Contents
Privacy and uninstall - Plugixa Chauffeur
A booking plugin holds personal data by nature: the name, email, phone number and addresses of everyone who books a ride. This page lists what is stored, where, what leaves your server, and what uninstalling removes.
What is stored
Everything is kept in your own WordPress database. The plugin creates eight
tables, named with your database prefix (shown here as {prefix}).
| Table | Holds | Personal data |
|---|---|---|
{prefix}plugixa_chauffeur_bookings |
Every booking: number, service and transfer type, status, vehicle, driver, pickup and drop-off addresses, pickup time, passengers, luggage, prices, currency, payment method and payment status | Yes. Customer name, email, phone, notes, and the pickup and drop-off addresses |
{prefix}plugixa_chauffeur_booking_forms |
Booking forms and their rules | No |
{prefix}plugixa_chauffeur_vehicles |
Vehicles, their capacity and prices, and the user ID of who created and last changed each one | Staff user IDs only |
{prefix}plugixa_chauffeur_vehicle_types |
Vehicle types | No |
{prefix}plugixa_chauffeur_locations |
Named places with an address and coordinates | No |
{prefix}plugixa_chauffeur_drivers |
Drivers: name, email, phone, photo, bio | Yes, about your drivers |
{prefix}plugixa_chauffeur_pricing_rules |
Pricing rules | No |
{prefix}plugixa_chauffeur_routes |
Flat-rate routes | No |
All eight tables are created by the free edition as well as Pro. The last three are only used by Pro, and stay empty without it. See Free vs Pro.
The plugin also keeps four rows in the WordPress options table.
| Option | Holds |
|---|---|
plugixa_chauffeur_settings |
Everything on the Settings screen, including the Stripe secret key and webhook signing secret, stored as entered |
plugixa_chauffeur_availability |
The availability rules |
plugixa_chauffeur_db_version |
The plugin version the tables were set up for |
plugixa_chauffeur_module_set |
A fingerprint of the installed feature modules, used to notice a switch between free and Pro |
And it adds five capabilities to the Administrator role:
plugixa_chauffeur_manage, plugixa_chauffeur_edit,
plugixa_chauffeur_delete, plugixa_chauffeur_publish and
plugixa_chauffeur_settings.
What is not stored
- No card details. Card payments happen on Stripe’s own page. The plugin stores the payment method and whether the booking is paid, nothing else.
- No visitor tracking. The booking wizard sets no cookies of its own and records nothing about a visitor until they submit a booking.
- No IP addresses and no browser details are saved with a booking.
- No copies of emails. Emails are handed to WordPress to send and are not logged by the plugin.
In the admin, the app keeps a few interface preferences in the browser’s local
storage under names starting plugixa_chauffeur_. They stay in that browser.
Who can see the personal data
Bookings are visible to users with the plugixa_chauffeur_manage capability,
which is administrators unless you delegate it. The public booking routes never
return a stored booking: they return prices and form settings only, and the
response to a new booking contains just that booking’s own reference and total.
See REST API.
Access and erasure requests
Version 1.0.0 does not register with WordPress’s Export Personal Data and Erase Personal Data tools, so those tools do not include bookings. To answer a request:
- Access. Search the customer’s email under Plugixa Chauffeur -> Bookings. With Pro, a report for the relevant period can be exported as CSV.
- Erasure. Delete the customer’s bookings, or open each one and replace the name, email, phone and notes.
There is no automatic retention period. Bookings are kept until you delete them.
External services
The plugin contacts two outside services. It loads no fonts, maps, analytics or scripts from anywhere else. The Google Maps API key field in Settings is stored only; version 1.0.0 makes no request to Google.
Stripe
Stripe is contacted only when all of these are true: the Stripe payment method is switched on, a secret key is entered, and a customer submits a booking with Stripe as the payment method.
