Privacy First Architecture

Privacy Policy & Telemetry

We believe in total transparency. Learn how our software protects shopper privacy and handles minimal licensing verification telemetry.

1. Zero Shopper Tracking Philosophy

FlexExt Store does not track, collect, or transmit any personally identifiable information (PII) regarding the customers who visit or purchase from your store. Customer names, addresses, credit cards, and order items remain strictly inside your own private Joomla database.

2. What Telemetry We Collect & Why

When your Joomla server communicates with our licensing API (api/license.php), the following minimal technical metadata is securely transmitted over TLS:

  • License Key: To identify and validate your commercial edition.
  • Domain Name: To ensure domain quota binding (1 domain for Basic/Pro, up to 3 for Ultimate).
  • Joomla & PHP Version: To ensure compatibility and provide accurate update alerts.
  • Cryptographic Nonce: To prevent replay attacks on verification tokens.

3. Client-Side Cookies Used

FlexExt Store only sets essential functional cookies required for core shopping cart operations:

  • flx_store_cart: Stores active cart items and quantities for the shopper's session.
  • flx_store_currency: Remembers the shopper's chosen currency preference across visits.
  • flx_store_consent: Records GDPR consent choices (granted/denied) for Google Consent Mode v2.

4. Data Security & Retention

All licensing data is stored on secure European servers and encrypted at rest. We never sell, rent, or distribute merchant data to third parties under any circumstances.