Effective June 10, 2026. Last updated June 10, 2026.
AxisTaylor, LLC (“AxisTaylor”, “we”, “us”) operates axistaylor.com and the customer-facing services at /login, /account/*, and /checkout. This privacy policy explains what data we collect when you create an account, place an order, or manage an active subscription on axistaylor.com, why we collect it, who else handles it on our behalf, and what rights you have over it.
If you only read the WooGraphQL blog or documentation on woographql.com without signing in, that surface is covered by a separate, lighter policy at woographql.com/privacy.
Information we collect
Account information
When you create an account at /login we store the name and email address you provide and a one-way hash of the password you choose. We do not store your plaintext password and cannot recover it for you — a reset goes through email verification only.
Billing and shipping addresses
When you reach /checkout or update your address through /account/addresses, we store the billing name, address, city, state/region, postal code, country, and phone number you provide. Shipping addresses are only collected when an order contains a physical item.
Payment information
Card payments are processed by Stripe directly. We do not see, transmit, or store your full card number, CVV, or expiration. Stripe returns a token and the last four digits of the card; those are the only payment details we retain so we can show them on receipts and in /account/payment-methods.
Subscription, license, and download history
For WooGraphQL Pro and other subscription products, we store the subscription state (active/cancelled/past-due), the plan you are on, your renewal date, the license keys we have issued to your account, and a log of which downloads you have requested. This information is shown back to you in /account/subscriptions, /account/licenses, and /account/downloads.
Support communications
If you email us, write through /support, or open a ticket, we retain the conversation so we can follow up. We do not mine support emails for unrelated marketing.
Web analytics and error data
We use Google Analytics 4 to measure aggregate page-view, session, and conversion data — page URL, referrer, approximate location from your IP, browser version, and a randomly-generated identifier in a cookie. We use Sentry to capture JavaScript and server errors so we can fix them; Sentry receives the URL where the error occurred, the stack trace, and a small amount of request metadata.
How we use this information
- Authenticate you and keep your session active.
- Process orders, charge subscriptions, and issue receipts.
- Provision and verify license keys for the products you have purchased.
- Send transactional email — receipts, renewal notices, password resets, security alerts. We do not send marketing email by default; opt-in is required.
- Provide customer support.
- Measure and improve the site through aggregate analytics.
- Diagnose and fix errors via automatic crash reports.
- Comply with our legal and tax obligations.
Who processes data on our behalf
We rely on the following subprocessors. Each receives only the data it needs to perform the function described:
- Stripe — payment processing and PCI-DSS card storage.
- WP Engine — application hosting, database storage, and backups.
- Cloudflare — CDN, DDoS protection, and TLS termination. Cloudflare sees your IP address and request headers as part of routing traffic.
- Google Analytics — aggregate web analytics. See Google’s privacy policy.
- Sentry — automatic error reporting.
- Transactional email provider — delivery of receipts, password resets, and similar account email.
Cookies
We set the following cookies:
- Authentication cookies (
authToken,refreshToken) — short-lived JWTs that prove you are signed in. Required for the account area to function. Cleared on logout or expiry. - Session cookies (
sessionToken,Cart-Token) — link your browser to the WooCommerce guest or customer cart. Required for/checkout. - Analytics cookies (set by Google Analytics, typically
_gaand_ga_*) — measure aggregate visits. You can opt out by installing the Google Analytics opt-out browser add-on or by enabling Do Not Track in your browser.
Your rights
Depending on where you live, you have some or all of the following rights with respect to the personal information we hold about you:
- Access — request a copy of the data we hold.
- Correction — ask us to correct inaccurate information. Most of this is editable directly in
/account/details. - Deletion — ask us to delete your account and the data we hold about it, subject to the records we must retain by law (e.g. tax records on completed orders).
- Portability — receive a machine-readable export of your data.
- Opt-out — opt out of analytics or marketing communications.
- Object or restrict processing — limit how we use specific data.
To exercise any of these rights, write [email protected] from the email associated with your account. We respond within 30 days. California residents may also use a verified agent; see the CCPA notice at the end of this policy.
Data retention
We retain personal information for as long as you have an active account, and after closure for as long as we are legally required (tax, fraud-prevention, and accounting records — typically seven years for completed orders). Support emails are retained for two years. Analytics data is retained at the default Google Analytics retention setting (currently 14 months).
Security
Application traffic is served over HTTPS with TLS terminated at Cloudflare. Passwords are stored as bcrypt hashes. Payment data is tokenized by Stripe and never crosses our servers in unencrypted form. We restrict administrative access to the minimum number of personnel and require multi-factor authentication for production access. No system is perfectly secure; if you become aware of a vulnerability, please report it to [email protected].
International data transfers
AxisTaylor, LLC is based in the United States. If you access the site from outside the U.S., your data is transferred to and processed in the U.S. by us and by the subprocessors listed above. Our subprocessors are themselves subject to GDPR-compliant data processing agreements where applicable.
Children’s privacy
The service is not directed to children under 13 (or under 16 in the EU/UK), and we do not knowingly collect data from them. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.
California (CCPA) notice
In the previous 12 months we have collected the categories of personal information listed above, all from you directly. We do not “sell” or “share” personal information as those terms are defined under the CCPA. California residents may submit access, deletion, and correction requests through [email protected].
Changes to this policy
If we change this policy materially, we will update the “Last updated” date at the top and email account holders before the change takes effect. Continued use of the service after the effective date constitutes acceptance.
Contact
AxisTaylor, LLC. [email protected] · axistaylor.com/support#contact.