Privacy Policy

Last updated: October 9, 2026

At OPMC, we respect your privacy and are committed to protecting the personal information you share with us.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you visit our website, purchase our products, use our services, or communicate with our team.

We aim to handle personal information transparently and responsibly, in accordance with applicable privacy and data protection laws, including the European Union General Data Protection Regulation (GDPR), UK GDPR, Australian Privacy Act 1988, California Consumer Privacy Act (CCPA), and other applicable international privacy laws.

1. Who We Are

OPMC develops, sells, and supports WooCommerce plugins, software integrations, and related eCommerce services.

Website: https://woocommerce.opmc.com.au

Business: OPMC — OPMC AUSTRALIA PTY LTD

Mailing Address: GPO Box 2060, Sydney NSW 2001, Australia

Email: support@opmc.co

For inquiries concerning your personal information, please contact us using the subject line Privacy Request.

For personal information collected through our own website and business operations, OPMC is generally responsible for determining how and why that information is processed.

Where we process personal information on behalf of a business customer under an applicable service arrangement, our responsibilities may differ, and the customer may act as the data controller.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal information collected through:

  • Our website and online store.
  • Customer accounts, purchases, subscriptions, and renewals.
  • Product registrations, licensing, and update services, where applicable.
  • Customer support requests, helpdesk communications, and technical assistance.
  • Newsletter subscriptions and marketing communications.
  • Affiliate programs and business inquiries.
  • Other direct interactions with OPMC.

This policy does not automatically apply to the websites or businesses operated by customers using our WooCommerce plugins. Those businesses are responsible for their own privacy practices and for informing their customers about the technologies and data processing they use.

Third-party marketplaces and service providers may also maintain separate privacy policies.

3. Personal Information We Collect

The information we collect depends on how you interact with us.

Information You Provide Directly

We may collect:

Contact information: Your name, email address, phone number, business name, and other contact details.

Account information: Usernames, account preferences, subscription details, and authentication information.

Purchase information: Products purchased, order history, billing information, subscription status, renewal history, invoices, and transaction references.

Support information: Helpdesk tickets, messages, screenshots, technical logs, website details, plugin versions, and information voluntarily provided when requesting assistance.

Product and licensing information: License references, registered website domains, installation details, and technical information where required to deliver a product or service.

Marketing preferences: Newsletter subscriptions, communication preferences, and records of consent or unsubscribe requests.

Business and affiliate information: Company details, affiliate account information, referral records, and payment-related information where relevant to an existing business relationship.

Please avoid sending passwords, complete payment card numbers, or sensitive personal information through support forms unless specifically requested through an appropriate secure channel.

Information Collected Automatically

When you visit or interact with our website, certain information may be collected automatically, including:

  • IP address and approximate location derived from network information.
  • Browser type, operating system, and device characteristics.
  • Pages visited, referral sources, and website interactions.
  • Dates and times of visits.
  • Cookies, session identifiers, and similar technology.
  • Security events, error reports, and diagnostic information.

We use this information as necessary to operate the website, maintain security, understand website performance, and improve our services, subject to applicable consent requirements.

Information Received From Third Parties

We may receive relevant information from authorized third parties, including payment processors, WooCommerce Marketplace operators, customer support providers, and integration partners.

This may include purchase confirmations, subscription information, payment status, product entitlement information, and support-related records.

Where information is obtained indirectly, we provide any additional notices required by applicable law.

4. How and Why We Use Personal Information

We process personal information for legitimate business purposes and only where an appropriate legal basis applies.

For individuals protected by GDPR or UK GDPR, the following explains the legal bases generally relevant to our activities.

