Privacy policy
Last Updated: January 14, 2026
1. Introduction
MyPluginWorld ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit or make purchases from https://www.mypluginworld.com/ (the "Site").
This policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
Elevator Program LTD
61 Trimlestown Park
Booterstown, Dublin
Ireland
Managing Director: Will Kinsella
VAT Number: IE3663463VH
Registry Court: Dublin, Ireland
For privacy-related inquiries, please contact us through our contact form or email us at the address provided on our website.
3. What Personal Data We Collect
When you visit our Site or make a purchase, we may collect the following types of personal data:
3.1 Information You Provide Directly
-
Name
-
Email address
-
Phone number (SMS)
-
Billing address
-
Payment information (processed securely through our payment providers)
3.2 Information Collected Automatically
-
IP address
-
Browser type and version
-
Device information
-
Pages visited and browsing behavior
-
Date and time of visits
-
Cookies and similar tracking technologies (see Section 6)
4. Legal Basis for Processing Your Data
We process your personal data under the following legal grounds:
-
Contractual Necessity: To fulfill orders, process payments, and deliver products/services you've purchased
-
Legitimate Interests: To improve our services, prevent fraud, and ensure website security
-
Consent: For marketing communications, cookies, and analytics (where required)
-
Legal Obligation: To comply with tax, accounting, and other legal requirements
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Order Processing and Fulfillment
-
Processing and completing your orders
-
Sending order confirmations and delivery updates
-
Providing customer support
-
Processing refunds or exchanges
5.2 Marketing and Communications
-
Sending promotional emails and newsletters (with your consent)
-
Remarketing and targeted advertising via Meta (Facebook/Instagram) and TikTok
-
Personalized product recommendations
5.3 Website Improvement and Analytics
-
Analyzing website usage and user behavior through Google Analytics and Shopify Analytics
-
Improving website functionality and user experience
-
A/B testing and optimization
5.4 Legal and Security
-
Preventing fraud and unauthorized transactions
-
Complying with legal obligations (tax, accounting, consumer protection)
-
Enforcing our Terms of Service
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your browsing experience and analyze website performance.
6.1 Types of Cookies We Use
Strictly Necessary Cookies (Functional)
-
Essential for website operation and shopping cart functionality
-
Cannot be disabled without affecting site performance
Analytics Cookies
-
Google Analytics: Tracks website traffic, user behavior, and performance metrics
-
Shopify Analytics: Monitors e-commerce performance and conversion data
Marketing Cookies
-
Meta Pixel (Facebook/Instagram): Enables remarketing and conversion tracking
-
TikTok Pixel: Enables remarketing and advertising optimization
6.2 Managing Cookies
You can control cookies through your browser settings. However, disabling certain cookies may limit website functionality. To opt out of targeted advertising:
-
Google: Visit Google Ads Settings
-
Google Analytics Opt-Out: https://tools.google.com/dlpage/gaoptout
-
Meta: Visit Facebook Ad Preferences
-
TikTok: Visit TikTok Privacy Settings
7. Third-Party Services and Data Sharing
We work with trusted third-party service providers to operate our business. Your data may be shared with the following partners:
7.1 Payment Processors
-
Stripe: Payment processing and fraud prevention
-
Privacy Policy: https://stripe.com/privacy
-
Shop Pay: Shopify's payment solution for faster checkout
-
Privacy Policy: https://www.shopify.com/legal/privacy
7.2 E-Commerce Platform
-
Shopify: Our website is hosted and powered by Shopify, which processes and stores order data, customer information, and website analytics
-
Privacy Policy: https://www.shopify.com/legal/privacy
-
Privacy Controls: https://privacy.shopify.com/en
7.3 Marketing and CRM
-
HubSpot: Email marketing, customer relationship management, and marketing automation
-
Privacy Policy: https://legal.hubspot.com/privacy-policy
-
Privacy Preferences: https://www.hubspot.com/hubspot-privacy-preferences
7.4 Analytics
-
Google Analytics: Website traffic analysis and user behavior tracking
-
Privacy Policy: https://policies.google.com/privacy
-
How Google Uses Data: https://www.google.com/policies/privacy/partners/
7.5 Customer Support
-
Flyweight: Shopify-native chatbot for customer support (data shared only when you interact with the chatbot)
-
Service: Shopify-native AI chatbot for customer support
-
Privacy Policy: https://www.flyweight.io/privacy-statement
-
GDPR Compliance Article: https://flyweight.io/articles/shopify-ai-chatbot-gdpr-compliance
7.6 Data Sharing Practices
We do not sell or rent your personal data to third parties. Data is only shared with service providers necessary to deliver our services, and these providers are contractually obligated to protect your data and use it only for specified purposes.
7.7 Plugin Developers and Vendors
In some cases, we may share minimal order information (e.g., license key, email) with plugin developers or vendors when required for product delivery or support purposes.
