Privacy and cookies

Privacy & Cookie Policy

This Privacy & Cookie Policy explains how personal data, technical data, cookies and similar technologies are processed through the Custom Auth Suite™ website, digital products, licensing services, checkout, support services, protected downloads, software update checks, remote administrative messages and related online features. In this Policy and across this website, Custom Auth Suite™ may also be referred to as “CAS”.

Data controller

Who is responsible for the processing

The data controller for this website is the person or business operating Custom Auth Suite™.

Brand / Website Custom Auth Suite™ — customauthsuite.com
Data controller Simone Mòllica / DevDorado
Privacy contact email [email protected]
Support contact Visit support page

This website and the related services are operated from Italy, within the European Union. The processing of personal data is carried out in accordance with Regulation (EU) 2016/679, also known as the General Data Protection Regulation (GDPR), and applicable Italian data protection rules.

Scope

What this policy covers

This policy applies to the Custom Auth Suite™ website and to the online services connected to the sale, delivery, licensing, support and documentation of Custom Auth Suite™ digital products.

Website and pages

This includes informational pages, commercial pages, checkout pages, account pages, license renewal pages, support pages, Privacy & Cookie file request pages, tutorials, product documentation and other public or customer-facing sections of the website.

Digital services

This includes WooCommerce checkout, customer account, license generation, license validation, package downloads, support tickets, support entitlements, remote messages, diagnostic-related support flows and other digital services connected to Custom Auth Suite™.

Categories of data

Personal data and technical data processed

The categories of data processed depend on how you interact with the website and services.

Data you provide directly

  • Name, surname, company name or billing details, if provided during checkout.
  • Email address and contact details.
  • Billing information, VAT number, tax code or invoicing details, where applicable.
  • Licensed domain, website URL, order details and support request details.
  • Messages, attachments or technical information submitted through forms or support tickets.

Data generated by the service

  • Order number, product purchased, license plan, license status and support entitlements.
  • License key tail, license hash, domain coverage, activation limits and license metadata.
  • Download events, package access events, token validation events, update check events and delivery logs.
  • Installed package, installed version, edition/package context, compatibility context and checksum-related metadata where package updates or protected delivery are enabled.
  • First license activation timestamp, activation domain and technical activation metadata.
  • Remote Admin Message request context, such as plugin version, selected placement, language/locale, edition/package context and privacy-preserving site hash where applicable.
  • Privacy-safe Interaction Analytics events, such as impressions, dismissals and CTA clicks, only if explicitly enabled. These events are anonymous, aggregated and global and do not track the website where Custom Auth Suite™ is installed.
  • Technical logs useful for security, fraud prevention, debugging and support.

Technical data

  • IP address or privacy-safe derived information where used for security, rate limiting or abuse prevention.
  • Browser, device, user agent, operating system and request metadata.
  • Session information, cookies, local storage values and similar technologies.
  • REST API requests, license validation requests and download endpoint interactions.

Payment data

Payments are processed through payment providers and/or WooCommerce-related payment methods. Custom Auth Suite™ does not intentionally store full card details. Payment providers may process payment data under their own terms and privacy notices.

Purposes

Why the data is processed

Personal and technical data are processed only for legitimate and defined purposes connected to the website, products and services.

Orders and licenses

To process purchases, create customer records, generate licenses, associate licenses with domains, manage renewals, deliver digital products and provide access to purchased items.

Digital delivery and downloads

To generate protected download links, validate download tokens, serve software packages, prevent unauthorized access and document digital delivery.

Support and diagnostics

To receive support requests, manage tickets, verify support eligibility, review diagnostic information provided by the customer and provide technical assistance.

Security and abuse prevention

To protect the website, prevent spam, fraud, brute force attempts, unauthorized downloads, license misuse, malicious requests and abuse of support channels.

Legal and accounting obligations

To comply with tax, accounting, billing, consumer protection, legal, regulatory and record-keeping obligations.

Service communications

To provide Remote Admin Messages, compatibility notes, license or support reminders, tutorials, product guidance and other service communications to Custom Auth Suite™ installations. These messages are JSON content payloads only and do not execute remote JavaScript or arbitrary remote HTML.

Website improvement and privacy-safe analytics

To understand how the website and product communications are used and improve content, navigation, performance, commercial flows and message relevance, where analytics tools or Privacy-safe Interaction Analytics are used in accordance with consent, explicit opt-in and applicable rules.

