Privacy Policy
Benecaster Privacy Policy
Last updated: September 2026
Overview
This Privacy Policy explains how Anadar Professional Services, LLC (“Benecaster,” “we,” “us,” or “our”) collects, uses, and protects information through the Benecaster WordPress plugin and the benecaster.com website.
Two separate contexts apply, and it matters which one you’re in:
1. benecaster.com — When you purchase and manage a Benecaster license, we are the data controller for your account and billing information.
2. The WordPress plugin — When you install Benecaster on your WordPress site, your subscribers’ data is stored on your server. You are the data controller for your subscribers. We never receive individually identifying data about your podcast subscribers.
This is not a technicality. It reflects a core design decision: podcasters’ audiences belong to the podcasters, not to Benecaster.
Who This Policy Covers
Podcasters (customers): People who create accounts, purchase licenses, and install the plugin. This policy governs our collection and use of your data.
Visitors: People who browse benecaster.com without an account.
Podcast subscribers: If you’re a podcaster using Benecaster, your subscribers’ data is governed by your privacy policy, not this one. We never receive individually identifying information about them.
Data We Collect
Account and Billing Information
When you create an account and purchase a license:
- Name and email address
- Billing address
- Payment and subscription details — billing and subscription management are handled directly through Stripe, which receives your name, email, billing address, plan, and billing history. Card data is entered directly into a Stripe-hosted payment form and never passes through Benecaster’s servers. We store only a Stripe customer ID. We never receive or store raw card numbers, CVV codes, or full card details.
- Your site’s connection token (stored as a hashed value; the token itself is issued to your site once, when you connect it, and is not stored in plaintext — we retain only a short prefix so support can identify a connection without being able to use it)
- Purchase history and subscription status
- Tax information on your invoices — where sales tax or VAT applies to your purchase, we record the tax charged, the rate, and the jurisdiction alongside your billing address, because a tax invoice has to show them
Legal basis: Contract performance. For the tax details on invoices, compliance with a legal obligation.
License Validation Data
Each Benecaster installation sends a daily validation request to our license server. This request includes:
- The URL of your WordPress installation
- Plugin version, WordPress version, PHP version
- Active add-on slugs
- Counts only, never identities: your total feed tokens, paying subscribers, followers, any tokens over your plan limit, and your published show count
- Whether the installation is a staging environment, and whether this is its first validation
- Validation timestamp
The request is authenticated by the site’s connection token, sent in the request header. It contains no subscriber names, email addresses, or feed tokens, and nothing that identifies an individual subscriber.
Purpose: To confirm your license is valid and deliver the correct feature set to your installation.
Legal basis: Contract performance.
Retention: The 30 most recent validation records per license are retained. Older records are purged automatically.
Telemetry Data (Opt-In Only)
If you choose to participate in usage data sharing — controlled in Benecaster → Settings — the daily validation request also includes aggregate statistics about your podcast installation. Participation is entirely voluntary and can be changed at any time.
What is included when you opt in:
- Subscriber counts by tier
- Episode counts
- Average feed request rate per subscriber
- Geographic distribution of subscribers: country and region/state totals only (e.g., “45 subscribers in Texas”) — never individual subscriber locations
- Listening pattern distributions (hour-of-day and day-of-week totals across all subscribers)
- Podcast app distribution
- Subscriber tenure distribution in buckets (0–30 days, 31–90 days, 91–365 days, 365+ days)
- Aggregate churn rate and episode reach rate
What is never included:
- Subscriber email addresses, names, or any individual identifiers
- Individual feed tokens or private RSS URLs
- Individual download records
- Any data that could identify a specific subscriber
Purpose: To improve the product and generate platform-wide benchmark analytics. Benchmarks are surfaced back to customers (e.g., “your churn rate compared to the platform median across all Benecaster sites”).
Legal basis: Consent. Customers who do not opt in transmit only the validation data in the previous section — no subscriber-related data of any kind.
Retention: Telemetry snapshots are retained for 24 months, then purged.
Support Communications
If you contact us for support, we may receive your email address, account details, and the content of your request. This data is processed by our support platform and retained in accordance with that platform’s policies.
Data the Plugin Stores (We Never Receive This)
The Benecaster plugin stores the following data about your subscribers on your WordPress server. This data never leaves your server — it is not transmitted to benecaster.com or any other party by Benecaster.
