Privacy & Cookie Policy

@shift processes information only as needed to provide, secure, and improve its services.

Controller and scope

Data controller
Yoshiya Tsuchisaka, trading as @shift
Privacy contact
Support form / support@upf.at-shift.net
Scope
The upf.at-shift.net website, software sales, license activation, updates, downloads, and support
Last updated
August 8, 2026

Information we collect

Purchases, licenses, and downloads

  • Email address, product and plan, language, and purchase or renewal timestamps
  • Stripe customer, subscription, payment, price, and Checkout Session identifiers
  • License status, site allowance, and activation or deactivation timestamps
  • Activated site URL and hash, plugin, WordPress and PHP versions, and locale
  • Hashed download tokens and expiry timestamps

We do not store plain-text license keys. We store a SHA-256 hash for verification and a short hint for identification. WordPress profile values and user classifications stored on your site are not sent to our license server.

Support

We collect your name, email address, request type, product, subject, message, and any optional site URL, plugin version, WordPress version, and PHP version you submit. Form contents are delivered and retained as email rather than in a dedicated support database.

Access and security data

We may process IP address, user agent, requested URL, date and time, response status, Turnstile verification data, and an irreversible hash derived from an IP address.

Why we process information

  • Process purchases and invoices, issue and manage licenses, deliver updates, and provide re-downloads
  • Respond to requests, verify identity, and investigate bugs or security reports
  • Prevent misuse, excessive submissions, attacks, and unauthorized license use
  • Analyze visits and improve content or products when you consent
  • Meet legal accounting, tax, contract, and dispute obligations

We do not use this information for advertising or provide it for third-party advertising.

Processors, external services, and disclosure

ServicePurpose and information transferred
StripePayments, billing, and subscriptions. Stripe handles card numbers and security codes; we do not store them.
XserverWeb hosting, databases, email, and backups. The primary server and backups are located in Japan.
Cloudflare TurnstileBot prevention. Verification tokens and communication data needed for risk assessment are sent to Cloudflare. Turnstile Privacy Policy
Google AnalyticsVisit analysis after consent. Advertising use is disabled, as are Google Signals and advertising personalization signals.
Google Fonts / Font AwesomeTypography and icons. IP address, user agent, and related request data may be sent to their delivery networks when displayed.

We do not disclose personal data without consent unless required by law, necessary to protect life or property, or requested through a lawful process by a court, police authority, or other public body.

Cookies and your choices

Essential storage

The support form uses the session cookie “upf_support” to prevent request forgery. It expires when you close the browser and is configured with Secure on HTTPS, HttpOnly, and SameSite=Lax. Your cookie preference is stored in your browser's localStorage.

Analytics

Google Analytics is not loaded by default. It is loaded only after you select “Allow analytics.” Refusing analytics does not prevent purchases, downloads, license activation, or support requests.

Retention periods

Purchase and accounting records
Seven years after the transaction
License and activation history
Five years after contract termination or expiry
Support email
Three years after closure, stored in the server mailbox and Apple Mail. The operator does not create a separate backup.
Access and security logs
Normally 90 days
IP-derived rate-limit hashes
Within 48 hours
Download tokens
Deleted progressively after expiry
Xserver backups
Normally 14 days

Information may be kept longer when required for legal, accounting, contract, security, fraud-prevention, or dispute purposes.

Your privacy rights

You may request access, correction, deletion, restriction, objection, portability where applicable, or withdrawal of consent by using our support form or emailing support@upf.at-shift.net.

To verify identity, we may use the purchase email address and limited order, payment, or license information relevant to the request. We will never ask for your password, complete card number, or complete license key. We normally respond within one month.

We may be unable to delete records required by law or needed for accounting, proof of contract, license-abuse prevention, security, or legal claims. If so, we will explain why.

International users and transfers

The services are available worldwide. Our primary servers and databases are located in Japan. Use of Stripe, Cloudflare, and Google may involve processing outside your country of residence or outside Japan.

Users in the EU, UK, and other jurisdictions may exercise applicable rights of access, correction, deletion, restriction, objection, portability, and consent withdrawal through the contact above. You may also complain to your local supervisory authority.

Minors

Purchasers must have legal capacity to enter into a contract in their country or region. Minors must obtain consent from a parent or legal guardian before purchasing. Payment through Stripe does not by itself verify the purchaser's age.