This Privacy Policy explains how WP Tango LLC ("WP Tango", "we", "us", or "our") handles personal information in connection with our websites, client portal, billing systems, support channels, and managed WordPress hosting services (collectively, the "Services"). It applies both to personal information we handle to run our business and, in a more limited way, to personal information contained in the Customer Content you host with us.
Please read this Policy together with our Terms of Service and Acceptable Use Policy. If you do not agree with this Policy, you must not use the Services.
Scope and Roles
This Privacy Policy ("Policy") describes how WP Tango LLC ("WP Tango", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information in connection with our websites, client portal, billing systems, support channels, and managed WordPress hosting services (collectively, the "Services").
For personal information we handle to operate our business (for example, information about account holders, prospects, applicants, and website visitors), WP Tango acts as an independent controller. For personal information contained in Customer Content that you upload to, store on, or process through the Services, WP Tango acts as a processor (or service provider under applicable U.S. laws) on your behalf, and your privacy notice and lawful basis govern that data.
This Policy does not apply to third-party websites, services, or applications that are linked from or integrate with the Services. Their own privacy notices govern.
Information We Collect
We collect the following categories of personal information:
- Account and billing information. Name, business name, email address, telephone number, mailing address, tax identifiers where required, and payment method identifiers (such as card brand and last four digits) returned by our payment processor. We do not store full card numbers or CVV codes on our systems.
- Authentication data. Usernames, hashed passwords, multi-factor authentication factors, session tokens, API keys, and SSH public keys you associate with your Account.
- Support and communications. The contents of tickets, chats, emails, and calls with our support and sales teams, including any attachments, screenshots, or diagnostic files you share.
- Server and application telemetry. Access logs, error logs, PHP-FPM and web server logs, security events, resource usage metrics, backup metadata, and configuration snapshots generated by the Services.
- Website and device data. IP address, user agent, referrer, pages viewed, timestamps, approximate location derived from IP, device and browser characteristics, and cookie or similar identifiers collected when you visit our marketing sites or client portal.
- Customer Content. Any files, databases, credentials, personal data of your end users, or other materials that you or your users upload to, store on, or transmit through the Services.
- Anti-fraud and compliance data. Signals used to detect fraudulent orders, chargeback risk, sanctions screening, and abuse (for example, order fingerprints, VPN and proxy detection scores, and correspondence patterns).
- Prospect and marketing data. Business contact details, information you submit through forms, newsletter subscriptions, event attendance, and engagement with our marketing communications.
- Applicant data. Information submitted through job applications, including CVs, work history, and interview notes.
We do not intentionally collect government-issued identifiers, biometric data, precise geolocation, or special categories of personal data described in Article 9 of the GDPR. Do not upload such data to our support channels unless required and appropriately protected.
Sources of Information
- Directly from you when you create an Account, place an order, use the portal, contact support, respond to a survey, or subscribe to our communications.
- Automatically from your devices and from the Services through cookies, server logs, and application telemetry.
- From service providers and partners, including payment processors, fraud prevention vendors, email delivery providers, analytics providers, and DNS and edge network providers.
- From public sources and third parties such as business registries, sanctions and denied-party lists, and referral partners.
How and Why We Use Information
We use personal information for the following purposes:
- Provide the Services. Provisioning, operating, maintaining, and supporting your hosting environments, including migrations, restores, and configuration changes.
- Account administration. Verifying identity, processing orders, invoicing, collecting payment, issuing credits or refunds, and managing renewals and cancellations.
- Security and abuse prevention. Detecting, investigating, and responding to fraud, abuse, malware, credential stuffing, DDoS activity, and violations of our Acceptable Use Policy or Terms of Service.
- Reliability and performance. Monitoring uptime, throughput, error rates, resource consumption, and capacity planning.
- Product improvement. Analyzing aggregated usage to improve stability, performance, features, and documentation.
- Customer support. Responding to your requests, troubleshooting issues, and communicating about service events.
- Communications. Sending transactional messages (billing, security, service notifications, policy changes) and, subject to your preferences and applicable law, marketing communications.
- Legal and regulatory compliance. Complying with tax, accounting, sanctions, anti-money-laundering, law-enforcement, and other legal obligations.
- Corporate transactions. Evaluating and completing mergers, acquisitions, financings, or asset transfers.
Legal Bases (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Contract. To provide the Services and administer your Account under our Terms of Service.
- Legitimate interests. To secure our infrastructure, prevent fraud, improve the Services, conduct direct marketing to business contacts, and defend legal claims, where those interests are not overridden by your rights and freedoms.
- Legal obligation. To meet tax, accounting, sanctions, and other statutory obligations.
