Skip to main content

Privacy Policy

What we collect, why, who sees it, and how long we keep it. This page also covers the Vortex Security Check plugin and the vulnerability feed it downloads from this site.

Last updated 5 September 2026.

At a glance

Who we are
Vortex Media, a WordPress development, web hosting and domain services company, reachable at hello@vortexmedia.io.
The plugin
Vortex Security Check downloads a vulnerability list from this site and matches it on your own server. It sends us your server's IP address plus the plugin version, as any web request does, and nothing else. Your site URL, plugin list and results never leave your site.
This website
Standard server logs, Google Analytics, Microsoft Clarity, and the details you type into our contact form or website audit tool.
Client portal
Account, billing and domain registration details you give us when you buy hosting or a domain.
Selling data
We do not sell personal information, and we do not run a mailing list.
Your rights
Ask us at any time to see, correct or delete what we hold about you.

Who this covers

This policy applies to the vortexmedia.io website, the client portal at vortexmedia.io/domains, the Vortex Security Check WordPress plugin, and the vulnerability feed the plugin reads. It does not cover websites we build or host for clients: those belong to their owners, who set their own policies.

The Vortex Security Check plugin

Vortex Security Check is a free WordPress plugin that checks the versions of your installed plugins, themes and WordPress core against a list of published vulnerabilities. The matching happens entirely on your server.

What the plugin sends to us

To get the vulnerability list, the plugin makes one HTTPS request to https://vortexmedia.io/api/vuln-feed.ndjson. This happens only when an administrator opens Tools > Security Check and the local copy is more than 12 hours old, or when an administrator clicks Scan now. There is no background schedule.

That request is a plain download. Like any web request, it carries the IP address of the server making it, and the plugin identifies itself with the text VortexSecurityCheck/ followed by its version number. The request has no body and carries no other headers about your site.

What the plugin never sends

  • Your site's name, URL or domain.
  • Your list of plugins, themes or their versions.
  • The results of any check.
  • Any user, customer or content data from your site.

What we see on our side

The download appears in our web server's standard access log as a line containing the requesting IP address, the timestamp, the feed URL, plus the plugin's version string. We use that log only to keep the feed running, to investigate abuse, and to size the service. We do not build profiles from it, and we do not link an IP address to a person or a website.

What the plugin stores on your site

A cached copy of the vulnerability list in your uploads folder, one WordPress option holding the result of your last check, and one transient recording when the list was last fetched. Uninstalling the plugin through WordPress removes all three.

Vulnerability feed terms of use

The feed at https://vortexmedia.io/api/vuln-feed.ndjson is published for use by the Vortex Security Check plugin. If you want to use it in another tool, email us first; the feed's header line carries attribution that must be kept in any case.

  • The vulnerability data comes from Wordfence Intelligence and MITRE. Wordfence's data is redistributed under the Wordfence Intelligence terms and conditions, which also bind anyone who uses the feed.
  • The feed is provided as is, with no warranty that it is complete, current or free of errors. A clean check does not mean your site has no vulnerabilities.
  • We may change the feed's format, location or update schedule, rate-limit clients, or withdraw the feed, without notice.
  • Do not use the feed to attack, probe or interfere with any site.

What this website collects

Server logs

Our web server records each request in a standard access log: your IP address, the timestamp, the page or file requested, the referring page if your browser sends one, plus your browser's user agent string. Logs are archived monthly on our server, then used only for security, troubleshooting or capacity planning.

Analytics and session recording

Pages on vortexmedia.io load Google Analytics 4 and Microsoft Clarity. Google Analytics measures visits, pages viewed and events such as clicks on our phone number, email address or booking link. Clarity records how visitors move through a page, as heatmaps and session replays. Both services set cookies in your browser: Google Analytics sets _ga plus _ga_R7K28YD4PJ; Clarity sets _clck plus _clsk on this site, along with its own cookies on the clarity.ms and bing.com domains. Both services receive your IP address. Their handling of that data is described in Google's privacy policy and Microsoft's privacy statement. Outside the client portal, this website sets no cookies of its own.

