Legal

Privacy Policy

Last updated: 25 September 2026

This policy explains what Sums Solution collects, why we collect it, and what you control. It covers the dashboard, the free scan, and the data the Sums Security Guard WordPress plugin sends when you choose to connect a site.

Who we are

Sums Solution runs the security dashboard at sumssolution.com/app. For personal data we are the controller, and questions or requests go to sumssolution@gmail.com.

Account information

Your name, email address, a hash of your password, whether the email is verified, your alert preferences and your account role. We take it when you register, verify your address or edit your profile.

Sites and scan data

The URLs you register, their platform and connection status, and the API key that identifies each site.

From scans and from the connected plugin we store findings — file paths, line numbers, rule text and evidence — the score, the installed plugin and theme inventory with versions, login events, and, when live traffic is on, buffered traffic entries: IP address, request path, user agent and status code.

Free scans

The URL you submit and, so we can rate limit and stop abuse, your IP address and browser user agent. A signed-in member's scan is saved to their account; guest scans go to a limited log used to keep the free scan working for everyone.

Payments

Card details are entered on Stripe's hosted checkout page and never reach our servers. We keep the plan, the start and end dates of the subscription and the Stripe references for our accounts.

Technical data

The session identifier kept in a cookie, the CSRF token that protects forms, your IP address, user agent and the pages you request — the ordinary server logs needed to run and secure the application.

How we use it

We use this data to:

  • run the dashboard, execute scans and show you your findings
  • send the alerts, digests and notices you asked for
  • take payments and manage subscriptions
  • stop abuse: rate limiting, brute-force and fraud checks
  • answer support requests and improve the product

We do not sell or rent your data, and we do not build advertising profiles from it.

Cookies

Only what the app needs to work: the session cookie that keeps you signed in, the remember-me cookie if you tick it, and the CSRF token. There is no advertising or analytics tracker on this site.

When the cookie notice appears, your Accept or Decline answer is remembered in your own browser (localStorage) so the notice does not reappear — it is not a cookie, it never leaves your device and it is not shared with anyone. The Cookies link in the footer clears that answer and brings the notice back.

You can clear cookies in your browser whenever you like; signing out ends the session.

Data sent by the WordPress plugin

If you paste a dashboard URL and API key into Sums Guard settings, the plugin posts its findings, the site's software inventory and buffered traffic entries to this dashboard, and the licence verdict decides whether that sync stays switched on.

Connecting is opt in: nothing leaves your site until you save those settings, and deactivating the plugin sends one goodbye call so the site shows as disconnected. The licence never turns off the plugin's local protection — scanning, firewall, login monitoring and real-time protection keep running on your server either way.

  • What is sent: file paths, line numbers and rule text of findings; WordPress and PHP versions; installed plugin and theme names and versions; and, when live traffic is enabled, the IP address, request path, user agent and status code of requests to your site.
  • How it is minimised: the values of sensitive query parameters (passwords, tokens, email addresses, nonces) are replaced with a redacted marker before a path leaves your site, the dashboard copy of IP addresses can be anonymised with the plugin option (local blocking keeps the real address), and live traffic can be limited to security events only.
  • Where it goes: your dashboard domain over HTTPS, and nowhere else. The plugin loads no scripts, styles or images from third parties.

Who we can share it with

Only what the service needs:

  • our hosting and infrastructure providers, who run the servers and backups
  • our email provider, which delivers alerts and notices
  • our payment processor, Stripe, for payments and refunds
  • authorities, when the law requires us to disclose something

We do not sell or rent personal information.

How long we keep it

We keep data only as long as it serves the purpose above:

  • account data: until you delete your account, after which it is removed from the live database and ages out of backups on their normal cycle
  • scan reports and findings: about a week by default, then pruned
  • free preview scans: 90 days, then pruned
  • traffic entries: 14 days, then pruned
  • billing records: as long as accounting rules require
  • activity and security logs: activity entries for 90 days and security alerts for 180 days, so we can investigate abuse

How we protect it

HTTPS on every page, passwords stored only as hashes, a separate rotatable API key per site, capability checks and nonces on every admin action, prepared database queries, and role-based access so only your own account sees your sites. Access for running the service is limited to the people who need it.

Your rights

You can ask us for a copy of your personal data, ask us to correct or delete it, object to how we use it, or withdraw consent where consent is the basis. Your profile lets you edit your details and delete your account yourself.

Email sumssolution@gmail.com and we reply within 30 days. You can also complain to the data protection authority in your country.

Where the data is processed

The service and its backups run on infrastructure chosen by us, which may be outside your country. By using the service you understand your data may be processed where protections differ from those where you live.

Children

The service is aimed at businesses and adults. It is not directed at children, and we do not knowingly collect data from anyone under 16.

Changes to this policy

We post the new version on this page and update the date above. For a material change we email the account owner before it applies.

Contact

Privacy questions and data requests go to sumssolution@gmail.com.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used