WooBaba
Features
Core Features How It Works 3D Gallery Showcase Compatibility Matrix
Live Demo Pricing Docs FAQ Sign In
Sign In Get 3D Gallery
Data Governance & Compliance

Privacy Policy & Data Protection Notice

Effective & Last Modified Date: August 27, 2026

This Privacy Notice for WooBaba (operated via https://woobaba.dev, referred to as "WooBaba", "we", "us", or "our") governs the collection, processing, storage, and retention of personal data when you access our website, use our client portal, purchase downloadable software packages, or communicate with our engineering and support departments.

We are dedicated to maintaining transparent and lawful data operations in accordance with international data protection frameworks, including the European Union General Data Protection Regulation (EU GDPR), the UK Data Protection Act, and applicable global electronic commerce privacy standards.


1. Identity of the Data Controller

The entity determining the purposes and technical means of processing personal data on this platform is:

  • Entity Name: WooBaba Engineering Team
  • Website: https://woobaba.dev
  • Data Protection Officer (DPO) Contact: privacy@woobaba.dev
  • Support Desk Endpoint: https://woobaba.dev/my-account/

2. Categories of Personal Data We Collect

We classify the data collected into distinct operational categories:

A. Directly Provided Identification & Account Data

  • Identity Information: First name, last name, business or corporate entity name.
  • Authentication Credentials: Unique username, securely hashed password representations (we never store plain-text passwords), and cryptographic user session tokens.
  • Contact Information: Primary billing email address, secondary contact email, and telephone number (if provided for technical verification).
  • Billing Details: Physical billing street address, city, state/province, postal/ZIP code, and country of tax residence.

B. Software Licensing & Deployment Metadata

  • Target Domain Records: The authorized top-level domain (e.g., clientstore.com) or designated local development/staging environment tied to an active license key.
  • Licensing Telemetry: When the plugin validates authorization against our license server, we process the active license key, installed plugin build version, WordPress core version, active WooCommerce build, and server PHP runtime environment.
  • Instance Status: Activation timestamps, expiration dates, activation lock flags, and update entitlement statuses.

C. Financial, Order & Cryptocurrency Transaction Data

  • Transaction Identifiers: Internal WooCommerce Order ID, invoice numbering, payment gateway transaction reference IDs, and public blockchain Transaction Hashes (TxID).
  • Cryptocurrency Settlement Data: When settling invoices via our cryptocurrency payment processors (such as NOWPayments), we record the selected cryptocurrency ticker, deposit address, fiat equivalent value at settlement, network confirmation counts, and payment completion status.
  • Absolute Financial Safety: WooBaba never collects, inspects, or retains your private keys, seed phrases, custody wallet credentials, or credit card CVV details.

D. Automated Telemetry, WebGL & System Logs

  • Server Log Records: Internet Protocol (IP) address, HTTP request headers, browser type and version, operating system architecture, referring URL paths, and precise UTC request timestamps.
  • Client State Identifiers: Theme visual preference state (dark vs. light mode saved locally), shopping cart persistence cookies, and active session identifiers.

3. Legal Bases for Data Processing (GDPR Compliance)

Under Article 6 of the GDPR, we only process personal information where a valid legal justification exists:

  • Contractual Necessity (Art. 6(1)(b) GDPR): Processing is mandatory to generate cryptographic license keys, grant software downloads, provide update channels, and fulfill sales contracts.
  • Legal Obligation (Art. 6(1)(c) GDPR): Retaining mandatory accounting ledgers, invoices, value-added tax records, and cooperating with statutory regulatory authorities.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Protecting our platform infrastructure against Distributed Denial of Service (DDoS) attacks, enforcing license authenticity, preventing unauthorized plugin redistribution, and troubleshooting technical errors.
  • Explicit Consent (Art. 6(1)(a) GDPR): Where you explicitly opt-in to optional technical announcements, beta testing releases, or direct marketing communications.

