Last updated September 30, 2026. Effective September 30, 2026.
On this page
- The short version
- 1. Who is responsible for your data
- 2. What this policy covers
- 3. What we collect, why, and on what legal basis
- 4. Your donors’ data and the free plugin
- 5. Who we share data with
- 6. Transfers outside the European Union
- 7. How long we keep data
- 8. Your rights
- 9. Your right to object
- 10. Complaints
- 11. Cookies and similar technologies
- 12. Do you have to give us your data?
- 13. Automated decisions
- 14. Children
- 15. Security
- 16. Notes for California residents
- 17. Changes to this policy
- 18. Contact
The short version
- Gratora, which runs gratora.net, is responsible for the personal data described here. You can reach us at support@gratora.net.
- The free Gratora plugin sends us nothing. Your donors’ data stays on your own site. We only see it if you put it in a support request.
- We collect what we need to run gratora.net, sell and deliver plans, check licenses and answer support requests.
- Google Analytics runs only if you select Accept, and you can change your mind at any time under Cookie settings.
- We use a few service providers to do this, several of them in the United States. They are listed in section 5.
- An AI model helps us sort support requests and draft answers. A person reviews every answer before we send it, and you can switch the AI off for your requests.
- We do not sell your data and do not use it for advertising. We do not send marketing email.
- You can ask to see, correct, export or delete your data by writing to support@gratora.net.
1. Who is responsible for your data
The controller of your personal data is Gratora, the operator of gratora.net and the seller of Gratora plans (“we”, “us” and “our” in this policy).
For anything about this policy or your data, email us at support@gratora.net.
2. What this policy covers
This policy covers the personal data we handle when you:
- visit gratora.net;
- write to us, create an account or sign in;
- buy, renew, change or cancel a plan, or ask for a refund;
- use our add-ons on your sites, which check their license with us; and
- ask for support.
It does not cover the data you collect on your own website with the Gratora plugin, such as your donors’ details. For that data, you are the controller. Section 4 explains more.
3. What we collect, why, and on what legal basis
For each use, we tell you the legal basis under the EU General Data Protection Regulation (GDPR). The bases we use are: performing a contract with you, or taking steps you ask for before one (Article 6(1)(b)); a legal obligation (Article 6(1)(c)); our legitimate interests, which we describe each time (Article 6(1)(f)); and your consent (Article 6(1)(a)). How long we keep each kind of data is in section 7.
3.1 Visiting gratora.net
- What. Our web server records each request: your IP address, the date and time, the address of the page or file requested (which can include a license key, or the short-lived code from a download link), the result, the page you came from, and your browser’s description of itself. To stop abuse, we also keep short-lived counters that use a scrambled (hashed) form of your IP address or email address. Our server’s intrusion-prevention tool also records the IP address and time of requests that look like an attack, such as many refused requests in a short time, and blocks such an address for a few hours.
- Why. To run the site, keep it secure, stop abuse and fix problems.
- Legal basis. Our legitimate interest in running a secure, working website.
3.2 Analytics, only if you accept
- What. If you select Accept in our cookie banner, we load Google Analytics. It records the pages you visit, the page you came from, the page title, information about your browser and device, and events on the page, and sets cookies with a random identifier (section 11). Google receives your IP address as part of the connection. If you select Decline, or do not answer, Google Analytics is not loaded at all.
- Why. To understand how the site is used and improve it.
- Legal basis. Your consent. You can withdraw it at any time under Cookie settings at the bottom of every page. Withdrawing does not affect what happened before.
3.3 Contacting us
- What. Your name, email address and message when you use our contact form or email us.
- Why. To answer you.
- Legal basis. Our legitimate interest in answering people who write to us, or steps you ask for before a contract.
- How it works. Contact form messages are not stored on our website. They are delivered by email to our mailbox, and our mail server logs the sender and recipient addresses of each email it sends.
3.4 Your account and sign-in links
- What. Your email address and name, when your account was created and last used, your AI preference (section 3.8), the choices you make under section 9, and the sign-in links we send you. Your browser keeps your sign-in for up to 30 days (section 11).
- Why. To create your account, let you sign in without a password, and show you your licenses and requests.
- Legal basis. Performing our contract with you.
3.5 Buying a plan
- What you give us. The email address you enter in the cart. On Stripe’s payment page, you give Stripe your payment details and whatever else Stripe asks for, such as your name on the card and your billing country or address.
