Privacy Policy
Last updated: 18 July 2026
1. Who we are
SPMarketing is a trading name of:
Steven Thomas Parkinson Ltd
Company number: 15600768
Registered office: 5 Eryngo Street, Stockport, England, SK1 4DH
For the purposes of UK data protection law, Steven Thomas Parkinson Ltd, trading as SPMarketing, is the data controller responsible for the personal information described in this Privacy Policy.
In this Privacy Policy, “SPMarketing”, “we”, “us” and “our” refer to Steven Thomas Parkinson Ltd trading as SPMarketing.
2. Scope of this Privacy Policy
This Privacy Policy explains how we collect, use, disclose, transfer, retain and protect personal information when you:
- visit the SPMarketing website;
- contact us or submit an enquiry;
- purchase an application, digital product, subscription, licence or WordPress plugin;
- use an application, progressive web application, website service or WordPress plugin supplied by SPMarketing;
- activate or manage a software licence;
- make a payment through Stripe or another authorised payment provider;
- request technical assistance, customer support, a refund or account help;
- subscribe to marketing communications; or
- otherwise interact with SPMarketing.
Some applications, plugins or services may include an additional product-specific privacy notice. Where there is a conflict, the product-specific notice will apply to the relevant data processing activity.
Third-party websites, platforms and services have their own privacy policies. We are not responsible for the privacy practices of organisations that we do not control.
3. Personal information we may collect
The information we collect depends on how you interact with us.
3.1 Identity and contact information
This may include:
- your name;
- business or organisation name;
- postal or billing address;
- email address;
- telephone or mobile number;
- country or region;
- username or account identifier; and
- your preferred contact method.
3.2 Enquiry and communication information
When you contact us, we may collect:
- information entered into a contact or support form;
- correspondence sent by email or another communication service;
- support requests and technical questions;
- attachments, screenshots or diagnostic information you provide;
- records of complaints, refunds or disputes; and
- notes relating to our communications with you.
Please do not send us complete payment-card information, passwords, secret keys or other unnecessary sensitive information through email or support forms.
3.3 Purchase and transaction information
When you make a purchase, we may receive:
- the product or service purchased;
- purchase date and transaction time;
- amount, currency and applicable tax;
- billing name, address and email address;
- transaction, invoice or receipt number;
- payment status;
- refund, chargeback or dispute information;
- payment method type;
- limited card information, such as the card brand, expiry date and last four digits; and
- subscription status and renewal dates.
Payments are processed through Stripe or another authorised payment provider. SPMarketing does not ordinarily receive or store your complete card number, card security code or online banking credentials.
3.4 Account, subscription and licence information
Where applicable, we may collect:
- account registration details;
- licence keys or subscription identifiers;
- licence activation and deactivation records;
- the website domain or installation associated with a software licence;
- subscription level and permitted number of installations;
- purchase history;
- renewal and expiry dates; and
- account or licence-management activity.
3.5 Application and WordPress plugin information
Depending on the product and the features used, we may collect:
- application or plugin version;
- WordPress version;
- PHP version;
- browser, operating system and device type;
- installation domain or website URL;
- licence activation status;
- language and general settings;
- feature usage;
- application access events;
- error, crash and diagnostic logs;
- security-related events;
- IP address;
- approximate location derived from an IP address;
- a locally generated or pseudonymous device identifier; and
- information voluntarily submitted when requesting technical support.
We aim to collect only the information reasonably required to provide, secure, license, support and improve the relevant product.
Where an application stores preferences, recent activity or settings locally on your device, that information may remain on the device and may not be transmitted to SPMarketing unless synchronisation, analytics, backup or support functionality is enabled.
3.6 Device, website and usage information
When you visit our website or use our online services, our systems and service providers may automatically collect:
- IP address;
- browser type and version;
- device and operating-system information;
- referring website;
- pages viewed;
- links or buttons selected;
- date, time and duration of visits;
- general geographic location;
- cookie or similar technology identifiers;
- server logs;
- failed login or security events; and
- website performance and error information.
