Privacy policy
Last updated: 8 August 2026
1. Who we are
Frey Gabor, trading as FreyGabor.com ("FreyGabor", "we", "us" or "our"), is the controller of personal data described in this Privacy Policy. This Policy applies to https://freygabor.com/developments/amelia-extensions/, customer and administrator accounts, product purchases, software licensing, downloads, updates, support, Free Install requests and associated communications.
Contact us about privacy at hello@freygabor.com. Please use the subject "Data protection request" and do not send account passwords, WordPress credentials, payment-card details or full Licence Keys by email.
This website supplies independent Amelia-compatible WordPress extensions. FreyGabor is not affiliated with Amelia/TMS.
2. Personal data we collect
We may collect and process the following categories:
- Account data: name, email address, password hash, account role, account status, registration and login timestamps.
- Order data: order number, purchased product, amount, currency, payment status, timestamps, Stripe customer, Checkout, payment-intent or subscription references, refund status and a snapshot of the purchased product.
- Legal acceptance data: the policy version, date and time at which you accepted the Terms and Refund Policy, requested immediate digital supply and acknowledged loss of the cancellation right once supply began.
- Licence data: Licence Key prefix and secure hash, product, status, issue and expiry dates, update entitlement, activation limits and validation timestamps. Plain Licence Keys may be shown securely when issued but are not stored in ordinary readable form for routine lookup.
- Website activation data: website URL and normalised domain, production or staging environment, WordPress or Extension version information where supplied, activation identifiers, status, timestamps and cryptographic request or response information.
- Download and update data: product and version requested, eligibility, secure download tokens, use and expiry timestamps and technical security records.
- Installation-request data: customer name, contact email and telephone, website address, environment, Amelia version, requested work, ticket status and updates. WordPress access credentials supplied for Free Install are encrypted separately.
- Support and communication data: messages, troubleshooting information, attachments, delivery status and notification logs.
- Technical and security data: IP address or a privacy-preserving hash where applicable, user agent, request metadata, rate-limit events, audit records, error logs and security incident information. Hosting providers may also retain standard server logs.
- Analytics and consent data: consent choice, random visitor and session identifiers, page path, referral source, device category and events such as page view, product view, checkout start or completed checkout. Raw IP addresses are not stored in the first-party analytics tables.
- Search and content administration data: public guide content, revisions and administrator actions where relevant to an authorised administrator account.
We do not intentionally collect special-category data, criminal-offence data or unnecessary sensitive information. Do not include such information in support or installation requests.
3. How we obtain personal data
We collect data directly from you when you register, purchase, activate a Licence, request a download, contact support, submit an installation request, change consent settings or otherwise use the Services.
We also receive limited data from:
- Stripe, such as payment, refund, dispute and subscription status;
- an installed FreyGabor Extension when it makes an activation, validation or update request;
- email providers such as Brevo when they report delivery or failure;
- your browser and device when essential security or consented analytics technologies operate; and
- hosting, security and infrastructure providers when they record or report technical events.
4. Purposes and lawful bases
We process account, order, Licence, activation, download and installation-request data where necessary to enter into or perform a contract with you. This includes taking payment, delivering digital content, validating single-site limits, providing updates, processing installation requests and responding to support enquiries.
We process transaction, tax, refund, complaint and compliance records where necessary to comply with legal obligations.
We process security, fraud-prevention, service-integrity, limited operational analytics, audit, compatibility and business-administration data where necessary for our legitimate interests in operating a secure and reliable licensing business, preventing unauthorised use, improving products, establishing legal claims and understanding service performance. We balance these interests against your rights and use data minimisation, hashing, access controls and retention limits.
We process optional analytics storage and any optional Google Analytics measurement on the basis of consent where consent is required. You may accept or reject analytics and later withdraw consent using the "Review analytics choice" control on this Privacy page.
We may process data to respond to a legal claim, protect vital interests in an emergency, or comply with a lawful request where another lawful basis applies.
We do not sell personal data. We do not use personal data for third-party behavioural advertising.
