Privacy Policy

How we collect, use, and protect your data.

Last updated: 28 July 2026


WebEnsure (WP-Ensure Oy) ("WebEnsure", "we", "us") operates webensure.com and related domains. This policy explains what data we collect, why, and what rights you have over it.

Who we are

WebEnsure is a managed website security and maintenance service based in Finland. For any privacy-related question or request, contact us at hello@webensure.com.

What we collect

  • Contact and audit request forms: name, email, website URL, and any details you provide. These are handled entirely by code we wrote ourselves; no third-party form service ever sees this data.
  • Quick Security Checker submissions: the URL you submit and the email address used to receive results.
  • Platform customers: site access credentials, hosting and technical data needed to monitor, secure, and maintain your website, and billing information.
  • Payment information: handled directly by Stripe. We never see or store your card details ourselves.
  • Anonymous site interaction data: which pages get viewed, which buttons get clicked, and whether a form gets opened or submitted. This is collected by a small first-party script we built ourselves, not a third-party analytics tool. It never records your IP address, carries no cookie, no visitor ID, and no way to connect one event to another or to you. See "Cookies & Analytics" below for the full detail.
  • Aggregate traffic data: general, anonymised traffic and performance data (top pages, approximate visitor country, general traffic sources) via Cloudflare Web Analytics, which is cookie-free by design and doesn't track individual visitors either.

How we use it

  • To deliver the service you requested (audit, check, or managed platform).
  • To send you the results of a Quick Security Checker scan and related follow-up.
  • To manage billing and account administration for platform customers.
  • To send marketing communications, run our email course content, and keep customers informed, only where you've opted in. The marketing consent checkbox is never pre-checked and is never a condition of using a free tool.
  • To understand, in the aggregate, which pages and buttons get used and whether our forms actually get completed, so we can improve the site. This never involves looking at what any individual visitor did.

Legal basis

We process data under one or more of: performance of a contract (platform customers), consent (marketing communications, Quick Security Checker follow-up), and legitimate interest (basic site security, fraud prevention, and understanding aggregate site usage).

Who we share it with

  • ActiveCampaign: our only email and CRM tool. Used for managing email lists, running our email courses, and keeping platform customers informed. Covered by ActiveCampaign's standard Data Processing Agreement.
  • Stripe: payment processing. Stripe handles your card details directly; we never store them.
  • Hosting and infrastructure providers (UpCloud, Cloudflare): to deliver and secure the service, to host embedded video (Cloudflare Stream), and to provide anonymised traffic analytics (Cloudflare Web Analytics).

We do not use a CRM, contact form relay, or email delivery service beyond ActiveCampaign. There is no Zoho, Mailgun, HubSpot, or any other third party in our stack. We do not sell your data, and third parties only ever receive what they strictly need to provide their part of the service. Our own interaction-tracking script never sends data anywhere outside our own servers; there's no third party involved in it at all.

How long we keep it

Contact form and audit request data is cleaned from our systems as soon as it's no longer needed to deliver what you asked for. Quick Security Checker submissions (the URL and email you gave us) are kept for 7 days, then deleted. Platform customer data is kept for as long as your account is active, and for up to 30 days after your contract ends, to handle any wind-down or billing queries. Anonymous interaction data (page views, button clicks, form opens/submits) carries no identifying information to begin with, so standard personal-data retention limits don't apply the same way; a sensible housekeeping period will still be set and confirmed separately.

Your rights

Under GDPR (and UK GDPR, where applicable) you have the right to access, correct, delete, or export your data, and to withdraw consent at any time. To exercise any of these rights, contact hello@webensure.com.

This doesn't apply to our anonymous interaction data or Cloudflare Web Analytics, since neither is ever linked back to you as an individual; there's nothing to look up against your name or email in the first place.

Cookies & Analytics

We don't use cookies for tracking, and we don't use Google Analytics or any similar third-party tool.

We built our own lightweight analytics script, interactions.js, which is served from our own domain. It logs anonymous, aggregate events (page views, button clicks, whether a form gets opened or submitted) with no cookie, no visitor identifier, no IP address, and no way to link one event to another or to a specific person. If you're curious, the file is unminified and readable in your browser's developer tools; we wrote it that way on purpose.

Alongside this, we use Cloudflare Web Analytics for general site traffic reporting. It's cookie-free and doesn't track individual visitors, consistent with everything above.

Videos on our site are embedded through Cloudflare Stream. This may set a small number of strictly necessary cookies to make playback work; it never sets tracking or advertising cookies.

None of the above requires a cookie consent banner, because none of it identifies you or tracks you across visits. If that ever changes, this section will change with it.

Changes to this policy

We'll update this page when our practices change and update the date at the top.


Why WebEnsure

Human where it matters.
Automated where it makes sense.

Automated tools are great at catching predictable issues, but not so great at judgement calls. We validate everything and act before it breaks anything.

Transparency

Each month our customers are well informed about what's been happening on their site. We tell you exactly what the bots have been up to, what we've been up to and what we recommend next.

Longevity

We get to know your site better over time. The longer we work together, the more effectively we protect and improve your site. Your site gets better with age.

AI tools, human judgement

We use AI extensively, but we validate everything. The market is being flooded with "cheap" automated-only solutions nobody checks. We're the human oversight layer that makes the output actually trustworthy.

Platform-agnostic

WordPress, Laravel, Drupal, Lovable.dev, HTML, or something we haven't heard of yet; we manage it. WebEnsure is built around your site, not around a platform we resell.

Problems don't reach you

We are all about proactive security. Issues are best caught and resolved before you even know they exist. Proactive, not reactive, is the only model that gives you peace of mind.

Fully-managed, invisibly

Security patches, CMS updates, backup verification, uptime monitoring, performance tracking. All the nerdy stuff. Handled for you. Your website just works.

Your website deserves someone obsessed with it.

Website management as it should be.