Privacy Policy
Effective 7 September 2026
This policy explains what Validate Plugin ("we", "us") collects when you use Validate Plugin, why we collect it, who else sees it, and what you can ask us to do with it.
Two kinds of people are described here
Customers are the people who hold an account with us and install our validation snippet on their sites. Visitors are the people who type a phone number into one of those customers' forms. We hold a great deal about the first group and very little about the second, and the difference matters throughout.
What we collect from customers
- Account details — your name, email address and a hashed password. We never store your password itself.
- Configuration — the domains you authorise, your API key, and the settings that control how validation behaves on your forms.
- Usage counters — how many validation requests each API key, domain and form made in a given month. These drive your dashboard and your billing.
- Billing details — your subscription status and plan. Card numbers are entered on Stripe's own hosted pages and never reach our servers.
- Support messages — anything you send us through the support page, kept so we can answer it and so you can see what you asked.
What happens to a visitor's phone number
When a visitor types a phone number into a form running our snippet, that number is sent to us and forwarded to a validation provider to determine whether it is real. We use the answer to tell the form whether to accept it.
We do not store the phone number. What we retain is a counter: that one more validation was performed for a given account, key and domain in a given month. The number itself is not written to our database and is not available to us afterwards. It is, however, seen by the validation provider named below, which handles it under its own policy.
If you are a customer, you are the controller of the numbers your forms collect. You are responsible for telling your own visitors that their number is checked by a third-party service, and for having a lawful basis to do so.
Who else sees this data
We do not sell personal data and we do not share it for advertising. The following providers process data on our behalf because the product cannot function without them:
| Provider | Why | What reaches them |
|---|---|---|
| PhoneValidator.com | Advanced phone number validation - line type, carrier, ported status and location | The phone number being checked |
| Twilio | Basic phone number validation | The phone number being checked |
| Stripe | Payment processing, subscriptions and invoices | Your name, email address and payment details |
| Mailgun | Sending account, support and alert email | Your name, email address and the content of those messages |
We may also disclose data where the law requires it, or where it is necessary to investigate abuse of the service.
Cookies
We set a session cookie to keep you signed in and a CSRF cookie to protect forms against cross-site request forgery. Both are strictly necessary to operate the application. We do not use advertising or cross-site tracking cookies.
How long we keep things
- Account and configuration data — for as long as your account is open.
- Usage counters — retained as a monthly total, which is what billing and your dashboard history are built from.
- Support tickets — deleted with your account.
- Billing records — kept by Stripe for as long as tax and accounting law requires, independently of your account with us.
Deleting your account from the profile page removes your account, its settings and its support history from our database.
Security
The service is served over HTTPS. Passwords are hashed. API keys are per-account and can be regenerated by you at any time, which immediately invalidates the old one. Validation requests are refused unless they originate from a domain you have authorised. No system is perfectly secure, and we do not claim otherwise.
Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy of it, or to object to how we use it. Email [email protected] and we will respond within 30 days.
Children
Validate Plugin is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If we change this policy we will update the effective date above, and we will email account holders before any change that materially reduces the protection described here.
Contact
Questions about this policy go to [email protected].