Notice updated 2026-09-22, revision 5 · Applies to RedirectNest’s website and service. The WordPress plugin’s local data is explained separately below.
Who is responsible?
The operator is A.M.E.X. Internet Marketing ltd, Makariou III, No.9, Larnaca, 7530, Cyprus. For privacy questions and requests, email [email protected].
What we use and why
- Private support: your message, subject, optional name/email and private-link verifier let us answer you. Customer support uses the contract or steps you request before a contract; general enquiries and abuse prevention use our legitimate interests, subject to a documented balancing assessment.
- Orders and accounts: product, site allowance, price, currency, payment status and provider references are needed to fulfil purchases and administer subscriptions. Required accounting records are retained to meet Cyprus tax and accounting obligations under the financial-record schedule below. Card entry is hosted by Stripe.
- Security: essential session data, access checks, owner MFA, audit records and short-lived rate limits protect the service. Rate limits use a keyed, daily rotating IP pseudonym, never a plain IP in the application’s limiter table. Hosting and provider logs are separate and require review.
- Optional analytics: only consent enables public-page and action counts, broad referral categories and approximate country totals. No advertising, cross-site profiling or automated decisions with legal or similarly significant effects are implemented.
- Privacy requests: we use your request and the minimum verification information necessary to fulfil our data-protection obligations. Do not send identity documents, passwords, API keys, sensitive personal information or full card details through support.
No account is required for browsing or submitting a private support ticket. Customer accounts are available for purchases. Support does not subscribe you to marketing. Replies to website tickets are shown on the private ticket page; save your private link and check it for replies. Customer account setup and password recovery use transactional email, as described below. Owner support notifications use Google Workspace and contain ticket references and owner-login links, not customer message text. If you contact us directly by email, Google Workspace processes the email content and addressing information. Optional name and email can be left blank. We cannot fulfil a purchase or answer a message without the information necessary for that request.
Cookies and browser storage
Optional analytics is currently off. We do not set advertising cookies. A choice applies to this browser, not automatically to your other devices. Rejecting is as easy as accepting; use Cookie choices in every footer to change or withdraw it. Do Not Track and Global Privacy Control disable our optional measurement. Withdrawal stops new events immediately; if offline, revocation is retried when you return.
| Storage | Purpose | Lifetime |
|---|---|---|
__Host-redirectnest_session | Essential form protection, owner sign-in and private-resource access. Secure, HttpOnly, SameSite=Lax; no cross-domain scope. | Guest browser session; each guest grant is valid for at most 8 hours. Authenticated owner sessions last up to 365 days, enforced on the server; signing out or revoking access ends them earlier. |
redirectnest_analytics_choice_v2 in local storage | Remembers a requested accept/reject choice and policy version. Acceptance includes a random receipt, stored as a hash on the server and never joined to page counts. | 180 days; expiry is checked before every event. Browser storage can also be cleared in your browser settings. |
redirectnest_pending_withdrawal_v2 in local storage | Retries a withdrawal after a connection failure. | Until the server acknowledges it, or until the old receipt expires (maximum 180 days). |
| Cloudflare Turnstile, when requested | Spam protection loads only after “Load spam protection”. Default one-use verification tokens; pre-clearance cookies must remain disabled unless separately reviewed and disclosed. | Token/provider behaviour follows the reviewed Cloudflare configuration. |
The private ChatGPT preview runs outside the VPS service. It does not accept purchases, support messages or RedirectNest analytics. The preview host may have its own access/session storage and logs; these are not covered by a claim that the entire hosting platform is cookie-free. Fonts and product assets are served locally.
