Privacy Policy
Last updated: September 17, 2026
Information we collect
When you use PluginSuggest, you may provide a name, email address, password, profile image, bio, website, social links, reviews, replies, upvotes, bookmarks, reports, and company-claim information. We may also process limited technical information needed for login, security, sessions, abuse prevention, and reliable operation of the service.
Social sign-in
PluginSuggest supports sign-in with third-party identity providers, including Google and Facebook. When you choose social sign-in, we receive only the information authorized for authentication. For Google, this may include your provider account identifier, name, email address, and whether Google reports the email as verified. For Facebook, this may include your provider account identifier, name, and email address when Facebook makes it available.
We use social sign-in information only to create, identify, authenticate, secure, or connect your PluginSuggest account. We do not use this information for advertising or unrelated profiling, and we do not sell it to advertisers.
OAuth access tokens are used only during the sign-in process to obtain the authorized identity information. PluginSuggest does not permanently store Google or Facebook access tokens or refresh tokens after sign-in. We retain the provider name, stable provider account identifier, linked PluginSuggest user ID, and limited linking information needed to keep the connection secure.
Google user data
PluginSuggest requests only the Google identity scopes needed for sign-in, such as OpenID, email, and basic profile information. Google user data is used only for the authentication and account-management purposes described in this policy. PluginSuggest's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements where applicable.
Account linking and security
If a social provider returns an email already associated with a PluginSuggest account, we do not silently merge accounts based only on the email address. We may require authentication of the existing account before connecting the provider. Passwords are protected through WordPress authentication and hashing, and sensitive account flows use time-limited tokens, nonces, rate limiting, and server-side validation.
You can manage connected sign-in methods from Account > Security.
Public information
If your public profile is enabled, your display name, profile image, bio, selected social links, published reviews, and limited community statistics may appear publicly. Email addresses are not displayed publicly.
Cookies and sessions
PluginSuggest and WordPress use essential cookies and session data for login, account security, preferences, and interactive features. PluginSuggest may remember the sign-in method last used in your browser so the login screen can show a "Last used" indicator. This preference does not contain your provider password or OAuth access token.
Service providers and sharing
Hosting, email delivery, analytics, security, and other technical providers may process limited information where necessary to operate PluginSuggest. We share information only as needed to provide, secure, maintain, or comply with legal obligations related to the service. We do not sell personal information or social-login data to advertisers.
Data retention and deletion
We retain account information while your PluginSuggest account remains active and for as long as reasonably necessary to provide and secure the service or meet legal obligations. Temporary verification and authentication tokens expire after limited periods.
Account deletion includes a 30-day recovery period. After that period, personal account data and private activity are removed where appropriate. Published community contributions may be anonymized as Deleted User. When an account is permanently deleted, its social-login identity mappings are also deleted. See our Data Deletion page for instructions and details.
Your choices and privacy rights
You can update profile information, manage connected sign-in methods, change profile visibility, reset a password, and request account deletion from your PluginSuggest account. Depending on applicable law, you may also have rights to request access to, correction of, deletion of, restriction of, or objection to certain processing of your personal information.
Policy updates and contact
We may update this policy when PluginSuggest changes features, providers, legal requirements, or data practices. For privacy, account, or data-deletion questions, use our Contact page. You can also review our Terms of Service and Data Deletion information.