OnePageCheckout

Privacy Policy — OnePageCheckout Pro

Privacy Policy

This Privacy Policy explains how TrafficFlow GmbH (“TrafficFlow”, “we”, “us”, “our”), the company behind OnePageCheckout Pro (the “Plugin”), collects, uses, discloses, and protects personal data when you visit onepagecheckout.pro (the “Site”), purchase or subscribe to the Plugin, activate a license, or contact us for support.

We are a Swiss company and act as the data controller for the processing described here. We comply with the Swiss Federal Act on Data Protection (revDSG) and, where it applies to visitors and customers in the European Economic Area and the United Kingdom, the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Last updated: July 2026. Please read this policy together with our Terms of Service and any product-specific notices.

1. Who we are (Data Controller)

The controller responsible for your personal data is:

  • TrafficFlow GmbH
  • Registered address: Staubstrasse 1, 8038 Zürich, Zurich, Switzerland
  • Commercial register / company number: CHE-364.165.705
  • VAT / UID: CHE-364.165.705
  • Privacy contact: support@onepagecheckout.pro

We have not appointed a statutory Data Protection Officer, but you can reach our privacy contact above for any question relating to this policy or your data.

2. Scope of this policy

This policy covers personal data we process as a controller: data collected through our website, our checkout, your customer account, our license and update servers, our support channels, and our website analytics.

It does not cover how you, as a WooCommerce store owner, process your own customers’ data when you install and run the Plugin on your own site. When the Plugin runs on your store, you are the controller of your shoppers’ data and we do not receive it. See “The Plugin on your own store” below.

3. What personal data we collect

3.1 Checkout and order data

Our own checkout at onepagecheckout.pro runs on WooCommerce. When you buy a subscription or a lifetime license, we collect the information needed to process your purchase, including:

  • Name and, where relevant, company name
  • Billing address and country
  • Email address and (optionally) phone number
  • VAT/tax identifier, where you provide one
  • Order details: products purchased, license tier, amounts, currency, taxes (including EU VAT/MOSS where applicable), invoices and order status
  • Payment confirmation data (see below) — we do not store full card numbers on our servers

3.2 Account data

If you create an account or customer portal login, we process your email address, hashed password, display name, and preferences, together with a history of your orders, subscriptions, invoices, and license keys.

3.3 License keys and activation domains

To operate per-site activation limits (Starter 1 site, Growth 5 sites, Agency unlimited sites) and to deliver updates and support, our license server records:

  • Your license key and the tier/plan it belongs to
  • The domain names (and, where technically necessary, IP address and WordPress/WooCommerce/PHP version) of the sites where you activate the Plugin
  • Activation, deactivation, update-check, and license-status timestamps

Domain names and site technical data are usually not personal data, but they can be linked to you through your license, so we treat them as covered by this policy.

3.4 Support correspondence

When you contact us for support, pre-sales questions, or refunds, we process the content of your messages and any attachments, your email address and name, and — where you share it to help us diagnose an issue — technical details about your site and configuration.

3.5 Website usage and basic analytics

When you browse the Site we collect limited technical and usage data, such as pages viewed, referring URLs, approximate location derived from IP address, device and browser type, and interaction events. We use this in aggregate to understand traffic and improve the Site. See “Cookies and similar technologies” below.

3.6 Communications and marketing

If you subscribe to our newsletter or product updates, we process your email address and subscription preferences, together with basic engagement data (for example whether an email was opened or a link clicked).

4. How and why we use your data, and our legal bases

We only process personal data where we have a lawful basis under the GDPR and a justification under the revDSG. Depending on the situation, our bases are:

  • Performance of a contract (GDPR Art. 6(1)(b)): to process your order, deliver and license the Plugin, provide updates and support, manage subscriptions and renewals, and honour the 14-day money-back guarantee.
  • Legal obligation (GDPR Art. 6(1)(c)): to meet accounting, tax, invoicing, and VAT obligations, including retaining invoices for statutory periods.
  • Legitimate interests (GDPR Art. 6(1)(f)): to secure our systems, prevent fraud and license abuse, enforce activation limits, keep basic analytics, and improve our products and Site — balanced against your rights and freedoms.
  • Consent (GDPR Art. 6(1)(a)): for non-essential cookies/analytics where required, and for marketing emails. You may withdraw consent at any time without affecting prior processing.