- What Stripe tells us. That the payment succeeded, your Stripe customer number, your email address, the plan and quantity, the amount and currency, and later the status of your subscription, renewals, failed payments and refunds. Stripe also sends us the name and billing details you gave it, which we do not keep.
- What we keep. Your email address, your Stripe customer number, your plan, its status and end dates, the add-ons it includes, the sites it covers, the currency you pay in and the amounts of your payments and refunds, the version of our Terms you accepted, and a scrambled (hashed) form of your license key with its first few characters. We never see or store your full card details.
- Why. To sell and deliver your plan, renew it, handle cancellations, refunds and withdrawals, and keep the records the law requires.
- Legal basis. Performing our contract with you. If you buy for an organization, our legitimate interest in dealing with the person who represents it. For accounting and tax records, a legal obligation.
- Stripe’s own role. Stripe processes payments for us. It also uses payment data for its own purposes, such as preventing fraud and meeting its legal duties, under its own privacy policy at stripe.com/privacy.
3.6 Licenses, updates, and what your sites send us
- What. Once you save a license key on a site, that site contacts us: when the key is saved, about every 12 hours after that, and when WordPress checks for updates, and once more to free its place when you remove or replace the key, or deactivate or delete an add-on. Each time, it sends the key, the site’s address, and which Gratora add-ons are installed and their versions. As with any web request, we also see the server’s IP address, and WordPress’s own description of itself, which includes the WordPress version and the site’s address. We keep, for each add-on, the sites activated on your license, the version each one last reported, whether it is a staging site, and when it first and last checked in. We also log activations, deactivations, downloads, renewals and similar events.
- Why. To check your license, count your sites, deliver updates and downloads, stop misuse of keys, and see which versions you run when you ask for support.
- Legal basis. Performing our contract with you, and our legitimate interest in preventing misuse of license keys.
- Where this data comes from. From the sites where you or your team saved the key. A site address can be personal data, for example when a site belongs to an individual.
- The free plugin sends us nothing. Nothing leaves a site for Gratora until a license key is saved in one of our paid add-ons.
3.7 Support requests
- What. When you ask for support through our support desk, your account, or by email, we keep your name, email address, the product, the subject, your messages and our replies, any files you attach, and, for emails, technical details needed to thread the conversation. We look up your plan and add-ons by your email address so we know what you use. If you use the AI Assistant add-on’s “open a support ticket” command and confirm it, your site also sends us your license key, the site’s address, your message, and a technical report about the site: the versions of Gratora, WordPress, PHP, the web server and the database, the theme and active plugins, the Gratora add-ons installed, the site and REST addresses, language, time zone, memory, debug and scheduling settings, and similar configuration details.
- Why. To answer your request and keep track of it.
- Legal basis. Performing our contract with you if you are a customer; otherwise our legitimate interest in helping people who use our software.
- Email we cannot match to the desk is forwarded to our mailbox so that it is not lost.
- Ratings, and what you type as a subject. When a request is resolved, we may ask you to rate our help, and we keep your rating and comment with the request. When you type a subject on the Submit a request form, we suggest matching help articles as you type. For this we keep the text you had typed each time we looked, the product and the number of articles found, without your name or email address, even if you do not send the request. Searches inside the help center itself are not recorded. Why: to improve our help and find articles that are missing. Legal basis: our legitimate interest in improving our support.
3.8 How we use AI in support
- What happens. We use Claude, an AI model made by Anthropic. When a request arrives, the model reads it, sets its topic and priority when it is confident enough (we can change them), and writes an internal note for us. Our support desk then looks for similar earlier requests and for known bugs on GitHub. The model also drafts replies and summaries when we ask, and a reply when a bug linked to your request is fixed. We may also use Claude directly to help read and answer requests, through an account covered by Anthropic’s commercial terms. A person reviews every reply before it is sent to you.
- What the model receives. For the steps our support desk runs, the request’s reference number, subject, product, status, your plan level, and the conversation, including your name and your messages, but not your attachments or our internal notes. When we use Claude directly, it can see the request as we see it. Anthropic handles these requests under its commercial terms: it does not use them to train its models, and it deletes them within 30 days unless it must keep them longer to enforce its usage policy or to comply with the law.
- Why. To answer requests faster and send each one to the right place.
- Legal basis. Our legitimate interest in giving quick and accurate support.
- Your choice. You can switch this off at any time: in your account under Settings, by ticking “Don’t use AI on my request” when you send a request, or by asking us. From then on, no AI model reads your requests.
