_Last updated: 2 August 2026_

This policy explains what hektechnologies.com collects about you, why, and what you can do about it. It is written to be read, not to be skimmed past.

Who we are

Hektechnologies is a sole operation owned and run by Spencer Heckathorn in Broken Arrow, Oklahoma. Spencer is the person who handles data requests, and the person who answers the phone.

Email: [email protected] Phone: (405) 283-2416

The site is hektechnologies.com. It runs on WordPress and sits behind Cloudflare.

There is no contact form on this site

Worth saying plainly, because most privacy policies claim otherwise. This site has no working contact form. If you want to reach us you email or you call, and the record of that conversation lives in our email or on a phone, not in a database on this site.

What we collect when you buy something

Orders run through WooCommerce, which is installed on our own site. When you place an order we collect:

  • your name
  • your email address
  • your phone number
  • your billing address
  • the products, seat counts and prices in the order
  • the date, the order status, and any notes we add while handling it

We use that to fulfil the order, to provision your licences with the software vendor, to invoice you, to support you afterwards, and to keep the tax records we are required to keep.

If you create an account on the site, we also store your username, a hashed password, and your order history so you can see it again.

How long we keep it. Order and invoice records are kept for 7 years, because that is what tax record-keeping needs. Site accounts are kept until you ask us to delete them, or until 3 years after your last order, whichever comes first.

Payments and Stripe

Card payments are processed by Stripe. Your card number, expiry date and security code go directly to Stripe. They are not stored on this site, and we never see the full number. What comes back to us is the last four digits, the card brand, and whether the payment worked.

Stripe is a data controller in its own right for the payment data it handles. Its privacy policy is at stripe.com/privacy.

If you pay by credit card, a card-processing surcharge is added and shown as a separate line. That is a billing matter rather than a privacy one, and it is covered in our terms and conditions.

Passing your details to the software vendor

We resell Cloudbrink, and Veraify powered by Cloudbrink. To give you working licences we have to create your users in the vendor’s system. That means passing on the account name, the email addresses of the people who need seats, and the seat count.

The vendor then holds that data under its own privacy policy. Once your users are provisioned, the vendor also holds whatever the software itself collects in normal operation, which is a matter between you and them. Ask us and we will point you to the current vendor policy for your product.

Analytics

We use Google Analytics, connected through the Site Kit by Google plugin. It tells us how many people visit, which pages they read, roughly where in the world they are, and what they clicked before they left.

Google Analytics sets cookies in your browser and collects your IP address, device and browser type, referring URL, and the pages you view. Google processes that data on our behalf and also for its own purposes under its own terms. IP addresses are truncated by Google before being stored.

Analytics data is retained for 14 months, then deleted automatically.

Site Kit also connects Google Search Console. That only shows us aggregated search data. It does not identify individual visitors.

You can opt out of Google Analytics entirely with Google’s browser add-on at tools.google.com/dlpage/gaoptout, or by blocking the cookies in your browser.

Cloudflare

The site sits behind Cloudflare, which acts as our CDN and security proxy. Every request to this site passes through Cloudflare before it reaches our server, so Cloudflare sees your IP address, the page you asked for, and your browser’s user agent.

Cloudflare uses that to serve pages faster and to block attacks. It sets its own cookies for security purposes, including a bot-management cookie. We cannot turn those off without turning off the protection.

Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.

Newsletter

Our newsletter runs on Mailster, which is installed on our own site rather than on an external mailing platform. If you subscribe we store your email address, any name you give us, the date you subscribed, the IP address you subscribed from, and which lists you are on.

Mailster records whether an email was delivered, whether it was opened, and which links were clicked. That is how we tell whether anyone is reading. Turning off image loading in your email client will stop the open tracking.

Every newsletter has an unsubscribe link at the bottom. Click it and you are removed. You can also email us and we will do it for you.

Subscriber records are kept until you unsubscribe. After you unsubscribe we keep a minimal record of the unsubscribe itself, so that we do not accidentally add you again.

