Skip to main content

Privacy & Data Handling

This page mirrors the plugin's own Privacy Policy disclosure (the canonical version ships inside the plugin readme.txt and at empora.aoneahsan.com/privacy). The principle: your store data stays on your site unless you actively enable an integration that sends it somewhere.

What never leaves your site​

Customer personal data, order details, your product catalogue, and store settings live on your own WordPress installation and are never transmitted to the author's servers. The only customer/order data that leaves your site is what you actively push through a third-party integration you turn on (for example, syncing an order to Klaviyo).

1. License activation & validation (premium only)​

  • Endpoint: https://empora-api.aoneahsan.com
  • When: only when an admin enters a license key (Settings → License → Activate) and on scheduled re-validations.
  • Data sent: license key, site URL, site name, WordPress version, WooCommerce version, PHP version, plugin version.
  • Why: to verify the license and determine which premium modules this site may enable.
  • Opt-out: don't enter a license key. With no key, the plugin makes no calls here and the free core works fully.

2. File / media uploads (premium features only)​

  • Endpoint: https://fileshub.zaions.com
  • What: FilesHub — a sister product operated by Zaions, the same organisation that publishes Empora, not a third-party vendor. It holds media a premium module generates or that an admin uploads, and sends the plugin transactional email.
  • When: only when an admin uses a feature that uploads media — PDF invoices, gift-card images, or import/export attachments. Nothing is uploaded in the free core, and nothing is uploaded in the background.
  • Data sent: the file you choose to upload, plus an authentication token identifying the site. No customer records and no order data are sent by this path.
  • Opt-out: do not enable the premium modules that upload files. They are off by default.

3. Per-module third-party integrations (off by default)​

These are off until you enable the module and configure credentials. What is sent depends on the module:

IntegrationEndpointData
Squareconnect.squareup.comProduct / inventory / payment sync.
Klaviyoa.klaviyo.comCustomer + order events.
Google Listings & AdsGoogleProduct feed sync.
Multi-Currency ratesexchangerate.host / openexchangerates.orgCurrency code list only — no store data.
Social LoginOAuth providersStandard OAuth handshake when a customer chooses it.
SMSTwilio (etc.)Message body + recipient phone, only when SMS is enabled.

4. Telemetry & analytics​

This release includes no built-in usage analytics. If telemetry is added later, it will be opt-in by default and disclosed here and in the plugin.

GDPR / compliance notes​

  • Because store/customer data stays on your site, you remain the data controller for it.
  • Where you enable an integration, that provider acts as a processor (or its own controller) for the data you send it — review each provider's terms.
  • Document any enabled integrations in your own store privacy policy so your customers' disclosures match reality.

Canonical sources​