Privacy Policy
Last updated: August 20, 2026
This Privacy Policy explains how SchemaGrove (“we,” “us,” or “our”), the business operating schemagrove.com, handles personal information through this website, its WooCommerce store, customer accounts, licensing and private-update service, and support.
This policy covers information processed by SchemaGrove through its vendor website and commercial services. SchemaGrove customers operate their own WordPress sites. Information stored locally by SchemaGrove Lite or Pro is generally controlled by that site owner, who should adapt the privacy-policy text supplied inside WordPress to its own use.
When you create an account, place an order, manage a subscription, request a refund, or access a protected download, we may collect your name, email, username and password hash, billing contact details, order and subscription history, purchased plan, coupons, refunds, download history, account status, communications, order notes, IP address, browser information, and timestamps. Purchasing requires a customer account.
Payments are processed by Square. Square receives information required to process the payment and may create a customer profile or store a card for recurring billing. SchemaGrove does not intend to store your full card number or card security code. WooCommerce may store a Square-issued token and limited payment metadata; we receive transaction identifiers, payment status, refund information, errors, and the payment-method label needed to administer an order and subscription.
When an administrator activates SchemaGrove Pro, the customer’s WordPress site sends the entered Product Order API Key, a random installation identifier, normalized site origin, WordPress environment type, multisite and blog context, product identifier, and installed Pro version. This is used to validate the customer, order, product, subscription, plan, site limit, and installation binding.
API Manager for WooCommerce maintains the canonical customer license resource. SchemaGrove’s private bridge uses the submitted key during activation but does not store an additional plaintext or encrypted copy of it in the bridge table. The bridge stores numeric commerce/provider references, environment and state, timestamps, and keyed hashes representing the installation, site, licensing authority, and bearer credential. Its custom activation table does not store the raw customer domain.
After activation, status, update, deactivation, and download requests use an installation-bound bearer credential. A keyed representation of the request’s network source may be retained for approximately 48 hours for abuse prevention. Hosting and security providers may separately process IP addresses and ordinary request metadata in access or security logs.
If you contact us, we process the information and files you choose to provide. SchemaGrove’s support bundle is created locally and is not uploaded automatically. Do not send passwords, raw API keys, payment-card information, database dumps, or unnecessary personal data through ordinary email.
The site uses essential WordPress and WooCommerce cookies for authentication, security, cart state, checkout, downloads, and customer sessions. These can include woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, WordPress login cookies, and order-attribution session data. Order attribution may record referral, campaign, and source information associated with an order.
WooCommerce usage tracking is currently enabled, which may send bounded store and software-environment telemetry to Automattic/Woo to improve WooCommerce. The site also retrieves fonts from Google Fonts; that request can disclose an IP address, browser information, and requested resource metadata to Google.
We do not currently use customer information for cross-context behavioral advertising, and we do not sell personal information. If tracking or advertising practices change, this policy and any required consent controls will be updated.
SchemaGrove Lite does not send site content or personal data to a SchemaGrove-operated external service. The licensing service does not automatically receive schema graphs, configured values, page content, Google Search Console analytics or OAuth credentials, OpenAI prompts or API keys, customer-site WordPress passwords, or locally generated support bundles.
A customer may optionally configure SchemaGrove Pro on its own WordPress site to communicate directly with Google Search Console or OpenAI. Search Console authorization and synchronization use credentials supplied by that site’s administrator; imported evidence remains on that WordPress site and is not sent to the SchemaGrove licensing service.
The optional OpenAI provider is disabled by default. It runs only after configuration, enabling the feature, separate consent to external data sharing, and an explicit analysis request by an authorized user. The customer site sends selected bounded content directly to OpenAI. Site owners are responsible for disclosing optional services they enable.
Where applicable, the legal basis may include contract performance, legal obligations, consent, and legitimate interests in operating and securing the Services.
We may disclose relevant information to Square and financial institutions for payment processing; our web host, infrastructure, backup, security, and delivery providers; email providers; professional advisers; authorities when required by law; and a successor in a business transaction subject to appropriate protections. WooCommerce, WooCommerce Subscriptions, API Manager for WooCommerce, and the SchemaGrove License Bridge operate within our vendor WordPress installation.
Optional customer-site integrations communicate directly from that customer’s site as described above. We do not send customer site content to Google or OpenAI merely because SchemaGrove is installed.
We retain information for as long as reasonably necessary for service delivery, subscription and license administration, security, tax and accounting duties, dispute resolution, and enforcement. Transaction records may be retained for the period required by financial and tax rules; licensing and support records may remain for the customer relationship and a reasonable period afterward; bridge rate-limit records last approximately 48 hours; and backups follow the host’s rotation schedule.
The store does not currently apply fixed automatic deletion periods to every completed, refunded, subscription, or inactive-account record. Until a formal schedule is adopted, those records may remain until manually reviewed and deleted. Information may be retained longer for legal holds, fraud prevention, or claims, and may be anonymized where practical.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; opt out of certain sales, sharing, or targeted advertising; appeal a denied request; and complain to a regulator. Email support@schemagrove.com to make a request. We may verify identity and retain information required for tax, accounting, security, fraud prevention, or legal obligations.
We use safeguards appropriate to the information processed, including HTTPS, account controls, restricted access, payment tokenization, bounded logging, keyed bridge identifiers, encrypted customer-site license credentials, and authenticated update downloads. No system is completely secure. Customers remain responsible for their own accounts, WordPress installations, credentials, and backups.
The Services are intended for adults and businesses and are not directed to children under 18. Contact us if you believe a child supplied personal information through a SchemaGrove customer account.
We may update this policy as practices, providers, or legal duties change. The date above will be revised, with additional notice where required. Privacy and support requests may be sent to support@schemagrove.com.