Purpose Legal Basis
Processing purchases, subscriptions, renewals, and providing products Performance of a contract
Delivering updates, managing licenses, and providing customer support Performance of a contract or legitimate interests, as applicable
Responding to business inquiries and customer communications Legitimate interests or steps requested before entering a contract
Maintaining website security, detecting abuse, and preventing fraud Legitimate interests or legal obligations
Maintaining accounting records, complying with tax obligations, and responding to lawful requests Legal obligation
Sending promotional communications and newsletters Consent or another lawful basis where permitted
Measuring website performance and improving usability Consent where required; otherwise legitimate interests where permitted
Resolving disputes and protecting legal rights Legitimate interests or legal obligations

Where processing is based on our legitimate interests, those interests include maintaining secure and reliable services, supporting customers, preventing misuse, and operating and improving our business.

Where consent is required, you may withdraw it at any time. Withdrawal does not affect processing lawfully carried out before consent was withdrawn.

Certain information is necessary to complete a purchase, maintain a customer account, or provide requested services. If you choose not to provide it, we may be unable to complete the relevant transaction or service.

You may browse publicly available content without creating an account or identifying yourself directly, although certain technical information may still be collected.

5. Online Purchases, Payments, and Subscriptions

When you purchase products through our website, we collect and process the information needed to complete your transaction and provide associated services.

This may include your name, billing details, email address, products purchased, order number, subscription status, and transaction confirmation.

Payment transactions may be processed by independent payment service providers. These providers may receive information necessary to authorize payments, prevent fraud, process refunds, and manage disputes.

Payment providers handle payment information under their own privacy and security practices. OPMC’s access to payment details depends on the payment method and integration used.

For purchases made through the WooCommerce Marketplace, the marketplace operator separately processes information under its own privacy policy.

OPMC may receive information necessary to fulfill product-related obligations, verify entitlements, provide updates, and assist customers who request support.

We retain transaction records as required for accounting, tax compliance, customer support, and other lawful business purposes.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies to support essential functionality, remember preferences, maintain security, and, where enabled, analyze website activity.

Cookies are small files stored on your device that help websites recognize sessions and preferences.

Essential Cookies

These support functions such as account login, authentication, shopping carts, checkout, security, and session management.

Essential cookies may be used without optional marketing consent where permitted by law.

Functional Cookies

These remember preferences, including selected settings and information that improves your website experience.

Analytics Cookies

Where analytics services are enabled, these may help us understand website traffic, technical performance, and how visitors interact with our pages.

Where required by law, we request consent before activating non-essential analytics cookies.

Marketing Cookies

Where advertising or marketing tracking technologies are used, they may measure campaign effectiveness or support personalized advertising.

Such technologies are subject to applicable consent and privacy-choice requirements.

WordPress Cookies

When the relevant features are enabled, WordPress may use cookies to:

  • Remember comment details for approximately one year.
  • Check whether a browser accepts cookies during login.
  • Maintain logged-in sessions, generally for two days.
  • Extend login sessions for approximately two weeks when “Remember Me” is selected.
  • Save certain display preferences for approximately one year.
  • Identify recently edited content through short-lived cookies.

Actual cookie names and durations may vary depending on website configuration and installed services.

Managing Cookies

You can control or remove cookies using your browser settings.

Where required, we provide mechanisms for accepting, rejecting, or withdrawing consent to non-essential cookies.

Disabling essential cookies may prevent some website features from functioning correctly.

We recommend reviewing our cookie disclosures for further information about the technologies currently operating on our website.

7. Comments, Uploaded Media, and Embedded Content

Comments

If comments are enabled and you submit one, we may collect the information entered into the comment form, together with your IP address and browser information, to assist with moderation and spam prevention.

An anonymized string derived from your email address may be transmitted to Gravatar to determine whether you have a profile image associated with that service.

Gravatar’s privacy practices are described in the Automattic Privacy Policy.

Approved comments and associated profile information may be publicly visible.

Uploaded Media

If you upload images or other media to our website, please ensure they do not contain personal information or embedded location metadata that you do not wish to disclose.

For example, photographs may contain GPS coordinates stored as EXIF metadata.

Embedded Third-Party Content

Some pages may contain embedded videos, images, articles, or other content from external websites.

These services may collect information about your interaction with embedded content and may use their own cookies or tracking technologies.

Where required, consent controls apply before optional third-party tracking is activated.