Contact form

When you send a message through our contact page, we receive the name, email address, phone number, enquiry type and message you enter, along with your IP address. The message is emailed to hello@vortexmedia.io, with a copy written to a log file on our server outside the web root, so we can follow up and keep a record of the conversation.

Website audit tool

Our free website audit runs in your browser. The URL you enter is sent from your browser directly to Google's PageSpeed Insights API, which fetches and analyses that page; Google therefore receives the URL along with your IP address. The URL is also recorded as an event in Google Analytics. If you ask us to email you the report, we receive your email address, the audited URL, the score, plus your IP address; these are emailed to hello@vortexmedia.io and logged the same way as contact form messages. The audit page also loads a typeface from Google Fonts, which means Google receives your IP address when that page loads.

Booking a call

"Book a free call" links take you to Calendly, a separate service with its own privacy policy. We receive the name, email address and any notes you enter when you book.

Email

If you email us, we keep the message and our reply in our mailbox for as long as we need it to help you. We do not run a newsletter or marketing list, and we do not add contact form or booking details to one.

The client portal

Hosting plans and domains are purchased through our client portal at vortexmedia.io/domains, which is also where you manage them. To open an account you give us your name, email address, postal address and phone number. The portal sets a session cookie so you can stay signed in. Payment details are entered at checkout, then handled by the payment provider shown there; the portal keeps a record of your invoices and payments.

When you register or transfer a domain, the registrant details you supply are passed to the registrar and the registry for that domain extension, as domain registration rules require. WHOIS privacy is included with our domains, so those details are not shown in public WHOIS lookups where the extension allows it.

The content of a website hosted with us belongs to you. Our staff access hosting accounts only to provide support you have asked for, to keep the server running, or to respond to a security or abuse problem.

How we use information

  • To answer enquiries, book calls, and deliver the services you have bought.
  • To send account, billing and service emails from the client portal.
  • To keep this site, the client portal and the vulnerability feed running securely.
  • To understand how the site is used so we can improve it, in aggregate.

We do not sell personal information, and we do not use it for advertising.

Who we share it with

  • Google (Analytics, PageSpeed Insights, Google Fonts on the audit page) and Microsoft (Clarity), as described above.
  • Calendly, when you book a call.
  • Payment providers, when you pay through the client portal.
  • Domain registrars and registries, when you register or transfer a domain.
  • Anyone we are legally required to share it with, such as in response to a valid court order.

We do not share information with anyone else.

How long we keep it

  • Server logs are archived monthly and kept on our server; they are not used for anything beyond the purposes above.
  • Contact form and audit tool messages are kept until you ask us to delete them.
  • Client portal records are kept for as long as your account is open, then for as long as we need them to meet tax or accounting obligations.
  • Analytics data is held by Google, Clarity data by Microsoft, each under its own retention settings.

Your choices and rights

Whatever your location, you can ask us to tell you what personal information we hold about you, to correct it, or to delete it. Email hello@vortexmedia.io and we will respond within 30 days. Deleting client portal records may not be possible while you still have an active service or an unpaid invoice, and we may keep what tax law requires.

To avoid analytics, use a browser setting or extension that blocks third-party scripts, or Google's own Analytics opt-out add-on. You can use every page on this site with those scripts blocked.

The Vortex Security Check plugin sends nothing you need to opt out of. If you do not want your server's IP address in our feed logs, do not install the plugin.

Security

This site and the client portal are served over HTTPS only. Form submissions are logged outside the web root; only our staff can reach those logs or the mailbox. No method of transmission or storage is completely secure, so we cannot promise absolute security, and we will tell you if a breach affects your information.

Children

Our services are for businesses and adults. We do not knowingly collect information from children under 13.

Changes to this policy

When we change this page we update the date at the top. If a change affects what the Vortex Security Check plugin sends, we will also update the plugin's description on WordPress.org.

Contact

Vortex Media
Email: hello@vortexmedia.io
Phone: 415.968.0905