3.9 Bug reports on GitHub
- What happens. When a request shows a bug in our software, we may record it as an issue in our source code repository on GitHub, which anyone can read. We write or review every issue before it is published, and leave out names, email addresses, site addresses and anything else that could identify you or your donors. The issue does not mention your request’s reference number; only we keep the link between the issue and your request. When we look for a known bug, the subject line of your request may be sent to GitHub’s search, unless you have switched off AI for your requests (section 3.8). GitHub may also notify our support desk when an issue linked to your request changes.
- Why. To track and fix bugs in the open.
- Legal basis. Our legitimate interest in fixing our software.
- Your choice. Tell us if you do not want your requests to lead to a public issue. We then mark your account, and our support desk refuses to open an issue from any of your requests.
3.10 Emails we send
We send email through our email provider, Resend: sign-in links, signup confirmations, your license key and purchase confirmation, notices before each renewal, confirmations of renewals, cancellations, plan changes and scheduled plan changes, notices when a renewal payment fails and when a plan has ended, acknowledgments of withdrawal, cancellation and refund requests, and support acknowledgments and replies. These are service emails, sent to perform our contract with you or to answer you. After a request is resolved, we may also email you a request to rate our help and one reminder, on the basis of our legitimate interest in improving our support, unless you ask us not to. Stripe sends its own emails about payments, such as receipts and refund receipts. We do not send newsletters or marketing email.
3.11 Backups
We back up our database every day and our uploaded files, including support attachments, every week. The backups are stored on our server in Germany. Legal basis: our legitimate interest in being able to recover from a failure.
3.12 Data we receive from others
Most of the data above comes from you. Some comes from elsewhere:
- Stripe tells us about your payments and subscription (section 3.5).
- Your sites send us their address, versions and license checks once a key is saved (section 3.6), and, if you confirm it, a technical report with a support request (section 3.7).
- GitHub may tell us when an issue linked to your request changes (section 3.9).
- Other people may give us your details, for example a colleague or an agency who buys a plan or opens a support request using your email address, or who names you in a message.
3.13 Refunds, withdrawals, cancellations and complaints
- What. Your request or complaint and how you sent it, our acknowledgment and answer, any refund, and the version of our Terms you accepted with each purchase or plan change. If you use our withdrawal or cancel page without signing in, the name, email address and purchase details you enter there.
- Why. To handle your request, and to be able to show that we handled it correctly.
- Legal basis. Performing our contract with you. A legal obligation: consumer law requires us to acknowledge withdrawals and cancellations, and to answer written complaints and keep a record of them. For the rest of the period in section 7, our legitimate interest in establishing or defending legal claims.
4. Your donors’ data and the free plugin
When you use the Gratora plugin and add-ons on your website, the data about your donors, fundraisers and attendees is stored in your own website’s database. You are its controller, and we do not receive it. Add-ons that connect to other services, such as payment providers, AI providers, email tools or analytics, use accounts you set up and send data directly from your site to those services, not to us.
We only see your donors’ data if you include it in a support request, for example in a message, screenshot or exported file. We then use it only to handle that request, as your processor, under section 13.7 of our Terms. The AI steps our support desk runs never receive your attachments. Please leave donor details out wherever you can, and do not send us lists of donors or anything that shows a donor’s religion or health.
5. Who we share data with
We share personal data with the service providers below, and only what each one needs to do its job for us; with the public only as described in section 3.9; and in the cases listed after the table.
- Hetzner Online. What it does for us: Hosts our website, database, files and backups. What it receives: Everything we store. Where it is based: Germany (servers in Nuremberg).
- Stripe. What it does for us: Payments, subscriptions, invoices, refunds and the billing page in your account. What it receives: Your email address, payment details and what Stripe asks for at checkout. Where it is based: United States (Stripe’s parent company).
- Resend. What it does for us: Sends our emails. What it receives: Email addresses and the content of every email we send, including license keys, sign-in links, support replies, and contact form messages on their way to our mailbox. Where it is based: United States.
- Cloudflare. What it does for us: Receives email sent to our support and contact addresses and passes it to our support desk or our mailbox. What it receives: The emails you send us. Where it is based: United States.
- Google (Gmail). What it does for us: Our mailbox. What it receives: Emails you send us, contact form messages, and email our support desk cannot match. Where it is based: United States.
