Privacy Policy
Last updated: December 26, 2025
Contents
Summary
We practice Data Minimization. We avoid collecting personal data whenever possible. We don't track your website visitors, we don't sell data, and we only process what's technically necessary to deliver optimized images.
1. Who We Are
The WPimg service ("Service") is operated by:
- Business: Trimbit Ltd
- Location: Finland
- Contact: [email protected]
As the data controller for the Service, we are responsible for ensuring your data is handled in accordance with applicable privacy laws, including the EU General Data Protection Regulation (GDPR).
2. What Data We Collect & Why
We collect only what is necessary to provide and improve the Service. Here's a clear breakdown:
2.1 Service Data (The CDN)
When a visitor views an image served by our CDN, their browser automatically sends technical data to our infrastructure. This includes:
| Data | Purpose | Retention |
|---|---|---|
| IP Address | Required to route image data back to the visitor's browser | Not permanently stored by us |
| User Agent | Determines browser capabilities to serve the optimal image format (AVIF, WebP, or original) | Not permanently stored |
| Referrer URL | Domain verification to ensure authorized usage | Not permanently stored |
Important: We do not use this data to track, profile, or identify individual visitors. We do not combine this data with other sources. We do not sell or share this data with advertisers.
2.2 Plugin User Data
Free Tier Users
If you use the free tier, no personal data is required. You simply install and activate the Plugin—no registration, email, or account needed. The only data processed is the technical CDN data described in Section 2.1 above, plus your domain name (automatically detected from where the Plugin is installed).
Paid Subscribers
When you purchase a paid subscription, we process:
| Data | Purpose | Legal Basis |
|---|---|---|
| Email Address | License key delivery, support communication, important service updates | Contract Performance (Art. 6(1)(b)) |
| Domain Name(s) | License validation and ensuring authorized CDN usage | Contract Performance (Art. 6(1)(b)) |
| License Key | Service authentication and access control | Contract Performance (Art. 6(1)(b)) |
All payment data is handled entirely by our Merchant of Record, Lemon Squeezy. We never receive, process, or store your payment card information.
2.3 Website Analytics
Our marketing website (wpimg.io) may use basic, privacy-respecting analytics to understand traffic patterns. We do not use invasive tracking technologies or share analytics data with third parties for advertising purposes.
3. Third-Party Subprocessors
We use trusted third-party infrastructure to provide the Service. Your data may flow through the following services:
Cloudflare
- Location: Global network
- Purpose: Content Delivery Network, image optimization, DDoS protection, and security
- Data Processed: IP addresses, request headers, image data
- Privacy Policy: cloudflare.com/privacypolicy
Cloudflare processes IP addresses to prevent DDoS attacks, route traffic, and deliver content efficiently. Cloudflare is certified under the EU-US Data Privacy Framework.
Lemon Squeezy
- Location: USA
- Purpose: Merchant of Record — handles all payments, invoicing, refunds, and tax compliance
- Data Processed: Name, email, payment information, billing address
- Privacy Policy: lemonsqueezy.com/privacy
Lemon Squeezy acts as the Merchant of Record for all purchases. They are responsible for PCI compliance and secure handling of payment data.
Email Service Provider
- Purpose: Transactional emails (license delivery, support responses)
- Data Processed: Email address, message content
4. Data Retention
CDN Logs
We do not permanently store end-user IP addresses. Request logs are retained by our infrastructure provider (Cloudflare) only for a short period necessary for security monitoring and debugging, after which they are automatically deleted.
We do not have access to historical logs that would allow us to identify individual visitors to your website.
Paid Subscriber Data
For paid subscribers, we retain your subscription and license information for as long as:
- Your subscription is active
- Required for legal or tax compliance (typically up to 7 years for invoicing records)
- Necessary to resolve disputes or enforce our agreements
Upon request, we will remove your personal data within 30 days, except where retention is required by law.
Free tier users: Since no personal data is collected, there is nothing to delete. Your domain is automatically removed from our system when you deactivate the Plugin.
Cached Images
Optimized images are cached on our CDN for performance. These caches are automatically purged based on cache policies and do not contain personal data.
5. Your Rights
Under the GDPR and other applicable privacy laws, you have the following rights:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restrict Processing
Request limitation of how we process your data.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests.
Since we do not permanently store end-user IP addresses or use them to identify individuals, we generally cannot fulfill Access Requests for visitors to websites using our Service. We cannot identify who visited which website or when, because we don't retain that data.
To exercise any of these rights regarding your personal data (paid subscribers only—free tier users have no personal data stored), contact us at [email protected]. We will respond within 30 days.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi).
7. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
For material changes that significantly affect how we handle your data, we will make reasonable efforts to notify you via email or through the Service before the changes take effect.
8. Contact
For any privacy-related questions, concerns, or to exercise your rights:
- Email: [email protected]
- Business: Trimbit Ltd
- Location: Finland
We aim to respond to all privacy inquiries within 30 days.