this application. A purchase needs payment verification; update activation needs a site URL. Without those details we cannot supply the relevant service. Share only what your request needs. Do not send passwords, access keys, card details, special-category data or your customers’ order records.

License checks automatically compare payment status, term and site limits. They do not profile shoppers or determine store profitability, and installed reporting features are not remotely disabled. If access appears wrong, request a human review through written support. This application makes no solely automated decisions intended to have legal or similarly significant effects on individuals.

Payments, providers and international transfers

We use the country supplied by our hosting service, or your browser’s language-region setting, to suggest USD, EUR, GBP, CAD or AUD. You can override this. We do not store the detected country for pricing. Separately, optional website measurement records an approximate country only after consent. The only saved display preference is the currency you explicitly choose in this browser. USD, EUR, GBP, CAD and AUD prices are set independently. Displaying prices does not require contacting an exchange-rate service.

Stripe handles payment credentials on its own website. We do not receive your card number or payment password. Stripe collects the billing details needed to process the payment, such as a billing address and email. This application stores payment references, amounts, currency, included tax and the accepted pricing revision, and the billing email needed to associate a purchase with its customer record. This email is not treated as verified account ownership. It does not copy payer names or billing addresses from those responses. Historic PayPal transactions, if any, retain their original provider records. Older purchases may also retain the exchange-rate details used at the time. Stripe controls its own payment processing; see its privacy statement.

Our public website, private administration, purchases, licences and support run on our GoDaddy VPS in the United States. OpenAI Sites and Cloudflare retain the older plugin service address as a forwarding service to this shared backend, together with historical records from before migration. Hosting and authentication services process request metadata to deliver and protect these services. Google Workspace handles our support mailbox.

A.M.E.X. Internet Marketing ltd operates OrderWorth from Cyprus. GoDaddy hosts our website, shared private administration, purchases, customer records, licences and support messages on our US VPS. OpenAI Sites and Cloudflare retain the older plugin service address as a forwarding service to this shared backend, along with historical records from before migration. Cloudflare also provides delivery and security. Stripe handles hosted payments, billing details and automatic tax. Google Workspace handles our support mailbox and email correspondence. Authorised staff and necessary professional advisers receive information only for their work. Purchase messages appear in My purchase. Google Workspace also delivers purchase and manual-renewal confirmations to the billing email supplied at checkout. Purchases do not subscribe you to marketing.

International transfers: Our GoDaddy VPS is in the United States. OpenAI, Cloudflare, Stripe and Google operate internationally; processing is not restricted to Cyprus or the EEA. Their applicable data-processing terms describe safeguards for covered transfers, including the European Commission’s standard contractual clauses and, where the recipient and processing qualify, an adequacy decision. The EU–US Data Privacy Framework covers participating organisations and covered processing, not every US service. Contact [email protected] for information about the safeguards applicable to your data or a copy. Provider terms and scope must be reviewed when the service or recipient changes.

Provider information: GoDaddy privacy, Cloudflare processing terms, OpenAI processing terms, Stripe processing terms, and Google Workspace processing terms.

Necessary records may also be shared with authorised professional advisers or competent authorities when required by law or needed for a legal claim. We limit disclosure to the purpose concerned.

How long data is kept

  • Checkout recovery: the browser cookie lasts up to 24 hours from issue or refresh. Server recovery for each order expires 24 hours after that order starts. Closing recovery invalidates its browser link sooner.
  • Written support: closed requests are eligible for deletion 730 days after their last activity.
  • Privacy requests: closed requests are eligible for deletion 1,095 days after their last activity, to document how the request was handled. These are our policy periods, not universal GDPR deadlines.
  • Open requests and holds: kept while needed for resolution or a documented legal claim. Holds require a reason and must be reviewed; they are not permission to retain data indefinitely.
  • License and payment records: kept while needed to provide access and for the applicable accounting, refund and claims periods. Activated site URLs can be removed in My purchase.

Authorised staff initiate deletion of eligible correspondence, expired browser associations and rate-limit records. This does not automatically erase financial records, provider logs, backups or data inside your WordPress store.

Financial and license retention: Paid purchase and licence records are retained while needed to provide purchased access, reconcile payments, handle refunds or disputes, and meet applicable accounting and legal obligations. The owner reviews these purposes at least monthly and deletes or anonymises records when they no longer apply. An open claim or legal hold must have a recorded reason and a next review date. Removing a site slot removes its active registration; it does not erase the purchase or the payment provider’s records. Ask [email protected] about the period and basis applicable to a particular record.

