Who We Are
EDGE22 Studios Ltd. provides the GeneratePress WordPress themes and plugins and operates this website. EDGE22 Studios Ltd. is a corporation registered in Alberta, Canada, and is the data controller responsible for your personal information.
We handle personal information in accordance with applicable privacy laws, including Alberta’s Personal Information Protection Act (PIPA), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union’s General Data Protection Regulation (EU GDPR) and the United Kingdom General Data Protection Regulation (UK GDPR), where applicable.
Payment processing is provided by our payment partners, Stripe and PayPal. For any privacy-related questions, you can reach us at support@generatepress.com.
Who We Share Your Data With
We do not sell our users’ private personal information.
We use service providers and other third parties across our site. Their privacy roles depend on the service they provide. We identify the principal third parties in use, with links to their privacy policies, in the sections below.
We disclose potentially personally-identifying and personally-identifying information only to team members, contractors, and service providers that need the information to process it on our behalf or provide their services and that are subject to appropriate confidentiality and data-protection obligations. Some of these recipients may be located outside your home country. Where required, we use contractual or other legally recognized safeguards for international transfers. We will not rent or sell potentially personally-identifying or personally-identifying information to anyone.
If you consent to affiliate tracking, limited visit and referral information may also be available to the affiliate who referred you, as described in the Affiliates section below.
We may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
If we ever were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we would provide you with an opt-out choice to limit the use and disclosure of your personal data.
Cookies
A cookie is a small amount of information stored on a visitor’s device and returned to a website on later requests. We use cookies and similar technologies for necessary functions such as security, fraud prevention, account access, checkout, and remembering preferences. We also use optional technologies in the limited circumstances described below.
Where we offer a consent control, you can accept or decline the optional technology and change your choice later through the corresponding settings control. We use a preference cookie to remember the choice you make so that we do not repeatedly ask you. You can also manage cookies through your browser, although blocking necessary cookies may prevent some features from functioning correctly.
What Personal Data We Collect And Why We Collect It
Registered Users
If you create an account on our site, you will be prompted to select a Username and provide your Email Address. When choosing a Username, we strongly advise you not use or include your real name. Usernames cannot be changed.
Your Username and Email Address are stored in the website’s database. Your Email Address is used to send you an email with a link to set your password or to send you an email with a link to reset your password in the event you forget your password.
An anonymized string created from your email address (also called a hash) is provided to the Gravatar service to see if a Profile picture of you is available for display. The Gravatar service privacy policy is available here: https://automattic.com/privacy.
You may optionally complete your Profile by providing your First Name, Last Name, Website (URL) and/or Biographical info. These additional details are also saved in the website’s database. You may edit these details, and your Email Address, in your Profile at any time. You may also choose how your name is displayed (your Display Name) to visitors to the site (e.g. in comments you create) in your Profile.
Your Username, First Name, Last Name and Email Address are accessible by our team on the site.
If you attempt to log in to our site, we will set a temporary cookie to determine if your browser accepts cookies at all. This cookie contains no personal data and is discarded when you close your browser.
If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
For users that register on our site, we also store the data they provide in their profile indefinitely. All registered users can see, change or delete most of that data at any time except their login name/nickname.
Publishing Content (Comments, Pages, Posts, Forums)
Your Profile Picture (Gravatar), Display Name, Website (URL) (if any) and Biographical Info (if any) may be visible to visitors to the website (e.g. if you leave a comment, forum post, or contribute an article/post).
If you author an article/post, your Username, User ID, Profile Picture (Gravatar), Display Name, Website (URL) (if any) and Biographical Info (if any) are provided to any visitor using the website’s REST API interface.
If you upload media (e.g. images) to the website (in forums, posts, or comments), you should avoid uploading images with EXIF GPS location data included. Visitors to the website can download and extract any location data included in images on the website. Visitors using the website’s REST API interface can correlate uploaded media to a particular user. This may allow such visitors to map a user to a particular time and location if EXIF GPS location data was included in the uploaded media.
If you edit or publish an article/post, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
When visitors leave comments on one of our sites we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
Comments may require manual approval by one of our team members or site owners. If you leave a comment on a site you may opt-in to saving your name, email address and website in cookies so we can recognise you as a commenter. These cookies will persist for one year.
Additional spam detection is provided by Automattic/Akismet. The Automattic privacy policy is available here: https://automattic.com/privacy/.
Published content and comments are stored indefinitely unless deletion/removal is requested by the original author.
All forum posts and replies are public. When you create a topic or a reply, we collect your logged in account data, and the IP address where the post came from. The IP address is only visible to our support staff. You can edit or delete your existing posts/topics at any time.
Email/Contact Forms
We use Google Workspace to process all internal email and communication with our customers. Google’s privacy policy is available here: https://policies.google.com/privacy.
