Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how Viz (“Viz,” “we,” “us”) handles information in connection with the website at vizwp.com, the accounts you create with us, and the Viz WordPress plugin. We built Viz to be privacy-respecting by design, and this document is meant to be read in plain language.
1. Overview
Viz is an analytics tool for WordPress that identifies and classifies the traffic reaching your site - humans, search engines, and AI bots. The plugin runs on your own WordPress installation, and by default the data it produces stays in your own database. We only receive that data if you explicitly opt in to our optional cloud features.
We do not sell personal information. We do not load third-party advertising or tracking scripts inside the plugin.
2. Two contexts: website and plugin
It is important to distinguish between the two situations in which information is involved:
- The website and your account (vizwp.com). When you visit our marketing site or create an account, we act as the data controller for the limited information described below.
- The plugin on your site. When the plugin logs your visitors’ requests, that data is written first to your own WordPress database. You are the controller of your visitors’ data. If you enable optional cloud sync, we process the synced data on your behalf as a processor, under these terms and any applicable data processing agreement.
3. Information we collect
Account and website information
- Account details you provide at sign-up: name, email address, and your site URL. Passwords are stored only as salted hashes.
- Billing information for paid plans is handled by Paddle.com, our Merchant of Record and payment processor. We never receive or store your full card details. See Paddle's privacy policy at paddle.com/legal/privacy.
- Website usage such as pages viewed, approximate region derived from IP, and basic device or browser information, collected with privacy-friendly, cookie-light analytics.
- Support communications you send us by email or other channels.
Information processed by the plugin
On your site, the plugin records request metadata so it can classify traffic. This typically includes the request URL, timestamp, user agent, referrer, and IP address, along with the resulting classification. This data is stored in your database. You control whether human visitors are logged, whether administrators are excluded, and the retention window.
Optional cloud-sync data
If you opt in to cloud features, the plugin transmits classified event data to us so we can provide cross-site bot intelligence and remote dashboards. Delivery is batched and HMAC-signed. You can disable cloud sync at any time.
Optional Google integration
If you connect Google Analytics or Search Console, we access aggregate reporting data (traffic and search query reports) to display it in your dashboard and improve prompt discovery. OAuth tokens are stored server-side only and are deleted when you disconnect. Viz's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use information
- To provide, operate, secure, and improve the website and the service.
- To create and manage your account and authenticate you.
- To process payments and manage subscriptions.
- To deliver optional cloud features, including aggregated, cross-site bot intelligence.
- To respond to your support requests and communicate service notices.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations.
5. Legal bases for processing
Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract (to provide the service you request), our legitimate interests (to secure and improve the service), your consent (for example, optional cloud sync), and compliance with legal obligations.
7. Data retention
We retain account information for as long as your account is active and as needed to provide the service, then for a limited period to meet legal, tax, and security requirements. For plugin data stored on your own site, you set the retention window. For cloud-synced data, we retain it for the period described in your plan or until you delete it or close your account. IP addresses of human visitors in cloud-synced data are anonymized after 30 days.
8. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, HMAC-signed cloud delivery, hashed passwords, access controls, and least-privilege practices. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to incidents.
9. International transfers
We may process and store information in countries other than your own. Where required, we use appropriate safeguards, such as standard contractual clauses, for international transfers of personal data.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR. If you are a California resident, you have rights under the CCPA and CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information; we do not sell or share personal information as those terms are defined.
To exercise any of these rights, contact us using the details below. We will not discriminate against you for exercising your rights, and you may have the right to lodge a complaint with your local supervisory authority.
11. Children
The service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the service after an update means you accept the revised policy.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at shikhar@sortcamp.com.
The data controller is Shibusa Ventures Private Limited, Ward No. 9 Gadarpur, Udham Singh Nagar, Rudrapur, Uttarakhand, India, 263152.