Docs Customer Info Data, Privacy & Retention

Data, Privacy & Retention

Customer Info brings a customer’s whole personal record onto one screen, and a few optional features send some of it to third parties. This page is the single reference for what the plugin stores of its own, where it lives, how long it stays, what leaves your store, and what remains after you uninstall. It complements — it does not replace — the privacy notes on each feature page.

📥 What the plugin stores of its own

Customer Info reads your existing WooCommerce customers and orders — those are WordPress and WooCommerce data, not the plugin’s. In addition it stores a small amount of its own:

WhatWhereKept for
Plugin settings, and your Intercom / Help Scout tokensA WordPress option (cf_settings) in your databaseUntil you change or remove them
Your AI settings and encrypted API keyWordPress options (one per provider)Until you change or remove them
Cached AI summaries (summary text, provider, model)The {prefix}customer_info_ai_insights table90 days, then pruned automatically
Email-verified flagUser meta (customer_email_verified)Until removed or the user is deleted
OTP codes (salted hash only, never plaintext)Short-lived transientsUntil the code expires (default 10 min)
MCP OAuth clients, codes and tokens (hashed)Custom tables ({prefix}ci_mcp_clients / ci_mcp_codes / ci_mcp_tokens)Access tokens 1 hour, refresh 30 days; a daily job prunes expired rows

📤 What can leave your store

Three optional features send data to a third party. All are off until you set them up.

FeatureWhat is sent, and whenDetails
Support IntegrationsThe customer’s email, to Intercom / Help Scout, each time you open a profileSupport Integrations
AI Customer SummaryA first name plus aggregate value, churn, subscription and support-subject data, to your AI provider, when you click GenerateAI Customer Summary
MCP ServerNames, addresses, orders, subscriptions and support history, to an approved AI client, on requestMCP Server

🗂️ Personal-data export and erasure requests

The data Customer Info adds is not wired into WordPress’s Tools → Export / Erase Personal Data. Those tools still cover the customer’s core WordPress/WooCommerce record, but the plugin does not register an exporter or eraser for its own additions — cached AI summaries and the email-verified flag will not appear in an export and will not be removed by the eraser. Handle those manually when you receive a request.

Practical steps for a subject-access or erasure request covering a customer:

  • Cached AI summary — ages out within 90 days on its own; to clear it sooner, remove the underlying data and it will not be regenerated.
  • Email-verified flag — clear it with Mark unverified on the Users list or Customers List.
  • Data already sent to a third party — an email sent to Intercom/Help Scout, or a digest sent to your AI provider, lives under their retention policy; erasing here does not reach their copy.
  • The customer’s orders and account — handled by WordPress and WooCommerce’s own privacy tools as usual.

📝 What is logged

Only AI provider errors are logged (WooCommerce → Status → Logs, source customer-info), and never your API key or the data sent. Nothing else is logged — there is no audit trail of who viewed a profile, edited a customer, switched into an account, or made an MCP call. If your store needs those actions to be auditable, keep your own record.

🗑️ What remains after uninstall

Deactivating the plugin stops the dashboard and unschedules its daily MCP cleanup job. Your customers, orders and subscriptions are never touched — the plugin only reads them.

Deleting the plugin does not remove the data it created. Its settings and saved keys/tokens (cf_settings and the AI options), the AI insights table, the MCP OAuth tables, and the email-verified user meta all remain in your database after uninstall. Remove them manually if you need a clean slate — for example when decommissioning a store or fulfilling a data-removal request.

For the encryption of your AI key, provider retention and how to revoke third-party access, see AI Customer Summary, Support Integrations and MCP Server.