Skip to main content
27Notice27Back to product

Privacy

Purpose-limited data, with optional consented measurement.

This notice explains the data practices of the Notice27 website, licensing service, customer account, support flow, and 2.1.0 plugin.

Last updated: 28 August 2026

Website and hosting

Hosting and security providers may process ordinary request data such as IP address, timestamp, requested URL and query parameters, browser details, and security events. Notice27 does not use a newsletter tracker. Google Analytics and Google Ads measurement are optional and remain inactive until the visitor makes the relevant choice described below.

Optional analytics and paid-campaign measurement

Notice27 offers three choices: analytics plus ad measurement, analytics only, or decline. No Google script or request is made before a positive choice. With either positive choice, Google Analytics loads only on ordinary public content pages; it is excluded from checkout, licence delivery, trial, account, owner, API, and private-preview routes. Analytics receives a filtered page location, an empty referrer, page title, a Google browser identifier, and a Google session identifier. Before the Google script is inserted, the browser performs a full-document reload onto that filtered public URL, so rejected, partial, or unknown query fields are not present in the document where Google runs. The complete UTM tuple is retained only when every field matches Notice27's bounded paid-campaign allowlist; otherwise all UTMs are removed. GA4 Enhanced Measurement is entirely disabled, and every event type under the separate Google Tag “Manage automatic event detection” control is disabled. The independent Google Tag “Allow user-provided data capabilities” setting is also disabled so Google cannot automatically inspect the page for email-like strings to hash and send. The separate GA4 “Manage data transmission” controls are set to transmit no advertising data, behavioral analytics data, or consent diagnostics while consent is denied. Production config stays disabled unless all four independent account settings are confirmed. Only the analytics-plus-ad-measurement choice permits a valid `gclid`, `gbraid`, or `wbraid` click identifier to be included so Google can associate a later purchase with the ad click. As with an ordinary browser request, Google can also receive the IP address and browser/device request metadata and processes the data under its own terms. Production enablement requires granular EEA location/device collection to be reviewed and optional collection to remain off unless separately justified. Google Signals, remarketing, and ad personalization are disabled for this launch. Google's browser cookies are limited by site configuration where supported; the Analytics cookie is configured for 30 days, while an advertising click cookie may be retained by Google for up to 90 days. The separate Notice27 choice cookie lasts up to 180 days.

After either positive choice, Notice27 stores a signed, first-party Google client/session link for no more than 24 hours and an opaque consent-grant receipt for up to 180 days. A random browser-family token is kept in a client-readable first-party cookie for up to 180 days; the server retains only its keyed one-way digest. Together these let a later withdrawal find unsent work without retaining the Google session cookie. Only the analytics-plus-ad-measurement choice can queue a server-side Google Analytics `purchase` event. It is queued only after Stripe confirms a completed paid Notice27 session and fulfilment succeed. The exact consent/attribution cookie state is reduced to a one-way digest inside that authoritative fulfilment transaction. A later recovery carrying different cookies becomes delivery-only and cannot attach a new click or consent to the old purchase. Pre-measurement fulfilled purchases are likewise recovered delivery-only. Its stable transaction identifier is a one-way hash of the already-hashed checkout reference, not the Stripe identifier. This lets an idempotent callback retry recover a transient enqueue failure without creating a second purchase identity, even across key changes. The event contains the purchased plan and is count-only: Notice27 does not send currency, value, tax, or item price. It never contains the licence key, email, name, address, domain, customer identifier, raw Stripe/order/session identifier, success-page URL, form content, IP override, or user identifier. The retry payload contains the pseudonymous Google client/session identifiers and consent-grant digest. Automated transport and unsent payload retention end at the earlier of 48 hours after immutable fulfilment or 24 hours after the linked Google session starts; up to eight attempts can fit inside that boundary. A separate grant record uses a keyed one-way browser-family digest to prevent concurrent tabs from creating grants that a later withdrawal cannot find. Grant records expire within 180 days and successfully sent retry records within 7 days. Production enablement requires Analytics data retention to be set to 2 months. This full-consent-only `purchase` is the sole event that may be imported into the isolated Notice27 Google Ads conversion action. Analytics-only consent permits public-page analytics but no server-side purchase, so analytics and Ads intentionally undercount visitors who did not grant ad measurement. Signed sessions, grants, and outbox rows also carry a non-secret keyed configuration fingerprint. A Google HMAC-key or destination change revokes mismatched grants and removes their unsent jobs; old cookies cannot authorize the new generation. A minimum reconciliation/dedup record is retained with the underlying fulfilment/business record. It contains only the one-way checkout reference, plan, stable pseudonymous transaction marker, one-way request-context digest, branch/delivery states, bounded error class, and timestamps—never raw Stripe, shopper, licence, Google client, or Google session data. A durable failed delivery remains owner-visible after its retry payload is removed until it is investigated and explicitly resolved.

