Legal
Privacy Policy
How CMS Inspect collects, uses, and protects your information.
Effective date: 27 August 2026
1. Who we are
CMS Inspect is operated by Revibe Digital Limited (company number 8188883, NZBN 9429049339697). Main office: 127 Te Hono Street, Maungatapu, Tauranga 3112, New Zealand. Mail and appointments: 2/138 Tamamutu Street, Taupo 3330, New Zealand. This policy covers cmsinspect.com, app.cmsinspect.com, and the site Agent. It is written under the New Zealand Privacy Act 2020. Privacy and security contact: support@cmsinspect.com.
If GDPR or UK GDPR applies to you, a short extra section and a data-processing addendum are available on request. We do not claim GDPR certification.
2. Roles
We are the controller for Account, billing, usage, and marketing data. For Site Data, scan findings, database backups, files backups, file-read snippets, and Google Analytics traffic you pull from your own properties, you are the controller and we are the processor. We process that data only on your instructions, which means to provide the product you asked for. If you are an agency, you are the controller for your clients’ Sites. A short DPA is available from support@cmsinspect.com.
3. What we collect
Account. Name, email, password hash, two-factor status, and — if you turn 2FA on — an authenticator TOTP secret plus recovery codes (stored only to check codes; we do not store a phone number). 2FA is optional for customers and required for staff admins. Google account id if you use Google sign-in. Company, plan, and staff-admin flags for our team.
Billing. Stripe customer and subscription identifiers, card brand, last four digits, and expiry month if Stripe sends them, invoices, GST number if you give us one, and country. We do not store full card numbers or CVC. Stripe holds cards.
Connected Sites. URL, CMS type, core / plugin / theme / extension versions, PHP version, Agent id, site secret (a security credential), plan mode, and last check-in.
Agent telemetry. Command types and success or fail, malware and permission-finding titles and file paths, uptime pings, and source IPs of the Site and of the dashboard user.
Privileged artifacts, only if that feature is on. Database dumps, files backups, file-read snippets, and one-click-login audit (who, when, which Site). Treat these as your confidential content. We do not collect WordPress or Joomla admin passwords. We do not write site secrets or backup bytes into application logs.
Auth. Session cookies, login IPs, 2FA status, and a Cloudflare Turnstile token if that check is enabled (we do not keep the token after verify). Google sign-in ids and tokens if you use Google login. Drive and Dropbox OAuth tokens if you connect backup.
Support. Emails, ticket contents, attachments you send, and the staff admin session if we open your dashboard to help. Impersonation does not change your plan. You can email support@cmsinspect.com to ask which staff accessed your Account.
Marketing-site forms. The affiliate application collects name, email, website, social-channel URLs or handles, combined follower count, niche, and a message, and emails that to support@cmsinspect.com. Contact on cmsinspect.com is email-only to that same address (stack, site count, and goals you choose to send).
Marketing site (cmsinspect.com). Essential cookies only. We do not load Google Analytics or an ads pixel on the marketing site today.
4. How we use information
We collect this information only for these purposes, under the New Zealand Privacy Act 2020:
- Provide the dashboard, Agent, scans, updates, backups, and billing
- Authenticate you, prevent abuse, rate-limit, and detect stolen accounts
- Support, including opening your dashboard when you ask for help
- Legal, tax, and dispute
- Product improvement from aggregated or anonymised usage only
Incident, billing, security, and login emails are transactional, not marketing. If we send promotional email, it will have an unsubscribe. We do not sell personal information. We do not mine backup contents for marketing. We do not use your database backups to train public AI models.
5. Sharing and subprocessors
We share data only where needed to run CMS Inspect. Recipients we actually use:
- DigitalOcean, provisioned with Laravel Forge — hosts app.cmsinspect.com and its database in Sydney, Australia (region syd1)
- Stripe — payments, subscriptions, and tax ids we send them (typically United States)
- Postmark — transactional mail such as login, reset, invoices, and alerts, from support@cmsinspect.com (typically United States)
- Cloudflare — CDN, Turnstile bot check if enabled, and DNS if we use it (global)
- Google — sign-in only if you choose Google login (typically United States)
- Google Drive and Dropbox — only if you connect backup or export. Content goes to your cloud account under their terms
- Google Analytics — if you link a property we store the property id and query traffic or context for reports. Those tokens and results are your GA property, not cmsinspect.com analytics. We do not get GA data unless you connect it
- A cleanup partner — only if you click through. We do not send backups to a partner unless you ask
- CMS Inspect / Revibe staff who need access to operate support
- Law enforcement or a court if required
Scans run on your Site as pattern and permission checks. We do not send backup archives or site secrets to a third-party CVE vendor. We do not sell personal information. We do not share backups with marketers. We will update this page when this list changes.
