Who we are
jkdevstudio is a small independent studio in Ukraine that makes WordPress themes and plugins. We are the data controller for everything described here. Write to hello@jkdevstudio.com about anything on this page and a person will answer.
34 Lenkavskoho St, Bldg 4, Ivano-Frankivsk, 76010, Ukraine.
What this policy covers
Two sites, because we run two and they do different jobs:
- jkdevstudio.com, the shop window. Product pages, the blog, the contact form and direct checkout.
- hub.jkdevstudio.com, the customer portal, which we call Hub. Accounts, licenses, downloads, documentation and support tickets. Hub keeps no separate policy of its own; this is its policy too.
It does not cover other people’s sites. If you bought on ThemeForest, that purchase is Envato’s and so is the data behind it. If you pay us directly, the payment page belongs to Creem. Both are covered further down, with links to their own policies. For the cookies specifically, see our Cookie Policy.
Reading the site
Browsing jkdevstudio.com asks nothing of you. No account, no cookie, no name. The server sets no cookie at all until you answer the analytics banner, and if you decline nothing is loaded and nothing is recorded.
Cloudflare sits in front of both of our sites as a content delivery network and security layer, so your request reaches Cloudflare before it reaches us. That is how a request gets served quickly and how an attack gets absorbed, and it means Cloudflare processes connection data such as your IP address on our behalf. Their handling is described in the Cloudflare Privacy Policy.
Analytics
We use Google Analytics 4 to see which pages get read and roughly where people arrive from. Each site has its own property: G-S54M8GLEXV for jkdevstudio.com and G-FE24PRDR2R for Hub.
It runs only if you accept it. Until then the Google script is never added to the page, so it has no opportunity to set a cookie or send anything. Decline and it stays unloaded on every visit. We do not run advertising or remarketing tags, we do not upload customer data to Google, and no analytics event carries your name, your email or an account identifier.
What Google does with what it does receive is governed by the Google Privacy Policy. You can also opt out of Analytics in every browser with Google’s own browser add-on.
When you write to us
The contact form asks for your name, your email address, a subject and your message. All four are emailed to our own inbox so we can reply. The message is not stored in the website’s database: it is sent and it lives in our mailbox from then on, like any other email.
The form is protected against automated abuse by Cloudflare Turnstile, which is a privacy-focused alternative to a CAPTCHA. It receives your IP address and browser signals in order to tell a person from a script. It does not ask you to identify traffic lights and it does not build an advertising profile.
Transactional email is delivered through Brevo, our sending provider, which processes the address and the message in order to deliver it.
When you ask for updates by email
There is one mailing list, and one way onto it: you tick a box that says you are happy to hear from us. Wherever the site asks that question, the footer signup, an offer panel, or any form we add later, the address goes on the same list and is handled exactly as described here. Nothing else puts you on it. Buying something does not, writing to us does not, and reading the site does not.
We keep the address and the date we last saw it. Nothing else, whichever form it arrived on. If a form asked you for anything more, a first name on an offer panel for instance, that stays with the thing you asked for and does not follow you onto the list. There is no marketing platform behind it, no scoring, no tracking pixel in what we send, and we do not sell, rent or share the list with anybody. To come off it, write to hello@jkdevstudio.com and say so, and it is done the same day.
When you claim a welcome offer
The offer panel asks for an email address and optionally a first name. Those go to Hub, along with your IP address, and Hub emails you the discount code.
The IP is there for one reason and it is worth stating: the request reaches Hub from our web server rather than from your browser, so without it Hub would see one address for every visitor on earth and could not stop one person claiming a thousand codes. It is used for that cap and nothing else.
Claiming a code is also a signup. That is what the tick on the panel asks for, so the address goes on the mailing list described above, on the same terms and with the same one line to come off it. It is added only if the code is actually issued. The name, if you gave one, stays with the offer and does not go on the list.
When you buy from us directly
Your card never touches this website. Pressing the buy button sends the product and the license tier to Hub, which asks Creem to open a checkout, and you are handed to Creem’s own hosted page to pay. Nothing about you is in that request: not your name, not your email, not your address.
Creem is our merchant of record. Legally it is the seller: it takes the payment, calculates and remits the tax, and holds the payment relationship with you. What it collects at checkout, which includes your billing details and whatever a card network requires, is described in the Creem Privacy Policy and the Creem Terms. We receive the confirmation that a purchase happened, and the email address it was made with, so that a license can be issued to you.
Our server keeps a short technical log of checkout attempts so we can tell a failed payment from a broken button: a timestamp, the product, the amount, and any error the payment returned. There is no name and no email in it, and the IP address is stored only as a salted one-way hash, which lets us count repeats without knowing whose they are.
If you leave a checkout unfinished
Creem’s checkout can be set to send a reminder when somebody enters an email address, begins to pay and then closes the page without finishing. Creem treats a checkout as abandoned twenty-four hours after it was opened. The reminder goes to the address typed into that page, and it carries nothing beyond that address and the product the checkout was for.
It runs on Creem’s side, under the Creem Privacy Policy. We never see the card details, and the address is not copied into our mailing list: coming off one has no effect on the other. Every reminder carries an unsubscribe link, and using it ends them. You can also tell us at hello@jkdevstudio.com that you would rather not receive any, and we will pass that on.