Legal bases

Legal basis of processing

The legal basis depends on the specific processing activity.

Processing activity Legal basis
Checkout, order processing, license creation, digital delivery and account services Performance of a contract or pre-contractual measures requested by the user.
Billing, tax records, accounting and statutory records Legal obligation.
Security, abuse prevention, license protection, fraud prevention and service reliability Legitimate interest in protecting the website, services, customers and digital products.
Support requests, technical assistance and diagnostics submitted by the customer Performance of a contract, pre-contractual measures, consent where required, or legitimate interest in handling the request.
Remote Admin Messages, compatibility notes, license/support reminders and service communications Performance of a contract, pre-contractual measures, or legitimate interest in providing service information, security notices, compatibility guidance and product-related administrative communications.
Privacy-safe Interaction Analytics for Remote Admin Messages, where explicitly enabled Consent or explicit opt-in by the administrator. These events are anonymous, aggregated and global and do not track the website where Custom Auth Suite™ is installed.
Newsletter or direct marketing, if introduced Consent or other lawful basis where permitted by applicable rules.
Non-technical cookies, analytics requiring consent, profiling or marketing tools Consent, where required.

Digital access and refund evidence

Immediate access and first activation metadata

When you request immediate access to a digital license, download or digital service, Custom Auth Suite™ may record technical metadata useful to document delivery, activation or start of the service.

Immediate digital access consent

During checkout, you may be asked to confirm that you request immediate access to the digital license, downloads and/or digital services purchased, acknowledging that, where provided by applicable law, this may affect the right of withdrawal after activation, download or start of the service.

First activation record

The license system may record the first activation timestamp in UTC, the activation domain, site or host hashes, instance identifier and source of activation. This record is designed to be factual and not normally overwritten by later validations, deactivations or domain-family checks.

Custom Auth Suite™ systems

How CAS services process data

The Custom Auth Suite™ website may use several internal systems to provide licensing, support, messaging, downloads and customer services.

Licensing and digital delivery system

This manages licenses, customer records, domain coverage, license validation, protected package downloads, license metadata, support entitlements and WooCommerce order/license synchronization.

Support and ticketing system

This manages support forms, support tickets, secure access links, support eligibility, attachments submitted by the customer, ticket status, support communications and, where applicable, diagnostic support flows.

Remote Admin Messages system

This may provide safe JSON administrative messages, compatibility notes, upgrade notices, support notices, renewal notices, tutorials or product guidance to installations that communicate with Custom Auth Suite™ endpoints. Remote Admin Messages are content payloads only: no remote JavaScript and no arbitrary remote HTML is executed.

Privacy-safe Interaction Analytics

Interaction events for Remote Admin Messages, such as impressions, dismissals and CTA clicks, are disabled by default and are sent only if explicitly enabled by the administrator. The collected data is anonymous, aggregated and global: it does not track the website where Custom Auth Suite™ is installed and is not required to receive Remote Admin Messages.

Website security and authentication layer

This may centralize website-specific security features on customauthsuite.com, including anti-bot checks, Math Check, reCAPTCHA Enterprise configuration, frontend token lifecycle, server-side risk assessment and, where enabled, WooCommerce account passkeys. Depending on the active configuration, the initial reCAPTCHA Enterprise script may be loaded directly from Google or through technical delivery methods controlled by the website, such as a site-hosted or proxy URL, to improve reliability where privacy, cookie-consent or security tools interfere with direct loading. Controlled delivery does not eliminate the runtime communications with Google infrastructure that may be required for challenge execution, token generation, validation and risk analysis.

Authentication and passkey technology

With the introduction of passkey and WebAuthn authentication on this website and related products, the system may store public credential identifiers and technical metadata required for authentication. Biometric information, such as fingerprint or facial recognition data, remains on the user’s device and is not transmitted to this website.

Forms and communications

Support forms, contact forms and emails

When you submit a form, request support, ask a pre-sale question, contact us by email or open a technical ticket, we process the information needed to handle your request.

Support form categories

Support forms may include license, purchase and billing requests, pre-sale or product questions, general requests and technical issue reports. Technical issue reports may require diagnostic information or a specific file generated by the customer’s website.

Do not submit unnecessary sensitive data

Please do not include passwords, full license keys, private keys, payment card details, unnecessary personal data or sensitive information unless specifically requested through a secure channel.

