Privacy Policy
MigraSync Privacy Policy
Effective date: 10 July 2026
Last updated: 10 July 2026
Published at: https://migrasync.com/privacy/
1. Introduction
This Privacy Policy explains how MigraSync (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you:
- Visit migrasync.com and related marketing pages (a “visitor”)
- Create an account, purchase a plan, or use the customer dashboard (a “customer” or “account holder”)
- Install and use the MigraSync Plugin on your WordPress site (a “connected site”)
MigraSync (https://migrasync.com) is operated by Elliyas Ahmed, an individual based in Bangladesh. MigraSync is a software product brand; there is no separate registered company entity for MigraSync at this time.
The Service includes Blogger-to-WordPress migration, managed cloud WordPress backup, and WP Restore. Our Terms of Service and Refund & Cancellation Policy apply alongside this policy.
Payments: Paid orders are processed by Freemius.com (Merchant of Record). Freemius’s privacy practices for payment data are described in the Freemius Privacy Policy.
Questions or privacy requests: [email protected] (subject line: Privacy request).
2. Who is responsible for your data?
| Role | Who | Applies to |
| Data controller (for MigraSync account, billing references, website, and platform operations) | Elliyas Ahmed operating as MigraSync (Bangladesh) | Your account email, checkout/entitlement records, API keys, job metadata, support messages, and website usage where we decide why and how data is processed |
| Data controller (for content on your WordPress / Blogger site) | You (the site owner) | Posts, pages, comments, media, customer lists, and other content you migrate or back up |
| Data processor (for your site content during migration/backup) | MigraSync (operated by Elliyas Ahmed) | We process your site content only to perform migration, backup, or restore jobs you start |
| Independent controller (payments) | Freemius.com | Card/payment details and tax invoicing as Merchant of Record |
If your WordPress site collects data from your visitors (forms, comments, ecommerce), you must provide your own privacy notice and lawful basis. MigraSync does not control your public website’s relationship with your audience.
3. Summary — what we store vs what we do not
3.1 Website visitors (no account)
| We store | We do not store |
| Essential cookies (login session if you sign in; cookie consent choice) | A marketing profile or advertising audience built from browsing |
| Short-lived server/security logs (IP address, browser type, pages requested, timestamps) | Your name or email unless you submit a form or register |
| Google Analytics data only if you accept analytics cookies (see §6) | Payment or billing details on our servers |
| Contents of your Blogger or WordPress site | |
| Google account passwords |
Without an account, we do not need your email to browse public pages. We do not sell visitor data.
3.2 Customers and account holders
| We store | We do not store |
| Account email address and authentication data (password stored as a secure hash) | Full payment card numbers or CVV (handled by Freemius, our Merchant of Record) |
| Subscription status, plan entitlements, API keys, and linked site records | Your Master Vault Key on MigraSync SaaS in plain text — vault keys are controlled on your WordPress site (you must save your Recovery Sheet) |
| Migration and backup job metadata (job IDs, counts, status, timestamps, error summaries) | Google / Blogger account passwords |
| Encrypted backup archives in MigraSync Managed Cloud when you use backup services | Permanent copies of backup ZIP files on your hosting disk (staging files are purged after cloud upload) |
| Temporary processing copies of migration/backup payloads on our infrastructure for the time needed to complete jobs and support | Your site content for advertising, resale, or unrelated AI training |
| Support correspondence you send us | OAuth refresh tokens on our servers after you disconnect (tokens are primarily stored on your WordPress site) |
| Billing references from Freemius (transaction IDs, receipts — not full card data) |
3.3 What MigraSync Plugin does on your WordPress site
The MigraSync plugin runs on your server. It stores configuration locally (for example API key reference, OAuth tokens in encrypted vault storage, job progress, debug logs you enable). That data stays on your hosting unless a job sends content to MigraSync SaaS / Managed Cloud as part of a migration or backup you start.
We do not use the Plugin to track your website visitors for MigraSync marketing.
