HMDIA Login & Registration Privacy Policy

Last updated: October 2, 2026

This policy explains how HMDIA Login & Registration (the “Plugin”), its optional Pro add-on, and related HMDIA add-ons handle personal information. It supplements the HMDIA website Privacy Policy.

The Plugin runs on websites operated by independent site owners. The owner of a website using the Plugin decides which features to enable, which information to request, how long to keep it, and which outside services to connect. If you registered, signed in, or submitted a form on such a website, contact that website’s owner about your information and read its privacy policy. HMDIA does not receive your account or form information merely because the website uses the free Plugin.

Information handled by the Plugin

Depending on the website’s settings and the information you provide, the Plugin may process:

  • Account and registration details: username, name, email address, password handled through WordPress, and optional phone number, custom fields, verification status, and records of accepting site terms.
  • Login and account security details: sign-in and password-reset requests, verification codes, session information, and technical information used to prevent abuse. With applicable Pro features, this may include two-factor authentication settings, passkey details, recovery information, authentication events, timestamps, browser information, and a masked IP address or IP-derived hash.
  • Contact form submissions: name, email address, subject, message, custom fields, submission time, and related administrative status, if the site enables the built-in Contact Form.
  • Registration documents: files submitted through an enabled registration form. Their content depends on the fields the site owner chooses to request.

The Plugin uses this information to create and manage WordPress accounts, verify registrations, process sign-ins and password resets, provide selected security features, deliver account messages, process contact submissions, and help the site owner prevent spam and unauthorized access. Anti-abuse checks may reject a form submission or sign-in attempt.

Where information is stored

Account information is stored in the website’s WordPress database. Contact submissions can be stored in a Plugin-managed table if the site owner enables the Contact Form and leaves submission storage on. Temporary verification and reset information is kept for the period needed to complete those actions. Pro features and other add-ons may store additional security or access records on the website.

Current private registration-document storage encrypts new protected uploads on the website. Older document uploads may require a separate migration by the site owner; copies previously exposed through public media URLs or external caches may remain until the owner removes them. Website owners are responsible for their hosting, backups, access permissions, and any copies held outside WordPress.

Cookies and browser storage

The Plugin relies on WordPress authentication cookies for sign-in. It can also set a temporary cookie for the password-reset process. Some interface preferences, such as the currently selected account or settings section, may be saved in the browser’s session storage. If a site enables an external CAPTCHA provider, that provider may use its own browser technologies under its privacy policy.

Optional external services and add-ons

The following connections occur only when the relevant feature is configured or used:

  • Google reCAPTCHA v3 or Cloudflare Turnstile: the visitor’s browser connects to the selected provider. The provider may receive the visitor’s IP address and browser/request information. The website also sends a challenge token, the provider’s secret key, and the visitor’s IP address to the provider’s verification API. These services help assess automated submissions. See Google’s Privacy Policy or Cloudflare’s Privacy Policy.
  • Twilio SMS through Pro: if the website administrator configures Twilio and enables SMS verification, the website sends the recipient number, configured sender, security-code message, and Twilio account credentials to Twilio. See Twilio’s Privacy Notice. Your mobile provider may also process SMS delivery information.
  • Pro licensing and updates: the separately installed Pro add-on contacts HMDIA to activate or check a license and obtain eligible updates. These requests include the website URL, license key, product and version details, and an activation identifier when available. License activation also includes WordPress and PHP versions. HMDIA processes this information to verify entitlement and deliver updates. The free Core Plugin does not send licensing or telemetry requests to HMDIA.
  • Website email and media services: account and contact messages are sent using the website’s WordPress email configuration, which may involve a separate email provider. If an administrator chooses externally hosted logos or backgrounds, a visitor’s browser or email client may request those files from the chosen host.

Other HMDIA add-ons, including Traffic & IP Security and Post Submission, may process additional information for their own enabled features. The website owner should disclose those features and any other connected services in the website’s own privacy policy.

Retention and deletion

The website owner controls WordPress user accounts and most Plugin settings. If the built-in Contact Form is enabled, its default submission-retention setting is 180 days; the owner can change this to 30, 90, or 365 days, choose to keep submissions until deleted, or turn off submission storage. Expired submissions are removed when the Plugin’s cleanup runs. Pro activity records have separate configurable retention. Temporary authentication records expire, while accounts and other records may remain until the site owner deletes them. Backups and third-party providers may have separate retention periods.

The Plugin integrates with WordPress personal-data export and erasure tools for some Plugin-managed records. Those tools do not automatically remove every WordPress user account, all security information, every backup, or copies held by external providers. Removing the Plugin also does not automatically delete WordPress users; Plugin data cleanup on uninstall is an administrator choice.

For information HMDIA receives directly through Pro licensing, purchases, or support, we retain it for the purposes described in the HMDIA website Privacy Policy and as needed for applicable legal obligations.

Your choices and requests

If your information is held on a website using the Plugin, contact that website’s owner to request access, correction, export, or deletion, or to ask which optional features and providers are active. The owner may need to verify your identity and may have legal reasons to retain certain information.

For information you have provided directly to HMDIA, including Pro license or support information, contact us through HMDIA’s contact page. Privacy rights and available choices depend on your location and the circumstances of the request.

Security and international processing

The Plugin uses WordPress authentication and access controls and includes protections for selected sensitive records. The security and location of information stored on an independent website also depend on that website’s hosting, configuration, administrators, email providers, backups, and connected services. Optional providers and HMDIA license services may process information in countries other than yours; consult their policies and the website owner’s policy for details.

Changes to this policy

We may update this policy as the Plugin or its optional services change. The latest version and its update date will be posted here. Questions about HMDIA’s handling of information can be sent through our contact page.