Privacy Policy

What we store about you, why we store it, and how to get rid of it.

Last updated 28 September 2026.

Who holds your data

Ryan Tipones, trading as RyanPlugins, a sole proprietor based in the Philippines, is the personal information controller for the data described here. Reach us at [email protected]; a postal address is available on request.

We are subject to the Philippine Data Privacy Act of 2012 (Republic Act No. 10173). Where you are somewhere with its own data protection law — the UK or the EU, for instance — that law can apply to your data as well, and nothing here limits the rights it gives you.

The short version

We hold enough to run your account and build your apps, and not much else. Your shoppers’ data is the part worth being clearest about: it never comes to us.

Your customers’ orders, addresses, payment details and accounts stay on your own WooCommerce site. The apps we build talk to your store directly through the connector plugin. That traffic does not pass through our servers, and we have no copy of it.

What we store, and why

Your account. Your name, email address, and — if you link it — your Patreon user ID. Needed to have an account at all and to know which plan you are on.

Sign-in codes. Your email address and a hashed copy of the code we sent, until it expires. The code itself is never stored in a readable form.

Security records. When an account signs in or an administrator acts, we record what happened, when, the IP address and the browser user-agent string. This exists so that an account taken over can be seen to have been taken over. It is the one place we keep something that identifies a device rather than an account.

Your stores. The domain, the connection status, the WooCommerce version reported, and a secret used to validate the connector’s licence.

Your builds. The app name, package identifier, colours, and any logo or hero image you upload. Finished build files are kept for a limited period and then deleted.

Signing keys. Where we generate an Android upload key for you, the keystore and its passwords are stored encrypted. They are never shown in the dashboard or included in any listing; they leave our servers only through the download you ask for.

Quote requests. What you asked for, in your own words, along with any budget range and timing you gave. This describes your business, so it is treated as confidential and is read only to answer you.

Why we are allowed to hold it

Most of it is necessary to provide the service you asked for — you cannot have an account without an email address. The security records rest on our legitimate interest in keeping accounts from being taken over, which we consider proportionate because they are read only when something looks wrong. Where we keep something to satisfy a legal obligation, that is the basis for it.

Who else sees it

We do not sell your data and we do not use it for advertising. It reaches other companies only where running the service requires it:

Patreon — when you link your account, we ask Patreon who you are and what you are entitled to. We request the narrowest scope that answers that, and read nothing else. What Patreon does with your data is covered by their own policy.

Our email provider — delivers sign-in codes and notifications, and so handles your address.

Our hosting provider — runs the servers the data sits on.

Cloudflare Turnstile — checks that a person, not a bot, is asking for a sign-in code. It sees your IP address and some details of your browser for that check only, and sets no tracking cookies.

Google Analytics — only if you allow it (see Cookies below). It sees which pages of RyanPlugins are visited and a handful of milestones — signing up, connecting a store, starting and downloading a build, choosing a plan — with no name, email address, store name or domain attached.

We will also disclose data where the law requires it, and will tell you unless we are prevented from doing so.

How long we keep it

Account data lasts as long as the account. Sign-in codes expire in minutes and are then removed. Build artefacts are deleted on the schedule shown against each build in the dashboard. Security records are kept while they are useful for investigating account access, and quote requests while the enquiry is live and for our records afterwards.

When an account is deleted we remove the account, its stores, its builds and its signing keys, keeping only what the law requires.

What you can ask for

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us holding it. Email [email protected] and we will respond within one month.

Deleting your account deletes your signing keys, and a deleted key cannot be recovered by anyone. If you have published an Android app, download the key first — without it you will not be able to update that listing again.

If you think we have handled your data badly, tell us first. You can also complain to the National Privacy Commission of the Philippines, which regulates us, and — if you are somewhere with its own regulator — to that one instead. You do not have to come to ours.

Cookies

The dashboard needs one cookie, which keeps you signed in. Clearing it signs you out.

Everything else is optional and off until you say yes. The first time you visit we ask whether we may use Google Analytics, which sets its own cookies (named _ga) to count visits and see where people get stuck. If you decline, nothing is loaded from Google at all. We have turned off Google’s advertising features, and nothing we send identifies you or your store.

Your answer is kept in your browser. You can change it at any time — changing it to no also removes the Google Analytics cookies.

Apps built for your store

This policy covers RyanPlugins. It does not cover the apps you build with it — those are yours, they talk to your store, and the data they handle is yours to account for. Both Apple and Google require your app to have its own privacy policy, which is why the builder asks you for one.

Changes

If this policy changes materially we will say so by email or in the dashboard before it takes effect, and the date at the top will change.

Questions about any of this go to [email protected].