Privacy Policy

Last updated: May 9, 2026

1. Introduction

Welcome to Niftytheme. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

By using our website, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Account Information

Upon registration, we may collect the following account information:

  • Name
  • Email address
  • Password (hashed)
  • Profile data collected on registration

2.2 Purchase & Billing Information

When you make a purchase, we collect the following billing details:

  • Billing name
  • Email
  • Payment method type (processed by Paddle — no raw card data stored on our servers)

2.3 License & Product Data

To manage your purchased products, we collect:

  • License keys issued
  • Products purchased
  • Download history

2.4 Support Data

When you interact with our support system, we collect the following support data:

  • Ticket content
  • Replies
  • Internal notes (admin-only)
  • File attachments uploaded in tickets

2.5 Contact Form Data

When you contact us through our contact form, we may collect the following personal information:

  • Name
  • Email address
  • Subject of inquiry
  • Message content
  • Timestamp of submission

2.6 Technical & Usage Data

We may automatically collect certain information about your device and how you interact with our website, including:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited
  • Time spent on pages
  • Referring website

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To respond to your inquiries and provide customer support
  • To process and fulfill your orders for our products and services
  • To improve our website and services
  • To send you important updates about our services
  • To comply with legal obligations
  • To prevent fraud and ensure security

Where required by law (e.g. GDPR), we process your data on the following legal bases: contractual necessity (order fulfilment, account management), consent (marketing communications), legitimate interest (fraud prevention, security), and legal obligation (tax and compliance records).

4. Third-Party Services

4.1 EmailJS

We use EmailJS to process contact form submissions. When you submit our contact form, your information is sent to EmailJS for email delivery. Please review EmailJS's Privacy Policy to understand how they handle your data.

4.2 Paddle

Paddle acts as our Merchant of Record and payment processor. They handle all payment transactions, billing, and tax. Your payment information is subject to Paddle's Privacy Policy.

4.3 Supabase

We use Supabase to host our PostgreSQL database, where account, purchase, license, and ticket data is stored. See Supabase's Privacy Policy.

4.4 Vercel

Our website and API are hosted on Vercel. Request logs may be processed on Vercel infrastructure. See Vercel's Privacy Policy.

4.5 Email Delivery

Transactional emails (order confirmations, ticket notifications) are sent via Nodemailer via a secure SMTP provider.

5. License Verification

Products purchased from NiftyTheme (themes and modules) include a license verification system. When installed, these products periodically contact our servers at www.niftytheme.website/api/licenses/verify to confirm the validity of the license key. During this process, we collect: the license key, the domain name where the product is installed, and the server's IP address. This data is used solely for license validation and fraud prevention, is not shared with third parties, and is retained for the duration of the license.

6. Data Storage and Security

We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure.

6.1 Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.

7. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your personal information

To exercise these rights, please contact us using the information provided below. To submit a request, email privacy@niftytheme.net. We will respond within 30 days.

8. Cookies and Tracking Technologies

We use essential cookies required for our website to function, including session and authentication cookies that keep you logged in. We do not use advertising or tracking cookies. During Paddle checkout, Paddle may set their own cookies governed by their privacy policy. You can control cookie settings through your browser preferences, but disabling essential cookies may affect site functionality.

9. Children's Privacy

Our services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately.

10. International Data Transfers

NiftyTheme is operated internationally. Your data may be transferred to and processed in countries outside your own, including the United States, where our hosting providers (Vercel, Supabase) operate. These transfers are conducted under appropriate safeguards, including Standard Contractual Clauses (SCCs) as part of our sub-processors' Data Processing Agreements.

11. Contact & Data Controller

Data Controller: NiftyTheme is the data controller for personal information collected through this website.

Contact: For any privacy-related requests, questions, or to exercise your rights under §7, please contact us at: privacy@niftytheme.net or via our Contact Page.

We will respond to all data requests within 30 days.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.