- Google. What it does for us: Google Analytics, only if you accept. What it receives: See section 3.2. Where it is based: United States.
- Anthropic. What it does for us: The AI model that helps with support (section 3.8), including when we use Claude, under Anthropic’s commercial terms, to read and answer requests. What it receives: The content of support requests, as described in section 3.8. Where it is based: United States.
- GitHub. What it does for us: Our public issue tracker (section 3.9). What it receives: The issue text we write, which contains no personal data, and request subject lines when we search. Where it is based: United States.
We may also share data when the law requires it, for example with a court or a tax authority; with our professional advisers, such as our accountant or lawyer, who must keep it confidential; and with a company that takes over the Gratora business, which would have to follow this policy.
6. Transfers outside the European Union
Resend, Cloudflare, Google, Anthropic and GitHub are based in the United States, and so is Stripe’s parent company. When your data goes to them, it leaves the European Union. Where a provider is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision for that framework; otherwise it relies on the European Commission's standard contractual clauses in our agreement with the provider. For people in the United Kingdom, the same transfers rely on the UK Extension to the Data Privacy Framework or on the UK Addendum to those clauses. You can ask us for a copy of these safeguards at support@gratora.net.
Our own servers and backups are in Germany.
7. How long we keep data
- Web server logs: 14 days.
- Security log of requests that look like an attack (IP address and time): About 5 weeks.
- Abuse-prevention counters: From 1 minute to 1 day.
- Google Analytics data: 14 months in Google Analytics. Its cookies last up to 2 years, unless you delete them or withdraw consent.
- Your cookie choice: 182 days.
- Contact form messages and emails to us: 2 years after the last message in the conversation.
- Your account (name, email address, AI preference): While you have a license or a support request with us, then 3 years after the last of them ends.
- Signup confirmation links: Valid for 1 hour. Nothing is stored in your account before you confirm.
- Sign-in links: Valid for up to 30 days, then deleted 7 days later.
- Records of purchases, renewals, payments, refunds, plan changes and the Terms you accepted: As long as accounting and tax law requires us to keep them. From 3 years after your license ends, they no longer name you or your sites.
- Licenses and the sites activated on them: While the license exists, then 3 years after it ends.
- License activity log (activations, deactivations, downloads and similar events): 12 months.
- Support requests, replies and ratings, and our support desk’s alerts about them: 3 years after the request was last updated.
- Support attachments: 1 year after the request is closed. Files uploaded but never sent are deleted after 24 hours.
- Records of AI processing (the start of what we sent the model, the model’s full answer, and, for drafted replies, the reply we actually sent): 90 days. The notes the model writes for us are part of the request and are kept with it.
- Alerts to us about payments, withdrawals and cancellations: 90 days.
- Text typed as a subject on the Submit a request form (section 3.7): 2 years.
- Public bug reports on GitHub: As long as the repository exists. They contain no personal data.
- Written complaints, and withdrawal, cancellation and refund requests: 3 years.
- Our mail server’s delivery log (sender, recipient, time): 30 days.
- Copies of the emails we send, kept by Resend: 30 days.
- Backups: Database backups 14 days; file backups 60 days.
We may keep data for longer if the law requires it, or while it is needed for a legal claim. When a period ends, we delete the data or make it anonymous. Deleted data disappears from backups as the backups expire. Stripe keeps its own payment records for the periods its legal duties require.
8. Your rights
You have the right to:
- access the personal data we hold about you and get a copy;
- correct it if it is wrong. You can change your name yourself in your account under Settings; for your email address, write to us;
- delete it, where we no longer need it or you withdraw consent or object, unless the law requires us to keep it;
- restrict how we use it, for example while we check a correction you asked for;
- data portability: receive the data you gave us in a common machine-readable format, or have us send it to someone else, where we use it on the basis of our contract or your consent;
- object to how we use it (section 9); and
- withdraw consent at any time, where we rely on it.
How. Write to support@gratora.net, or send a request through the support desk. To make sure a request comes from you, we answer at the email address on your account, or ask you to sign in with a link we email you.
When. We answer within one month. If a request is complex, we may need up to two more months; we will tell you within the first month if so. We do not charge for this.
9. Your right to object
Where we use your data on the basis of our legitimate interests (sections 3.1, 3.3, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 3.13), you can object at any time, for reasons relating to your situation. We will then stop, unless we have compelling legitimate grounds that override your interests, or need the data for a legal claim.