Under the revDSG we process personal data in good faith and proportionately for the purposes stated at collection; the categories above describe those purposes for our Swiss-law compliance as well.

5. Payment processing

Payments are processed by Stripe; we do not store card details. Stripe collects and processes your card or payment-method details directly under its own privacy terms. We receive only the information needed to confirm and reconcile your order (for example, a transaction reference, payment status, the last four digits of a card, and billing country). We do not store full payment card numbers.

6. Service providers and processors

We share personal data with a limited number of vendors who process it on our behalf under data processing agreements and only on our instructions. Categories include:

  • Hosting and infrastructure — the providers who host onepagecheckout.pro, our database, and our license/update servers [Hosting provider].
  • Payment processingStripe, our payment processor.
  • Email and support — the providers used to send transactional and marketing email and to run our support inbox/helpdesk [Email/support provider].
  • Analytics — the provider used for basic website analytics [Analytics provider].

We do not sell your personal data. We may disclose data where required by law, to establish or defend legal claims, or in connection with a merger, acquisition, or asset sale, in which case we will notify you as required.

7. The Plugin on your own store

OnePageCheckout Pro is software you install on your own WooCommerce store. When your shoppers check out, their personal data is processed on your site and infrastructure — you are the controller of that data and responsible for your own privacy notice. The Plugin does not transmit your shoppers’ checkout or order data to TrafficFlow. Deactivating the Plugin instantly restores the stock WooCommerce checkout with no lock-in. The only data the Plugin sends to us is license-related (see “License keys and activation domains”).

8. Cookies and similar technologies

We use cookies and similar technologies to make the Site and checkout work, remember your session and cart, keep you signed in, secure the Site, and — where you allow it — measure traffic. We distinguish:

  • Strictly necessary cookies (including WooCommerce cart/session and security cookies) that do not require consent.
  • Analytics and preference cookies that we set only with your consent where the law requires it.

You can manage non-essential cookies through our cookie banner (where shown) and through your browser settings. Blocking strictly necessary cookies may break checkout or login.

9. How long we keep your data

  • Order, invoice, and tax records: retained for the statutory retention period (in Switzerland generally 10 years).
  • Account and license data: retained while your account or license is active and for a reasonable period afterwards to handle renewals, updates, and disputes.
  • Support correspondence: retained for as long as needed to resolve your request and for a limited period thereafter for quality and reference.
  • Analytics data: retained in aggregated or limited form for a short period.
  • Marketing data: retained until you unsubscribe or withdraw consent.

When data is no longer needed for these purposes, we delete or anonymise it.

10. International data transfers

We are based in Switzerland. Some of our providers may process data in the EEA, the United Kingdom, the United States, or other countries. Where we transfer personal data outside Switzerland or the EEA to a country without an adequacy decision, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses (with the Swiss addendum recognised by the Swiss Federal Data Protection and Information Commissioner) or equivalent safeguards — to protect your data. You may request a copy of the relevant safeguards using the contact details below.

11. Your rights

Subject to the GDPR and the revDSG, you have the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where there is no overriding legal ground to keep it.
  • Portability — receive certain data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
  • Restriction — ask us to restrict processing in certain circumstances.
  • Withdraw consent — where processing is based on consent, without affecting prior processing.

To exercise any right, contact us at support@onepagecheckout.pro. We will respond within the timeframes required by law and may need to verify your identity first.

You also have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC); in the EEA it is the authority in your country of residence, work, or the alleged infringement.

12. Security

We use appropriate technical and organisational measures — including encryption in transit, access controls, and hashed passwords — to protect personal data against loss, misuse, and unauthorised access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children

The Site and the Plugin are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with a new “Last updated” date and, where changes are material, take reasonable steps to notify you.

15. Contact us

For any question about this policy or how we handle your personal data, contact:

  • TrafficFlow GmbH
  • Staubstrasse 1, 8038 Zürich, Zurich, Switzerland
  • support@onepagecheckout.pro