At that moment your server sends a request to https://api.stripe.com to create
a Checkout session. It contains:
| Sent | Why |
|---|---|
| The booking total and currency | The amount to charge |
| The customer’s email address | Pre-fills Stripe’s payment page |
| The booking ID and booking number | So the payment can be matched to the booking |
| The vehicle name and booking number | The line shown on Stripe’s payment page |
| The address of the page the booking was made on | Where Stripe sends the customer afterwards |
The customer’s name, phone number, addresses and notes are not sent. The customer is then redirected to Stripe’s page, where Stripe collects the card details under its own terms.
Afterwards Stripe calls your site’s webhook to confirm the payment. The plugin verifies the call’s signature and reads which booking was paid. See Payments.
With Stripe switched off, or no secret key entered, no data goes to Stripe at
all. Stripe’s terms are at https://stripe.com/legal and its privacy policy at
https://stripe.com/privacy.
Freemius
The plugin includes the Freemius SDK, which handles licensing, updates and the account pages. This is the plugin’s own description of it, from its readme:
We use Freemius to handle licensing, software updates, and, only if you opt in, anonymous usage diagnostics. On activation you are shown an opt-in screen; if you skip it, no identifiable data is sent. When you opt in, or when you manage a license or make a purchase, data such as your site URL, WordPress and PHP versions, active theme and plugins, and the email address used at opt-in may be transmitted. This occurs on activation, plugin updates, and license actions.
Freemius receives information about your site and its administrator. It does
not receive your bookings or your customers’ details: nothing in the plugin
passes booking data to the SDK. Freemius’s terms are at
https://freemius.com/terms/ and its privacy policy at
https://freemius.com/privacy/.
The SDK is only started when the plugin’s Freemius ID and public key are set.
A site owner can blank them in wp-config.php to run the plugin without it:
define( 'PLUGIXA_CHAUFFEUR_FS_ID', '' );
define( 'PLUGIXA_CHAUFFEUR_FS_PUBLIC_KEY', '' );
Without the SDK there are no licence or account pages and no updates through Freemius.
Booking emails are sent through WordPress’s own mail function, so they travel through whatever mail service your site uses. They contain the booking’s reference, trip details, vehicle, total and payment instructions. Switch them off under Settings -> Notifications.
Deactivating
Deactivating the plugin removes nothing. Tables, options and capabilities all stay, and reactivating picks up where you left off.
Uninstalling
Deleting the plugin from the Plugins screen runs its clean-up. What it does depends on one setting: Settings -> Advanced -> Delete all data on uninstall, which is off by default.
| Item | Setting off (default) | Setting on |
|---|---|---|
The eight plugixa_chauffeur_ tables, with all bookings, vehicles, forms, drivers, rules and routes |
Kept | Removed |
The plugixa_chauffeur_settings option |
Removed | Removed |
The plugixa_chauffeur_db_version and plugixa_chauffeur_module_set options |
Removed | Removed |
| The five capabilities on the Administrator role | Removed | Removed |
The plugixa_chauffeur_availability option |
Kept | Kept |
Read this table carefully, because it differs from what the setting’s description suggests:
- Settings are removed either way. With the setting off, a reinstall finds your bookings, vehicles and forms again, but the Settings screen is back to its defaults, and your Stripe keys must be entered again.
- The availability rules are not removed in either case in version 1.0.0.
To remove them, delete the
plugixa_chauffeur_availabilityoption by hand. - Capabilities are removed from Administrator only. If you gave a plugin capability to another role, remove it from that role yourself.
- On a multisite network the clean-up covers the site it runs on. Tables on other sites of the network are not touched.
Removing the tables cannot be undone. Take a database backup first if there is any chance you will want the bookings later, for example for your accounts.
Options the Freemius SDK created for itself are managed by the SDK, not by the plugin’s clean-up.
Removing everything by hand
To be certain nothing is left after uninstalling with the setting on:
DELETE FROM wp_options WHERE option_name = 'plugixa_chauffeur_availability';
Replace wp_ with your database prefix.