8. Customer Support and Technical Assistance

When you contact OPMC for assistance, we may collect information necessary to investigate and resolve your request.

This may include contact details, product information, error messages, screenshots, diagnostic logs, website configuration details, and relevant correspondence.

Support information is accessible to authorized personnel and service providers who require it to provide assistance.

Where temporary access to a customer’s website is needed, access should be arranged through an appropriate secure process and restricted to the requested support purpose.

We use support information to troubleshoot issues, provide product assistance, investigate defects, improve our services, and maintain a record of customer communications.

Support information may be retained after a request is resolved where reasonably necessary for follow-up assistance, recordkeeping, dispute resolution, or legal compliance.

9. Marketing Communications

If you subscribe to our newsletter or otherwise authorize promotional communications, we may send information about products, plugin updates, special offers, and relevant eCommerce news.

Where legally permitted, we may also communicate with existing customers about similar products or services, subject to applicable opt-out rights.

You can unsubscribe from promotional emails at any time using the unsubscribe link included in the message or by contacting us.

Opting out of marketing does not prevent us from sending essential transactional, security, subscription, or support communications.

10. Who We Share Personal Information With

We may share personal information with trusted service providers and other parties when reasonably necessary for the purposes described in this policy.

Recipients may include:

Payment providers: To process payments, refunds, subscription transactions, and payment disputes.

Website hosting and infrastructure providers: To host our website, maintain databases, deliver content, and support technical operations.

Security and fraud-prevention providers: To protect accounts, identify suspicious activity, and reduce fraudulent or abusive use.

Customer support platforms: To manage support tickets, customer communications, and service requests.

Email and communication services: To deliver transactional notifications, product updates, and marketing communications.

Analytics and advertising providers: Where used, and subject to applicable consent or opt-out requirements.

Marketplace and licensing partners: To administer purchases, entitlements, subscriptions, and product support.

Professional advisers and authorities: Where disclosure is necessary for legal compliance, regulatory obligations, accounting, dispute resolution, or the protection of legitimate rights.

Authorized employees and contractors: Where access is needed to perform business responsibilities under appropriate confidentiality and security arrangements.

We limit disclosures to what is reasonably necessary and use appropriate contractual and organizational safeguards where required.

We may also disclose information in connection with a business restructuring, merger, or sale, subject to applicable legal protections.

11. International Data Transfers

OPMC operates internationally and works with customers, service providers, and authorized personnel in multiple countries.

As a result, personal information may be accessed, stored, or processed outside the country where it was originally collected.

Our principal published mailing address is in Australia.

Countries where personal information is likely to be disclosed or processed: Australia, United States of America, New Zealand, Canada

Where applicable law requires safeguards for international transfers, we use appropriate legal and contractual mechanisms.

For transfers subject to GDPR or UK GDPR, these may include applicable adequacy decisions, approved Standard Contractual Clauses, UK transfer instruments, or other legally recognized safeguards.

For transfers governed by Australian privacy law, we take reasonable steps to meet applicable cross-border disclosure obligations.

You may contact us to request information about the safeguards relevant to your personal information.

12. How Long We Retain Personal Information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including applicable legal, accounting, contractual, security, and regulatory requirements.

Retention depends on the information involved.

Purchase and billing records are retained for the period necessary to administer transactions and meet applicable financial and tax obligations.

Customer account and subscription information is generally retained while the relationship remains active and for an appropriate period afterward where necessary for legitimate business or legal purposes.

Support requests and correspondence are retained for the period necessary to provide assistance, manage follow-up requests, and maintain appropriate business records.

Marketing information is retained while you remain subscribed or until the information is no longer necessary. Limited suppression records may be retained to respect unsubscribe requests.

Security logs and technical information are retained for periods appropriate to their security, diagnostic, and operational purposes.

Comments and associated metadata, where applicable, may be retained until removed, subject to moderation requirements, privacy requests, and applicable legal obligations.

When personal information is no longer required, we take reasonable steps to securely delete, anonymize, or otherwise dispose of it.

