Privacy policy
This policy explains what personal data Header Genie collects, why we use it, and the rights you have under UK GDPR.
Effective 18 September 2026.
1. Controller
The controller of personal data processed through https://headergenie.com is the operator of Header Genie (“we”, “us”). You can contact us from your account after you sign in, using the email address registered to that account.
2. Data we collect
Depending on how you use the service, we may process:
- Account data: email address and a hashed password (we do not store your password in plain text).
- Licence data: plan, status, renewal date, an encrypted copy of your licence key, and related identifiers so you can retrieve the key after login.
- Payment data: Stripe customer, subscription, and checkout identifiers. Full card numbers stay with Stripe; we do not receive them.
- Session data: a session token in an HTTP-only cookie, plus limited request metadata such as IP address and user agent to secure the account.
- Plugin telemetry that you or the site owner enable (for example activation or usage events, and Content-Security-Policy reports) so Pro monitoring can work.
- Website logs needed to operate and protect this site (including security events).
- Analytics data if Google Analytics is enabled on this site (page views and similar measurements). It is not loaded unless a valid measurement ID is configured.
3. Why we use it
- To create and authenticate your account, issue and display licence keys, and provide Pro features (performance of a contract).
- To take payment, issue invoices, handle renewals and cancellations via Stripe (performance of a contract and legal obligation for tax records).
- To keep the service secure, prevent abuse, and debug faults (legitimate interests).
- To understand how this marketing site is used, only if analytics is switched on (legitimate interests, and consent where the law requires a cookie banner).
4. Stripe
Payments are processed by Stripe. Stripe acts as an independent controller or processor for card data under its own terms and privacy policy. We receive enough information to know that you paid, to link the subscription to your account, and to open the Stripe customer portal when you ask.
5. Cookies
We use an HTTP-only session cookie (hg_session) so you stay signed in. It is required for the account pages to work and is not used for advertising. If Google Analytics is enabled, Google may set its own cookies subject to Google’s policies.
6. Retention
We keep account and licence records for as long as the account exists and for a reasonable period afterwards so we can handle renewals, chargebacks, security investigations, and tax or accounting duties. Session tokens expire (currently after seven days unless you sign in again). You can sign out to drop the current session cookie.
7. Sharing
We do not sell your personal data. We share it only with:
- hosting and infrastructure providers that run this website and the licence API;
- Stripe, for payments and the customer portal;
- Google, if analytics is enabled;
- professional advisers or authorities where the law requires it.
8. International transfers
Some providers (including Stripe and, if used, Google) may process data outside the UK. Where that happens we rely on an appropriate safeguard such as the UK addendum to the EU Standard Contractual Clauses or a UK adequacy decision.
9. Your rights
Under UK GDPR you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability. You may also complain to the Information Commissioner’s Office at ico.org.uk.
To exercise rights, sign in and use your account controls where possible (including the Stripe portal for billing details), or contact us as described above. We may need to verify the request. Some records must be kept even if you ask for erasure, for example tax records.
10. Children
Header Genie is aimed at website operators and is not intended for children. We do not knowingly collect data from anyone under 16.
11. Security
We hash passwords, encrypt stored licence keys, sign server-to-server API calls, and send security headers on this site. No method of transmission or storage is completely secure. You should use a unique password and keep your WordPress site updated.
12. Changes
We may update this policy by publishing a new version here. The effective date at the top will change. Continued use after an update is acceptance of the revised policy where the law allows.
13. Related terms
Use of the paid product is also governed by our terms and conditions.