Skip to main content
Login Join
Legal

Privacy Policy

What data we collect, how we use it, and how you can get a copy or delete it.

Last updated: April 24, 2026

This Privacy Policy explains what data WPFolks collects about you, how we use it, who we share it with, and what rights you have over it.

We’ve tried to write this in plain English. Where legal terms are necessary, we’ve kept them as short as possible.

Who we are

WPFolks (“WPFolks”, “we”, “us”, or “our”) is a free community platform for WordPress people, operated by Ankit Panchal, an individual based in Pune, India.

You can reach us at hello@wpfolks.org for any privacy-related question, request, or complaint.

What data we collect

Data you give us

Data we collect automatically

Data from third parties

Why we process your data (and on what legal basis)

Under the GDPR (and similar laws), we can only process your personal data when we have a lawful basis. Ours are:

What we doWhyLawful basis
Create and maintain your accountTo give you the service you signed up forContract (Art. 6(1)(b) GDPR)
Display your profile publiclyPlatform requires public profiles by designContract + Legitimate interest
Send transactional emails (welcome, password reset, verification)Essential service communicationContract
Send the weekly newsletterYou opted inConsent (Art. 6(1)(a) GDPR)
Prevent spam and abuseProtect the community and platformLegitimate interest
Analytics and product improvementUnderstand what’s usefulLegitimate interest (opt-out available)
Moderate contentEnforce our Community GuidelinesLegitimate interest
Respond to legal requestsComply with lawLegal obligation

You can withdraw consent for anything consent-based at any time (see Your rights below).

Who we share data with

We do not sell your personal data, ever. We share it only with:

Service providers (sub-processors)

These are the companies we use to run WPFolks. Each is bound by a data-processing agreement:

ProviderWhat they handleLocation
WordPress.com (Atomic) / hosting providerSite hosting, database, file storageGlobal CDN + US data centers
Brevo (sendinblue.com)Transactional emails, newsletter deliveryFrance / EU
Google AnalyticsUsage analytics

We review sub-processors annually. If we change a sub-processor, we’ll update this page.

Other people who can see your data

International data transfers

WPFolks is operated from India, and uses service providers located in the European Union, United States, and globally (via CDN). If you are an EU/EEA or UK resident, your data may be transferred to countries outside your home region.

We rely on Standard Contractual Clauses (SCCs) published by the European Commission to protect these transfers where required.

How long we keep your data

Data typeRetention
Active account dataFor as long as your account is open
After account deletionPermanently deleted within 30 days, except legal-obligation records (see below)
Server / security logs90 days
Financial or legal records (if any)7 years (legal requirement)
Deleted content in the feedRemoved immediately from public view; purged from backups within 35 days
BackupsRolling 30-day encrypted backups

When you delete your account, your submissions (plugins, events, resources) remain visible but are re-attributed to “Deleted member.” Your feed posts and comments are replaced with your username showing as “Deleted member.” This preserves the community history while removing your personal identifiers.

Your rights

Depending on where you live, you have some or all of these rights:

To exercise any right, email hello@wpfolks.org from the email address on your account. We respond within 30 days.

EU / EEA / UK residents: you can also file a complaint with your local data protection supervisory authority. We’d appreciate the chance to resolve it first, but the choice is yours.

California residents (CCPA/CPRA): you have specific rights under California law, including the right to know, delete, correct, and opt-out of sale/share of personal information. We do not sell or share personal information as defined under CCPA.

India residents (DPDP Act, 2023): you have rights under India’s Digital Personal Data Protection Act, including the right to access, correction, erasure, and grievance redressal.

Cookies

We use a small number of cookies. Here’s the full list:

NamePurposeDurationCategory
wordpress_logged_in_*Keeps you signed inSession + 14 daysEssential
wp-settings-*Remembers your admin preferences1 yearEssential
wpfolks_community_notice_v2Remembers that you dismissed a notice1 yearEssential

Essential cookies are always on (the site doesn’t work without them). WPFolks uses only essential cookies necessary to operate the platform. We do not use tracking or analytics cookies.

You can clear cookies at any time in your browser settings.

Children

WPFolks is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has given us their data, email hello@wpfolks.org and we’ll delete the account.

Security

We use TLS encryption for all traffic, bcrypt password hashing, rate-limiting on login attempts, two-factor authentication (for admin accounts), and regular dependency updates. No system is ever 100% secure, but we take this seriously.

If you discover a security issue, please email security@wpfolks.org before disclosing publicly. We aim to acknowledge reports within 48 hours.

Changes to this policy

We may update this policy. Material changes will be notified via:

Continued use after the notice period constitutes acceptance.

Contact