13. How We Protect Personal Information

We use reasonable technical and organizational measures designed to protect personal information from unauthorized access, disclosure, alteration, misuse, loss, or destruction.

Our safeguards may include secure website connections, access restrictions, authentication controls, software security updates, monitoring, and appropriate service-provider protections.

Access to personal information is limited according to operational needs.

No method of internet transmission or electronic storage can be guaranteed completely secure.

We periodically review security practices and respond to identified risks as appropriate.

Data Breaches

If we identify a security incident involving personal information, we assess its nature, potential impact, and applicable legal obligations.

Where notification is required, we will notify affected individuals, relevant regulators, or other parties in accordance with applicable law.

14. Your Privacy Rights and Choices

Depending on your location and applicable law, you may have rights concerning your personal information.

These may include the right to:

  • Access: Request confirmation of whether we process your personal information and receive a copy where legally required.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of eligible personal information.
  • Restriction: Request that certain processing activities be restricted.
  • Data portability: Request eligible information in a portable format.
  • Object: Object to certain processing, including processing based on legitimate interests.
  • Withdraw consent: Withdraw consent where processing relies on consent.
  • Opt out: Decline certain marketing, targeted advertising, or data-sharing activities.
  • Challenge automated decisions: Request information or review where applicable laws provide rights relating to automated decision-making.
  • Appeal or complain: Challenge the handling of a privacy request or submit a complaint to an appropriate privacy regulator.

You may object to the use of your personal information for direct marketing at any time.

We will not unlawfully discriminate against you for exercising your privacy rights.

How to Submit a Privacy Request

Send an email to support@opmc.co with the subject line Privacy Request.

Please describe the action you would like us to take and provide sufficient information to help us identify the relevant records.

We may request reasonable verification of your identity or authority before acting on a request.

We respond within the timeframes required by applicable law.

Certain rights are subject to lawful exceptions, including situations where information must be retained for financial reporting, legal compliance, security, or the establishment or defense of legal claims.

Where permitted, an authorized representative may submit a request on your behalf.

15. Additional Rights for European Union and United Kingdom Residents

Individuals whose personal information is subject to GDPR or UK GDPR have rights that may include access, rectification, erasure, restriction, portability, objection, and safeguards relating to certain solely automated decisions.

Our relevant processing purposes and legal bases are described in Section 4.

Where we rely on consent, you may withdraw it at any time.

Where we rely on legitimate interests, you may object in circumstances provided by law.

You also have the right to lodge a complaint with the relevant data protection supervisory authority in your country.

UK residents may contact the Information Commissioner’s Office (ICO) at https://ico.org.uk.

Individuals in the European Economic Area may contact their relevant national data protection authority.

Where a data protection officer or EU/UK representative is legally required, the applicable contact details will be made available.

16. Additional Information for California Residents

California residents may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, where those laws apply to OPMC.

Categories of Personal Information

Depending on your interaction with our website and services, the categories of personal information collected during the preceding 12 months may include:

Category Examples
Identifiers Name, email address, IP address, account identifiers
Customer and commercial records Billing details, purchases, subscriptions, transaction history
Internet or network activity Website interactions, browser information, cookie identifiers
Professional information Business name and business contact details
Account authentication information Login credentials and associated security information
Communications and submitted content Support tickets, messages, comments, and diagnostic submissions

The categories of sources include customers and visitors directly, devices and browsers, authorized service providers, and marketplace or transaction partners.

The business purposes for collection and use are described in Section 4.

Categories of recipients for business-purpose disclosures are described in Section 10. Retention practices are described in Section 12.

Sale or Sharing of Personal Information

We use Google Analytics to understand website traffic, monitor performance, and improve the visitor experience. We do not use Google Analytics for targeted advertising. Analytics cookies and related technologies are subject to applicable privacy and consent requirements.

We use Stripe and PayPal to securely process purchases, subscription payments, and refunds. Relevant billing and transaction information is shared with the selected payment provider as necessary to complete transactions, prevent fraud, and meet legal obligations.