6. International transfers
We are based in New Zealand. The application server and database sit on DigitalOcean in Sydney, Australia (region syd1). Stripe, Postmark, Google, Dropbox, and Cloudflare may hold data outside New Zealand (Australia, the United States, or other regions). We use them only to run the product and take steps we consider reasonable in the circumstances (Privacy Act IPP 12), including the vendor’s contract. Drive and Dropbox transfers are started by you to your own account.
7. Retention
These windows match how the app is configured today.
- Account profile — life of the Account, then 30 days after close unless you ask sooner
- Site secret and Agent credentials — until disconnect, then rotate or delete immediately
- Database dumps and files backups while a Site is connected — uploaded to your Drive or Dropbox. We do not keep a rolling archive of those backups on our servers
- After disconnect — a leftover database dump is a copy of the database (users, orders, comments, password hashes, config), not the whole filesystem. A leftover files backup, if one was taken, can include site files. We delete leftovers we still hold within 30 days. The site secret is rotated or deleted immediately on disconnect and is not kept with that leftover. Files already in your Drive or Dropbox stay there until you delete them
- Finished Agent commands — typically 14 days. File-read snippets are stripped after about 2 days
- Uptime, activity, file-change, scan, and similar telemetry — typically 30 days
- Daily traffic rows — typically 90 days
- Resolved incidents — typically 60 days
- Login and session records — typically 12 months unless a shorter prune applies
- Support email — typically 3 years
- Stripe, tax, and invoices — 7 years where New Zealand tax law requires
- Marketing-mail unsubscribe — we keep a suppression email so we do not mail you again
After a valid deletion request to support@cmsinspect.com we remove tenant data we hold within 30 days, except billing or tax records and security data still inside its window. We can refuse deletion of invoices we must keep, or data needed to investigate abuse.
8. Security
The app is served over HTTPS. Dashboard passwords are hashed with bcrypt. We do not store them in plaintext. Agents authenticate with a per-site secret and a signed request (HMAC and a short time window). Treat that secret like a root password. Sessions use cookies. 2FA (authenticator TOTP) is available and optional for customers; it is required for staff admins. We store the TOTP secret and recovery codes only to check codes. Email verification is required for the app. Payments go through Stripe. Mail goes through Postmark.
We do not claim encryption at rest, bank-grade or military-grade security, SOC 2, or ISO 27001. We do not claim we encrypt every secret in the database, that we always verify TLS to your Site, or that Turnstile stops all bots.
You must use a unique password, turn on 2FA, keep the site secret private, uninstall the Agent when you sell or drop a Site, and email support@cmsinspect.com if you think a secret leaked. We may disable an Agent or rotate a secret to contain abuse.
9. Cookies
App (app.cmsinspect.com): essential session cookie, CSRF cookie, and a remember-me cookie if you tick it. Turnstile may set a Cloudflare cookie on the login page if that check is enabled. Stripe Checkout and the Customer Portal set Stripe cookies on Stripe’s domain.
Marketing site (cmsinspect.com): essential cookies only. We do not currently load an analytics or ads cookie there. We do not run a cookie banner because we are not setting non-essential cookies on that site today.
10. Your rights
Under the New Zealand Privacy Act 2020 you may request access, correction, or deletion of personal information we hold about you, and you may withdraw marketing consent. Email support@cmsinspect.com from the Account address. We may need to verify it is you. You may complain to the Office of the Privacy Commissioner.
You can export some reports, logs, audits, and findings as CSV from the app. For a wider tenant export or deletion, email support. If GDPR or UK GDPR applies to you, you may also have rights of access, rectification, erasure, restriction, portability, and objection. We do not claim we are GDPR-certified.
11. Automated decisions
Plan limits, rate limits, malware or permission flags, and Turnstile or fraud checks can block an action automatically. A human at support@cmsinspect.com can review. We do not use backup contents for automated marketing profiles.
12. Children
CMS Inspect is a business service. It is not for anyone under 18. We do not knowingly collect children’s data. If a child account appears, we delete it.
13. Changes and contact
Material privacy changes: we update this page (effective date above) and email the Account address. Continued use after the effective date is acceptance. If you do not accept, close the Account and we follow the retention and deletion rules.
If we confirm a breach that the Privacy Act 2020 requires us to notify, we will tell affected customers at the Account email and the Office of the Privacy Commissioner, without undue delay.
Privacy and security: support@cmsinspect.com. Main office: 127 Te Hono Street, Maungatapu, Tauranga 3112, New Zealand. Mail and appointments: 2/138 Tamamutu Street, Taupo 3330, New Zealand.

