Privacy Policy
Last updated: Sep 24, 2026
This policy explains what personal data WP Monitor collects, why, how long we keep it and what rights you have. We collect as little as possible: no advertising, no analytics, no tracking.
Who we are
WP Monitor is run by WEBDEV SRL, Bucharest, Romania, VAT code RO14810481, trade registry number J40/7484/2002 ("we"). We are the controller of the personal data described here.
For anything about your data, write to [email protected].
What we collect and why
Scans without an account. When you scan a site we store the site address you entered, the scan results, a screenshot of the site's public homepage, and your IP address (for IPv6, only the network part). The IP address is used to limit the number of free scans per day and to make sure only you can run your scan. Legal basis: our legitimate interest in providing the free scanner and protecting it from abuse (Art. 6(1)(f) GDPR).
Your account. Name, email address, preferred language, your plan, your alert setting and, if you set one, a password (stored only as a secure hash). Each login creates a session, stored with your IP address and browser name so the login can be secured. Legal basis: the contract with you (Art. 6(1)(b) GDPR).
Monitored sites. The sites you add, their scan history and reports, and the activity shown on your dashboard. Legal basis: contract.
Emails. We send you the confirmation email, login links, security alerts about your sites (you can turn these off on your dashboard) and messages about your subscription. We do not send newsletters or advertising. Legal basis: contract.
Billing and payments. For paid plans: the billing details you enter (name, company, VAT ID, address) and your payment history. Card payments are handled by NETOPIA Payments (NETOPIA FINANCIAL SERVICES S.A., Romania) on its own secure page; we never see or store your card details. For monthly renewals NETOPIA can keep your card and give us a token that only works for charging our plans, and the masked card number (e.g. 9900****1234) to show on your profile. The token is deleted when you cancel your plan or delete your account. When you enter a VAT ID we check it in the European Commission's VIES service. Legal basis: contract, and our legal obligations under tax and accounting law (Art. 6(1)(c) GDPR).
Messages. When you use the contact form or report a problem or abuse, we store and receive by email what you write, your name, email address, the site and report it is about, and your IP address. Legal basis: our legitimate interest in answering you and improving the service; for customers also the contract.
How we scan websites
A scan only looks at what any visitor can see: the public pages and files of the site, requested over the internet. We never log in to a site and never need any access to it.
To answer some checks we ask outside services about the site's domain name, never about you: WordPress.org (current WordPress, plugin and theme versions) and the NordSpam, Quad9 and Cloudflare blocklists (whether the domain is listed as malicious or spam). Only the domain name of the scanned site is sent to them.
Reports have a random, hard to guess address. Anyone you share that address with can open the report.
Who receives your data
We host WP Monitor and send its emails ourselves, on servers operated by WEBDEV SRL in the European Union. We do not sell your data, and we do not share it with anyone for their own purposes.
Your data only leaves us in these cases: NETOPIA Payments, which processes your payment in the European Union, the VIES check of a VAT ID, our accountant and the tax authorities for invoices, and authorities where the law obliges us.
How long we keep it
- Account data, monitored sites and dashboard activity: until you delete your account.
- Login sessions: they end after 24 hours without activity, and at most 7 days after you log in.
- Login and confirmation links: 15 minutes and 24 hours; deleted a day after they expire.
- IP addresses stored with scans and the daily scan counters: 30 days.
- Scan reports: they remain available at their link. When you delete your account, the reports you ran are no longer linked to you.
- Messages and reports sent through the contact form: 2 years.
- Invoices and payment records: as long as Romanian accounting law requires (currently up to 10 years).
Cookies and storage in your browser
We use one cookie, and only after you log in: wpm_session, which keeps you logged in. It is strictly necessary for the service you asked for, so it does not require consent, and it is deleted when you log out.
The site also remembers a few choices in your browser's own storage, which never leaves your device: the light or dark theme (theme), the cards or list view of your sites (wpm.sitesLayout), and, for a moment, the site you asked to scan from your dashboard (wpm.scan).
We do not use analytics, advertising or social media cookies, and pages do not load anything from other companies.
Your rights
You have the right to access your data, have it corrected or deleted, restrict its processing, receive it in a portable format, and object to processing based on our legitimate interest. You can correct your details and delete your account yourself on your profile page; for anything else, write to [email protected]. We answer within one month.
You can also complain to the Romanian data protection authority (ANSPDCP, https://www.dataprotection.ro) or to the authority in the EU country where you live.
Security
All traffic is encrypted (HTTPS). Passwords are stored only as secure hashes, and login cookies and email links are random values of which we keep only a hash, so a copy of our database could not be used to log in.
Children and changes
WP Monitor is meant for website owners and is not directed at children under 16.
If we change this policy we will publish the new version here with a new date, and tell account holders by email about important changes.