When you buy on Envato
ThemeForest is Envato’s marketplace. If you bought there, Envato is the seller, Envato took your payment and Envato holds your account and purchase data. We never see your payment details, and the personal data we can see about you is what Envato shows an author about a sale.
Their handling is theirs: the Envato Privacy Policy, the Envato Terms of Use and the Envato license terms. Hub also loads product preview images from Envato’s own image CDN, so your browser contacts Envato when a page shows one.
Your Hub account
An account on Hub is where your licenses, your downloads and your support tickets live. You can sign up with an email address and a password, or sign in with Google or GitHub, in which case that provider tells us your name, your email address and your profile picture and nothing else. Their side of it is the Google Privacy Policy and the GitHub Privacy Statement.
Against that account we hold what the account is for: which products you own, the license keys, which sites each license is activated on, what you have downloaded, and the support tickets you have opened along with anything you attached to them. A ticket is attached to your licensed product automatically, which is why we can answer without asking you to prove anything.
Hub sets two cookies before you have signed in or answered anything, and both are strictly necessary: a session cookie and a cross-site request forgery token. Neither is analytics and neither can be switched off, because with them blocked signing in does not work. They are listed in full in our Cookie Policy.
When a licensed site checks for updates
This one is easy to miss, so it gets its own section. A WordPress site running one of our products asks Hub whether there is a newer version, and to do that it sends its license key and its own domain name, along with the product and the version it currently has.
Both are needed and neither is incidental. The key is what proves the site is entitled to the download; the domain is what an activation is counted against, which is the whole mechanism behind “one site” or “unlimited sites”. It means we know the addresses of the sites your license is active on. We use that for licensing and for support context, and for nothing else: it is not sold, not shared, and not used to look at your site.
You can free an activation yourself from your account, which removes that domain.
Free products on WordPress.org
Where we publish a free theme or plugin in the WordPress.org directory, the download happens on WordPress.org and we receive nothing about you. No account, no license key, no email. Their handling is in the WordPress.org Privacy Policy.
If you write to us about a free product on the WordPress.org support forum, that conversation is public and lives on their site under their rules. If you write to us on Hub instead, the account section above applies.
Everyone who processes data for us
| Who | What they do for us | Their policy |
|---|---|---|
| Creem | Merchant of record for direct sales. Payment, tax and the checkout page. | Privacy (Creem) · Terms (Creem) |
| Envato | Seller for marketplace purchases. Holds those accounts and payments. | Privacy (Envato) · Terms (Envato) · Licenses (Envato) |
| Cloudflare | CDN and security in front of both sites; Turnstile on the contact form. | Privacy (Cloudflare) |
| Analytics on both sites, after consent. Sign-in with Google on Hub. | Privacy (Google) | |
| GitHub | Sign-in with GitHub on Hub. | Privacy (GitHub) |
| Brevo | Delivers the email we send you. | Privacy (Brevo) |
| WordPress.org | Hosts and distributes our free products. | Privacy (WordPress.org) |
Nobody on that list is an advertiser and none of them is paid in data. We do not sell personal data, and we have never shared it with anyone for their own marketing.
Why we are allowed to hold it
- To perform a contract: your account, your licenses, your downloads, your support. You bought something and this is us delivering it.
- Your consent: analytics cookies, the mailing list, the welcome offer. Given by an action you took and withdrawable at any time.
- Our legitimate interest: keeping the site up, stopping abuse, answering a message you sent us, knowing that a payment failed, and reminding you once about a checkout you left open.
- A legal obligation: tax and accounting records for a sale, which we are required to keep whether either of us wants to or not.
How long we keep things
- Your account and licenses: for as long as the account exists. Ask us to close it and it goes, except where tax law requires us to keep a record of the sale.
- Support tickets: kept while they are useful, because the next person with your problem is helped by the last one we solved.
- Contact messages: they live in our mailbox and are cleared out periodically.
- The mailing list: until you ask to come off it.
- The checkout log: the last two hundred attempts, and older entries are overwritten automatically.
- An unfinished checkout: held by Creem under its own policy, and never stored here.
- Anti-abuse counters: hashed, and gone within a day.
Your rights
Under the GDPR and comparable law elsewhere you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interest, and ask for your data in a portable form. Where we rely on consent you can withdraw it at any time, and that does not undo processing that was lawful while it was in force.
Write to hello@jkdevstudio.com. We answer within 30 days, and usually a great deal sooner because there are not many of us and the queue is short. If you think we have handled your data badly you can complain to your local data protection authority, and we would rather you told us first so we can put it right.
Where your data goes
We are in Ukraine and the services above are spread across the European Union, the United Kingdom and the United States, so data reaches countries outside the European Economic Area. Where that happens we rely on the safeguards those providers put in place, which for the ones listed above means Standard Contractual Clauses or an adequacy decision. Each provider’s policy sets out its own arrangements.
Children
Our products are development tools and are not aimed at children. We do not knowingly collect data from anyone under 16. If you think we have some, tell us and it will be deleted.
Changes to this policy
If we add a service that handles your data, or drop one, this page changes with it and the date at the top moves. Anything that would need your consent will be asked for rather than assumed.