4. Information we collect in detail
4.1 Information you provide directly
| Source | Examples | Purpose |
| Registration / login | Email address, password | Create and secure your account |
| Checkout | Email, billing country (via Freemius), plan selection | Process orders and entitlements |
| Dashboard & support | Messages, ticket content, optional feedback | Provide support and improve the Service |
| Reviews / comments (if enabled) | Name, email, review text | Display testimonials and moderate spam |
| MigraSync Plugin wizard | Blogger OAuth authorization (via Google), import options, API key | Run migration or backup jobs you request |
| Consent modal | Acceptance of the Service Responsibilities Agreement before migration/backup/restore | Document authorization and shared operational duties |
4.2 Information collected automatically
| Source | Examples | Purpose |
| Server logs | IP address, request URL, HTTP status, user agent, approximate timing | Security, abuse prevention, debugging |
| Essential cookies | WordPress session cookie (wordpress_logged_in_*), cookie consent cookie (msw_cookie_consent) | Authentication and remember consent choice |
| Analytics cookies (optional) | Google Analytics identifiers when you opt in | Understand aggregated site usage (see §6) |
4.3 Information from third parties
| Provider | What we receive | Purpose |
| Freemius | Payment status, transaction IDs, tax/billing country, subscription events | Billing and entitlement sync |
| Google (Blogger OAuth / APIs) | Access to Blogger content you authorize; we do not receive your Google password | Migration from Blogger |
| Google Analytics | Usage metrics when you consent to analytics cookies | Website analytics |
4.4 Site content processed during migration and backup
When you run a job, we may process:
- Post and page text, HTML, metadata, and URLs
- Media files referenced in content or included in backup scope
- Comments and replies (if you enable comment import)
- WordPress database tables included in backup scope (users, options, plugin data, etc.)
- Technical job logs needed to complete or troubleshoot the job
We use this content only to perform the operation you requested. We do not use it for advertising.
5. Cookies and similar technologies
We use a cookie consent banner on migrasync.com with essential and optional analytics categories.
| Category | Examples | Required? |
| Essential | Login session, security nonces, consent preference (msw_cookie_consent) | Yes — needed for account access and to remember your cookie choice |
| Analytics | Google Analytics cookies (e.g. _ga, _ga_*) | No — only placed if you accept analytics in the banner or cookie settings |
You can change your choice anytime via the cookie settings link in the banner (where shown) or by clearing cookies in your browser.
For more detail, see our Cookie Policy (companion document).
6. Google Analytics
We use Google Analytics 4 (GA4) on migrasync.com to understand how visitors use our marketing and account pages (for example which pages are read, general traffic levels, and device/browser types in aggregate).
6.1 When Analytics runs
- Analytics scripts and cookies are loaded only after you consent to analytics cookies, except where local law allows strictly necessary measurement without consent.
- If you choose “Essential only” or reject analytics, we do not set Google Analytics cookies for that visit (beyond any strictly necessary technical measurement your browser performs).
6.2 What Google Analytics may collect
When enabled, Google may process:
- Pages viewed and approximate time on page
- Referring URL / campaign parameters
- Browser, device type, and screen resolution (aggregated)
- IP address (Google may apply IP anonymization or similar settings depending on our GA configuration)
- Pseudonymous identifiers in cookies
We use this to improve content, navigation, and conversion paths — not to sell data or serve third-party ads on other websites.
6.3 Google as a separate controller
Google processes analytics data under its own terms:
You can opt out of Google Analytics using Google’s browser add-on or by rejecting analytics cookies on our site.
7. How we use personal data
We use personal data to:
- Provide migration, backup, restore, and account features
- Authenticate API requests between your WordPress site and MigraSync SaaS
- Process payments and manage subscriptions (via Freemius)
- Send service emails (for example backup completion, security notices, password reset)
- Provide customer support
- Secure the Service (fraud prevention, rate limits, audit logs)
- Comply with legal obligations
- Measure website performance with consent (Google Analytics)
We do not:
- Sell your personal data
- Use your migrated or backed-up site content for advertising
- Use your site content to train unrelated machine-learning models
- Share your data with third parties for their independent marketing without a lawful basis
8. Legal bases (EEA, UK, and similar jurisdictions)
Where GDPR or equivalent law applies, we rely on:
| Purpose | Typical legal basis |
| Account creation and contract performance | Contract (Art. 6(1)(b) GDPR) |
| Migration / backup / restore you request | Contract and, for site content, your instructions as controller |
| Payment processing | Contract and legal obligation (tax/records) |
| Security logging and abuse prevention | Legitimate interests (securing the Service) |
| Google Analytics (optional) | Consent (Art. 6(1)(a) GDPR) |
| Marketing emails to existing customers (if sent) | Legitimate interests or consent, with unsubscribe where required |
You may withdraw consent for analytics at any time without affecting the lawfulness of processing before withdrawal.