5. Information required to provide the Services
Account identity, contact, payment and Licence information is contractually required to supply a paid Extension and manage a single-site Licence. If you do not provide it, we may be unable to create an account, take payment, issue a Licence, provide a download or complete support.
Free Install details are optional unless you request that service. Website credentials are required only where necessary to perform the requested installation. Analytics consent is optional and refusing it does not prevent use of the website or purchase of a product.
6. Licence-server communications
Licensed Extensions connect to https://freygabor.com/developments/amelia-extensions for activation, validation, update checks and protected downloads. A request may include the Licence Key, product or plugin identifier, Extension version, website URL or domain, environment type, WordPress or PHP compatibility information where needed, and technical request metadata.
We use this information to enforce the purchased website limit, sign validation responses, provide eligible updates, diagnose compatibility and prevent fraud or abuse. We do not use licence validation to access WordPress content, Amelia customer records, bookings, payment details or the WordPress administrator area.
7. Payments
Stripe processes payment-card details on its hosted systems. We receive transaction references and status, but do not store complete payment-card numbers or card security codes. Stripe acts under its own privacy terms and may process data internationally as described in its privacy documentation.
If another payment provider is added and shown at checkout, it will process payment details under its own privacy terms. We retain only the information reasonably required to record and administer the transaction.
8. Free Install credentials
WordPress administrator and related access details submitted through the Free Install form are encrypted at rest, are not included in customer emails, and are available only to authorised administrators when necessary to perform the request. Credential access is audited.
When an installation request is marked completed, the stored credential ciphertext is permanently purged and the completed request cannot be reopened with those credentials. You should use temporary credentials where possible and revoke or change them immediately after completion. If you cancel an open request, contact us to request earlier credential deletion.
9. Cookies, local storage and analytics
The site uses an essential session cookie named fglm_session to keep accounts signed in, protect forms and maintain security. It expires when the browser session ends and is marked Secure, HttpOnly and SameSite=Lax where supported.
The fg_analytics_consent cookie stores your analytics choice for up to 12 months. If you consent, random analytics visitor and session identifiers may be stored in localStorage and sessionStorage. These identifiers are cryptographically hashed by the server before detailed events are stored.
First-party analytics records page paths, referral sources, device categories and conversion events. Raw IP addresses are not stored in the analytics tables. Detailed events are retained for 90 days; aggregated statistics that no longer identify a visitor may be retained longer for historical reporting.
Google Analytics 4 is optional and is not currently loaded unless a valid Measurement ID is configured and you have granted analytics consent. Non-essential analytics is not loaded before consent where consent is required. You can review or withdraw your analytics choice using the control on this page; withdrawal does not affect processing that was lawful before withdrawal.
10. Who receives personal data
We disclose only what is necessary to:
- hosting, database, security, backup and infrastructure providers that operate the website and licence service;
- Stripe and any clearly identified payment provider for checkout, fraud prevention, refunds and disputes;
- Brevo or another configured email-delivery provider for transactional emails;
- professional advisers, insurers, auditors, tax authorities, regulators, courts or law enforcement where necessary or legally required;
- contractors authorised to support or maintain the Services under confidentiality and data-protection obligations; and
- a successor organisation if the business or relevant assets are lawfully transferred, subject to appropriate safeguards and notice where required.
IndexNow receives public sitemap URLs when we submit published pages to participating search engines. Google Search Console may receive public sitemap URLs and inspection requests when connected. These services are not used to transmit customer Licence Keys or private account content.
11. International transfers
Some processors, including payment, email, analytics, hosting or support providers, may process data outside the United Kingdom or the European Economic Area. Where required, we rely on an applicable adequacy regulation or approved safeguards such as the UK International Data Transfer Agreement, UK Addendum to standard contractual clauses, or equivalent contractual and technical safeguards. You may ask for further information about the relevant safeguard by emailing hello@freygabor.com.