How long information is kept
| Information | Application rule |
|---|---|
| Support messages and optional contacts | Deleted by the daily cleanup 365 days after the latest message, or earlier on an authorised deletion. An open privacy request or a documented, time-limited legal hold pauses automatic deletion. |
| Privacy-request cases | Closed cases: 365 days from the last update, unless their ticket is erased earlier. Open cases require owner review; they are not silently expired. |
| Private links and checkout links | Guest links: up to 1 year; browser access: 8 hours. Replaced/revoked and expired verifiers are cleaned daily. Stored checkout URLs: at most 24 hours. Submission deduplication records: 30 days. |
| Consent evidence and aggregate analytics | Receipt: up to 180 days plus 30 days, or 30 days after withdrawal. Public-page totals: 90 days. Receipt records contain no IP address or user agent. |
| Security records | Limiter pseudonyms: at most the configured rate-limit window (normally 5–60 minutes). Owner audit history: at most 180 days and 2,000 entries. Deployment logs require a separate approved schedule. |
| Orders and payment records | Invoices and necessary accounting/payment records are retained for six years from the relevant tax-return filing deadline or actual filing date, whichever is later, including applicable amended returns. Retention may be extended where legally required, including applicable tax-audit requirements or documented legal holds. This period does not apply to all customer data. Records required by law are not automatically deleted by a support-ticket request. Deletion or anonymisation requires review of the applicable filing dates and holds; no automatic six-year erasure is currently implemented. If Union OSS is used in future, records covered by that scheme will follow its ten-year requirement. |
| Backups and deletion journal | Encrypted backups are stored in a dedicated Cloudflare R2 EU-jurisdiction bucket. An hourly retention task selects snapshots older than 35 days for removal and prunes backup data no longer referenced by retained snapshots. Removal requires a recent verified recovery point and successful safety checks. Outages, repository locks and failed checks can delay expiry; 35 days is the normal retention target, not an unconditional deletion deadline. This policy applies to the dedicated R2 repository, not automatically to provider logs, email, or other local copies. A minimal deletion journal records erased ticket references for replay during restoration; recovery must preserve the latest journal and replay it before returning to service. Owner-notification delivery metadata stores opaque ticket references and delivery identifiers for duplicate suppression. These records do not contain ticket text or contact details and are reviewed when handling erasure requests and restoring service. |
Recipients and international transfers
Only authorised owners administer private records. The current deployment uses a GoDaddy VPS located in the United States for hosting, Cloudflare for proxy/DNS and Turnstile, Cloudflare R2 in its EU jurisdiction for encrypted backups, and Google Workspace for support email and owner notifications. Stripe processes hosted payment, billing and subscription information. Depending on the service, Stripe acts as our processor or as an independent controller for its own fraud-prevention, regulatory and other purposes. See Stripe’s processing agreement. Cloudflare receives the IP address and browser signals needed for Turnstile. It acts as a processor when protecting this website and as a controller for its separate purpose of improving Turnstile’s bot detection, as explained in its linked privacy notice. Loading spam protection is a deliberate request for that feature, not consent to analytics or marketing. Use our privacy contact if the challenge is inaccessible. See Stripe’s privacy information and Cloudflare’s Turnstile privacy information.
Support is operated from Cyprus using the providers listed above, including US hosting. The R2 EU setting applies to that bucket; it does not establish EU-only hosting, email or all provider processing. Provider processing terms include GoDaddy’s DPA, Cloudflare’s DPA and Google’s CDPA. These documents describe applicable transfer arrangements, including standard contractual clauses and, where applicable, adequacy arrangements. You may contact us for information about the safeguards relevant to your data. Hosting, email and network services can involve processing outside the EEA; EU backup storage does not make the complete service EU-only. WordPress.org statistics and Search Console jobs fetch plugin/search observations; support content is not sent to these jobs. Google Workspace is configured for support email and operational notifications. When customer accounts are enabled, Google Workspace also delivers transactional account and purchase-notification emails, as described below.
Email correspondence and manual review
Direct email correspondence is separate from website support tickets. Company-wide automatic mailbox deletion is not enabled. We review correspondence monthly and retain it while needed to resolve enquiries, provide ongoing service, handle disputes or meet documented legal obligations. We identify information no longer needed for deletion through that review. Account and licence records are reviewed separately from required financial records. Privacy requests are handled when received; they do not wait for the monthly review.
Your rights and how to use them
You can request access, correction, erasure, restriction, objection to processing based on legitimate interests, and portability where its legal conditions apply. You can withdraw optional analytics consent without affecting the lawfulness of earlier processing. A private ticket/order includes a JSON export and a privacy-request form. The export covers that resource; contact us for a complete access request, including other records and provider-held data. A ticket can be deleted directly unless a pending review or documented hold applies.
