Contents

Privacy and uninstall - Plugixa Chat

This page lists what the plugin stores, what it sends to outside services and when, and what is removed when you deactivate or uninstall it.

The short version: showing a widget contacts nobody outside your site. The plugin sets no cookies and loads no third-party scripts. The only personal data it stores is what a visitor types into your contact form.

What a visitor’s browser does

  • Channel links point straight at each service: WhatsApp, Telegram, your phone app and so on. Nothing is requested from a service until the visitor presses its channel.
  • No cookies are set by the plugin.
  • No third-party scripts are loaded. Icons and the QR code are part of the widget itself. The exception is Cloudflare Turnstile, if you switch it on.
  • Views, opens and presses are reported to your own site as counts. They carry no identifier.
  • Rules about the visitor are checked with one request to your own site.

What is kept in the visitor’s browser

What Where When
Events waiting to be sent to your site Session storage While a page with a widget is open
That a widget’s trigger has already fired Session storage After a delay, scroll or leave trigger fires
That the unread badge was dismissed Local storage After the visitor opens a widget that has a badge
Which side of an A/B test the visitor drew PRO Local storage The first time they meet a running test
Which agent the visitor was given PRO Local storage The first time they meet a widget whose agents take turns
A count of the pages on which a visits rule was checked Local storage Only for a widget that carries a visits rule, which can be set through the REST API only

These never leave the browser, except the events, which are sent to your own site as counts. Where a browser blocks storage, the widget still works: the badge and the triggers simply behave as on a first visit.

What is stored on your site

Database tables

Table Holds Edition
{prefix}plugixachat_widgets Your widgets and their look Free
{prefix}plugixachat_widget_channels Each widget’s channels Free
{prefix}plugixachat_widget_rules Each widget’s targeting rules Free
{prefix}plugixachat_leads Contact form messages Free
{prefix}plugixachat_events Analytics counts per widget, channel, kind of event and hour Free
{prefix}plugixachat_agents The people on the Agents screen Pro PRO
{prefix}plugixachat_lead_answers Answers to your own form questions Pro PRO
{prefix}plugixachat_webhooks Webhooks, with their signing secrets Pro PRO
{prefix}plugixachat_crm_connections CRM connections Pro PRO
{prefix}plugixachat_experiments A/B tests Pro PRO

The events table holds totals, not a row per visitor. It stores no IP address, no user agent and no identifier of any kind.

What a lead holds

Field Notes
Name, email, phone, message As the visitor typed them
Consent, newsletter Whether each box was ticked
Page address The page the form was sent from, when it is on your site
Widget Which widget’s form was used
IP address In the form chosen under Settings -> Privacy: a one-way hash by default, a shortened address, nothing, or the full address
Status, date New or Read, and when it arrived

Options

Option Holds
plugixa_chat_settings Everything on the Settings screen except secret keys
plugixa_chat_secrets The Turnstile secret key, and in Pro the API keys of CRM connections. Not loaded automatically, and never sent to a browser
plugixa_chat_apps Which of the plugin’s parts are switched on
plugixa_chat_db_version, plugixa_chat_module_set, plugixa_chat_config_version, plugixa_chat_caps_backfilled Housekeeping for updates and for the front-end data
plugixa_chat_migration_failed Present only while a database update has not finished

The settings screen is told only whether each secret is set, never its value.

Capabilities

On activation the Administrator role is given the plugin’s eight capabilities. They are listed in the REST API page.

Short-lived records

Record Kept for Purpose
A salted, one-way hash of a visitor’s IP address, with a counter Five minutes Limits how often one visitor can send the contact form, report events, or look up an order

It is always a hash, whatever is chosen under Visitor IP addresses, and it cannot be read back into an address.

Scheduled tasks

Task Runs Does
plugixa_chat_prune_leads Daily Deletes leads older than the retention period, when one is set
plugixa_chat_prune_events Daily Deletes analytics counts older than the retention period, when one is set
plugixa_chat_webhook_deliver PRO Per lead Delivers a lead to a webhook
plugixa_chat_crm_deliver PRO Per lead Delivers a contact to a CRM connection

WordPress privacy tools

The plugin works with the tools under Tools -> Export Personal Data and Tools -> Erase Personal Data.

Tool What the plugin does
Export Adds a group called “Contact form messages” with every lead sent from that email address: name, email, phone, message, newsletter choice, page and date
Erase Permanently deletes every lead sent from that email address

Leads are matched by the email address typed into the form. A lead sent with a phone number only cannot be found this way; delete it from the Leads screen.

The plugin also adds suggested text to Settings -> Privacy -> Policy guide, describing what the contact form stores, the newsletter checkbox and Turnstile. Pro adds a paragraph about CRM connections.

Outside services

Apart from Freemius, every connection is optional and happens only after you switch the feature on.

Service When What is sent Edition
Freemius When you activate a licence or check for an update, and for diagnostics if you opt in Your site address, the plugin version and your licence key. With opt-in, anonymous information about your WordPress and PHP versions and the plugin features you use in the admin Both
Cloudflare Turnstile Only when you have saved Turnstile keys. A visitor’s browser loads Cloudflare’s script when they open a contact form, and your server verifies the result when they send it From your server to Cloudflare: the check’s token, your secret key and the visitor’s IP address Free
A webhook address you entered Each time a lead is stored The lead: name, email, phone, message, consent, newsletter choice, page and widget Pro PRO
Mailchimp or Brevo Each time a lead qualifies for a connection The contact’s email address and name, and your tags Pro PRO

On activation Freemius shows an opt-in screen. If you skip it, no identifiable data is sent.

The plugin does not contact Google or Meta. The tracking events are handed to tags that are already on your page, in the visitor’s browser.

The plugin contacts no location service. Country rules read a header your hosting already provides. See Country and language rules PRO.

FluentCRM is a plugin on your own site, so a FluentCRM connection sends nothing outside it.

Deactivating

Deactivating the plugin:

  • removes the widget from your site, along with chat buttons and the product button,
  • clears the plugin’s scheduled tasks,
  • deletes nothing else. Widgets, leads, analytics and settings are all kept and are there when you activate it again.

Uninstalling

Deleting the plugin from the Plugins screen removes its data from the site.

Removed Detail
Tables Every table whose name starts with {prefix}plugixachat_, Pro’s included
Options All the options listed above, including the secret keys
Capabilities The plugin’s capabilities, from every role and every user
Scheduled tasks Every scheduled task whose name starts with plugixa_chat_
Short-lived records The rate limit records

Nothing the plugin created is left in the database.

On a multisite network

The clean-up runs once, for the site WordPress is working on when the plugin is deleted. On a network that is normally the main site. The plugin does not go through the other sites of the network, so their plugixachat_ tables, their options and their scheduled tasks stay in the database. Remove the plugin’s data from each of those sites before deleting the plugin from the network, or drop their tables by hand afterwards.

What is not removed:

  • Images you uploaded to the media library for icons, photos or the WeChat QR code. They are ordinary media items.
  • [plugixa_chat] shortcodes and Chat button blocks in your content. With the plugin gone, a shortcode is shown as its text, so remove them from your pages.
  • Contacts already sent to a mailing list or a webhook.
  • What visitors’ browsers kept, listed above.

To keep your leads, export them from the Leads screen before uninstalling.

What to do next

Quick Links