1. Who we are
SteerWP is a WordPress management plugin suite operated by Websyy Tech Solution. When this policy says “we,” “us,” or “SteerWP,” it means Websyy Tech Solution acting as the operator of the SteerWP product and the steerwp.com website. For questions about this policy or the data we hold, write to us at privacy@steerwp.com.
2. What data we collect
We collect only what we need to run the product and support you.
Account and license data
- Your name, email address, and business details supplied at checkout or account creation
- License key, purchase history, and Freemius customer identifier
- Support conversations and any information you share when contacting us
Website usage data
- IP address, browser type, device information, and pages visited on steerwp.com
- Referral source, session duration, and click behavior collected through Google Analytics
- Contact form submissions on our website
Data from the SteerWP plugin
The plugin itself is installed on your servers. What it shares with us is described in section 6.
3. Why we use it
- Deliver the product, activate licenses, and provide the features you paid for
- Send you the license key, invoices, product updates, and important service notices
- Respond to your support requests and improve the product based on the issues we see
- Detect fraud, abuse, and license misuse
- Comply with our legal obligations, including tax and accounting requirements
We do not sell your personal data. We do not use your data for advertising to third parties.
4. Legal basis for processing
Where GDPR or a comparable law applies, we process your personal data under the following bases:
- Contract: processing needed to deliver the plugin, activate licenses, and provide support to paying customers.
- Legitimate interests: running the website, understanding how it is used, and protecting the product from abuse.
- Consent: for marketing emails and non-essential cookies, where you have opted in.
- Legal obligation: retaining tax records and responding to lawful requests from authorities.
5. Third parties we share data with
We share data only with the specific service providers we rely on to run SteerWP. Each of them has their own privacy policy and is contractually obligated to protect your data.
- Freemius: handles our checkout, license issuance, and billing. Freemius processes your payment details, name, email, and business information for tax and invoicing.
- Brevo (via WP Mail SMTP): delivers transactional email such as license keys, receipts, and password resets.
- Google Analytics and Google Tag Manager: measure how visitors use steerwp.com. Data is anonymized where possible.
- Our hosting provider: stores the website and database.
- Authorities, when legally required: we will disclose data only in response to a valid legal request and only to the extent required.
We do not sell, rent, or trade your personal data with any third party for marketing or advertising purposes.
6. Data handled by the SteerWP plugin
The SteerWP plugin runs on your own WordPress server and connects to client sites you manage. Most data processed by the plugin never touches our servers.
Data that stays on your servers
- Your list of client sites, client contact records, groups, and internal notes
- Backups you create (stored in your configured cloud storage, not ours)
- Proposals, e-signature records, and audit certificates
- Site health reports, activity logs, and stored documents
- Any content published through Content Composer
SteerWP is a self-hosted plugin. Your client data, backups, and proposals live on infrastructure you control. We do not have access to them.
Data the plugin sends to us
The plugin communicates with our systems only for the following, all handled through Freemius:
- License activation, deactivation, and validity checks
- Anonymous usage telemetry, if you have opted in during setup (you can opt out at any time from plugin settings)
- Version and update checks for the plugin and add-ons
Your role as a data controller
If you use SteerWP to manage sites belonging to your clients, you are the data controller for the personal data held on those sites. We act as a technical processor only for the limited license and telemetry data listed above. If your business is subject to GDPR, DPDP, or similar, you may need your own Data Processing Agreement with your clients. Contact us and we can provide a DPA covering the license-related processing on our end.
7. Cookies and analytics
Our website uses cookies for three purposes:
- Essential cookies that make the site work, such as session management and security. These do not require consent.
- Analytics cookies set by Google Analytics to help us understand how the site is used. Loaded only after you accept the cookie banner where required by law.
- Marketing cookies set by Google Tag Manager for conversion tracking. Loaded only with your consent.
You can withdraw consent at any time from the cookie banner or your browser settings. Blocking cookies may affect how some parts of the site behave.
8. How long we keep data
- Customer accounts and license records: for as long as your license is active, and afterwards as required by tax and accounting law (typically seven years).
- Support tickets and emails: three years after the last interaction.
- Website analytics: up to 26 months in Google Analytics.
- Marketing email lists: until you unsubscribe.
You can ask us to delete your data sooner where the law permits. See section 10.
9. How we protect data
We use industry-standard measures to protect the data we hold: TLS encryption in transit, encrypted storage at rest, restricted administrative access, and regular security reviews of our own website and infrastructure. Payments are handled entirely by Freemius, which is PCI-DSS compliant, and we never see or store full card details.
No system is perfectly secure. If a data incident affecting you does occur, we will notify you within the timeframes required by applicable law.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data, subject to our legal retention obligations
- Restrict or object to how we process your data
- Receive a copy of your data in a portable format
- Withdraw consent for anything you consented to previously
- Lodge a complaint with your data protection authority
To exercise any of these, email privacy@steerwp.com. We respond within 30 days, and sooner where the law requires it. We may need to verify your identity before we can act on a request.
11. Children
SteerWP is a professional business tool. It is not directed at children under 18, and we do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. International data transfers
Websyy Tech Solution operates from India. Some of our service providers (Freemius, Brevo, Google) process data in the United States, the European Union, and other jurisdictions. Where we transfer data across borders, we rely on the safeguards those providers use, such as Standard Contractual Clauses and equivalent mechanisms recognized under GDPR and DPDP.
13. Changes to this policy
We may update this policy from time to time as the product evolves or the law changes. When we do, we will update the “Last updated” date at the top of this page. Material changes will also be notified to active customers by email.
14. Contact us
For any question about this policy, the data we hold, or to exercise any of your rights:
Websyy Tech Solution
Operator of SteerWP
New Delhi, India
privacy@steerwp.com
See also our Terms of Service and Refund Policy.
privacy@steerwp.com →