12. Retention
We retain personal data only for as long as reasonably necessary for the purpose collected, including legal, accounting, security and dispute requirements. Our usual criteria are:
- Account data: while the account is active, then for up to six years after closure or the last relevant transaction where needed for legal claims, tax or fraud prevention.
- Orders, payments, refunds, invoices and tax records: normally six years after the end of the relevant financial year or longer if law requires.
- Licence and activation records: for the Licence lifetime and normally up to six years afterwards to establish entitlement, prevent abuse and resolve disputes.
- Free Install credentials: until the request is completed or earlier deletion is requested and operationally possible; credentials are purged automatically on completion.
- Installation ticket details and customer-visible updates: normally up to six years after completion where needed to record the service performed or resolve a claim.
- Support correspondence and complaints: normally up to six years after the matter closes where relevant to a contract or legal claim; routine enquiries may be deleted sooner.
- Detailed first-party analytics events: 90 days. Aggregated non-identifying statistics may be retained longer.
- Password-reset links and download tokens: expire after their stated security period; related audit evidence may be retained for security and dispute purposes.
- Security, rate-limit and audit records: for a proportionate period based on risk, normally no longer than necessary to investigate incidents, prevent abuse or establish legal claims.
Data may be retained longer where required by law, a court order, an active dispute, fraud prevention or a legal hold. It may be deleted or anonymised earlier when no longer needed.
13. Security
We use measures appropriate to the risk, including HTTPS, password hashing, encrypted secrets and installation credentials, signed licence responses, least-privilege administration, CSRF protection, rate limiting, audit logs, restricted downloads and backups. No internet service is completely secure, so you must also protect your account and website credentials.
If a personal-data breach creates a risk to individuals, we will assess it, contain it and notify the Information Commissioner's Office and affected individuals where required by law.
14. Your data-protection rights
Depending on the circumstances and lawful basis, you may have rights to:
- be informed about processing;
- request access to your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing relies on consent; and
- complain to a supervisory authority.
These rights are not absolute. For example, we may retain transaction information needed for tax obligations or the establishment of legal claims. We may request information necessary to verify identity and protect another person's data. We normally respond within one month, subject to any lawful extension.
15. Your right to object
You have the right to object to processing based on our legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
You have an absolute right to object to direct marketing. We do not currently use customer data for third-party advertising, and any future marketing message will include a clear opt-out.
16. Automated decision-making
Automated security and licence rules may reject an invalid key, excess website activation, ineligible download, rate-limited request or failed payment. These controls protect the contract and service but are not intended to make solely automated decisions that produce legal or similarly significant effects beyond administering the requested Licence or transaction. Contact us if you believe an automated control is wrong and you want human review.
17. Children
The Services are intended for adults and organisations and are not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has supplied data, contact us so that we can investigate and delete it where appropriate.
18. Complaints
Please contact hello@freygabor.com first so we can try to resolve a privacy concern.
You also have the right to complain to the UK Information Commissioner's Office:
- Website: https://ico.org.uk/make-a-complaint/
- Telephone: 0303 123 1113
If you live outside the UK, you may also contact the data-protection authority in your country where applicable.
19. Changes to this Policy
We may update this Policy to reflect legal, technical or operational changes. The current version and last-updated date will be published here. Where a change materially affects how existing personal data is used, we will provide additional notice or seek consent where required.
20. Contact
Data controller: Frey Gabor, trading as FreyGabor.com
Website: https://freygabor.com/
Privacy email: hello@freygabor.com
Website analytics and privacy choices
When enabled, this website uses first-party analytics to understand page visits, referral sources, device categories and purchase-funnel events. Raw IP addresses are not stored. Random visitor and session identifiers are cryptographically hashed on the server. Detailed analytics events are retained for 90 days; aggregated daily totals may be retained for historical reporting.
Analytics storage is disabled until you accept it where consent is required. Google Analytics 4 is optional and loads only after analytics consent when the administrator has configured a Measurement ID. Signed-in account IDs are not linked to analytics unless the administrator explicitly enables that setting.