Contents

Privacy and uninstall - Plugixa Car Parking

A booking plugin holds personal data by nature: the name, email, phone number and licence plate of everyone who books a space. This page lists what is stored, where, what leaves your server, and what uninstalling removes.

What is stored

Everything is kept in your own WordPress database. The free plugin creates thirteen tables, named with your database prefix (shown here as {prefix}).

Table Holds Personal data
{prefix}plugixacarparking_bookings Every booking: reference, location, space type, status, entry and exit, quantity, prices, coupon, payment method and payment status Yes. Customer name, email, phone, licence plate, vehicle details, billing details, notes, the answers to your form’s custom fields, and the WordPress user ID of a signed-in customer
{prefix}plugixacarparking_booking_items The price lines of each booking No
{prefix}plugixacarparking_payments One row per payment or refund: gateway, transaction ID, type, amount, currency, status and the gateway’s response Linked to a booking. The stored response is whatever the gateway returned.
{prefix}plugixacarparking_notification_log One row per message sent or attempted: channel, recipient, status and any error Yes. The recipient’s email address or phone number
{prefix}plugixacarparking_coupons Coupons No
{prefix}plugixacarparking_coupon_usage Which booking used which coupon, the amount, and the user ID of a signed-in customer A user ID
{prefix}plugixacarparking_locations Locations No
{prefix}plugixacarparking_location_hours Opening hours No
{prefix}plugixacarparking_location_exceptions Date exceptions No
{prefix}plugixacarparking_location_spaces The spaces of each location No
{prefix}plugixacarparking_space_types Space types No
{prefix}plugixacarparking_space_type_prices Prices of each space type No
{prefix}plugixacarparking_booking_forms Booking forms No

Most record tables also store the user ID of the staff member who created and last changed each row.

Pro PRO adds five tables. They are created when Pro is installed, not before.

Table Holds Personal data
{prefix}plugixacarparking_booking_extras Extras No
{prefix}plugixacarparking_tax_rates Tax rates No
{prefix}plugixacarparking_pricing_rules Pricing rules No
{prefix}plugixacarparking_customer_groups Customer groups No
{prefix}plugixacarparking_customer_group_members Which user belongs to which group User IDs

Options

Option Holds
plugixacarparking_settings Everything on the Settings screen
plugixacarparking_db_version The plugin version the tables were set up for
plugixa_carparking_module_set A fingerprint of the installed feature modules, used to notice a switch between free and Pro
plugixa_carparking_audit_utc A marker for a one-off conversion of old timestamps
plugixa_carparking_caps_backfilled A marker for a one-off carry-over of old capabilities

API keys and other credentials saved in the settings PRO are encrypted before they reach the database, with a key derived from the salts in your wp-config.php. That protects them in a leaked database or a stolen backup. It does not protect them from somebody who can read wp-config.php. If you change the salts, stored credentials can no longer be read and have to be entered again. On a server without the OpenSSL extension they are stored as entered.

Temporary data

What Where How long
Rate-limit counters for the public routes Transients named plugixa_carparking_rl_... Until the window ends, an hour at most. The name contains a hash of the visitor’s address, never the address.
Which page holds the booking form The transient plugixa_carparking_form_page Up to a week

Capabilities

Seven capabilities are added to the Administrator role: plugixa_carparking_manage, plugixa_carparking_view, plugixa_carparking_create, plugixa_carparking_edit, plugixa_carparking_delete, plugixa_carparking_export and plugixa_carparking_manage_settings. See REST API.

Scheduled events

Event Schedule
plugixa_carparking_expire_holds Hourly
plugixa_carparking_send_reminders PRO Hourly
plugixa_carparking_scheduled_reports PRO Daily

What is not stored

  • No card details. With Pro, card payments happen on Stripe’s or PayPal’s own pages. The plugin stores the gateway, the transaction ID and the amount.
  • No visitor tracking. The public pages set no cookies of their own and record nothing about a visitor until they submit a booking.
  • No IP addresses are saved with a booking. The rate limiter keeps a hash of the address in a short-lived transient and nothing else.
  • No copies of emails. The message log records that a message was sent, to whom and whether it worked. It does not keep the text.

In the admin, the app keeps two interface preferences in the browser’s local storage: plugixa_carparking_nav_collapsed (which sidebar groups are folded) and, with Pro, plugixa-car-parking-theme (light or dark). They stay in that browser.

Who can see the personal data

Bookings are visible to users with the plugixa_carparking_view capability, which is administrators unless you grant it to another role.