Separately, an allowlisted paid URL can use Notice27's internal aggregate attribution. With ad-measurement consent, its signed first-party cookie stores only source, campaign, and numeric ad-group/creative identifiers for up to 30 days. A later verified purchase contributes to UTC daily plan/count totals and a configured tax-inclusive listed-price reference. The reference is not collected revenue, profit, CAC, or ROAS. Its stable, domain-separated SHA-256 receipt/dedup digest expires after 90 days and aggregate rows after 400 days. This internal ledger rejects click IDs and never stores email, domain, raw order/session identifiers, licence data, search queries, or shopper data. A click identifier present in the initial requested URL can still be processed by ordinary hosting/security logs even before a consent choice.

Declining blocks both measurement paths and requests removal of the first-party measurement cookies and queued, retrying, sending, or failed Google events tied to the browser's opaque consent grant, including after the 24-hour session link expires. Switching from ad measurement to analytics only revokes the old ad-measurement grant and removes the same unsent work. A request that the server cannot confirm keeps the HttpOnly revocation handle so removal can be retried. A non-identifying first-party pending-revocation cookie records only the requested measurement choice or denied state for up to 180 days and is removed after the server confirms revocation. While that request is pending, a bounded localStorage coordination record holds only a random operation UUID, the requested choice, and a hard expiry of no more than 180 days. It contains no personal data or Google identifiers and is removed on its matching confirmed completion or expiry. Browser-cookie deletion is best effort. Anonymous session changes are protected by a per-IP/per-method limit using a one-way key. The preferred edge control stores no value in the measurement database; its verified D1 fallback stores only the one-way key and a counter that expires after two minutes. Raw IPs are not stored in the measurement database. A valid signed withdrawal bypasses that quota so it cannot be stranded. The tag-free checkout-success route retries a durable pending revocation before fulfilment, reconciliation, or licence-page rendering; failure preserves the retry cookies and returns a private retry response. A conversion already sent to Google cannot be withdrawn. An event already in network transmission may complete before a later confirmed revocation, but the server does not confirm deletion while its sending lease remains active and no new transport starts after confirmation. Declining does not affect site access, checkout, delivery, licensing, or support.

Google choice: loading. First-party paid attribution: loading.

Payments and fulfilment

Stripe Checkout processes payment, billing, tax-identification, and fraud-prevention data under its own terms. Notice27 receives the Checkout Session result and, after server-side verification of a completed paid session, stores the checkout email, a one-way session digest, fulfilment state, entitlement, licence digest/prefix, and audit events. Full card details are not received or stored.

Licence keys are shown only at issuance or recovery and stored as a one-way digest. Email jobs contain delivery metadata and a key prefix, not the full key.

Plugin and licence service

The public trial-installer form processes the owner email and normalized production domain to issue a short-lived, single-use protected download. When the trial is deliberately started on staging, the plugin sends that staging domain, a random site identifier, version facts, and the declared production domain used as the one-trial anchor. Expired installer-request records are purged after no more than 30 days. Receiving the installer does not start a trial.

The plugin stores configuration, reviewed scope facts, product decisions, and order legal records in the merchant's WordPress database. It sends only licence/trial, site identity, activation, release, update, and support requests initiated by the merchant to the Notice27 service. It does not send order payment data, card data, or the contents of legal snapshots.

A domain/site identity and technical version details are used to enforce activation limits, issue signed trials, deliver updates, prevent abuse, and diagnose support requests. Deactivations, transfers, and recovery actions are audit logged.

Retention and rights

Purchase, entitlement, security, and accounting records are retained while needed to provide the product, prevent fraud, meet legal duties, and resolve disputes. Expired transient grants and magic links are kept only as operationally necessary. Merchants control the shopper/order records stored in their own WordPress installation.

For a privacy request concerning data controlled by Kastovia Holdings LLC, email contact@kastovia.com. Applicable rights depend on location and processing context.

Notice27 is operated by Kastovia Holdings LLC, identification number 402371679, Lochini 3, apt 5, 0100 Tbilisi, Georgia.

DocsCompatibilitySecurityPrivacyTermsRefundsSupport