These providers maintain their own privacy policies, which explain how they handle personal information.

California Consumer Rights

Subject to applicable law, California residents may request access to personal information, correction of inaccuracies, deletion of eligible information, and information about collection and disclosure practices.

Where applicable, they may also opt out of the sale or sharing of personal information and request limitations on certain uses of sensitive personal information.

We use account authentication information for account access and security purposes. Any additional uses of sensitive personal information are subject to applicable legal requirements.

We do not unlawfully discriminate against consumers for exercising their rights.

Requests may be submitted using the contact information in Section 14.

17. Other Regional Privacy Rights

Australia

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, individuals may request access to personal information and correction of inaccurate records.

You may also submit a complaint about our handling of personal information by contacting us.

We will investigate privacy complaints and respond in accordance with applicable requirements.

If a complaint remains unresolved, you may be able to contact the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.

Canada

Where Canadian federal or provincial privacy laws apply, individuals may request access to personal information, seek corrections, withdraw consent where permitted, and raise concerns about privacy practices.

You may also contact the Office of the Privacy Commissioner of Canada or the relevant provincial authority.

Brazil

Where Brazil’s Lei Geral de Proteção de Dados Pessoais (LGPD) applies, individuals may have rights to confirmation of processing, access, correction, deletion or anonymization in applicable circumstances, data portability, information about disclosures, and review of certain automated decisions.

Individuals may also contact Brazil’s Autoridade Nacional de Proteção de Dados (ANPD).

Other Jurisdictions

We recognize that additional privacy protections may apply under laws in other jurisdictions, including New Zealand, Switzerland, and individual US states.

Where applicable, we will respect legally enforceable rights to access, correct, delete, restrict, or object to the processing of personal information.

Residents of US states with applicable appeal rights may submit a request for reconsideration by emailing support@opmc.co with the subject line Privacy Appeal.

18. Automated Processing and Fraud Prevention

We may use automated systems to help protect our website, customer accounts, transactions, and services from spam, suspicious activity, unauthorized access, and potential fraud.

Such systems may evaluate technical information, transaction characteristics, or security indicators and may result in additional verification or security restrictions.

Where automated processing is used to make decisions that significantly affect an individual’s rights or interests, we provide the information, safeguards, and opportunities for review required by applicable law.

If you believe a decision affecting your account or transaction was made incorrectly, please contact support@opmc.co.

OPMC Plugin Functionality: Some OPMC products offer automated fraud detection, security screening, or integration capabilities for third-party WooCommerce stores. The information processed by those plugins depends on the merchant’s configuration and enabled services.

Merchants using such products are responsible for understanding their own processing activities, informing their customers, and meeting applicable privacy and automated decision-making requirements.

OPMC’s responsibilities for any information it separately receives are determined by its actual role and the relevant service arrangements.

19. Children’s Privacy

Our website, software products, and commercial services are intended for business customers and general adult audiences.

We do not knowingly solicit personal information from children under 16.

If we become aware that personal information has been collected from a child in circumstances prohibited by applicable law, we will take appropriate steps to address the situation, including deletion where required.

Parents or guardians may contact us concerning information they believe has been provided by a child.

20. Third-Party Websites and Services

Our website may contain links to third-party websites, platforms, marketplaces, or integrated services.

These third parties are responsible for their own privacy policies and data-handling practices.

We encourage you to review their privacy policies before providing personal information or enabling optional integrations.

21. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, business practices, technologies, or applicable legal requirements.

When changes are made, the revised version will be published on our website with an updated revision date.

Where required by law, we will provide additional notice or obtain consent before implementing material changes.

We encourage you to review this page periodically.

22. Contact Us

If you have questions about this Privacy Policy, would like to exercise your privacy rights, or wish to report a privacy concern, please contact us.

OPMC

Website: https://woocommerce.opmc.com.au

Email: support@opmc.co

Mailing address: GPO Box 2060, Sydney NSW 2001, Australia

Email subject: Privacy Request

We take privacy inquiries seriously and will handle requests in accordance with applicable data protection laws.