Compliance & Security Policy

Last Updated: July 2026

1. Introduction

At MetaMate, we take privacy, data protection, and user trust seriously.

This Compliance & Security Policy outlines how we handle and protect data, maintain security standards, and comply with global privacy laws.

MetaMate is developed and managed by RankRider Solutions, based in the United Kingdom.

Our website and related services are securely hosted on Hostinger, a GDPR-compliant, ISO-certified hosting provider.

2. GDPR & Data Protection Compliance

MetaMate complies with the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

We ensure that:

  • Personal data is collected and processed lawfully, fairly, and transparently.
  • Only the minimum necessary data is collected (for billing, licensing, and communication).
  • You can request access, correction, or deletion of your data at any time.
  • All processing by third-party providers follows strict GDPR and security protocols.

Our key third-party processors and infrastructure include:

  • Hostinger (web hosting and security)
  • Stripe / PayPal (payment processing)
  • MetaMate’s own AI processing service, which uses the OpenAI API to generate suggestions
  • Google Analytics (website analytics, optional)

For data requests or concerns, contact:

support@metamateplugin.com

3. Hosting & Infrastructure Security (Hostinger)

Our website is hosted on Hostinger’s GDPR-compliant infrastructure, which provides:

  • ISO 27001 & ISO 27017 certified data centers (EU and UK regions)
  • SSL certificates (HTTPS) securing all data exchanges
  • Automated daily backups and data recovery tools
  • 24/7 infrastructure monitoring and DDoS protection
  • Access control and network-layer security

We rely on Hostinger’s built-in security layers, SSL encryption, and proactive monitoring to maintain data integrity and uptime.

4. Payment & Subscription Security

MetaMate uses Stripe and PayPal for all payment and subscription processing.

Both providers are fully certified under the Payment Card Industry Data Security Standard (PCI DSS Level 1).

We:

  • Do not store or access any customer credit card or financial information.
  • Use secure, encrypted payment forms and redirect flows managed by our payment partners.
  • Allow customers to cancel subscriptions at any time through their account dashboard or by contacting support.

5. AI Transparency & Data Handling

MetaMate’s AI features generate SEO content suggestions such as meta titles, descriptions, and alt text. Requests are processed through MetaMate’s own AI service, which acts only as a bridge between your site and the OpenAI API, so no OpenAI account or key is required from you.

  • Only the content relevant to your request (such as a post title, body text, or image) is sent for processing.
  • This content passes through to OpenAI and back; it is not stored or logged by MetaMate’s AI service, and is not used to train AI models.
  • Content processed for background AI tasks (e.g. schema generation, internal linking) is stored temporarily in your own WordPress database and automatically deleted within 24 hours.

Since AI suggestions are generated from your own post and page content, we’re not able to guarantee the absence of personal or sensitive information in any given request, that depends on what your content contains. We recommend reviewing any content before submitting it for AI processing if it includes information you’d rather not send for processing.

6. User Consent & Cookie Management

When you visit metamateplugin.com, you will see a cookie banner allowing you to:

  • Accept all cookies
  • Customise cookie preferences
  • Reject non-essential cookies

MetaMate only uses cookies for essential functions and anonymised analytics.

You can modify your cookie preferences at any time.

7. Data Retention & Storage

We retain user data only as long as necessary to:

  • Maintain billing and licensing records
  • Provide customer support
  • Meet tax or legal obligations

Plugin-generated data (e.g. SEO suggestions or AI results) is stored locally in your WordPress installation and can be deleted at any time by the user.

8. Security Maintenance & Updates

We follow WordPress and Hostinger security best practices, including:

  • Regular plugin updates and version testing
  • SSL-secured API communication
  • Prompt vulnerability patching when needed
  • Continuous monitoring for security alerts

MetaMate is designed to remain lightweight and secure without slowing your site.

9. Reporting a Security Concern

If you believe you’ve found a vulnerability or data issue, please report it to us immediately.

support@metamateplugin.com

10. Compliance Alignment & References

MetaMate’s ecosystem aligns with internationally recognised standards through its hosting, payment, and technology partners.

Framework / StandardManaged ByCompliance Coverage
GDPR (EU Regulation 2016/679)RankRider SolutionsFull user data protection rights
UK Data Protection Act 2018RankRider SolutionsApplies to UK users and servers
EU ePrivacy Directive (Cookie Law)RankRider SolutionsManaged via cookie banner consent
PCI DSS Level 1Stripe / PayPalSecure payment processing
ISO 27001 & 27017HostingerCertified server infrastructure and data protection

MetaMate does not claim to hold these certifications directly. Instead, we align with these standards through the certified compliance of our trusted partners and infrastructure providers.

11. Contact Information

If you have questions about our compliance, data protection, or security measures, please contact:

support@metamateplugin.com

We respond to compliance inquiries within 72 hours (Mon-Fri).

12. Revision Policy

This policy is reviewed annually or when regulations or partnerships change. All updates will be published on this page with a revised “Last Updated” date.