3.7 Application permissions
Some applications may request access to device features such as:
- microphone access;
- notifications;
- camera access;
- files or media;
- approximate or precise location; or
- other device capabilities.
Permission will normally be requested through your browser, operating system or device. You can refuse or withdraw permissions through your device or browser settings, although some features may then be unavailable.
Where speech recognition, maps, notifications or similar services are supplied by your browser, operating-system provider or another third party, that provider may process information under its own privacy policy.
3.8 Marketing information
We may collect:
- your marketing preferences;
- records of your consent;
- email campaign engagement information; and
- unsubscribe or suppression records.
3.9 Sensitive personal information
We do not intentionally request special-category information such as medical information, religious beliefs, political opinions, sexual orientation or biometric information through our ordinary website, payment or support processes.
Please avoid including sensitive information in support requests unless it is genuinely necessary. Where sensitive information is voluntarily provided, we will only use it where legally permitted and necessary for the relevant request.
4. How we obtain personal information
We may obtain information:
- directly from you;
- automatically from your device, browser, application or plugin;
- from Stripe and other payment providers;
- from banks, card networks and payment-method providers;
- from application stores, software marketplaces or authorised resellers;
- from website hosting, analytics and security providers;
- from a business or organisation purchasing a product on your behalf;
- from publicly accessible business sources; or
- from professional advisers, regulators or law-enforcement authorities where legally permitted.
5. How and why we use personal information
We use personal information only where we have a lawful basis under applicable data protection law.
Providing products and fulfilling contracts
We use information to:
- process orders and payments;
- supply purchased applications, plugins, licences and services;
- create and manage accounts;
- activate and validate software licences;
- manage subscriptions and renewals;
- provide invoices and receipts;
- provide updates and service communications;
- respond to support requests;
- process cancellations, refunds and disputes; and
- enforce applicable product or licence terms.
The lawful basis is normally that processing is necessary to enter into or perform a contract with you.
Legal and regulatory compliance
We may process information to:
- maintain accounting, tax and transaction records;
- comply with company, consumer, payment and financial regulations;
- respond to lawful requests;
- prevent money laundering or fraud;
- manage disputes and legal claims; and
- comply with card-network and payment-provider requirements.
The lawful basis is compliance with a legal obligation or, where applicable, our legitimate interests in protecting the business and establishing or defending legal rights.
Security, fraud prevention and service integrity
We may use information to:
- detect suspicious or unauthorised activity;
- protect accounts, licences, applications and websites;
- investigate misuse, malware, attacks or payment fraud;
- prevent unauthorised licence sharing;
- maintain logs and backups;
- identify technical problems; and
- protect SPMarketing, our customers and other users.
The lawful basis is normally our legitimate interest in operating secure and reliable services and protecting against fraud and misuse.
Analytics and product improvement
We may use information to:
- understand how our website, applications and plugins are used;
- measure performance and reliability;
- diagnose errors;
- improve accessibility and usability;
- develop new features; and
- produce aggregated or anonymised statistics.
The lawful basis may be our legitimate interests or your consent where consent is required for analytics cookies or similar technologies.
Customer communications
We may use contact information to send:
- purchase confirmations;
- invoices and receipts;
- licence or subscription notices;
- important product or security updates;
- changes to terms or policies;
- support responses; and
- service interruption or maintenance notices.
These are operational communications and are not necessarily marketing messages.
Marketing
Where legally permitted, we may send information about SPMarketing products, updates and services.
We rely on consent where consent is required. In limited circumstances, we may rely on legitimate interests or the existing-customer marketing rules permitted by applicable law.
You can unsubscribe at any time by using the unsubscribe facility in a message or by contacting us.
6. Stripe and payment processing
SPMarketing uses Stripe to process some or all customer payments.
When you make a payment, information may be sent directly to Stripe. Stripe may collect and process:
- your name and contact details;
- billing information;
- payment-card or bank information;
- transaction details;
- IP address and device information;
- fraud-prevention information; and
- identity or verification information where required.
