Privacy Policy

Who We Are and What This Policy Covers

Hello there! We’re the team behind a wide range of products and services designed to empower everyone—from bloggers and photographers to small business owners and large enterprises—to harness the open web. Our mission is to democratize publishing and commerce, ensuring that every story gets told and every great idea has a chance to thrive. We proudly support the open internet with open source code, much of which is released under the General Public License (GPL). Since our source code is freely available, you’re welcome to review it and see exactly how our systems work.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Visitor comments may be checked through an automated spam detection service.

Your Privacy Matters Immensely to Us

At Iris Secure Technology Solutions, we adhere to a set of core principles:

Thoughtfulness: We carefully choose which personal details to request and collect as our services operate.

User Control: We strive to make it simple for you to manage what information on your site is public, indexed by search engines, or permanently deleted.

Data Minimization: We retain your personal data only as long as there is a legitimate need.

Protection: We work to shield you from excessive governmental requests for your personal data.

Transparency: We are committed to complete openness regarding how we collect, use, and share your information.

Below is our detailed Privacy Policy, which expands upon these principles.

This policy applies to the data we collect about you when you use:

Our Mobile Applications: For example, the WordPress mobile app for Android and iOS.

Our Other Offerings: This includes products, services, and features provided by Iris Secure Technology Solutions through our websites (such as WordPress.com plans, payment options, the Pay with PayPal feature, Jetpack, Woo Shipping, Woo Tax, Gravatar, the IntenseDebate comment system, Akismet plans, Simplenote, Simperium, Cloudup, Longreads, MailPoet, AutomateWoo, Jetpack CRM, Happy Tools, WordPress.com Courses, WPScan, and Newspack).

Third-Party Sites: Any websites that use our services while you’re logged into your account with us.

Information You Provide Directly

This policy also covers data collected when you apply for a job at Iris Secure Technology Solutions or one of our subsidiaries.

Throughout this document, “Services” refers collectively to our websites, mobile apps, and other offerings. For further details about which Iris Secure Technology Solutions entity manages your data, please refer to the section on Controllers and Responsible Companies.

Note: This Privacy Policy does not apply to products or services (such as Tumblr) that have separate policies.

How We Collect, Use, and Share Your Information
Below, we outline the methods we use to gather, utilize, and disclose your information, along with the options available to you.

We collect the information you choose to share with us. For example:

Basic Account Details: To register an account (e.g., on WordPress.com), you must provide an email address, a password, and a username or full name. Additional details (like your physical address) are optional.

Public Profile Data: When you create a profile, information such as your username, profile picture, or “About Me” becomes public. Choose wisely what you disclose.

Payment and Contact Information: When you make purchases, subscribe to plans, or earn revenue via our services, we collect your name, payment details (credit card, bank account, or payment service credentials), and contact information. We also record your transactions.

Business Information: For users of products like Jetpack CRM or Happy Tools, we may store additional details like your company name, job title, timezone, and team information.

Content You Create: This includes blog posts, comments, images, or any files you upload.

Site Credentials: For services such as one-click restore (via Jetpack or VaultPress), you may need to provide credentials (SSH, FTP, SFTP) for your self-hosted site.

Communications: We save your messages from surveys, support interactions, forum posts, or newsletter sign-ups.

Job Application Data: When you apply for a role, we collect your resume/CV, references, work eligibility details, and possibly additional background information. We may also ask for voluntary demographic data to support diversity initiatives. This sensitive data is used solely for its intended purpose.

Information Collected Automatically
We also capture data automatically when you use our Services:

Log Data: Information such as your browser type, IP address, device identifiers, language preference, referral URL, date/time of access, operating system, and network details.

Transactional Data: Details about your purchases, including product information, pricing, and transaction dates/locations.

Usage Data: We track how you interact with our Services (e.g., page views, clicks, and feature usage) to better understand and improve your experience.

Location Data: We may estimate your location based on your IP address or, if permitted, obtain precise location data via your mobile device.

Stored Data Access: With your permission, our apps may access files stored on your device (for example, to upload a photo).