A customer reaches a booking in three ways, none of which lists other people’s bookings:

  • Signed in, the account page lists the bookings made under that account.
  • As a guest, the account page finds one booking from its reference and the email address it was made with. Both must match.
  • By link, the booking summary opens from a private link carrying a token derived from the reference and your site’s salts.

See Customer account.

Access and erasure requests

Version 1.0.0 does not register an exporter or an eraser with the WordPress personal data tools (Tools -> Export Personal Data and Erase Personal Data). To answer a request:

  • Access. Search Car Parking -> Bookings for the email address, and use Export CSV to download the matching bookings.
  • Erasure. Move the bookings to the trash, then delete them permanently from the Trash view. A booking with a payment recorded against it cannot be deleted permanently. See Bookings.

What leaves your server

The free plugin

The free plugin contacts no outside service during normal operation. It loads no fonts or scripts from a CDN: the date picker and every stylesheet ship inside the plugin. Emails are handed to WordPress, which sends them the way your site is set up to.

One optional exception:

Freemius. The plugin bundles the Freemius SDK, which handles licensing, updates and an optional diagnostic opt-in. Nothing is sent unless you click Allow & Continue on the screen shown after activation. Choosing Skip leaves the plugin fully working with no connection made. If you opt in, the SDK sends your site URL, your WordPress and PHP versions and the administrator’s email address to https://api.freemius.com. A Pro licence is activated and checked through the same service.

Pro services

Each of these is contacted only after you enter your own credentials for it in Car Parking -> Settings. None is contacted by the free plugin, which does not contain their code.

Service Host When What is sent
Stripe PRO api.stripe.com A customer pays by card The amount, currency, booking reference, booking ID and the customer’s email
PayPal PRO api-m.paypal.com, or api-m.sandbox.paypal.com in sandbox mode A customer pays with PayPal The amount, currency and booking reference
Twilio PRO api.twilio.com A text message is sent The customer’s phone number and the message
Vonage PRO rest.nexmo.com A text message is sent The customer’s phone number and the message
Telegram PRO api.telegram.org A booking event is posted to your chat The message, which you write from booking placeholders
Google Maps PRO maps.googleapis.com A visitor opens a page that holds the map shortcode Loaded by the visitor’s browser with your API key. Google sees the visitor’s address and browser.

The first five are called from your server. Google Maps is the only one loaded in the visitor’s browser, and only on a page where you placed the map.

See Stripe, PayPal, SMS and Telegram and Map.

Deactivating

Deactivating the plugin removes its scheduled events and nothing else. Every table, option and capability stays. Activating it again picks up where you left off.

Deleting

By default, deleting the plugin removes its files and keeps all of its data. Nothing in the database is touched: not the tables, not the settings, not the capabilities. Installing the plugin again finds everything as it was.

This is deliberate. Buying Pro installs a second copy of the plugin beside the free one, and both copies use the same tables. Deleting the free copy must not take the bookings with it.

Erasing the data

To have a delete erase everything, switch on Car Parking -> Settings -> Advanced -> Erase all data when the plugin is deleted before deleting. Only a site administrator can change that switch.

With the switch on, deleting the plugin:

  1. Fires the plugixa_carparking_uninstall action.
  2. Drops every table whose name starts with {prefix}plugixacarparking_, including the Pro tables and any left by a module that is no longer installed.
  3. Deletes the options plugixacarparking_settings, plugixacarparking_db_version, plugixa_carparking_module_set, plugixa_carparking_audit_utc and plugixa_carparking_caps_backfilled.
  4. Removes every capability starting with plugixa_carparking_ from every role and from every user it was granted to directly.

There is no undo.

When the switch is ignored

Even with the switch on, nothing is erased while another copy of the plugin is still installed, active or not. The plugin looks in the plugins folder for any other folder that holds a plugixa-car-parking.php with the same text domain. If it finds one, the data is kept, because that copy runs on the same tables.

To erase the data on a site that has both the free and the Pro copy, delete one copy first, then delete the other with the switch on.

What an erase leaves behind

  • The temporary transients listed above, which expire by themselves.
  • What the Freemius SDK stores for its own use.
  • Pages you created for the booking form, the account and the summary. Their shortcodes show as plain text once the plugin is gone.
  • Emails already sent, and anything already recorded by Stripe, PayPal, Twilio, Vonage or Telegram on their side.

On multisite

The tables and options belong to the site the plugin is activated on. Each site of a network has its own.

Quick Links