Last updated: September 2, 2026
This privacy notice explains what personal data we process when you use GPLClub, why we process it, how long we keep it and what you can require from us. It is written against what the system actually does: every piece of data mentioned here corresponds to information the platform really stores or transmits.
Data controller
Lofitec S.A.S. (hereinafter "GPLClub"), with registered address in Polanco, Mexico City (Mexico), is the controller of the personal data collected through gplclub.com.
For anything concerning your personal data, including the exercise of your rights, write to [email protected].
We operate from Mexico and serve customers worldwide. This document is therefore governed by the Mexican Federal Law on the Protection of Personal Data Held by Private Parties and, where the user resides in the European Economic Area or the United Kingdom, also by the General Data Protection Regulation.
What we process and why
User account
We store your name, your email address and your password, the latter always protected by an irreversible hash function, so nobody, ourselves included, can read it. We also record whether you have verified your email and when. Legal basis: performance of the membership contract.
Subscription and payments
Payments are processed entirely through Stripe. We never receive or store your card details. On our side we only keep the identifiers Stripe returns to us (customer and subscription IDs), your plan, its status and the billing period dates, plus your order history and any coupons applied. Legal basis: performance of the contract and compliance with our accounting and tax obligations.
Updater plugin licences
When you activate the GPLClub Updater plugin on one of your WordPress sites, we record that site's domain, the last IP address it connected from and the plugin version installed. This lets us enforce your plan's site limit, support you when something breaks and detect account sharing between third parties. Legal basis: performance of the contract and our legitimate interest in preventing fraud.
Downloads
Every download is logged with the product, the date and time, the domain it was requested from and the browser identifier (user agent). We use this to apply your plan's daily credits and to detect automated abuse. Legal basis: performance of the contract and our legitimate interest in the security of the service.
Support
If you write to us through the support form, we process the name, email and message you send, together with the IP address you send it from (the latter solely as an anti-spam measure). Legal basis: handling your own request.
Support access to your account
When you write to us with an issue that cannot be resolved blind (a download that fails, a licence that will not activate, a charge that does not add up), someone on our team may sign in to your account to see exactly what you see. It is how we fix it without asking you for screenshots or making you repeat steps over email. Legal basis: handling your own request and our legitimate interest in providing support.
We do it with these safeguards, and they are technical, not a promise:
- We never see your password. It is stored hashed with a one-way algorithm: neither we nor anyone else can read it from the database. Signing in to your account does not require knowing it and does not reveal it to us.
- We never see your card number. Payment details are held by Stripe, our processor, and only the card type and its last four digits ever reach our systems. The full number, the expiry date and the security code never pass through our servers.
- It is logged. Every access records who signed in, into which account, when it started and when it ended, plus every change made while inside. That log is read-only for us too.
- It expires on its own. A support session ends after 60 minutes without anyone having to remember to close it.
- Administration team only. No other user can sign in to anyone else's account.
We use this access solely to handle the issue you wrote to us about. If you would rather we did not sign in to your account, tell us when you write and we will resolve what we can over email.
If you left us your email to be notified of an opening
During the move to the new platform, the screen you saw offered to take an email so we could let you know when we reopened. If you left one, we store only that: your email, the language you were browsing in and the IP address you sent it from (the latter solely as an anti-spam measure). Legal basis: your consent.
That email has a single purpose and is spent on it: sending you one notice that we are open. It is not a mailing list, we do not use it for promotions and we do not share it with anyone. As soon as we send that notice, we delete your address from that list.
If you would rather we deleted it sooner, write to us and it is done.
Security and technical logs
We keep session records (IP address and user agent) and an audit log of actions performed from the administration panel. Legal basis: our legitimate interest in keeping the platform secure and being able to investigate incidents.
Who we share your data with
We do not sell your data and we do not share it for advertising purposes. Only the providers strictly necessary to run the service are involved:
- Stripe: payment processing and subscription management.
- SMTP2GO: delivery of transactional emails (confirmations, receipts, renewal notices, password recovery).
- Cloudflare: content delivery network and protection against attacks; it processes requests made to our site.
- Hosting and file storage provider: the servers where the platform runs and the catalogue files are kept.
Each of them acts as a processor and handles the data only on our instructions. We may also disclose data where a legal obligation or a request from a competent authority requires us to.
International transfers
GPLClub is a Mexican company: your data is processed in Mexico and in the countries where the providers listed above operate, mainly the United States and the European Union.
If you reside in the European Economic Area or the United Kingdom, this means your data is transferred outside that region. Mexico is not currently covered by an adequacy decision of the European Commission, so the transfer relies on the standard contractual clauses approved by the Commission or another mechanism under Chapter V GDPR, together with the security measures described below. You may request information about these safeguards by writing to [email protected].
Cookies
This site uses no analytics, advertising or third-party tracking cookies. We only set the first-party cookies the site cannot work without:
- Session cookie: keeps you signed in while you browse. It expires when you close your browser or after a period of inactivity.
- CSRF token: prevents a third party from submitting forms on your behalf. It is a security measure, not a tracking one.
- Language preference: remembers whether you chose Spanish or English so we don't ask again on every visit.
Because these are strictly necessary cookies, they do not require your prior consent. Should we add analytics or affiliate tracking in the future, we will ask for your consent before setting them and will reflect it here.
How long we keep your data
We keep your account data for as long as your membership is active. If you cancel, we keep the account for a reasonable period in case you come back, and then delete or anonymise it. Download and licence records are kept for as long as they remain useful to enforce your plan's limits and detect fraud. Billing data is kept for the period required by the applicable accounting and tax obligations.
Your rights
Your rights depend on where you live, but in practice we handle both the same way: write to [email protected] from the address linked to your account, stating what you want to exercise.
If you reside in Mexico: ARCO rights
Under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties you may request:
- Access: to know what data of yours we hold and what we use it for.
- Rectification: to correct anything inaccurate or incomplete.
- Cancellation: to remove it from our records, except what we must keep by law.
- Objection: to object to a specific processing activity on legitimate grounds.
You may also withdraw any consent you have given us. We will answer your request within twenty business days at most and, where applicable, act on it within the following fifteen business days. If you believe we have not handled it properly, you may turn to the competent Mexican data protection authority.
If you reside in the EEA or the UK: GDPR rights
- Access: to know what data of yours we process.
- Rectification: to correct anything inaccurate.
- Erasure: to delete it, except what we must keep by law.
- Portability: to receive your data in a machine-readable format.
- Objection and restriction: to object to processing based on our legitimate interest, or to ask us to restrict it.
We will reply within one month at most. If you believe we have not handled your request properly, you may lodge a complaint with the supervisory authority of your country of residence.
Minors
The service is intended for people aged 18 or over, consistent with our Terms and Conditions. We do not knowingly collect data from minors.
Security
Passwords are stored hashed with a modern algorithm, all traffic travels over HTTPS, and catalogue files are scanned by an antivirus engine before being made available to members. No system is invulnerable, but if a breach occurred that posed a risk to your rights, we would notify you.
Changes to this notice
If we amend this notice we will update the date shown at the top. Where a change affects you significantly, we will let you know by email.
Other documents
Any questions about these terms? Get in touch