The owner reviews records at least monthly. Closed purchase-support messages become eligible for deletion after 730 days and closed privacy requests after 1,095 days, unless a documented open matter or hold applies. Cleanup is an explicit authorised action, not an automatic deletion promise. VPS access logging for OrderWorth is disabled; error logs rotate daily with 14 retained rotations. Mailbox correspondence, exports and other operational records are reviewed against the same continuing support, security, dispute and legal needs. Local and provider recovery copies rotate separately; deleting a live record does not erase existing backups immediately. Backups are restricted to recovery, and erasure or restriction decisions must be reapplied before restoring service. We do not claim a fixed maximum age for every provider or backup copy. Encrypted VPS recovery copies cover native purchase, licence, customer and support records and their service credentials. Historical Sites-managed data outside the migrated commerce export, Sites runtime secrets and TLS private keys are excluded. Restore verification is recorded in our private administration. Starting the service on a replacement server has not yet been tested.

Optional visitor measurement

When enabled by the operator, our first-party measurement counts visits and page views on public product and help pages. It excludes checkout, My purchase, staff pages and API URLs. The browser sends only a permitted page name, a random visit identifier and a random event identifier after acceptance. The service adds the date and approximate country supplied by the hosting network. It does not store a full URL, query string, referral URL, IP address, precise location, name or email in analytics.

A visit is a 30-minute session in one browser tab, not a unique person. Another tab or later visit can be counted again. Common bots and staff cookies are filtered where detected; coverage is incomplete and automated traffic can still appear. VPNs and proxies may affect the country. These statistics are not used to change individual prices, profile shoppers or track activity across other websites.

The choice is remembered for 180 days, whether accepted or rejected. A visit identifier expires after 30 minutes or when its tab closes. Server event identifiers become eligible for cleanup after 24 hours; daily country/page totals cover 90 days. Cleanup runs in bounded batches during measurement and report requests; an inactive service does not run a background cleanup job. Expired records are excluded from reports. Authorised staff can delete visitor statistics; deletion requires the service to run or staff to initiate cleanup. Aggregated totals cannot reliably be linked back to a named person.

Measurement remains off until controller and privacy-contact details are configured and the operator has reviewed these disclosures. Accepting analytics does not consent to marketing. Change your measurement choice.

Staff accounts and access

The staff workspace uses invitation-only email/password accounts. The owner grants roles and can revoke access. Passwords are hashed; optional TOTP authenticator secrets and recovery codes are encrypted using a server-held secret. Sessions use Secure, HttpOnly, SameSite cookies and expire after eight hours. The application does not save staff IP addresses or user-agent strings in its session table. Hosting services may separately process request metadata.

Invitation links last 48 hours and are bound to the invited email address. Recovery links last 30 minutes and do not remove an enabled authenticator. Invitation and recovery links are shared privately and are not automatically emailed. Names and emails identify staff within the workspace and are not made public by the application. Last activity and security events are visible to the owner. Price changes also have a separate revision history.

Expired sessions and verification records are eligible for deletion once expired. Invitations are eligible 30 days after expiry, and security activity after 365 days. Authorised staff initiate cleanup; eligibility does not mean immediate deletion. Revocation disables access immediately; it does not by itself erase the account or its audit history. A revoked staff account can be deleted after reviewing retention needs; credentials, factors and sessions are removed, while security and price history retain the account identifier. Staff can contact the privacy address above to exercise their rights. Retention of price and security records must remain proportionate to operational and legal needs.

Your choices and rights

You may request access, correction, erasure, restriction, portability where applicable, or object to processing based on legitimate interests. If processing relies on consent, you can withdraw that consent without affecting earlier lawful processing. Use Privacy choices to accept, reject or withdraw optional website measurement. Withdrawal stops future collection and removes the visit identifier from this browser. Your browser’s Global Privacy Control or Do Not Track signal also disables measurement. We do not use marketing trackers.

Open My purchase → Privacy & your data to download a JSON copy of the application records linked to that purchase or send a privacy request. These tools are free and remain available after the paid update term expires or is suspended. The export excludes security credentials and does not include provider logs, email correspondence or local WordPress records. Request a complete access review if you need data beyond the export. A purchase can be linked to several people; we protect others’ information when answering individual requests.