8. International Data Transfers
Some of our third-party service providers (e.g., Shopify, Google Analytics, HubSpot) may process data outside the European Economic Area (EEA). When data is transferred internationally, we ensure appropriate safeguards are in place, including:
-
Standard Contractual Clauses (SCCs) approved by the European Commission
-
Adequacy decisions recognizing equivalent data protection standards
-
Privacy Shield frameworks (where applicable)
Our service providers comply with GDPR requirements and implement robust security measures to protect your data.
9. Data Retention
We retain your personal data for 2 years from your last interaction with us (e.g., last purchase, last email opened). After this period, data is securely deleted or anonymized unless:
-
We have a legal obligation to retain it longer (e.g., tax records)
-
It is necessary to resolve disputes or enforce our terms
You may request earlier deletion of your data at any time (see Section 10).
10. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights regarding your personal data:
10.1 Right to Access
You can request a copy of the personal data we hold about you.
10.2 Right to Rectification
You can request correction of inaccurate or incomplete data.
10.3 Right to Erasure ("Right to Be Forgotten")
You can request deletion of your personal data, subject to legal retention requirements.
10.4 Right to Restrict Processing
You can request that we limit how we use your data in certain circumstances.
10.5 Right to Data Portability
You can request your data in a structured, machine-readable format.
10.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
10.7 Right to Withdraw Consent
You can withdraw consent for marketing emails or cookies at any time.
10.8 How to Exercise Your Rights
To exercise any of these rights, please:
-
Use our contact form on our website
-
Submit a written request specifying which right you wish to exercise
We will respond to your request within 30 days of receipt. If your request is complex, we may extend this period by an additional 60 days and will notify you of the extension.
10.9 Right to Complain
If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority:
Data Protection Commission (Ireland)
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: https://www.dataprotection.ie
Email: info@dataprotection.ie
11. Data Security
We implement industry-standard security measures to protect your personal data, including:
-
Encryption: SSL/TLS encryption for data transmitted between your browser and our servers
-
Secure Payment Processing: PCI DSS-compliant payment processors (Stripe, Shop Pay)
-
Access Controls: Restricted access to personal data on a need-to-know basis
-
Regular Security Audits: Ongoing monitoring and vulnerability assessments
While we take reasonable precautions, no online transmission is 100% secure. We cannot guarantee absolute security but continually work to protect your data.
12. Children's Privacy
Our Site is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make significant changes, we will:
-
Update the "Last Updated" date at the top of this policy
-
Notify you via email (if you have an account) or through a prominent notice on our website
We encourage you to review this policy periodically to stay informed about how we protect your data.
14. Marketing Communications
14.1 Email Marketing
With your consent, we may send you promotional emails about new products, special offers, and other updates. You can unsubscribe at any time by:
-
Clicking the "Unsubscribe" link in any email
-
Adjusting your preferences in your account settings
-
Contacting us through our contact form
14.2 SMS Marketing
If you opt in to receive SMS messages, you can opt out at any time by replying "STOP" to any message.
14.3 Remarketing
We use remarketing technologies (Meta, TikTok) to show you relevant ads based on your browsing behavior. You can opt out of personalized advertising through the links provided in Section 6.2.
15. Use of the Chatbot with Forms
We offer you an AI-based chatbot from Flyweight GmbH, Jungbuschstraße 28, 68159 Mannheim, Germany (https://flyweight.io/legal-notice / https://flyweight.io/privacy-statement) on our website to answer your questions. When using the chatbot, your queries are combined using the database created from the website information read from our own website and a large language model to provide you with answers to your query. The chatbot is instructed not to ask for personal data. Good to know: If separate forms appear as a result of your inquiries, in which you may then have to provide personal data based on your inquiry, the information you provide there will be processed separately and accordingly will not be sent to AI.
Processed Data Categories: The data categories result from your inquiries when you enter personal data within your question.
-
For example, if you ask: “Where is my order?”, a form will appear in which you can enter your order number and your zip code.
-
If, for example, you would like to find out more about a product and receive appropriate advice, a form will appear in which you can enter the relevant information (e.g. name, telephone, e-mail, etc.).
Purpose of Processing: Processing the information you provide to create responses to your requests using the chatbot.
-
Example: For example, if you ask: “Where is my order?” and enter your order number and zip code in the form, this information is used to make a direct request to the store system (Shopify) so that the delivery information can be sent and you can be informed about the status of the order.
-
Example: If you would like advice on a product, your request (with the data you provide in the form and the entire chat history) will be forwarded to the store operator so that they can contact you.
Data Source: We collect this data directly from you.
Legal Basis: We process data to fulfill contractual or pre-contractual obligations in accordance with Article 6, paragraph 1, point (b) of the General Data Protection Regulation (GDPR).
Data Retention: Data is stored until your inquiry is resolved or for the contract’s duration and beyond until legal retention periods (6 to 10 years) have passed.
Location of Recipients: EU and non-EU.
Guarantees for Transfers to Third Countries: EU Standard Contractual Clauses (SCC), Adequacy Decision
16. Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal effects or significantly affects you without human intervention.
15. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
Elevator Program LTD
61 Trimlestown Park
Booterstown, Dublin
Ireland
We are committed to resolving any privacy concerns promptly and transparently.
By using our Site, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.