Helpdesk Hero
Trust

Privacy, security and accessibility

Helpdesk Hero gives your team access to customers' sites. Here's exactly how that's kept safe, in plain language.

Privacy

There's no Helpdesk Hero service in the middle. No account, no tracking, no analytics, no "phone home". Your hub and your customers' sites talk to each other directly, and everything stays in your own databases.

What a ticket includesThe customer's message, name and email, and the site details your policy asks for: versions, plugins and theme, recent errors and changes.
What never leavesPasswords, API keys, tokens and the site's configuration secrets. Email addresses in logs are masked.
Customer controlCustomers see everything before a ticket is sent, and can untick anything your policy doesn't require.
UninstallingRemoves the plugin's tables, settings and scheduled tasks, and deletes any support accounts.

What is stored where, in detail →

Security

  • Paired with a one-time code. Codes are created in your hub, work once and expire after 7 days.
  • Signed requests. Each site has its own secret. Every request is signed (HMAC-SHA256), timestamped and single-use; changed, replayed or stale requests are refused.
  • No passwords. Support logs in with one-time links behind a confirmation page; sites store only a hash of each link.
  • Least privilege. The default support account is an administrator who can't manage users, change roles or edit code, and it's deleted when access ends.
  • Enforced on both sides. Your policy is checked by your hub and by the customer's site.
  • Everything logged. The customer sees every page support opened and every change support made.
  • Reviewed. Every release passes WordPress's Plugin Check and an automated test suite of almost 200 checks across the hub, customer and Pro plugins.

GDPR

  • Data minimisation: your policy decides what's collected; secrets are removed and emails masked.
  • Access and erasure: both plugins work with WordPress's Export Personal Data and Erase Personal Data tools.
  • Transparency: both plugins add suggested text to Settings → Privacy → Policy Guide.

Accessibility

The hub and the customer help center are designed to meet WCAG 2.2 level AA: fully keyboard operable, a table view for every chart, status shown with text and icons rather than colour alone, AA contrast in light and dark themes, and reduced-motion support. This website follows the same rules. If something doesn't work with your assistive technology, please tell us.

External services

  • Your own sites. The hub and connected customer sites send each other signed requests.
  • Help Scout or Zendesk (Pro, coming soon; only if you choose one): tickets, replies and diagnostics will be sent to create and update conversations.
  • Your AI provider (optional): only if WordPress's AI Client is connected and someone uses an AI feature.
  • Lemon Squeezy (Pro): to activate and check your license key, and our update server for Pro updates. These send your license key and site address only.

Reporting a problem

Security issues: please report them privately with GitHub's private vulnerability reporting, not in public.

Everything else: open an issue on GitHub.