Cookies

Cookie and similar technologies

Cookies are small text files stored on the user’s device. Similar technologies may include local storage, session storage, pixels, SDKs or other tracking and storage mechanisms.

Technical cookies

Technical cookies are used to provide the service requested by the user, such as navigation, authentication, session management, cart management, checkout, account access, language preferences, security, fraud prevention and cookie consent storage. These cookies do not normally require consent, but they require clear information.

Analytics and tracking cookies

Analytics or tracking tools may be used to understand website usage. Where required, analytics cookies, profiling tools or marketing tools are activated only after consent through the cookie banner or consent management platform.

Cookie consent platform

The website uses CookieYes or another consent management platform to show a cookie banner, record consent choices, allow users to accept or reject non-essential cookies and change their preferences later. Closing the banner using the available X control keeps the default consent settings and allows navigation to continue with only cookies and technologies that do not require consent.

Withdrawal of consent

Where processing is based on consent, you can withdraw or change your consent at any time through the available cookie settings or by using the options provided on the website.

Indicative cookie table

Main cookies and storage technologies

The table below combines cookies observed in the current configuration with conditional technologies that may appear only when specific services are enabled. Actual cookies may vary depending on language, checkout flow, account status, consent choices, payment method, browser rules and services enabled on the website.

Cookie / Storage Purpose Type Typical duration Category
wordpress_logged_in_* Keeps authenticated users logged in and recognizes account sessions. Cookie Session / days depending on “Remember me” Technical / essential
wordpress_sec_* Security cookie for WordPress authentication and administration areas. Cookie Session / days Technical / security
wordpress_test_cookie Checks whether cookies are enabled in the browser. Cookie Session Technical
wp-settings-* / wp-settings-time-* Stores WordPress user interface preferences, mainly for logged-in users. Cookie Up to 1 year Technical / functional
woocommerce_cart_hash, woocommerce_items_in_cart Helps WooCommerce manage cart contents and checkout flow. Cookie Session / short term Technical / ecommerce
wp_woocommerce_session_* Stores a unique customer session identifier for WooCommerce cart and checkout. Cookie Typically 2–7 days, depending on the active WooCommerce session configuration Technical / ecommerce
sbjs_session, sbjs_udata, sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, sbjs_migrations Used by WooCommerce Order Attribution to remember traffic-source, referrer, campaign, device and session information associated with the shopping journey, where the active consent settings permit it. Cookie Session; sbjs_session typically 30 minutes Analytics / order attribution / consent where required
pll_language Stores language preference where multilingual features are enabled. Cookie Months / up to 1 year Technical / functional
cas_site_device_id Stores a first-party device identifier used by the website security and authentication layer to support device recognition, authentication security and related account-protection features. Cookie Up to 1 year Technical / security
Cookie consent cookie, such as cookieyes-consent or similar Stores cookie consent preferences and banner choices. Cookie Up to 1 year in the current CookieYes configuration Technical / consent management
_GRECAPTCHA / Google reCAPTCHA Enterprise storage Set by Google reCAPTCHA when executed to support risk analysis, anti-bot checks, token validation, fraud prevention and abuse prevention for protected forms and authentication-related features. Cookie / request signals Typically up to 6 months in the currently observed configuration; managed by Google Technical / security / anti-abuse
__Secure-ENID / Google service cookie, where present Stores preferences and other information used by Google services. It is not the reCAPTCHA-specific cookie and may be present depending on the Google service context and browser session. Cookie Up to 13 months Functional / third-party service
enterprise.js / reCAPTCHA Enterprise script Security script required, where reCAPTCHA Enterprise is enabled, to generate tokens and support risk assessment. On this website, the initial script may be loaded directly from Google or made available through technical delivery methods controlled by the website, such as a site-hosted or proxy URL. Regardless of the initial delivery method, runtime requests may still be sent directly to Google-hosted infrastructure, including google.com and gstatic.com, for challenge execution, token generation, validation and risk analysis. Script / technical request Not a persistent cookie by itself; related requests and signals may be processed according to the active reCAPTCHA Enterprise configuration and Google’s applicable documentation Technical / security / anti-abuse
Website security and authentication layer’s AntiBot / Math Check fields Technical form fields or request values used to verify that a form submission is not automated, where Math Check or similar anti-bot checks are enabled on support or contact forms. Form field / request data / server-side validation Short-lived; generally used only for the form submission or related security log Technical / security / anti-spam
_ga, _ga_* or similar analytics cookies, where enabled May be used for website analytics and usage measurement only if Google Analytics or a similar analytics service is enabled and, where required, the relevant consent has been obtained. Cookie Varies by analytics configuration Analytics / consent where required
CAS license/download/update/support tokens Used to validate protected download links, package access, update access, license actions, support access or ticket access. Token / URL parameter / server-side record Limited duration depending on context Technical / security
CAS Remote Admin Message preferences and dismissals Used to remember temporary dismissals, message visibility preferences or administrative communication state. Remote Admin Messages are JSON content payloads only and do not execute remote code. WordPress option / server-side record / local administrative preference Limited duration depending on placement and message context Technical / administrative communication
Privacy-safe Interaction Analytics events Used only if explicitly enabled by the administrator to send aggregated events such as impressions, dismissals and CTA clicks. These events are anonymous, aggregated and global and do not track the website where Custom Auth Suite™ is installed. Server-side event / technical request According to CAS service configuration and retention policy Analytics / opt-in
Passkey / WebAuthn public credential metadata Used only if passkey authentication is enabled and the user registers a passkey. Biometric data remains on the user’s device. Server-side public credential metadata / local authenticator Until removed by the user or account administrator Technical / security

