Privacy Policy
Last updated: 10 August 2026
1. Who we are
Vario is a WooCommerce variation management tool that provides a spreadsheet interface for editing product variations. The Service is operated by WP Butler, established in Denmark, in the European Union.
For the personal data described in this policy, we are the data controller as defined by the EU General Data Protection Regulation (GDPR). Where we process product data from your WooCommerce store on your behalf, we act as a data processor and you are the controller.
You can reach us about anything in this policy at info@getwebbed.dk.
2. What data we collect
We try to collect as little as possible. Here is the complete list:
- Account data: your email address, your name (if you provide one), and a hash of your password. We never store your password in readable form – it is hashed with bcrypt and cannot be reversed.
- Store connection data: the URL of your WooCommerce store and the name you give the connection.
- WooCommerce API credentials: the consumer key and consumer secret issued by your store. These are encrypted at rest with AES-256-GCM before they are written to our database.
- Cached product and variation data: product names, variation attributes, SKUs, prices, sale prices, stock quantities and stock status, synced from your store so the spreadsheet can be shown and searched quickly.
- Subscription data: your plan, subscription status and a customer reference from our payment provider. We do not store card numbers – we never see them.
- Technical and usage data: server logs (IP address, timestamp, requested URL, error messages) and basic product usage such as when a sync last ran. Logs exist so we can keep the Service secure and working.
We do not collect customer data, order data, or payment data from your WooCommerce store, and we do not buy personal data from third parties.
3. Why we process it, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account data | Creating your account, signing you in, service emails | Performance of a contract (Art. 6(1)(b)) |
| Store URL & API credentials | Connecting to your store so you can read and edit variations | Performance of a contract (Art. 6(1)(b)) |
| Cached product data | Showing, filtering and editing the spreadsheet without re-querying your store | Performance of a contract (Art. 6(1)(b)) |
| Subscription data | Billing, invoicing and plan limits | Performance of a contract and legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Logs & security data | Keeping the Service available, debugging, preventing abuse | Legitimate interests (Art. 6(1)(f)) |
| Product update emails | Telling you about new features, if you opt in | Consent (Art. 6(1)(a)) – withdrawable at any time |
We do not use your data for automated decision-making or profiling, and we do not sell it to anyone.
4. How your API credentials are protected
Your WooCommerce consumer key and secret are the most sensitive thing you give us, so we treat them accordingly:
- They are encrypted at rest using AES-256-GCM, an authenticated encryption scheme.
- The encryption key is held in the application environment, not in the database, so a database dump on its own does not reveal your credentials.
- They are decrypted only in memory, only for the duration of a request you triggered.
- They are never shown back to you in full after the connection is made, never written to logs, and never shared with third parties.
- All traffic to Vario and from Vario to your store runs over HTTPS.
Vario only contacts your store when you ask it to – when you run a sync or save your changes. It does not poll your store in the background, and it does not touch your store while you are not using it. See our Security page for the full technical picture.
5. Sub-processors
We use a small number of service providers to run Vario. They process data only on our instructions and are bound by data processing agreements:
- Our hosting and database provider – runs the application and stores the data described above. Servers are located in the EU/EEA.
- Polar – handles subscriptions, payments and invoicing. Polar receives your email address and billing details. Card details go directly to Polar and its payment partners; they never pass through Vario.
- Our transactional email provider – delivers account emails such as password resets, and receives your email address for that purpose.
Where a sub-processor transfers data outside the EU/EEA, that transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision. We will tell you before adding a new sub-processor that materially changes how your data is handled.
6. How long we keep data
- Account and store connection data: for as long as your account exists.
- Cached product and variation data: for as long as the store connection exists. It is overwritten on each sync, and deleted immediately when you disconnect the store.
- API credentials: deleted immediately when you disconnect the store or delete your account.
- Server logs: kept for a short period (normally up to 30 days) and then deleted.
- Invoices and accounting records: retained for five years after the end of the financial year, as required by the Danish Bookkeeping Act.
Inactive free accounts may be deleted after a long period of inactivity. We will email you first.
7. Deleting your data
You can delete your account at any time from your account settings. Deleting your account removes your account record, your store connections, your encrypted API credentials, and all cached product and variation data. Backups containing the deleted data are rotated out within 30 days.
Deleting your Vario account does not revoke the API key inside your WooCommerce store. We recommend also deleting the key under WooCommerce → Settings → Advanced → REST API so it can never be used again.
Deleting your Vario account never changes or deletes anything in your store. Your products and variations stay exactly as they are.
8. Your rights under the GDPR
If you are in the EU/EEA, you have the right to:
- Access – get a copy of the personal data we hold about you.
- Rectification – have inaccurate data corrected.
- Erasure – have your data deleted (“the right to be forgotten”).
- Restriction – ask us to pause processing while a dispute is resolved.
- Portability – receive your data in a structured, machine-readable format, or have it sent to another provider.
- Objection – object to processing based on our legitimate interests.
- Withdraw consent – at any time, where processing is based on consent. This does not affect processing that already happened.
Write to info@getwebbed.dk and we will respond within one month. Exercising your rights is free.
If you are not satisfied with how we handle your data, you can complain to the Danish Data Protection Agency, Datatilsynet (Carl Jacobsens Vej 35, 2500 Valby, Denmark – datatilsynet.dk), or to the supervisory authority in your own country.
9. Cookies
Vario uses cookies that are strictly necessary to run the Service: a session cookie that keeps you signed in, and a security cookie that protects against cross-site request forgery. These do not require consent under the ePrivacy rules because the Service cannot work without them.
We do not use advertising cookies, and we do not embed third-party trackers on the pages you use while signed in.
10. Data breaches
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high. If the breach could have exposed store credentials, we will tell you which connections are affected so you can revoke the keys in WooCommerce.
11. Children
Vario is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this Privacy Policy as the Service evolves. The “Last updated” date at the top always reflects the current version. If a change materially affects how we handle your data, we will notify you by email or inside the Service before it takes effect.
13. Contact
Questions, requests, or complaints about privacy? Email info@getwebbed.dk and a human will read it.