Customer Info brings a customer’s whole personal record onto one screen, and a few optional features send some of it to third parties. This page is the single reference for what the plugin stores of its own, where it lives, how long it stays, what leaves your store, and what remains after you uninstall. It complements — it does not replace — the privacy notes on each feature page.
📥 What the plugin stores of its own
Customer Info reads your existing WooCommerce customers and orders — those are WordPress and WooCommerce data, not the plugin’s. In addition it stores a small amount of its own:
| What | Where | Kept for |
|---|---|---|
| Plugin settings, and your Intercom / Help Scout tokens | A WordPress option (cf_settings) in your database | Until you change or remove them |
| Your AI settings and encrypted API key | WordPress options (one per provider) | Until you change or remove them |
| Cached AI summaries (summary text, provider, model) | The {prefix}customer_info_ai_insights table | 90 days, then pruned automatically |
| Email-verified flag | User meta (customer_email_verified) | Until removed or the user is deleted |
| OTP codes (salted hash only, never plaintext) | Short-lived transients | Until the code expires (default 10 min) |
| MCP OAuth clients, codes and tokens (hashed) | Custom tables ({prefix}ci_mcp_clients / ci_mcp_codes / ci_mcp_tokens) | Access tokens 1 hour, refresh 30 days; a daily job prunes expired rows |
📤 What can leave your store
Three optional features send data to a third party. All are off until you set them up.
| Feature | What is sent, and when | Details |
|---|---|---|
| Support Integrations | The customer’s email, to Intercom / Help Scout, each time you open a profile | Support Integrations |
| AI Customer Summary | A first name plus aggregate value, churn, subscription and support-subject data, to your AI provider, when you click Generate | AI Customer Summary |
| MCP Server | Names, addresses, orders, subscriptions and support history, to an approved AI client, on request | MCP Server |
🗂️ Personal-data export and erasure requests
Practical steps for a subject-access or erasure request covering a customer:
- Cached AI summary — ages out within 90 days on its own; to clear it sooner, remove the underlying data and it will not be regenerated.
- Email-verified flag — clear it with Mark unverified on the Users list or Customers List.
- Data already sent to a third party — an email sent to Intercom/Help Scout, or a digest sent to your AI provider, lives under their retention policy; erasing here does not reach their copy.
- The customer’s orders and account — handled by WordPress and WooCommerce’s own privacy tools as usual.
📝 What is logged
customer-info), and never your API key or the data sent. Nothing else is logged — there is no audit trail of who viewed a profile, edited a customer, switched into an account, or made an MCP call. If your store needs those actions to be auditable, keep your own record.🗑️ What remains after uninstall
Deactivating the plugin stops the dashboard and unschedules its daily MCP cleanup job. Your customers, orders and subscriptions are never touched — the plugin only reads them.
cf_settings and the AI options), the AI insights table, the MCP OAuth tables, and the email-verified user meta all remain in your database after uninstall. Remove them manually if you need a clean slate — for example when decommissioning a store or fulfilling a data-removal request.For the encryption of your AI key, provider retention and how to revoke third-party access, see AI Customer Summary, Support Integrations and MCP Server.