Customers that email us, or use any of the contact forms on our websites, will have their email address, IP address, and any data provided in the contact form or body of the email stored in Google Workspace archives and in our help desk third-party service provider, Help Scout. The Help Scout privacy policy is found here: https://www.helpscout.com/company/legal/privacy/.
Embedded Content From Other Websites
Embeds are pieces from other websites that are shown from time to time on our websites. They behave in the exact same way as if the visitor has visited the other website and may use cookies or capture information. Typically embedded content is from websites that share videos, images, or other content. These services may collect your IP Address, your User Agent, store and retrieve cookies on your browser, embed additional third-party tracking, and monitor your interaction with that embedded content, including correlating your interaction with the content with your account with that service, if you are logged in to that service.
Links to the privacy policies of the most common services have been included below.
Analytics
We want to process as little personal information as possible when you use our website. That’s why we’ve chosen Fathom Analytics for our website analytics, which doesn’t use cookies and complies with the GDPR, ePrivacy (including PECR), and CCPA. Using this privacy-friendly website analytics software, your IP address is only briefly processed, and we (running this website) have no way of identifying you. As per the CCPA, your personal information is de-identified. You can read more about this on Fathom Analytics‘ website.
The purpose of us using this software is to understand our website traffic in the most privacy-friendly way possible so that we can continually improve our website and business. The lawful basis as per the GDPR is “Article 6(1)(f); where our legitimate interests are to improve our website and business continually.” As per the explanation, no personal data is stored over time.
Marketing Campaigns
We use email marketing to communicate with customers and potential customers from time to time. All email lists and campaigns are “opt-in” meaning we will not send you these sorts of emails unless you indicated that you wish to receive them during signup or other interactions on our website.
We may send you “system” emails, such as password reset requests or payment notifications/receipts even if you have not opted-in to email marketing lists.
All marketing emails sent by us will include an unsubscribe link in the footer of the email. Emails sent to you may also include standard tracking, including open and click activities.
We manage our email lists and newsletters using FluentCRM, a self-hosted system that stores subscriber data within our own systems rather than transferring it to a third-party email marketing provider.
While our subscriber list is stored within our own systems, the delivery of our emails is handled by Amazon Simple Email Service (Amazon SES), provided by Amazon Web Services (AWS). To send email to you, your email address is processed by Amazon SES. The AWS privacy notice can be found here: https://aws.amazon.com/privacy/.
We may utilize social media and web advertising campaigns. These service providers use cookies on our sites and/or pixel tracking to serve ads across the different platforms. Google: https://policies.google.com/privacy X (Twitter): https://x.com/en/privacy Facebook: https://www.facebook.com/about/privacy/
If we activate advertising cookies or pixels that require consent, we will provide the required notice and choice before using them.
Paying Customers
For payment transactions, we use Stripe and PayPal. Your payment is processed by EDGE22 Studios Ltd. through these providers. Stripe’s privacy policy can be found here: https://stripe.com/privacy. PayPal’s privacy policy can be found here: https://www.paypal.com/webapps/mpp/ua/privacy-full.
We load Stripe.js across our website, not only at checkout, to help Stripe and us secure our payment services, detect and prevent fraud, and reduce unauthorized transactions and chargebacks. Stripe may process information such as your IP address, device and browser characteristics, transactional information, and activity signals, including through cookies and similar technologies. Stripe identifies m, __stripe_mid, and __stripe_sid among the cookies it may use for fraud prevention. The exact cookies and their duration depend on the Stripe services and configuration in use. You can learn more in Stripe’s Privacy Center and Cookie Policy. We use this processing for payment security and fraud and loss prevention.
In the checkout, we ask for:
- Email Address: So we can deliver our products and contact you if needed.
- First Name: To personalize your account experience.
- Username: So you can log in to your account to ask questions or download our products.
- Billing Country: For tax purposes.
- Billing Province: If you live in Canada, we need to know which province you live in for tax purposes.
- Credit Card Information: So we can process your payment. This data is sent to Stripe, and is never stored on our server.
- Zip/Postal Code: To verify your credit card purchase.
You’re also asked if you’d like to receive email updates and news. If you check this box, your information will be added to our newsletter list, which we manage in FluentCRM.
Web Services
Our website hosting is provided by Rocket.net (operated by onRocket.com, LLC). This includes website hosting, backups, databases, file storage, and related infrastructure. Rocket.net’s privacy policy can be found here: https://rocket.net/privacy-policy/
Our website traffic is served and proxied through Cloudflare’s global network. Cloudflare’s privacy policy can be found here: https://www.cloudflare.com/privacypolicy/
License Keys and Automatic Updates
When you add your license key to your Dashboard to receive automatic updates, your website URL and computer IP address are logged in our license key system. If you do not wish to be in our license key system, you can simply manually update GP Premium.