- Subscriber email addresses (through WordPress user accounts)
- RSS feed tokens (stored as SHA-256 hashes; the plaintext token is shown once and never stored)
- Subscription tier and status
- Last feed access timestamp
- Geographic location: country and region/state derived from IP address at first feed access — the raw IP address is discarded immediately after the lookup; only country code and region code are stored
- Download history (if you enable the optional download proxy): episode, timestamp, podcast app, geographic data, and a hashed IP (SHA-256 with a site-specific salt — not reversible to the original IP)
- Email preferences and unsubscribe state
Geographic data handling: IP lookups are performed using a MaxMind GeoLite2-City database stored locally on your server. No IP addresses are sent to MaxMind or any third party. The database provides city, postal code, and coordinate data, but Benecaster deliberately does not extract or store anything below the country/region level.
Your responsibility as a podcaster: You are responsible for disclosing to your subscribers how you collect and use their data, including geographic data derived from IP addresses. This is standard practice for podcast analytics and is handled the same way by podcast hosting providers. See our support documentation for suggested privacy disclosure language you can use in your own privacy policy.
How We Use Your Information
We use the information we collect to:
- Deliver and maintain your Benecaster license
- Process payments and send billing confirmations, receipts, and renewal notices
- Send operational emails about your license (threshold notifications, upgrade eligibility notices, plan changes)
- Respond to support requests
- Improve the product (with your consent, using aggregate telemetry data)
- Generate anonymized platform-wide benchmarks available to all customers
We do not:
- Sell your personal data to any third party
- Use your data for advertising purposes
- Access subscriber data stored on your WordPress installation
Third-Party Services
| Service | Data we share | Purpose |
|---|---|---|
| Stripe | Name, email address, billing address, plan selection, subscription status, billing history, renewal dates | Payment processing and subscription management — Stripe manages the full customer billing relationship on our behalf, including recurring charges, plan changes, and payment method storage. Card data enters Stripe’s servers directly and never passes through ours; we store only a Stripe customer ID and never receive raw card numbers |
| [Support platform — HelpScout or equivalent] | Support inquiry content, email address, account info | Customer support |
| Email platform (if applicable) | Email address, account status | Product update and transactional emails (with your consent for marketing; required for transactional) |
Stripe operates under its own privacy policy. We encourage you to review it. Stripe is bound by contractual obligations to process your data only as directed and to maintain appropriate security standards.
MaxMind GeoLite2: Used locally on your server for geographic lookups. No data is transmitted to MaxMind.
The table above lists services we use to run Benecaster, and we are accountable for them. It is not a list of software on your site. Membership and commerce plugins that Benecaster connects to — MemberPress, WooCommerce Subscriptions, Paid Memberships Pro, Restrict Content Pro, and others — are third-party products you have chosen and installed. We interface with them; we do not own them, receive their data, or control what they collect. See Cookies → Cookies set by other plugins on your site.
Data Retention
| Data | Location | Retention |
|---|---|---|
| Account and billing records | benecaster.com | Duration of account + as required by applicable law |
| Invoices and tax records | benecaster.com | 7 years, or 10 years for customers in the EU, as tax law requires. Retained even if you close your account or ask us to delete your data — see below |
| Account credit records | benecaster.com | Kept as part of our financial records. Retained even if you close your account or ask us to delete your data — see below |
| Support diagnostic logs | benecaster.com | 90 days, then purged automatically. Deleted immediately if you ask us to delete your data |
| License records | benecaster.com | Duration of account + 2 years |
| Validation logs | benecaster.com | 30 most recent per license; older records purged automatically |
| Telemetry snapshots | benecaster.com | 24 months |
| Subscriber tokens, feed logs, geographic data | Your WordPress server | Until you delete it — we have no access |
| Download proxy logs | Your WordPress server | Configurable in Benecaster → Settings → Tools; no automatic deletion by default |
| Subscriber unsubscribe log | Your WordPress server | Indefinitely (regulatory compliance — proof that opt-outs were honored) |
Your Rights
Customers (Benecaster.com Account Holders)
Access: Your account data, order history, and license records are available through your account at benecaster.com/my-account/.
Correction: Update your account information at any time in your account dashboard.