Interactions on Other Sites: If you engage with other websites using our Services (e.g., by liking or commenting), that activity may be recorded.

Cookies and Tracking: We use cookies, pixel tags, and similar technologies to track your visits, preferences, and engagement. For more details, see our Cookie Policy.

Information from Third Parties
We may receive data about you from other sources:

Third-Party Logins: If you sign in using another service (such as Google), we may obtain your username, email address, or connection token.

Social Networks: Connecting your account to a social media service (e.g., Twitter) through our Publicize feature may transfer your profile information and friend list.

Financial Data: For transactions processed through WooPayments or WooPay, we receive the relevant payment details from our partners (like Stripe).

Google Integration: Linking your Google account to a Newspack-powered site might allow us to access certain ad manager and analytics data for streamlined management.

Additional data—such as mailing addresses for non-users—may also be provided to us by third parties for marketing purposes.

How and Why We Use Your Data
We use your information for several key purposes:

Service Delivery: To create and maintain your account, host and back up your site, offer customer support, process payments, and verify your identity.

Service Improvement: To monitor and analyze usage, enabling us to upgrade our Services, add features, and enhance usability.

Advertising Management: To run and evaluate ad campaigns on our sites and those of our users.

Marketing: To tailor our marketing messages, measure campaign performance, and predict user retention.

Protection and Compliance: To detect and prevent fraudulent or illegal activities, protect our systems, and meet legal obligations.

Troubleshooting: To diagnose, debug, and resolve issues.

Customization: To deliver personalized notifications, recommendations, and content that suit your interests.

Communication: To update you on news, gather your feedback, and notify you of important account-related changes.

Recruitment: To evaluate and communicate with job applicants, verify credentials, and conduct background checks.

Legal Grounds for Processing
For users in the European Union, our processing of your data is based on one or more of the following:

It is necessary to fulfill our service commitments or manage your account.

It is required for legal compliance.

It is needed to protect vital interests.

It is justified by our legitimate interests (e.g., improving services, marketing).

It is based on your consent (e.g., cookie usage).

How We Share Your Information
We share your data only in limited circumstances and with the proper safeguards:

Within Our Group: We may share information with our subsidiaries and trusted partners who help run our Services.

With Third-Party Vendors: External service providers (e.g., payment processors, fraud detection services, cloud storage) may receive your data to support our operations.

For Legal Reasons: We may disclose your information in response to legal requests (such as subpoenas or court orders) or to comply with regulatory requirements.

To Protect Rights: If necessary to defend the rights, property, or safety of our users or the public, we may disclose relevant data.

In Business Transactions: In the event of a merger, sale, or bankruptcy, your data might be transferred as part of the company’s assets.

With Your Consent: We share your data when you explicitly authorize it (for instance, linking your account with a social network).

In Aggregated Form: Anonymized or aggregated data may be published or shared without identifying you.

To Site Owners: If you interact with a website using our Services, the site owner may receive certain information (such as your public profile or contact details).

Public Support Requests: Support queries you submit may be published to help resolve your issue or assist other users.

Publicly Shared Information

Any data you choose to make public—such as your profile, posts, likes, or comments—will be visible to others. For example, your profile picture (or a default avatar) and other public details may appear alongside your comments or likes on various websites. We also provide a public “Firehose” feed of data (like posts and comments) from some sites using our Services; however, this data cannot be republished without permission and may be indexed by search engines or used by third parties.

Data Retention
We keep your data only as long as necessary for the purposes outlined above or as required by law. For instance, our server logs (recording IP addresses, browser types, etc.) are typically stored for about 30 days to help analyze traffic and resolve issues. Similarly, if you delete a post or comment, it remains in a recovery folder for 30 days before being permanently removed. For job applicants, we retain your data during the application process and for a defined period afterward, in line with legal and operational requirements.

Security Measures
Although no online service can guarantee 100% security, we take significant steps to protect your data from unauthorized access, alteration, or destruction. We continually monitor our systems for vulnerabilities and implement reasonable security measures. For enhanced account protection, we recommend enabling features such as Two-Step Authentication.