- Consent. Where required by law, for example, for certain cookies, marketing emails to individuals, or optional analytics. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
International Data Transfers
WP Tango is headquartered in the United States, and our infrastructure and sub-processors may operate in the United States and other countries. When we transfer personal information from the EEA, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms.
You acknowledge that laws of destination countries may differ from those of your jurisdiction and that government authorities in those countries may be able to access personal information under applicable law.
Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, including to satisfy legal, tax, accounting, security, and audit obligations, and to defend or bring legal claims. Typical retention approaches:
- Account and billing records are retained for the life of the Account and for a period afterward to satisfy accounting, tax, and dispute-resolution requirements.
- Server and access logs are retained for a short operational window sufficient for security investigations and performance troubleshooting.
- Backups are retained according to the Service Plan backup retention window and expire on a rolling basis.
- Support communications are retained for reference, quality assurance, and dispute resolution.
- Marketing lists are retained until you unsubscribe or become inactive under our list-hygiene practices.
When personal information is no longer required, we securely delete, destroy, or anonymize it, unless retention is required by law.
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include encryption in transit, encryption at rest for backups, network segmentation, least-privilege access controls, multi-factor authentication for staff, endpoint protection, logging and monitoring, and regular reviews of vendor security posture.
No method of transmission or storage is completely secure. You are responsible for using strong, unique passwords, enabling two-factor authentication where available, protecting your credentials and API keys, and keeping your WordPress installations, plugins, and themes up to date.
Customer Content and Your Site Visitors
You control what personal information is collected, stored, and transmitted through your websites and applications hosted with us. As between you and WP Tango, you are the controller (or business) for that Customer Content. You are responsible for:
- Providing an accurate privacy notice, cookie banner, and consent mechanism on your sites.
- Establishing a lawful basis for processing personal information of your end users.
- Responding to data subject requests from your end users.
- Executing a Data Processing Addendum with us where required. Contact us at privacy@wptango.com to request one.
- Not uploading personal information that is unlawful, that you lack authority to process, or that requires safeguards beyond those offered by the Services.
Your Privacy Rights
Depending on where you live, you may have rights with respect to personal information we hold about you, including the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete personal information, subject to legal exceptions.
- Restrict or object to certain processing, including direct marketing.
- Data portability, where applicable, for information you provided to us.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local supervisory authority (EEA and UK residents).
- Non-discrimination for exercising your rights (U.S. state privacy laws).
- Appeal a denial of your request, where required by U.S. state law.
To exercise any of these rights, email privacy@wptango.com from the email address associated with your Account, or use the contact form on our website. We may need to verify your identity before responding. If you are exercising rights on behalf of your website's end users, please contact the operator of that website directly, as we act as their service provider.
We do not use personal information to make decisions that produce legal or similarly significant effects about you solely through automated processing.
U.S. State Privacy Disclosures
This section provides additional disclosures for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other U.S. states with comprehensive privacy laws.
Categories collected and disclosed. In the past 12 months we have collected and disclosed for business purposes the categories of personal information described in "Information We Collect" and "How We Share Information", including identifiers, commercial information, internet or network activity, geolocation derived from IP, professional information, and inferences drawn from the foregoing.
No sale, no cross-context behavioral advertising. We do not sell personal information and we do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of consumers under 16 years of age.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would require an opt-out right under applicable law.
Right to appeal. If we deny your request, you may appeal by replying to our decision. If your appeal is denied, you may contact your state attorney general.
Authorized agents. You may designate an authorized agent to submit requests on your behalf. We may require the agent to provide proof of your authorization and may require you to verify your identity directly.
Children
The Services are directed to businesses and are not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@wptango.com and we will delete it in accordance with applicable law.
Third-Party Sites, Plugins, and Integrations
Our Services may link to or integrate with third-party websites, plugins, and services (for example, payment processors, CDN providers, analytics tools, email delivery providers, or WordPress plugins you install). We are not responsible for the content, privacy practices, or security of those third parties. Review their privacy notices before providing personal information.
Do Not Track and Global Privacy Control
Our marketing sites do not currently respond to browser "Do Not Track" signals. Where required by applicable U.S. state law, we treat a recognized Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing for cross-context behavioral advertising, to the extent such activities occur.
Marketing Communications
You may opt out of promotional email at any time by using the unsubscribe link included in each promotional message or by contacting privacy@wptango.com. You cannot opt out of transactional messages relating to your Account, billing, security, or the Services.
Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Effective" date and notify you by email, through the client portal, or by other reasonable means. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
How to Contact Us
Questions, requests, or complaints about this Policy or our privacy practices can be sent to:
- Email: privacy@wptango.com
- Postal: WP Tango LLC, Attn: Privacy, United States
If you are located in the EEA, the United Kingdom, or Switzerland and prefer to contact a local representative, email privacy@wptango.com and we will route your request appropriately.