Stripe may act as our payment processor for certain activities and may also process information for its own regulatory, fraud-prevention, security and service-improvement purposes.
Stripe may share transaction information with banks, payment-method providers, card networks, fraud-prevention providers, regulators and other parties involved in completing or securing the transaction.
Stripe may process information in the United Kingdom and other countries. Stripe’s own processing is governed by its Privacy Policy and applicable payment-service terms.
SPMarketing receives only the payment and transaction information reasonably required to confirm the purchase, provide the product, manage the customer relationship and maintain appropriate business records.
7. Who we disclose information to
We do not sell personal information.
Where necessary, we may disclose limited information to:
- Stripe and other authorised payment processors;
- banks, card networks and payment-method providers;
- website, application, database and cloud-hosting providers;
- email, communication and customer-support providers;
- licence-management and software-delivery providers;
- application stores, marketplaces and authorised resellers;
- analytics and performance-monitoring providers;
- security, firewall, anti-spam and fraud-prevention providers;
- Google services, including reCAPTCHA and, where enabled, analytics services;
- accountants, insurers, solicitors and other professional advisers;
- contractors working under appropriate confidentiality and data-protection obligations;
- tax authorities, courts, regulators, law-enforcement bodies or public authorities;
- organisations involved in investigating fraud, security incidents or legal claims; and
- a prospective purchaser, investor or successor if our business or assets are reorganised, transferred or sold.
We disclose only the information reasonably necessary for the relevant purpose.
Method of disclosure
Information may be disclosed:
- through secure payment and checkout integrations;
- through encrypted application programming interfaces;
- through password-protected or access-controlled administrative systems;
- through encrypted web connections;
- through secure business email or file-transfer systems;
- through authorised access to hosted systems; or
- where legally required, through formal disclosure to a court, regulator or public authority.
Our service providers are required, where applicable, to process information only in accordance with our instructions, maintain appropriate security and comply with relevant data-protection requirements.
8. International transfers
Some suppliers, payment providers, hosting providers and technology services may process information outside the United Kingdom.
Where personal information is transferred internationally, we take reasonable steps to ensure that an appropriate legal transfer mechanism is used. Depending on the destination and provider, this may include:
- United Kingdom adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- approved standard contractual clauses;
- binding contractual safeguards; or
- another mechanism permitted by applicable data protection law.
You may contact us for further information about safeguards relevant to your personal information.
9. Cookies and similar technologies
Our website, applications and payment services may use cookies, local storage, pixels, software-development kits or similar technologies.
These may include:
- strictly necessary technologies required for security, payments and basic website operation;
- preference technologies that remember settings;
- analytics technologies used to understand usage and performance; and
- marketing technologies, where enabled.
Where required by law, non-essential cookies and similar technologies will not be activated until you have given consent.
You can manage your choices through the cookie controls presented on the website and through your browser or device settings. Blocking some technologies may affect website or application functionality.
Further information may be provided in a separate Cookie Policy or through the website’s cookie-preference centre.
10. Data retention
We retain personal information only for as long as reasonably required for the purpose for which it was collected, including legal, accounting, security and dispute-management requirements.
Our normal retention periods are:
- order, invoice, payment and tax records: normally seven years from the end of the relevant financial or customer relationship;
- customer account and licence records: for the duration of the account or licence and for an appropriate period afterwards;
- enquiries that do not result in a purchase: normally up to 24 months after the last meaningful contact;
- support tickets and related correspondence: normally up to three years after closure;
- security and server logs: normally up to 12 months, unless required for an investigation;
- marketing records: until consent is withdrawn or you object, with limited suppression information retained to respect your request;
- analytics information: according to the relevant analytics configuration, normally no longer than 26 months unless anonymised;
- dispute, chargeback and legal information: until the matter and applicable limitation periods have expired; and
- backup copies: until they are securely overwritten under our normal backup cycle.
We may retain information for longer where required by law, a regulator, a payment provider, an unresolved dispute, fraud prevention or the establishment or defence of legal claims.