Email we send you

Transactional email from the site, meaning order confirmations, password resets and similar, is sent through the Post SMTP plugin. Post SMTP writes a log entry on our server for each message. That log records the recipient address, the subject line, the time, and whether sending succeeded.

We use it to prove an email actually went out when a customer says it did not arrive. Logs are kept for 30 days, then cleared.

Affiliate and tracked links

Some outbound links on this site are tracked redirects, generally under a /recommends/ path. They are managed by the Easy Affiliate Links plugin.

When you click one, our site records that the link was clicked and then sends you on to the destination. Some of those destinations are affiliate programs, so the third party may set its own cookies to record that we sent you. Once you land on their site, their privacy policy applies and ours does not. Clicking never changes what you pay.

Cookies

Cookies set by or through this site fall into a few groups:

Necessary. WordPress sets a login cookie and a session cookie if you have an account. WooCommerce sets cart and session cookies so your basket survives a page reload. If you leave a comment, WordPress offers to save your name, email and website in a cookie so you do not retype them next time; that one lasts a year and only appears if you tick the box.

Security. Cloudflare sets cookies to identify trusted traffic and to filter bots.

Analytics. Google Analytics sets cookies to count visitors and sessions.

You can block or delete cookies in your browser settings. Blocking the necessary ones will break checkout and login.

Comments

If you leave a comment on a post, we collect what is in the comment form, your IP address, and your browser user agent. That helps with spam detection. Comments and their metadata are kept indefinitely so that follow-up replies still make sense in context, unless you ask us to remove yours.

If you have an approved comment, your profile picture may be visible to the public through the Gravatar service.

Media and embedded content

If you upload an image to the site, avoid uploading images with embedded location data, because visitors can extract it.

Articles on this site may include embedded content such as videos or maps from other sites. Embedded content behaves exactly as if you had visited that other site directly. Those sites may collect data about you, set their own cookies, and track your interaction with the embedded item, particularly if you have an account and are logged in with them.

Backups

The site is backed up using Duplicator Pro, and by our hosting provider. Backups are copies of the whole site, so they contain the data described above until they age out. Where you ask us to delete something, it will disappear from the live site immediately and will drop out of backups as the older backup sets are rotated.

Backup files are stored encrypted and are not shared with anyone.

Who else sees your data

The site is hosted on a WordPress multisite, so our hosting provider necessarily has access to the server that holds it. Beyond that, your data reaches:

  • Stripe, for payment processing
  • Cloudbrink, for licence provisioning
  • Google, for analytics
  • Cloudflare, as our CDN and security proxy
  • our email provider, which carries the messages Post SMTP sends

We do not sell your data. We do not share it for anyone else’s advertising. We will disclose it if we are legally required to, and we will tell you when we are allowed to tell you.

Data is processed in the United States.

Your rights

You can ask us to:

  • send you a copy of the personal data we hold about you
  • correct anything that is wrong
  • delete your data
  • stop sending you marketing email

Email [email protected] and say what you want. We will confirm your identity first, usually by replying to the address already on the account, and answer within 30 days.

Deletion has limits worth stating up front. We cannot delete invoices and order records that tax law requires us to keep, and deleting your account here does not delete the users your organisation created inside the software vendor’s system. For those, the request has to go to whoever administers your licence.

If you are a California resident, you have the right to know what is collected, to request deletion, and not to be discriminated against for asking. The same email address handles those requests.

Children

This site sells business software. It is not aimed at children, and we do not knowingly collect data from anyone under 13. If you think we have, email us and we will delete it.

Security

The site runs over HTTPS. Passwords are stored hashed, never in plain text. Payment card data never touches our server. Cloudflare filters malicious traffic before it reaches us.

No site is perfectly secure. If we ever have a breach that affects your personal data, we will tell you.

Changes to this policy

We update this page when what we do changes. The date at the top tells you when it last happened. If a change materially affects how we handle your data, we will say so by email to customers and subscribers.

Contact

Hektechnologies Broken Arrow, Oklahoma, USA [email protected] (405) 283-2416