Privacy Policy
This Privacy Policy explains how WP Guard collects, uses, stores and shares personal information when you visit wpguard.ai, download or use our scanner plugin, or subscribe to one of our plans. We take privacy seriously, because a security company that is careless with your data has no business asking for your trust.
Last updated: 29 July 2026
Who we are
WP Guard (“WP Guard”, “we”, “us”, “our”) is a WordPress security and managed hosting service, operated by WP Guard Pty Ltd (ABN 29 670 353 045), an Australian company based in Queensland. For any privacy question or request, contact us at support@wpguard.ai.
We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are in the United Kingdom or the European Economic Area, we also handle your personal data in line with the UK GDPR and EU GDPR, and the section on your rights below applies to you.
The information we collect
Information you give us
- When you contact us: your name, email address, company name, the number of sites you manage, and anything you write in your message.
- When you subscribe to a paid plan: your name, email, billing details and the website or websites you want us to protect. Card payments are handled by our payment provider; we do not store your full card number on our systems.
- When you deal with our team: the content of emails, support requests and any information you choose to share while we help you.
Information the WP Guard scanner plugin sends
The free scanner and the Pro scanner are plugins that run on your own WordPress site. When you run a scan, the plugin may send us technical information about that site so we can report on its security: the site URL, WordPress core, theme and plugin versions, server environment details, and the vulnerabilities or issues the scan finds. The scanner is a security tool, not a data-harvesting tool. It is not designed to read, collect or transmit your site’s content, your customer records, or the personal data your own site stores.
Information from the Guaranteed managed service
If you join our Guaranteed plan, we are hosting and actively managing your site, so we necessarily hold access credentials, backups, monitoring data and logs relating to your site. We use this only to run, protect, monitor and repair the service you have asked us to provide.
Information we collect automatically
- Usage and device data: your IP address, browser type, device, pages viewed, referring page and the date and time of your visit.
- Cookies and analytics: see the section below.
Cookies and analytics
We use cookies and similar technologies to make the site work and to understand how it is used. These fall into two groups:
- Essential cookies that are needed for the site to function and cannot be switched off.
- Analytics cookies set through Google Analytics 4 and Google Tag Manager, which help us see which pages are useful and where people get stuck. This data is aggregated and used to improve the site.
You can control or delete cookies through your browser settings. Where the law requires your consent for non-essential cookies, we will ask for it before those cookies are set.
How we use your information
- To reply to your enquiries and give you the information or quote you asked for.
- To provide, run, monitor and support the plans and services you subscribe to.
- To deliver scan results and security reporting for your site.
- To take payment and manage your subscription.
- To improve our website, plugins and services.
- To send you service messages about your account, and, where you have agreed or the law allows, occasional updates about WP Guard. You can opt out of marketing at any time.
- To meet our legal, tax and regulatory obligations, and to protect our rights and the security of our systems.
Our legal bases (UK and EU visitors)
Where the GDPR applies, we rely on: your consent (for example, for analytics cookies and marketing email); the need to perform a contract with you (to deliver a plan you have bought); our legitimate interests (to run and improve our business and keep our systems secure), balanced against your rights; and legal obligations (such as keeping financial records).
When we share information
We do not sell your personal information. We share it only with trusted providers who help us run WP Guard, and only so far as they need it to do that job. These include:
- Hosting and infrastructure providers that run our servers and network.
- Cloudflare, for content delivery, DNS and security protection.
- Google Analytics and Google Tag Manager, for website analytics.
- Our customer and forms platform, which receives and manages enquiries submitted through the site.
- Our payment provider, which processes subscription payments.
- Professional advisers and authorities, where we are required to share information by law.
We may also share information if WP Guard is involved in a business sale, merger or restructure, in which case your information would remain protected under terms consistent with this policy.
International transfers
Some of our providers are located outside Australia, the UK and the EEA, which means your information may be processed overseas. Where we transfer personal data internationally, we take reasonable steps to ensure it is protected by appropriate safeguards and handled consistently with this policy and applicable law.
How long we keep it
We keep personal information only for as long as we need it for the purposes described here, or for as long as the law requires. Enquiry details are kept while we are in contact and for a reasonable period afterwards. Account, billing and service records are kept for the life of your subscription and for the period required by tax and record-keeping laws. When information is no longer needed, we delete it or de-identify it.
How we protect it
We use technical and organisational measures appropriate to a security company to protect personal information against loss, misuse and unauthorised access. No system is ever completely secure, but keeping data safe is the core of what we do, and we hold ourselves to that standard.
Your rights and choices
Depending on where you live, you have rights over your personal information. These can include the right to:
- ask for a copy of the information we hold about you;
- ask us to correct information that is wrong or out of date;
- ask us to delete your information, where we are not required to keep it;
- object to, or ask us to restrict, certain uses of your information;
- withdraw consent where we relied on it; and
- opt out of marketing messages at any time.
To make a request, email support@wpguard.ai. We will verify your identity and respond within the timeframe the law allows. There is no charge to make a request in most cases.
Children
WP Guard is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, contact us and we will delete it.
Other websites
Our site and emails may link to other websites, including wpguard.app. We are not responsible for the privacy practices of sites we do not operate, and we encourage you to read their policies.
Changes to this policy
We may update this policy from time to time. When we do, we will change the “last updated” date above, and for significant changes we will take reasonable steps to let you know.
Contact us and complaints
If you have a question, a request, or a concern about how we handle your information, please contact us first at support@wpguard.ai so we can put things right. If you are in Australia and are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are in the UK or EU, you may also complain to your local data protection authority.