Privacy policy
What we collect, why, who else sees it and how long it stays — for the website, the account portal and the plugin itself. Written to be read rather than to cover us: the list is short, and this page says exactly what is on it.
The short version
We hold your email address, what you bought, and which sites your licence key is installed on. That is close to the whole list.
- No advertising, no profiling, no data sold or shared for marketing. Ever.
- No marketing email. Every message we send is about something you bought or asked for.
- No tracking cookies. Site analytics are self-hosted and cookieless, and count visits rather than people.
- We never see your card details. They belong to the payment provider.
- The plugin sends us nothing about your content or your visitors. Only what a licence check needs.
The rest of this page is the detail: each thing we hold, why we hold it, who else sees it, and how long it stays.
Who we are
Syntaxion Limited, a company registered in England & Wales under number
12604886, is the data controller for everything described here. GutenFields is our product;
guten-fields.com is its website and
api.guten-fields.com is its licence server.
For anything about your data — a question, a correction, a deletion — email support@guten-fields.com.
Visiting this website
Analytics
We use Umami, self-hosted on our own
server at analytics.syntaxion.co.uk. It sets no cookies, stores no
identifiers on your device, and does not follow you between sites. What it records is
the page you viewed, the referrer, and coarse country, browser and device type —
which is enough to know that the pricing page is being read and the docs page is not.
Because it is self-hosted, that data goes to us and nowhere else. Because it is cookieless and holds no identifier, we cannot tie a visit to a person, and neither can anyone else.
Sign-in links are kept out of it
A sign-in link arrives as account.html#signin=…, and a naive
analytics tag would report the whole URL. Ours is told to strip the fragment on
every page that can carry a credential, so the token in your sign-in link is never
sent to the analytics server.
Server logs
The website is served by Vercel and the licence server runs on a hosted server of our own. Both keep ordinary request logs, which include IP addresses, for security and for working out what broke. We do not mine them, and they are kept only as long as that purpose needs.
Buying a licence
Checkout happens with our payment provider — Paddle, which is the merchant of record, or PayPal. Your card details are entered into their fields and never reach us. They collect what a payment and its tax treatment need, including your billing country, under their own privacy policies.
What comes back to us, and what we then store, is:
- your email address;
- the tier you bought and the date, which set your entitlement year;
- the provider's order reference, so a purchase can be matched to a payment and a refund to a purchase; and
- the licence key issued to you.
We keep an append-only log of what happened to each licence — issued, extended, refunded, activated — because a licence dispute is unanswerable without one.
Your account
The account portal has no passwords. You give an email address, we mail a one-time code, and you are signed in. So the account itself is: your email address, when it was created, and when it last signed in.
Sign-in codes and the links that carry them are stored hashed, and so are the session tokens your browser holds afterwards. That is deliberate: it means a copy of our database cannot be replayed into anybody's account.
We answer /v1/portal/login identically for an address we know, an address
we do not, and one that has asked too often. Otherwise the sign-in form would be a way
for anyone to find out who our customers are.
What the plugin sends
The free edition makes no network requests at all. The paid edition talks to our licence server on exactly three occasions: when you activate a site, on a daily entitlement re-check, and when WordPress checks for updates.
What it sends on those occasions is:
- the licence key;
- the site URL — we store it, and a hash of it, so the same site is recognised on the next call rather than counted twice;
- the environment type — production, staging or development — which is what keeps your non-production copies free; and
- on an update check, the plugin version you have, which is what the answer depends on.
That is the entire payload. As with any HTTP request, our server also sees the request's IP address and the user agent WordPress sends, which is how a web server works rather than something the plugin adds.
It sends nothing else. No post content, no field values, no user accounts, no visitor data, no usage telemetry. Field rendering and editing make no external requests whatsoever — a page built with GutenFields does not contact us when someone views it.
If the site you are activating belongs to a client, the site URL and environment are the only things about it that reach us. You can see and remove any activation from your account.
Email we send you
All of it is transactional: your licence key, sign-in codes, a receipt or refund confirmation, and the occasional notice about something that affects your licence. There is no newsletter and no marketing list, so there is nothing to unsubscribe from.
Delivery goes through a transactional email provider on our behalf. They handle the message and the address it is going to, and nothing else about you.
Why we are allowed to hold it
Under UK GDPR, each thing here rests on one of three grounds:
- Performing a contract — your email, purchase, licence key and activations. We cannot sell you a licence or deliver an update without them.
- A legal obligation — keeping records of a sale for tax purposes.
- Legitimate interests — security logs, rate limiting, the licence audit log, and cookieless analytics that count visits without identifying anyone. In each case we have weighed it against your privacy and kept the data minimal, which is why the analytics hold no identifier and the logs are not mined.
We do not rely on consent for any of it, because we do not do the things consent is needed for — no tracking, no profiling, no marketing email.
How long we keep it
- Licences, purchases and the audit log — for as long as the licence exists, and then as long as tax law requires records of the sale (currently six years).
- Activations — until you remove the site, or the licence is deleted.
- Sign-in codes — minutes. They expire, and are hashed in the meantime.
- Sessions — until they expire or you sign out.
- Analytics — aggregate counts, held indefinitely; they identify nobody.
- Server logs — a short rolling window, set by our hosts.
Your rights
Under UK GDPR you can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to what we do with it, or to have it sent to you in a portable form. Email support@guten-fields.com and we will answer within one month. There is no charge.
Two honest caveats. Deleting your account is straightforward and does not touch your licences — an account is a sign-in, a licence is a sale, and they are joined only by the email address. Deleting the purchase record is different: we have to keep enough of it to satisfy tax law and to answer a later dispute about the sale, so what we can do is remove everything not needed for that.
If you think we have got this wrong, please tell us first — but you are entitled to complain to the Information Commissioner's Office, the UK regulator, at any time.
Security
Everything travels over HTTPS. Sign-in codes, magic-link tokens and session tokens are stored hashed, never in the clear. Licence keys are HMAC-signed, so a key cannot be guessed or hand-written. The portal uses bearer tokens scoped to your own account, and an endpoint is explicitly either yours-only or admin-only rather than open by default.
No system is perfect. If we ever have a breach that puts your rights at risk, we will tell you and the ICO, as the law requires.
Changes to this policy
We will update this page when what we do changes — a new payment provider, a new thing the plugin sends. The date at the top is when it last changed. If a change is significant and we hold your email address, we will tell you rather than leaving you to notice.
Contact
Syntaxion Limited is the controller for the data described on this page.
- Registered in England & Wales, company number 12604886
- Registered office: Lytchett House, 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, England, BH16 6FA
- Email: support@guten-fields.com
- Company website: syntaxion.co.uk
- UK regulator: ico.org.uk
See also the terms of service and the refund policy.