You do not need to buy Pro, renew it, have an access key, make a phone call or use this form to exercise your rights. Email the privacy contact above if you are a visitor, use Free, lost your key, or prefer email. We may ask for proportionate verification where there are reasonable doubts about identity; do not send identity documents unless needed and requested through a secure route.

We respond without undue delay and normally within one month. A permitted extension of up to two further months for complexity or number of requests must be explained within the first month. If we cannot grant a request, we explain why and how to challenge it. Some records may have to be kept for a legal obligation or claim; erasure does not automatically cancel a purchase.

Replies to requests made in My purchase appear there; no email notification is sent. Check the request thread for updates, or use email if you need a different written channel.

You may complain to the supervisory authority where you live, work or believe an infringement occurred. Find your authority in the EDPB directory. You do not have to contact us first.

Your WordPress store

Optional Local progress records daily workflow counts in the signed-in manager’s WordPress user profile, only after that person enables it. Counts cover report completion, saved reviews and selected workflow links; they contain no order IDs, costs or customer contact fields. The view and requested CSV export show up to 90 days. Older stored counters are pruned on the next recorded event or when cleared. Turning recording off clears counts; contextual-suggestion dismissals remain separate. No counts are transmitted to OrderWorth or a tracking provider.

Free makes no external API or telemetry calls. Calculations and order reviews run on your WordPress server. Report payloads and CSV exports exclude customer names, emails and addresses. Order IDs and staff user IDs can still identify people when combined with other store records: these reports are not guaranteed anonymous. Your store controls this local data and its retention, including exports, backups and mail providers. Installing OrderWorth does not make a store GDPR compliant.

The plugin stores your expense assumptions, manual review values, and the reviewing WordPress user ID and time. Scan ID lists belong to the requesting user and expire after one hour. Deactivation and uninstall preserve settings and review records.

Pro background reports store the requesting manager’s user ID, selected internal order IDs during processing, financial report rows, dates, progress and aggregates locally. Processing expires after 24 hours. New reports expire after seven days by default; a manager can select 30, 90 or 365 days and a maximum of 12, 24 or 60 retained reports. Existing expiry dates are unchanged. Cleanup runs through WordPress. An owner may grant up to 25 signed-in accounts read-only access to one completed revision; stored grants identify those accounts and are checked on every view/download. Grants expire with the report or can be revoked. Sharing sends no email. Deactivation pauses manual work; local records remain.

Stripe and PayPal fee assistance reads locally stored gateway metadata and makes no provider request. Reviewed CSVs can supply product costs, payment fees and shipping/fulfilment expenses. Files contain internal IDs, costs and non-personal references; avoid uploading customer contact details. Previews and results are private to their owner. Imported source files are read from PHP temporary upload storage and are not retained as public files. Payment-fee and shipping/fulfilment previews and guarded undo expire after one hour; bulk product-cost work and undo expire after 24 hours.

Optional tutorial progress

Inside WordPress, Quickstart stores your reading status and lesson progress for your WordPress user. Separate local records hold the latest completed report date, date ranges, order counts and currency, plus the latest reviewed order ID and change signature. These checks help you resume; reading a lesson does not certify your store data. Replay resets reading progress only. These records stay in WordPress and are preserved on uninstall. See the named data records and removal reference. The public website guide does not save reading progress.

Imports, presets and scheduled summaries

Free cost-import previews are private to the importing WordPress account, contain product identifiers and costs, and expire after 24 hours. Undo checks that an imported cost has not changed. Product stamps and the user’s last-import reference remain; imports do not rewrite existing order costs.

Pro keeps up to 10 personal date presets and the latest 10 original aggregate summaries in WordPress. Its separate Scheduled reports & alerts workflow supports independent daily, weekly and monthly report packs. Schedules and email start off. Action Scheduler or WP-Cron runs work locally; your host scheduler must be operating.

If you enable summary or report-notice email, the schedule owner’s current WordPress profile email address and financial figures or alert details pass through your store’s mail service. Scheduled report notices contain an authenticated link, no report attachment or customer contact fields. These emails are not sent through OrderWorth’s license service. Turn email off to stop notices or pause the relevant schedule to cancel its pending work. Deactivation disables scheduled work; re-enable explicitly after reactivation. Mail acceptance does not prove inbox delivery.