Information may be anonymised so that it can no longer identify an individual. Anonymised information may be retained for statistical, security and product-development purposes.
11. Security practices
We use technical and organisational measures appropriate to the nature of the information and the risks involved.
These measures may include:
- HTTPS and encrypted transmission;
- payment processing through established payment providers such as Stripe;
- not storing complete payment-card numbers or card security codes on SPMarketing systems;
- access controls and restricted administrative permissions;
- strong passwords and multi-factor authentication where available;
- security updates and patch management;
- firewall, anti-spam and malware-protection services;
- logging and security monitoring;
- backup and recovery procedures;
- service-provider reviews and contractual data-protection requirements;
- confidentiality obligations;
- data minimisation; and
- procedures for investigating and responding to suspected data breaches.
No internet transmission, website, application or storage system can be guaranteed to be completely secure. You are responsible for protecting your passwords, licence keys and devices and for informing us promptly if you suspect unauthorised use.
12. Automated decision-making
SPMarketing does not ordinarily make decisions about customers based solely on automated processing where those decisions have a legal or similarly significant effect.
Stripe, banks, card issuers and fraud-prevention providers may use automated systems to assess transactions, verify identity or detect fraud. This may result in a transaction being delayed, declined or referred for further review.
Where you believe a payment or account action has been made incorrectly, contact SPMarketing support.
13. Your data-protection rights
Depending on the circumstances and applicable law, you may have the right to:
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion of your information;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- request transfer of information you provided in a portable format;
- withdraw consent where processing is based on consent; and
- complain to a data-protection supervisory authority.
These rights are not absolute and may be restricted where information must be retained for legal, security, contractual, fraud-prevention or dispute-management purposes.
Your right to object to direct marketing
You have the right to object at any time to the use of your personal information for direct marketing.
We will stop using your information for direct marketing after receiving your request, although we may retain limited information on a suppression list to ensure that further marketing is not sent.
14. How to exercise your rights
To submit a privacy or data-protection request, email:
Please use the subject line:
Privacy Request
You may also contact us using the details on the SPMarketing Support page.
We may need to verify your identity before releasing or changing personal information. We will respond within the period required by applicable law, normally within one month for UK data-protection requests.
There is normally no charge for exercising your rights. We may charge a reasonable fee or refuse a request where legally permitted, such as where a request is manifestly unfounded or excessive.
15. Complaints
Please contact us first so that we have an opportunity to investigate and address your concern.
You also have the right to complain to the UK Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Individuals outside the United Kingdom may also have the right to complain to the relevant data-protection authority in their country.
16. Children’s information
Our paid products and commercial services are not intended to be purchased directly by children under the age of 13.
We do not knowingly collect personal information from children through our payment or account processes without appropriate authorisation. A parent or guardian who believes that a child has provided personal information should contact us.
Some free applications may be suitable for general or family use. Where an application is likely to be accessed by children, we will seek to minimise data collection and provide any additional information required for that application.
17. Third-party links and services
Our website, applications and plugins may contain links to third-party websites or integrate with third-party services.
Selecting a third-party link or enabling an integration may allow that organisation to collect information directly from you. Its use of information will be governed by its own privacy policy.
The presence of a link does not mean that SPMarketing controls or accepts responsibility for the third party’s privacy or security practices.
18. Changes to this Privacy Policy
We may update this Privacy Policy when our products, payment arrangements, suppliers or legal obligations change.
The latest version will be published on the SPMarketing website with a revised “Last updated” date.
Where a change materially affects how we use existing personal information, we will take reasonable steps to bring the change to the attention of affected customers.
19. Contact details
Questions about this Privacy Policy or the handling of personal information should be sent to:
SPMarketing
Steven Thomas Parkinson Ltd
Company number: 15600768
Registered office: 5 Eryngo Street, Stockport, England, SK1 4DH
Email: support@spmarketing.info
Please include “Privacy Request” in the email subject line when exercising a data-protection right.
We are a start-up company, and as such, we have not yet commenced taking payments. Once we receive our initial payments, we will upgrade our company house listing to show that we are trading.
