UltimaSEO

Security & privacy

Understand the connections before you enable them.

Your accounts, configured securely

UltimaSEO connects to the provider accounts you choose through WordPress settings. Relevant content, queries and evidence may be sent to the providers required for the workflows you enable. Review each connection and its permissions before use. Never send passwords or API credentials to support.

Content stays under your control

Private preparation and substantive publication are separate steps. Use the review and approval workflow, administrator permissions and provider spending limits.

One commerce authority

UltimaTour manages checkout, billing records, licensing, entitlements and authorized downloads. Stripe or PayPal hosts payment entry when available at checkout. This storefront displays verified commerce responses; a browser return cannot create payment or license status.

Support conversations

The support assistant uses a contracted external processing provider. Your question, recent conversation and relevant product references may be sent to that provider to prepare an answer. We save conversations, tickets and reusable Q&A privately in our WordPress database so you can return and our team can help. FAQ candidates become reusable or public only after review; personal contact details stay out of published answers.

A necessary support cookie remembers your conversations in this browser for up to one year. A private access code lets you recover them on another browser. Keep it private. Saved records remain available until the team handles a deletion request through Support. Support archives preserve the records and exclude API keys.

Guests can ask up to two support questions per IP in a rolling 24 hours, at least 30 seconds apart. For ongoing questions and human tickets, we verify an active public website and an email address on its domain. We store that verification for 30 days and use hashed connection identifiers, IP-based guest counters, email and website counters to limit abuse. Google reCAPTCHA checks automated traffic for every guest question, every other visitor answer and verification-code request; Google receives the browser and interaction data needed for that check. Verification codes expire after 15 minutes.

Cookies & measurement

This storefront adds no advertising tags or marketing analytics. Sign-in uses WordPress authentication cookies. Optional referral attribution in the commerce flow requires a separate explicit choice and can be withdrawn.

The product has an optional aggregate commerce funnel for product views, checkout starts, trusted account readiness and authorized downloads. It begins disabled and needs the supported product version and configuration.

Web hosting and external providers may process ordinary connection metadata. Retention, processor details and final policy text remain subject to owner review.

Read the policy drafts →