Your Choices
You have several options regarding your personal data:

Control Your Information: You may opt not to provide certain optional details, although this might limit access to some features.

Manage Mobile Data Access: Adjust your device settings to block our apps from accessing stored data or location information.

Opt Out of Marketing: You can choose not to receive promotional communications (though essential account notifications will still be sent).

Cookie Preferences: Modify your browser settings to refuse cookies, keeping in mind that some site features may not work properly without them.

Analytics Opt-Out: Disable internal tracking via your account settings.

Account Closure: You may close your account at any time, though some data might be retained for legal or business purposes.

Your Rights
Depending on your location, especially under the GDPR or certain U.S. state laws, you have the right to:

Access your personal data.

Correct or Delete your information.

Object to our data processing.

Restrict our processing of your data.

Port your data in a transferable format.

Complain to a supervisory authority if you feel your rights have been violated.

For some U.S. states, additional rights include requesting details about the categories of data collected, its sources, and the third parties with whom it is shared. Detailed information about these rights is available in our Privacy Report.

Right to Opt Out of Data Sharing
We do not sell your personal data. However, we may share it with third-party providers to deliver our Services. In certain instances, this sharing may be considered a “sale” or “share” under specific state laws, and you have the right to opt out. To exercise this right, please use the “Do Not Sell My Personal Information” link on our websites or within our app settings. (This link may appear only for visitors from certain jurisdictions.) Note that opting out is managed via cookies; if you clear your cookies or switch browsers, you might need to opt out again.

Contacting Us About Your Rights
You can typically access, correct, or delete your data using the tools available in your account settings. For further assistance with your rights, please contact us via our web form or email. To verify your identity, we may ask you to use the email address associated with your account or provide written authorization if acting on another’s behalf. If we deny your request (for example, due to inability to verify your identity or legal obligations), you will receive a written explanation. You may appeal such decisions as outlined in our procedures.

Controllers and Responsible Parties
Iris Secure Technology Solutions operates globally, and different entities within our group may be responsible for processing your data based on the service you use and your location. Typically, the “controller” is the Iris Secure Technology Solutions entity with which you have an agreement. For certain processing activities, our U.S. office acts as the controller worldwide.

Designated Countries refers to Australia, Canada, Japan, Mexico, New Zealand, Russia, and all European countries (including the UK and ROI).

For Services (excluding Woo-related products):

If you reside outside the Designated Countries:
Iris Secure Technology Solutions
60 29th Street #343
San Francisco, CA 94110

How to Reach Us
If you have any questions regarding this Privacy Policy or wish to exercise your rights, please contact us via our web form or email. For quicker assistance, you may also call us at 1-877-273-3049.

Other Important Information
Transferring Data:
Since our Services are global, data collected from users in the EU may be processed, stored, or accessed by individuals outside the European Economic Area (EEA). We use appropriate measures (such as standard contractual clauses approved by the European Commission) to protect your data during such transfers.

Ads and Analytics by Third Parties:
Advertising networks and analytics providers may use tracking technologies (like cookies) to collect data on how you use our Services and other websites. This helps them analyze trends, measure content popularity, and serve targeted ads. This Privacy Policy covers only the data collected by Iris Secure Technology Solutions, not by third-party advertisers.

Third-Party Software and Services:
If you interact with third-party plugins, embeds, or services (such as WooPayments powered by Stripe), please note that they may collect information about you. Their data practices are governed by their own privacy policies.

Visitors to User Websites:
We may process data about visitors to websites that use our Services on behalf of our users. This processing is subject to separate agreements, and users should display their own privacy policies.

Policy Updates:
While most updates to this Privacy Policy are minor, Iris Secure Technology Solutions may periodically revise it. We recommend reviewing this page regularly. If significant changes occur, we may provide additional notice (such as on our homepage or via email). Continued use of our Services signifies your acceptance of any changes.

Additional Resources:
For more information, please refer to our related documents or contact us directly.

Scroll to Top