Who we are
Shilpi is a WordPress theme published by the Shilpi team. For anything in this policy, write to support@shilpibuilder.com.
What we collect on this website
- Contact form submissions: your name, email address, optional site URL and the message itself. We keep these for as long as the conversation is useful, and delete them on request.
- Newsletter subscriptions: your email address, and the date you subscribed. Every email contains a one-click unsubscribe.
- Purchase records: name, billing address, the licence purchased and the invoice. Payment card details never reach our servers; they are handled by our payment processor.
- Server logs: standard web server logs including IP address, retained for 14 days for security and troubleshooting.
We do not run behavioural advertising trackers on this site, and we do not sell or rent personal data to anyone, under any circumstances.
What the theme does on your own site
This part matters more than the previous one, because it concerns your visitors rather than you.
- No phone-home to render. A Shilpi page renders without contacting us. If our servers vanished tomorrow, your site would keep working.
- Licence checks contact our servers periodically to confirm your key and offer updates. That request includes the site URL and the licence key, nothing about your visitors.
- Form submissions stay on your site. They are stored in your WordPress database and delivered through your mail transport. They do not pass through us.
- Fonts can be fully local. Shilpi includes a switch that blocks every Google Fonts request site-wide, so no visitor IP address is sent to Google. Whether you enable it is your call, and in some jurisdictions it is the safer one.
- Submission retention is configurable in days, so you can decide how long personal data lives on your install rather than accumulating it by default.
MCP connections and AI agents
When you connect an AI agent to your site, that connection is between your WordPress install and whichever AI provider you chose. We are not a party to it and we do not see the content of those sessions.
What your agent sends to its provider is governed by that provider’s policy, worth reading before you point an agent at a site containing client data.
Legal basis
Where the GDPR applies, we rely on contract to sell, deliver and support a licence you bought; consent for the newsletter, which you can withdraw at any time; and legitimate interests for security logging and preventing abuse, balanced against your rights.
Who else sees your data
A small number of processors, each contractually bound and each used for one job: a payment processor for transactions, an email provider for transactional and newsletter mail, and a hosting provider for this website. We do not add processors casually, and we do not use analytics products that build cross-site profiles.
Your rights
You may ask us to show you what we hold, correct it, delete it, or send it to you in a portable format. Write to support@shilpibuilder.com and we will respond within 30 days. You do not need to explain why, and asking will never affect your licence or support.
If you are in the EU or UK and you think we have handled this badly, you may complain to your data protection authority. We would prefer you tell us first, but that is your choice.
Cookies
This website sets no marketing or analytics cookies. If you buy a licence, the checkout sets a session cookie that is strictly necessary to complete the purchase, and it expires when the session ends.
Changes
If we change this policy in a way that affects you, we will say so on this page and, for material changes, email licence holders. We will not quietly widen the scope and hope nobody rereads it.