Deletion: Request account deletion by contacting us at [support/privacy email]. We will remove your personal data from our systems subject to our obligations to retain records under applicable law.
What we cannot delete, and why. Tax law requires us to keep invoices and the account credit records that go with them, including the billing details on them — your name, billing address, and the tax charged — for 7 years, or 10 years for customers in the EU. Those records are kept even after you close your account or ask us to delete your data, because we are legally required to hold them.
Because the rest of your account is deleted, your name and email address are copied onto those retained records so they remain valid financial documents. An invoice that cannot say whose it is is not an invoice.
Everything else is removed — including any support diagnostic logs you sent us, which are deleted immediately rather than waiting out their 90-day window. We will tell you exactly what was retained when we action your request.
Aggregate telemetry data, which cannot be attributed to a specific customer, may be retained for platform benchmark calculations.
Portability: Order history and license data are available for export from your account dashboard.
Opt-out of marketing communications: Use the unsubscribe link in any marketing email or contact us.
California Residents (CCPA)
- We do not sell your personal information.
- You have the right to know what data we collect, request deletion, and receive the same service regardless of whether you exercise these rights.
EU and UK Residents (GDPR)
- You have the rights of access, rectification, erasure, restriction of processing, and data portability.
- You have the right to lodge a complaint with your supervisory authority.
- To submit a request, contact us at [privacy email or postal address].
Your Subscribers’ Rights
Your subscribers’ privacy rights with respect to data stored on your WordPress site are your responsibility to handle, not ours. Benecaster provides tools to export and delete individual subscriber records — see our support documentation for instructions on processing data subject requests.
Cookies
benecaster.com uses:
- Session and login cookies — strictly necessary for account login and checkout functionality. These cannot be opted out of while using the account or checkout.
- Your cookie choice (
benecaster_ls_cookie_consent) — records the answer you give our cookie banner so we do not ask again. Strictly necessary, kept for one year, and set by us. It stores a preference and nothing else. - Stripe fraud-prevention cookies — our checkout, signup and account pages load Stripe’s payment library, which sets its own cookies (
__stripe_midand__stripe_sid) to detect fraudulent payment activity. These are set by Stripe, not by us, and are used for payment security rather than advertising or profiling. Stripe’s own privacy policy governs them. They load only if you accept them. Decline and we do not load Stripe’s library at all on those pages — you can still browse, sign in and read your invoices, and you are asked again at the point you need to enter a card. - No analytics cookies, no advertising cookies, and no cross-site tracking. We do not run Google Analytics, Google Tag Manager, advertising pixels, or any similar service on benecaster.com.
The Benecaster plugin does not set cookies on your WordPress site beyond standard WordPress session handling.
Cookies set by other plugins on your site
Benecaster does not control, and cannot report on, the cookies or data practices of other software running on your WordPress site.
Benecaster is designed to work alongside membership and commerce plugins — MemberPress, WooCommerce Subscriptions, Paid Memberships Pro, Restrict Content Pro and others. We interface with those products; we do not own them. They are developed by other companies, they set their own cookies, they collect and process their own data, and they change independently of us. We have no visibility into what they do and no ability to keep pace with their releases.
If you run any of them, you are responsible for reviewing that product’s own privacy policy and cookie disclosures and for reflecting them in your site’s privacy notice and, where required, its consent banner. Nothing in this policy describes, warrants, or accepts responsibility for their behaviour. The same applies to your theme, your host, and any other plugin on the site.
This is not a disclaimer of our own obligations: we remain fully responsible for what Benecaster itself does, which is set out above and in Data the Plugin Stores.
Children’s Privacy
Benecaster’s services are directed at adults operating podcast businesses. We do not knowingly collect personal information from anyone under 13 (US) or under 16 (EU/UK). If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.
If your podcast content is directed at children, you are responsible for ensuring appropriate consent mechanisms are in place before using Benecaster’s subscriber features with that audience.
Changes to This Policy
We may update this policy from time to time. For material changes, we will notify you by email (to the address on your account) or through a notice in your Benecaster admin dashboard before the change takes effect. The “Last updated” date at the top of this page reflects the most recent revision.
Contact
For privacy-related questions or to submit a data subject request:
Anadar Professional Services, LLC
Connecticut, United States
privacy@benecaster.com