Third parties

Processors and external services

Some services may be provided with the help of third-party providers acting as independent controllers or processors, depending on the context.

Possible providers

  • Hosting provider and server infrastructure.
  • Payment providers and WooCommerce payment methods.
  • Email delivery services.
  • Cookie consent platform, such as CookieYes or equivalent.
  • Analytics provider, such as Google Analytics, if enabled.
  • Security, anti-spam, CDN, backup or technical service providers, if enabled, including Google reCAPTCHA Enterprise where configured for form protection, fraud prevention, token validation and risk assessment.

International transfers

If data is transferred outside the European Economic Area, appropriate safeguards will be used where required, such as adequacy decisions, standard contractual clauses or other mechanisms provided by applicable data protection law.

Retention

How long data is kept

Personal data is kept only for the time necessary for the purposes for which it was collected, unless a longer period is required by law or justified by legitimate interests.

Data category Indicative retention
Orders, invoices, billing and accounting records For the period required by tax and accounting laws.
License records and activation metadata For the license duration and for a reasonable period needed to document access, support, renewal, fraud prevention and legal claims.
Support tickets and attachments For the time needed to manage the request and for a reasonable period afterwards for continuity, accountability and dispute prevention.
Download, token and security logs For a limited period appropriate to security, abuse prevention and technical troubleshooting.
Cookie consent records According to the consent management platform configuration and applicable rules; the current CookieYes consent cookie is configured for up to 1 year.
Analytics data According to the analytics provider configuration and consent settings.
Privacy-safe Interaction Analytics events For a limited period appropriate to aggregate product communication analysis, message relevance and abuse prevention. These events are anonymous, aggregated and global and do not track the website where Custom Auth Suite™ is installed.
Remote Admin Message dismissals and preferences For the duration needed to respect the selected visibility preference or temporary dismissal period.

Rights

Your data protection rights

Under the GDPR, where applicable, you may have the right to access, rectify, erase, restrict, object to processing, request portability of your personal data and withdraw consent where processing is based on consent.

How to exercise your rights

You can contact the data controller using the privacy contact details indicated in this policy. We may need to verify your identity before responding to certain requests.

Supervisory authority

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority. In Italy, the competent authority is the Garante per la protezione dei dati personali.

Security

Security measures

Custom Auth Suite™ applies technical and organizational measures intended to protect personal data, licenses, support flows, downloads and customer access against unauthorized access, loss, misuse or alteration.

Practical limits

No website, software system, authentication mechanism, hosting platform or transmission method can guarantee absolute security. Customers should also maintain secure passwords, backups, updated websites and safe operational practices.

Incident handling

If a security issue affecting personal data is detected, appropriate measures will be taken according to applicable law and technical circumstances.

Changes

Updates to this policy

This Privacy & Cookie Policy may be updated to reflect changes in the website, products, services, cookies, analytics tools, legal requirements or technical infrastructure. The updated version will be published on this page.