Affiliates
If you come to our site through a valid affiliate referral link, we ask whether you agree to optional affiliate tracking. Unless and until you select “Accept affiliate cookies,” AffiliateWP does not set affiliate tracking cookies or record an AffiliateWP visit or referral attribution as a result of that link. Declining does not affect your ability to use our website or the price you pay.
We use the following first-party cookies for this feature:
gp_affiliate_consentremembers whether you accepted or declined affiliate cookies for 180 days. It is set after you make either choice and is used only to remember that preference.affwp_refidentifies the referring affiliate for 30 days after you accept.affwp_ref_visit_idconnects your browser to the recorded affiliate visit for 30 days after you accept.affwp_campaign, when applicable, remembers an optional affiliate campaign identifier for 30 days after you accept.
If you accept, we record the referring affiliate, the landing-page URL, the referring URL, an optional campaign identifier, your IP address, and the visit date and time. If the visit results in a purchase, we connect the visit to the resulting referral, order, and commission. We use this information to attribute referrals, administer commissions, prevent and investigate fraud, audit the affiliate program, and resolve disputes.
The referring affiliate may see limited program information, including landing and referring URLs, visit and referral dates, conversion status, purchased product descriptions, commission amounts and statuses, and an order reference. We do not provide the affiliate with your name, email address, billing information, or payment details through the Affiliate Area.
For EU and UK visitors, we rely on your consent for optional affiliate tracking. If a tracked purchase occurs, we may also process the resulting referral and transaction records as necessary for our legitimate interests in administering the affiliate program, preventing fraud, and resolving disputes, and to meet applicable accounting, tax, and other legal obligations.
You can change your choice at any time through the “Affiliate cookie settings” control. Changing your choice to decline removes the affiliate tracking cookies and stops future AffiliateWP tracking and attribution. Withdrawal does not affect the lawfulness of processing completed before withdrawal, and records associated with completed purchases or commissions may still be retained where necessary for accounting, fraud prevention, dispute resolution, or legal compliance.
We retain affiliate visit and referral records only for as long as reasonably necessary for those purposes. Records connected to completed purchases and commission payments may be retained for the applicable accounting and tax record-retention periods. When records are no longer required, they are deleted or de-identified unless they must be preserved for a legal claim or other legal requirement.
What Rights You Have Over Your Data
If you are a registered user or have left comments on our site you can request to see or download the data we have about you.
Typically for visitors that have left comments, the data will be their email address, any IP addresses assigned to them at the time of leaving the comments and the user agent strings of the browsers they used. The rest of the data is public as published by the visitors.
For registered users or paying customers, this will also include profile information and download/payment histories.
You can also request “to be forgotten” and we will erase any personally identifiable data we have about you. Of course, this excludes data we need for administrative or security purposes or if we are required by law to retain some of the data.
You may edit or delete any post or topic you make in our support forums at any time.
An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his/her query to support@generatepress.com.
How We Protect Your Data
The security and reliability of our service is our number one priority.
See wordpress.org/about/security for details on the security of the WordPress core itself.
Prevention is best when it comes to security, and as a first step, we follow all WordPress Code Standards in the plugins that we build and use.
All team members only have access to systems that are directly required to complete the functions of their job.
All team members (including any contractors) undergo initial training to ensure proper understanding of all security-related processes.
What Data Breach Procedures We Have In Place
Should any event occur where customer data has been lost, stolen, or potentially compromised, our policy is to alert affected customers by email without undue delay after our team becomes aware of the event. We will also report such incident to any required data protection authority as required by applicable law. We will work closely with any customers affected to determine next steps such as any end-user notifications, needed patches, and how to avoid any similar event in the future.
Privacy Policy Changes
Although most changes are likely to be minor, EDGE22 Studios Ltd. may change this Privacy Policy from time to time, and in EDGE22 Studios Ltd.’s sole discretion.
Changelog
August 2026 – Added disclosures for optional affiliate tracking and consent preferences, corrected the affiliate cookie lifetime to 30 days, explained limited information made available to referring affiliates, added Stripe fraud-prevention disclosures, and added Alberta’s PIPA.
June 2026 – Updated entity references to reflect that EDGE22 Studios Ltd. (Alberta, Canada) is the owner of the products and the data controller. Updated hosting provider to Rocket.net, confirmed analytics as Fathom Analytics, and updated email marketing to FluentCRM.
December 2024 – Updated entity references and payment processing relationship.
June 29, 2023 – Removed Google Analytics
May 21, 2018 – Updated language of the policy to be more user-friendly, specifically outlining requirements in preparation for meeting the GDPR.