Privacy Policy
Last updated: 26 July 2026
This policy explains what the Z-CMS Marketplace collects when you sign in as a developer and publish packages, and what we do with it. It is written to describe how the service actually behaves — not to reserve rights we do not exercise.
1Who we are
The Z-CMS Marketplace is operated by Z-SOFT. It is the registry through which developers publish themes and plugins for the Z-CMS content management system, and through which Z-CMS instances install them. You can reach us any time at [email protected].
2What we collect
When you sign in we receive, from Google or GitHub, only a provider-verified email address, your display name and your avatar URL, plus the stable account identifier the provider uses for you. We never receive or store a password. If you register as a publisher we also store the profile you enter yourself — publisher name, optional contact email and the PUBLIC signing key you paste in. We keep a security and audit log of sign-ins and sensitive actions, and the packages and metadata you submit.
3How we use it
We use this information to create and secure your developer account, to attribute the packages you publish, to run security review, to notify you of review decisions, and to protect the marketplace against abuse. We do not use it for advertising and we do not sell it.
4Sign in with Google and GitHub
Signing in uses OAuth 2.0. We request the narrowest scopes that still yield a verified identity — for Google, `openid email profile`. We ask for no offline access and hold no long-lived provider token: the token is used once to read your profile at sign-in and is then discarded. An account is only ever linked on an email the provider tells us it has verified.
5Cookies
We use a small number of strictly functional cookies: an httpOnly session cookie that keeps you signed in, a short-lived httpOnly cookie that protects the sign-in flow against CSRF, and a cookie that remembers your chosen language and theme. We use no advertising or third-party tracking cookies.
6What others can see
Publishing is a public act. Your publisher name, your public signing key and the packages you publish are visible to everyone who browses or installs from the registry. Your email address and sign-in identity are not published.
7Retention and your rights
We keep your account data for as long as your developer account exists, and audit records for as long as we need them to keep the marketplace safe. You may ask us to access, correct or delete your personal data by writing to [email protected]; note that already-published packages other sites depend on may be retained or revoked rather than erased.
8Changes and contact
If we change this policy in a material way we will update the date above and, where appropriate, notify you in the developer portal. Questions about privacy go to [email protected].