Free site audit · No lock-in contracts · US-based WordPress team hello@thinkflow.agency Book a call
Legal

Privacy Policy

Last updated October 2026.

This Privacy Policy explains how WP Maintenance Packages ("we", "us"), operated by ThinkFlow Media, handles information when you use this website and our services.

Information we collect

Information you provide. We collect information you give us directly, such as your name, email address and website URL when you contact us, request an audit or book a call. If you purchase a plan, we also collect billing details through our payment processor.

Automatically collected data. When you visit our site, we automatically collect standard technical data including your IP address, browser type, device type, operating system, referring URL, pages visited, time on page and approximate geographic location. This data is collected through server logs and analytics tools.

How we use your information

  • To respond to enquiries and provide the services you request
  • To send you information you asked for, such as a site audit or proposal
  • To process payments and manage your account
  • To operate, secure and improve our website and services
  • To detect and prevent fraud, abuse or security incidents
  • To meet legal, tax and accounting obligations

We do not sell your personal information. We do not use your data for automated decision-making or profiling.

Cookies and analytics

We use the following types of cookies:

  • Essential cookies — required for the site to function (session management, security tokens, cache keys). These cannot be disabled.
  • Analytics cookies — help us understand how visitors use the site (pages visited, time on site, traffic sources). We use Google Analytics with IP anonymisation enabled.
  • Preference cookies — remember choices you make such as timezone or form prefills.

You can control non-essential cookies through your browser settings. Disabling them may affect some features but will not prevent you from using the site.

Third-party services

We use trusted third parties to run our business. Each processes data only as needed to deliver their service and under their own privacy terms:

  • Calendly — scheduling calls and consultations
  • Stripe — payment processing (we do not store card details)
  • Google Analytics — website usage analytics
  • Hostinger — website hosting and infrastructure
  • LiteSpeed Cache — performance optimisation

We do not share your personal data with any third party for their own marketing purposes.

Data retention and security

We keep personal data only as long as needed for the purposes above or as required by law. Enquiry data is retained for up to 24 months after your last interaction. Billing records are retained for the period required by applicable tax law (typically 7 years). When data is no longer needed, it is securely deleted or anonymised.

We take reasonable technical and organisational measures to protect your data, including encrypted connections (TLS), access controls, regular software updates and off-site backups.

International data transfers

Our servers are located in the United States. If you are visiting from outside the US, your data may be transferred to and processed in the US. By using our site, you consent to this transfer. Where required by law (such as under the GDPR), we rely on Standard Contractual Clauses or equivalent safeguards.

Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate or incomplete data
  • Deletion — request that we delete your personal data
  • Portability — request your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests

California residents (CCPA): You have the right to know what personal information is collected, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us using the details below.

EEA/UK residents (GDPR): You have the additional right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

To make any data request, email us at hello@thinkflow.agency. We respond to all verified requests within 30 days.

Children’s privacy

Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of the site after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy or your data? Email hello@thinkflow.agency.

This policy is a general starting point and not legal advice. Have it reviewed against your jurisdiction before relying on it.

Packages Book a call