In particular, you can switch off AI for your support requests in your account under Settings, by ticking “Don’t use AI on my request” when you send a request, or by telling us; you can ask us not to turn your request into a public GitHub issue; and you can ask us not to send you requests to rate our help.
10. Complaints
If you are unhappy with how we handle your data, you can tell us at support@gratora.net, and we will try to put it right. You do not have to contact us before going to an authority. You have the right to complain to a data protection authority, in particular in the country where you live or work, or where you think the problem happened. The European Data Protection Board lists the national authorities of the European Union and the European Economic Area on its website, edpb.europa.eu.
If you live in the UK, you can complain to the Information Commissioner’s Office (ico.org.uk).
11. Cookies and similar technologies
We use the following cookies and browser storage on gratora.net.
gratora_consent. What it does: Remembers whether you accepted or declined analytics. How long: 182 days. Needs your consent? No, it records your choice.gratora_cart_v1(browser storage). What it does: Remembers the plan in your cart. Holds no personal data. How long: Until the cart is emptied. Needs your consent? No, it is needed for the cart you use.gratora_cart_notice(browser storage). What it does: Shows a cart notice once. Holds no personal data. How long: Until you close the browser tab. Needs your consent? No.gratora_currency(browser storage). What it does: Remembers the currency you chose with the currency switch, or with a link that picks a currency. Holds no personal data. How long: Until you clear your browser’s site data. Needs your consent? No, it records your choice.gratora-support-portal-token(browser storage). What it does: Keeps you signed in to your account. How long: 30 days. Needs your consent? No, it is needed to sign you in._ga,_ga_J6E071334X. What it does: Google Analytics: tells visits apart. How long: Up to 2 years. Needs your consent? Yes. Set only if you accept.- WordPress login cookies. What it does: Sign-in to the site’s admin area. How long: WordPress’s defaults. Needs your consent? No. Customers never receive them.
Currency. To decide whether to show you prices in euros or in US dollars first, a script on our pages reads your device’s time zone setting inside your browser. The time zone is not sent to us and is not stored. We do not use your IP address to choose the currency. If you use the currency switch, or follow a link that picks a currency, your choice is stored as gratora_currency above.
Before you choose, we do not load Google Analytics, and no analytics cookies are set. If you select Decline, it stays that way. If you select Accept, Google Analytics loads and sets its cookies.
To change your choice, select Cookie settings at the bottom of any page. If you withdraw consent, we stop loading Google Analytics and delete its cookies from our site.
Payment pages. When you pay or manage billing, you are on Stripe’s own pages (checkout.stripe.com and billing.stripe.com), where Stripe sets its own cookies under its own policy.
12. Do you have to give us your data?
No law requires you to give us personal data. But we need your email address to sell you a plan, send you your license key and let you sign in, and to answer a support request. A site needs to send its address to receive updates. If you do not give us these, we cannot provide those services.
13. Automated decisions
Our AI model may set the topic and priority of a support request automatically; a person always handles the request itself. Our license server checks automatically whether a site is covered by a license; this is how the service works under our contract, and you can ask us to look at any result. We do not make decisions that have legal or similarly significant effects on you by automated means alone.
14. Children
Our services are meant for organizations and adults. They are not directed at children, and we do not knowingly collect children’s personal data. If you think a child has sent us personal data, tell us and we will delete it.
15. Security
We protect personal data with encrypted connections (HTTPS), access limited to the people who need it, a scrambled (hashed) form of license keys in our database, and regular backups. Your payment details are entered on Stripe’s pages and never reach our servers. No system is perfectly secure. If a breach puts your rights at risk, we will tell the authority and, where the law requires, you.
16. Notes for California residents
- The personal data we collect, and the kinds of companies we share it with, are described in sections 3 and 5.
- You can review and ask us to correct your data as described in section 8.
- We do not change what the site does in response to “Do Not Track” browser signals. Instead, Google Analytics runs only if you accept it in our cookie banner. Google Analytics is the only service on our site that can collect data about your activity over time and across other websites, and only after you accept.
- We do not sell personal information, and we do not share it for advertising.
- If we change this policy in a material way, we will tell you as described in section 17.
17. Changes to this policy
We will update this policy when what we do changes. We publish each version at gratora.net/privacy/ with its effective date. If a change is significant, we will also email customers and show a notice on the site before it applies.
18. Contact
For anything about this policy or your data, write to support@gratora.net, or send a request through our support desk at gratora.net/support/.