4. Third-Party Service Providers & Data Transfers

We do not sell, rent, monetize, or disclose your personal data to external data brokers. Data sharing is strictly limited to authorized third-party processors operating under binding Data Processing Agreements (DPAs):

Third-Party Processor Processing Category Purpose & Scope
NOWPayments Payment Gateway Validating blockchain crypto transactions and order settlements.
Cloud Infrastructure & CDN Hosting & Edge Network Encrypted delivery of software builds, CDN routing, and firewall protection.
Transactional Mail Relay SMTP Infrastructure Dispatching order receipts, account reset links, and license keys.
Support Desk Platform Customer Service Tracking technical inquiries, license renewals, and bug reports.

5. Cookies & Local Storage Architecture

Our website utilizes zero tracking or invasive third-party behavioral advertising cookies. We only use functional and strictly necessary client-side storage technologies:

  • WooCommerce Session Cookies (wp_woocommerce_session_*): Retains cart state, order items, and checkout totals as you navigate the website.
  • Authentication Tokens (wordpress_logged_in_*): Maintains secure session persistence inside your Client Account area.
  • Browser LocalStorage (wb_theme): Retains your dark/light UI preference locally on your device without transmitting data back to our web servers.

6. Data Retention Timelines

We maintain defined data lifecycle policies:

  • Active License & Account Records: Maintained for the entire duration of your active software subscription plus 24 months thereafter to facilitate hassle-free renewals.
  • Commercial & Financial Invoices: Retained for a mandatory statutory period of seven (7) to ten (10) years in compliance with international taxation and corporate auditing rules.
  • Licensing Server Logs: Technical validation pings and server access logs are automatically rotated and purged after 90 days.
  • Support Ticket History: Retained for 36 months to provide ongoing technical context for complex plugin installations.

7. Technical & Organizational Security Controls

To safeguard personal information against unauthorized access, destruction, loss, or alteration, we maintain industry-standard security safeguards:

  • End-to-End Encryption: Enforced TLS 1.3 cryptographic protocols with modern cipher suites across all public web requests.
  • Database Hardening: Principle of least privilege (PoLP) access control on license server clusters and isolated production environments.
  • Integrity Monitoring: Continuous automated malware scanning, strict Content Security Policies (CSP), and automated encrypted off-site backups.

8. Your Statutory Rights Under GDPR & International Law

You have full autonomy over your personal information. You are entitled to exercise the following rights free of charge:

  • Right of Access (Art. 15 GDPR): Request written confirmation of whether your data is being processed, including a portable export of all records.
  • Right to Rectification (Art. 16 GDPR): Request prompt correction of inaccurate or outdated contact, billing, or domain data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request the permanent deletion of your account and personal details from our active databases, provided there is no conflicting legal obligation (such as tax record preservation).
  • Right to Restriction of Processing (Art. 18 GDPR): Request the temporary restriction of processing activities under contested conditions.
  • Right to Data Portability (Art. 20 GDPR): Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
  • Right to Object (Art. 21 GDPR): Object at any time to data processing based on legitimate business interests.
  • Right to Lodge a Complaint: File a formal complaint with your relevant national Data Protection Supervisory Authority if you believe our data processing infringes applicable laws.

9. Protection of Minors

WooBaba software tools and commercial licensing services are intended strictly for professional businesses, agency operators, and adult store administrators. We do not knowingly solicit or collect personal information from individuals under eighteen (18) years of age. Any inadvertent record identified from a minor will be immediately deleted.

10. Policy Revisions & Notifications

We reserve the right to modify this Privacy Notice to reflect structural feature enhancements, new payment gateways, or updated regulatory requirements. Material revisions will be highlighted with an updated "Effective Date" at the head of this page, and registered license holders will receive notification via their account dashboard.

11. Contacting the Privacy Officer

For inquiries, access requests, or license domain transfers, please reach out to our team:

  • Dedicated Privacy Mailbox: privacy@woobaba.dev
  • Direct Account Portal: Client Dashboard → Support Desk
  • Typical Response Window: Within 24 to 48 business hours.
WooBaba

Next-generation 3D spatial commerce tools for WordPress & WooCommerce.

⚡ Instant Crypto Payments via NOWPayments

Products

  • 3D Gallery Store
  • Live Walkthrough
  • Pricing & License
  • FAQ

Resources

  • Documentation
  • Changelog
  • Client Dashboard
  • Support Desk

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
© 2026 WooBaba. All rights reserved. Built for high performance & clean WebGL rendering.