We normally respond within one calendar month. Complex or numerous requests may require up to two additional months; we must explain and notify you within the original month. Verification must be proportionate: possession of a private link proves access to that resource, not every record associated with an email address. Rights can have lawful limits, such as retaining accounting records or protecting another person’s rights. We explain any refusal and your complaint rights.
You may complain to the Cyprus Commissioner for Personal Data Protection or the competent supervisory authority in the EU country where you live, work or where the alleged infringement occurred. You do not have to contact us first.
WordPress plugin data
A site owner using RedirectNest is responsible for their site’s own privacy notice and lawful operation. The plugins do not set visitor cookies. Free makes no product-service requests. Pro licensing and optional fleet sharing are described below. Redirect rules, migration drafts and reports are stored in that WordPress database. URLs and paths can contain personal data even without IP addresses; avoid placing secrets or personal details in them.
Optional 404 collection is off by default. It stores limited local path counts for 7 days by default (configurable to 30 or 90), skips common private/token paths, and does not collect query strings, IPs, referrers or user agents. Pro makes destination requests only when an administrator starts a check or explicitly enables scheduled monitoring; the destination receives the server IP and requested URL. Common secret query parameters are redacted in stored check results. Plugin privacy tools can remove logs, drafts, archived reports and history; they preserve active redirects. Site backups are controlled by the site owner and require their own retention and restoration procedures.
Pro connections and optional fleet sharing
When a site administrator connects a site-specific install key, the service receives its WordPress site address, environment, entitlement reference and connection timestamps to activate that site and deliver updates. Keys are encrypted locally using WordPress salts and stored as one-way hashes on the service. Each production entitlement can include one associated staging site. This service processing supports the requested purchase; it is separate from optional analytics.
Fleet sharing is off by default and separately enabled by the site administrator. It sends Free, Pro and WordPress versions, rule count, latest failed-check count and check/worker timestamps to the private purchase dashboard. It sends no visitor identifiers or rule URLs. Remote summaries expire after 30 days. Disabling sharing stops further local sharing immediately and attempts to erase the saved summary; if the service is unreachable, retry or erase it through the purchase page. Revoked site addresses are cleared after 30 days. Minimal key-revocation records survive restore operations to prevent old credentials returning.
Optional monitoring emails use the WordPress site's configured mail transport and chosen recipient. They contain aggregate results and an administration link. The site operator is responsible for recipient authorisation and the mail provider's arrangements. Mail acceptance is not proof of delivery. Licensing and account records support ongoing service. On closure or an erasure request, we review them separately from required financial records and remove or anonymise information no longer needed, subject to documented obligations and holds. This is a manually reviewed process; the financial retention period does not automatically apply to every account field. Private sandbox licensing and update-delivery tests are kept separate from live purchases.
Changes
We update this notice when the service or processing changes. A materially changed optional-analytics purpose or policy requires a new choice. The processing described here applies when you use the corresponding support, account, purchase or plugin feature.
Customer accounts and account emails
When customer accounts are enabled, we associate verified paid purchases with the billing email returned by Stripe. That address does not prove mailbox ownership: you must use a single-use setup email to choose a password before signing in. Sandbox and live accounts are separate. We store your account email, password hash, verification time, purchase associations, hashed sessions and recovery tokens, and security activity. We never store readable passwords.
Essential customer cookies use the __Secure-redirectnest_customer prefix. The Secure, HttpOnly, SameSite=Lax customer session cookie lasts up to 365 days; form and setup cookies last up to two hours. Signing out, changing the password or revoking account access ends the applicable sessions earlier. Setup links last two hours, reset links 30 minutes. Password changes revoke previous account sessions, recovery links and linked private purchase links. Existing purchases and site licences remain.
Google Workspace delivers account setup, purchase, recovery and password-change emails. This is not marketing. Queued messages may be retried; sent or cancelled mail records are removed after 30 days, expired tokens after seven days and security activity after 180 days. Failed mail remains for operator review. Account and purchase records are retained for ongoing service and applicable recordkeeping, subject to review. Use Account & security to export account records or contact support for a complete privacy request.