The upf.at-shift.net website, software sales, license activation, updates, downloads, and support
Last updated
August 8, 2026
Information we collect
Purchases, licenses, and downloads
Email address, product and plan, language, and purchase or renewal timestamps
Stripe customer, subscription, payment, price, and Checkout Session identifiers
License status, site allowance, and activation or deactivation timestamps
Activated site URL and hash, plugin, WordPress and PHP versions, and locale
Hashed download tokens and expiry timestamps
We do not store plain-text license keys. We store a SHA-256 hash for verification and a short hint for identification. WordPress profile values and user classifications stored on your site are not sent to our license server.
Support
We collect your name, email address, request type, product, subject, message, and any optional site URL, plugin version, WordPress version, and PHP version you submit. Form contents are delivered and retained as email rather than in a dedicated support database.
Access and security data
We may process IP address, user agent, requested URL, date and time, response status, Turnstile verification data, and an irreversible hash derived from an IP address.
Why we process information
Process purchases and invoices, issue and manage licenses, deliver updates, and provide re-downloads
Respond to requests, verify identity, and investigate bugs or security reports
Prevent misuse, excessive submissions, attacks, and unauthorized license use
Analyze visits and improve content or products when you consent
Meet legal accounting, tax, contract, and dispute obligations
We do not use this information for advertising or provide it for third-party advertising.
Processors, external services, and disclosure
Service
Purpose and information transferred
Stripe
Payments, billing, and subscriptions. Stripe handles card numbers and security codes; we do not store them.
Xserver
Web hosting, databases, email, and backups. The primary server and backups are located in Japan.
Cloudflare Turnstile
Bot prevention. Verification tokens and communication data needed for risk assessment are sent to Cloudflare. Turnstile Privacy Policy
Google Analytics
Visit analysis after consent. Advertising use is disabled, as are Google Signals and advertising personalization signals.
Google Fonts / Font Awesome
Typography and icons. IP address, user agent, and related request data may be sent to their delivery networks when displayed.
We do not disclose personal data without consent unless required by law, necessary to protect life or property, or requested through a lawful process by a court, police authority, or other public body.
Cookies and your choices
Essential storage
The support form uses the session cookie “upf_support” to prevent request forgery. It expires when you close the browser and is configured with Secure on HTTPS, HttpOnly, and SameSite=Lax. Your cookie preference is stored in your browser's localStorage.
Analytics
Google Analytics is not loaded by default. It is loaded only after you select “Allow analytics.” Refusing analytics does not prevent purchases, downloads, license activation, or support requests.
Retention periods
Purchase and accounting records
Seven years after the transaction
License and activation history
Five years after contract termination or expiry
Support email
Three years after closure, stored in the server mailbox and Apple Mail. The operator does not create a separate backup.
Access and security logs
Normally 90 days
IP-derived rate-limit hashes
Within 48 hours
Download tokens
Deleted progressively after expiry
Xserver backups
Normally 14 days
Information may be kept longer when required for legal, accounting, contract, security, fraud-prevention, or dispute purposes.
Your privacy rights
You may request access, correction, deletion, restriction, objection, portability where applicable, or withdrawal of consent by using our support form or emailing support@upf.at-shift.net.
To verify identity, we may use the purchase email address and limited order, payment, or license information relevant to the request. We will never ask for your password, complete card number, or complete license key. We normally respond within one month.
We may be unable to delete records required by law or needed for accounting, proof of contract, license-abuse prevention, security, or legal claims. If so, we will explain why.
International users and transfers
The services are available worldwide. Our primary servers and databases are located in Japan. Use of Stripe, Cloudflare, and Google may involve processing outside your country of residence or outside Japan.
Users in the EU, UK, and other jurisdictions may exercise applicable rights of access, correction, deletion, restriction, objection, portability, and consent withdrawal through the contact above. You may also complain to your local supervisory authority.
Minors
Purchasers must have legal capacity to enter into a contract in their country or region. Minors must obtain consent from a parent or legal guardian before purchasing. Payment through Stripe does not by itself verify the purchaser's age.