Optional WooPayments fee lookup

With official WooPayments 11.1.0 installed, you may explicitly confirm a lookup in Bulk payment fees. The selected order’s saved payment-intent ID is sent through WooPayments’ authenticated merchant client to its existing payment service to retrieve transaction details for fee verification. No lookup happens just by viewing a page, collecting a report, importing a CSV or running scheduled work. The request does not charge, refund, enrol or change gateway settings. Stop requesting lookups to stop future requests.

OrderWorth retains only the reduced amount, currency, time and provenance needed for the review; it does not retain provider secrets or customer contact details from the response. Applying the fee requires separate confirmation. The payment provider handles its existing transaction records under its own terms. See WooPayments service documentation and Automattic’s privacy policy.

Pro workflow records and retention

Pro’s private Review queue retains up to 100 findings per owner, their report/revision reference, dates, status, reason and latest 10 changes. Period review retains up to 30 frozen-report checklists and notes per owner. These records remain until removed; the source report keeps its original access and expiry rules. Do not enter customer contact information into notes. Scenarios run in your browser and do not save or transmit assumptions or alter store records.

ShipStation preparation handles the supplied shipment file locally on your WordPress server, with no provider request. The raw file is discarded after preparation; the private expense preview retains normalized order IDs, amounts and a hashed source reference for one hour. Applied costs and source references follow order retention. This does not change the existing retention of merchant exports, logs or backups.

Supplier mappings and saved filter definitions belong to their WordPress user, with up to 20 of each. Background imports keep progress, product identities, costs and undo provenance for 24 hours; up to five recent jobs can be reopened. Multiple schedules store owner IDs, cadence, filter choices, alert thresholds and separate email preferences. Up to eight schedules per owner and 32 per site are supported. Pausing stops future work; report expiry still applies. Existing date presets and the original latest-ten summary history remain separate.

Cost history records observed changes with the WordPress actor, time, source, reason and before/after values. Defaults are 730 days / 100,000 records; administrators may choose 30–3,650 days / 1,000–250,000 records, with gradual hourly cleanup. Future-cost records retain owner/product IDs, cost components and confirmation details, expiring after their effective date plus the retention duration selected at confirmation. Historical changes are not reconstructed.

The optional local calculation index retains financial rows and validation signatures, bounded at 100,000 rows / 256 MiB, with 7-, 30- or 90-day expiry. Turning it off stops new reuse; stored rows follow their expiry. Frozen completed reports keep their original expiry. Deactivation and uninstall preserve settings, reviews and retained records. Downloaded reports, backups and mail copies follow your own organisation’s retention and access controls.

Pro historical exchange rates

Pro queues historical-rate requests for foreign orders and requested backfills through your WordPress background scheduler. Frankfurter receives the currency pair and historical date range over HTTPS. The request does not include your order ID, customer details, costs, purchase key or installation token. Like any contacted server, the provider receives the connection from your server; review Frankfurter’s service information for its current handling.

WordPress stores the locked order rate, its source and effective date, shared rate caches, retry records and backfill progress. Where configured by an integration, it also records payment-fee amounts and currencies locally. Opening a report does not fetch new rates. Valid historical snapshots are preserved. These plugin requests are separate from this website’s independently fixed USD, EUR, GBP, CAD and AUD purchase prices.

Pro activation and updates

When you choose to activate update access, Pro sends your purchase key, site URL and plugin version to the OrderWorth service. It stores an installation token in WordPress instead of the full purchase key. Subsequent update checks send that token, site URL and version. A site slot stores the URL, token hash, activation time, last authenticated check time and the result (active, expired or suspended). The timestamp is not evidence that a store is online. Historical installations have no last-check time until they contact the updated service.

No order data, customer details, product costs or report totals are sent to the license service. License requests do not determine whether the locally installed reporting features can run.

Security and changes

Purchase access is protected by a private bearer key. Keep it secret: it opens downloads, site slots and correspondence for that purchase. We store key and installation-token hashes; the service can reproduce purchase keys for authorised delivery and recovery. Keys stay in page memory unless you choose to copy or save them. Use a private device for exports and receipts.

We use HTTPS, role-restricted staff management, server-side authorisation, request limits and output escaping. No system can guarantee zero risk. We update this notice when the service changes and provide information before new uses require it. Policy version: 2026-09-28.4.

Plugin suggestion preferences

Inside your own WordPress administration, Free uses browser session storage to limit contextual suggestions to one per tab session, scoped to the site and signed-in account. Continuing a Free workflow hides its card for that session. Persistent dismissal is saved in your WordPress user preferences. These choices are not sent to OrderWorth.