A privacy operations toolkit for WordPress and WooCommerce — built to help you manage consent, data subject requests, retention, incident records, privacy documentation, and operational audits from one WordPress dashboard.
Managing website privacy involves much more than displaying a cookie banner. WPStore+ PDPA Privacy & Cookie Manager brings the major privacy-management workflows together in a single WordPress plugin, helping site owners document decisions, manage requests, control optional services, and maintain a clearer operational record of how personal data is handled.
The plugin is designed as a privacy management toolkit, not as an automatic legal certification system. It helps administrators configure and document privacy-related operations while leaving legal assessments and organizational decisions in the hands of the website owner or responsible privacy professional.
Consent Management That Keeps Visitors in Control
Display a customizable consent banner with clear controls for Necessary, Preferences, Analytics, and Marketing categories.
Visitors can:
- Accept all optional services
- Reject optional services
- Customize individual consent categories
- Reopen Privacy Settings at any time
- Update or withdraw their preferences
- Receive a new consent request when your Policy Version changes
Necessary services remain available while optional categories can be controlled according to the visitor’s saved preferences.
Consent Records & Audit Trail
Maintain a server-side record of important consent events without intentionally storing raw visitor IP addresses or browser User-Agent strings.
The audit trail can record actions such as Accept All, Reject Optional, and Save Preferences, together with policy versions and pseudonymous Consent IDs.
Administrators can search and review consent records, inspect current and previous consent states, and export records to CSV when operational review is required.
Advanced Script & Service Control
Control optional third-party services according to consent categories.
The Service Manager supports common service scenarios such as:
- Google Analytics
- Google Tag Manager
- Meta Pixel
- YouTube embeds
- WordPress script handles
- External script URL patterns
- Custom services and inline scripts
Saved blocking rules continue to protect the frontend even if the commercial license becomes temporarily unavailable.
WooCommerce Privacy Integration
Get a dedicated privacy inventory for WooCommerce without directly modifying customer or order data.
Document how your store uses information related to:
- Customer accounts
- Checkout and contact details
- Shipping and fulfillment
- Order history
- Payment metadata
- Saved payment tokens
- Download permissions
- Reviews and comments
- Cart, session, and technical data
The plugin also detects WooCommerce privacy settings, enabled payment gateways, shipping methods, and HPOS-related environment information to help administrators maintain a clearer internal privacy data map.
Data Subject Request Center
Provide visitors with a frontend privacy request form using the included shortcode.
Supported request types include:
- Access
- Export
- Correction
- Erasure
- Restriction
- Objection
- Withdraw Consent
Requests use email verification before entering the administrative workflow. Administrators can manage request status, internal notes, event history, verification, and completion while retaining manual control over sensitive actions.
Where appropriate, Export and Erasure requests integrate with WordPress native personal-data tools.
Privacy Notice Builder
Build a structured privacy notice draft using information already configured inside the plugin.
The builder can bring together information from Consent Records, Service Manager, WooCommerce Privacy, Data Subject Requests, Retention rules, payment gateways, and other documented privacy settings.
Missing or incomplete configuration is marked for review rather than silently guessed.
The plugin creates a new WordPress draft page for administrator review and does not automatically publish or replace your existing Privacy Policy.
Data Retention Manager
Review and manage retention rules for plugin-owned privacy records.
Features include:
- Monitor-only mode
- Dry Run before cleanup
- Manual cleanup with explicit confirmation
- Automatic scheduled cleanup
- Retention activity history
- Bounded cleanup batches
- Cleanup locking to reduce overlapping operations
- Read-only WooCommerce retention overview
- Documentation-only custom retention rules
Existing retention operations are intentionally preserved as part of the plugin’s Safety Core.
Data Breach Incident Manager
Maintain an internal incident register for privacy-related events.
Track:
- Incident type
- Detection and awareness timestamps
- Risk assessment status
- Affected systems and data categories
- Containment and remediation actions
- Notification decisions
- Operational 72-hour reference timer
- Incident timeline and audit history
The plugin does not automatically decide whether an incident must be reported to a regulator or data subjects and does not automatically send breach notifications.
Privacy Audit & Reports
Bring the plugin’s major privacy workflows together in one operational overview.
The Audit Center uses three practical finding states:
OK · Review · Attention
Instead of producing a legal compliance score, the plugin highlights observable configuration and workflow conditions that administrators may need to review.
Create Audit Snapshots, compare changes over time, and export reports in CSV or standalone HTML format.
Security & Privacy-Aware Architecture
The plugin includes additional hardening around administrative actions and public-facing workflows, including capability checks, WordPress nonces, validation, sanitization, output escaping, privacy-preserving request throttling, CSV formula-injection protection, bounded retention cleanup, and secure export handling.
WPStore+ License & Secure Updates
Commercial releases integrate with WPStore+ License services for:
- License activation and validation
- Site synchronization
- Offline grace handling
- Secure commercial updates
- Product and version guards
- HTTPS and package-host validation
- License diagnostics
- Support reporting
The Safety-First Feature Gate is designed so essential privacy operations do not suddenly stop merely because the license server is temporarily unreachable.
Built for Operational Privacy Management
WPStore+ PDPA Privacy & Cookie Manager is suitable for WordPress site owners, WooCommerce stores, agencies, developers, and administrators who want a structured way to manage privacy-related workflows directly inside WordPress.
Important: This plugin is a technical and operational privacy-management tool. It does not provide legal advice, legal certification, or a guarantee that any website or organization complies with PDPA or other privacy laws.
















Reviews
There are no reviews yet.