9. Storage, encryption, and retention
9.1 Security measures
- TLS encryption in transit between your site, our APIs, and cloud storage
- Encrypted backup database packages (AES-256) using your Master Vault Key — we cannot decrypt backups without the key you hold
- Access controls and API key authentication
- MigraSync Plugin never holds direct cloud storage credentials for Managed Cloud; uploads go through MigraSync SaaS
Details: Security & GDPR
9.2 Retention periods
| Data type | Typical retention |
| Account data | While your account is active, then deleted or anonymized within a reasonable period after closure (subject to legal hold) |
| Billing records | As required for tax and accounting (often 6–7 years, depending on jurisdiction) — held by Freemius and in our order history |
| Server / security logs | Limited period (typically days to 90 days) unless needed for an active investigation |
| Migration processing copies | Temporary — generally up to 30 days for operational and support needs, then deleted or anonymized where applicable |
| Cloud backup archives | Per your Auto purge policy while subscription is active; see Terms §5.3 for grace period and deletion after cancellation |
| Cookie consent record | Up to 12 months (renewed when you interact with the banner again) |
| Google Analytics | Per Google’s configuration and our retention settings in GA4 (aggregated reports) |
When backup subscriptions end, cloud backups are deleted after the grace period described in our Terms — even if you selected a longer per-backup retention while subscribed.
10. Where data is stored and international transfers
MigraSync uses infrastructure providers that may process data in countries other than your own, including the United States and the European Economic Area.
Subprocessors may include:
| Provider | Role |
| Freemius.com | Payment processing and Merchant of Record |
| Cloud infrastructure for MigraSync Managed Cloud | Encrypted backup object storage (currently Cloudflare R2) |
| Blogger OAuth/APIs; Google Analytics (if consented) | |
| Hosting / email providers | Website, SaaS application, transactional email |
Where required, we use appropriate safeguards for international transfers (for example Standard Contractual Clauses or equivalent mechanisms offered by vendors).
11. Sharing and disclosure
We share personal data only when necessary:
| Recipient | Why |
| Freemius | Payment, tax, invoicing, subscription lifecycle |
| Infrastructure subprocessors | Hosting, storage, email delivery |
| Analytics (with consent); Blogger API (when you connect Google) | |
| Professional advisers | Legal, accounting, or insurance where required |
| Law enforcement / regulators | When required by applicable law or valid legal process |
We do not share your migration or backup content with other customers.
If MigraSync is involved in a merger, acquisition, or asset sale, we will notify account holders where required by law before personal data becomes subject to a different policy.
12. Your rights
Depending on your location, you may have the right to:
- Access a copy of personal data we hold about you
- Correct inaccurate data
- Delete data (subject to legal and contractual exceptions — for example active subscriptions or tax records)
- Restrict or object to certain processing
- Port data you provided in a structured format where technically feasible
- Withdraw consent (for analytics and any consent-based processing)
- Lodge a complaint with your local data protection authority
EU / UK: You may use the EU Online Dispute Resolution platform for consumer disputes, but please contact us first at [email protected].
How to exercise rights: Email [email protected] with the subject Privacy request, your account email, and the right you wish to exercise. We may verify your identity before responding. We aim to respond within 30 days (or as required by law).
Note on backup content: If you want content removed from an encrypted backup, you may delete the backup from your dashboard/plugin, allow retention purge to run, or delete your account per our Terms. Decryption requires your vault key — we cannot recover backups if you lose the key.
13. Children
MigraSync is a business service not directed at children under 16 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child provided us data, contact us and we will delete it promptly.
14. Third-party links
Our site links to third parties (for example Google, Freemius, documentation hosts). Their privacy practices are governed by their own policies. We are not responsible for third-party sites you visit from our pages.
15. Changes to this policy
We may update this Privacy Policy from time to time. The Last updated date at the top will change when we do. Material changes will be posted on migrasync.com. Continued use after the effective date constitutes notice, except where law requires explicit consent.
16. Contact
| Purpose | Contact |
| Data controller / operator | Elliyas Ahmed (individual), Bangladesh — brand: MigraSync |
| Privacy requests & questions | [email protected] |
| Product support | [email protected] |
| Security reports | [email protected] |
| Contact form | https://migrasync.com/contact/ |
| Website | https://migrasync.com |
| Freemius billing support | [email protected] |
17. Related documents
- Terms of Service
- Service Responsibilities Agreement
- Refund & Cancellation Policy
- Cookie Policy
- Security & GDPR
- Freemius Privacy Policy
18. Legal notice
This document is provided for transparency and customer communication. It is not legal advice. MigraSync recommends that you review this policy with your own counsel if you use the Service for business-critical, regulated, or high-risk workloads.
For questions about this Privacy Policy: [email protected]