GDPR - personal data protection
GDPR requires stores to obtain explicit consent for personal data processing. The plugin adds 7 configurable checkboxes on the order page, consent logging and consent management tools.
Required consents in Polish e-commerce
Section titled “Required consents in Polish e-commerce”An online store should collect consents for:
- Acceptance of store terms and conditions
- Acknowledgment of the privacy policy
- Right of withdrawal from the contract (confirmation of acknowledgment)
- Consent to deliver digital content before the withdrawal period expires
- Delivery notifications (SMS/email)
- Review reminders
- Marketing (newsletter, commercial offers)
Checkbox configuration
Section titled “Checkbox configuration”Go to Polski > Settings > Checkout & Orders and configure consents.
1. Store terms and conditions
Section titled “1. Store terms and conditions”Mandatory checkbox linking to the terms and conditions page.
| Setting | Description |
|---|---|
| Text | Configurable, default: “I have read the [terms and conditions] and accept their terms” |
| Required | Yes (always) |
| Terms page | Select from WordPress pages |
2. Privacy policy
Section titled “2. Privacy policy”Mandatory checkbox linking to the privacy policy.
| Setting | Description |
|---|---|
| Text | Default: “I have read the [privacy policy]” |
| Required | Yes (always) |
| Policy page | Select from WordPress pages |
3. Right of withdrawal from the contract
Section titled “3. Right of withdrawal from the contract”Information about acknowledgment of withdrawal conditions.
| Setting | Description |
|---|---|
| Text | Default: “I have read the [withdrawal from contract] conditions” |
| Required | Yes |
| Withdrawal page | Select from WordPress pages |
4. Digital content
Section titled “4. Digital content”Consent required when selling digital content (e.g. e-books, downloadable files).
| Setting | Description |
|---|---|
| Text | Default: “I consent to the delivery of digital content before the withdrawal period expires and acknowledge the loss of the right of withdrawal” |
| Required | Yes (when cart contains digital products) |
| Condition | Display only when cart contains virtual or downloadable products |
5. Delivery notifications
Section titled “5. Delivery notifications”Consent to receive SMS/email notifications about shipment status.
| Setting | Description |
|---|---|
| Text | Default: “I consent to receiving delivery status notifications” |
| Required | No |
| Channel | Email, SMS or both |
6. Review reminder
Section titled “6. Review reminder”Consent to receive an email requesting a review after purchase.
| Setting | Description |
|---|---|
| Text | Default: “I consent to receiving an email requesting a review of the purchased product” |
| Required | No |
| Delay | Number of days after delivery (default 7) |
7. Marketing
Section titled “7. Marketing”Consent to marketing communication.
| Setting | Description |
|---|---|
| Text | Default: “I consent to receiving commercial information by electronic means” |
| Required | No |
| Scope | Newsletter, offers, promotions |
Consent logging
Section titled “Consent logging”Every consent is saved in the database with data:
| Field | Description |
|---|---|
| User ID | WordPress customer ID (or 0 for guests) |
| Session ID | WooCommerce session identifier |
| Consent type | Checkbox identifier (e.g. terms, privacy, marketing) |
| Value | Consent given or not |
| IP address | Anonymized customer IP address |
| User Agent | Browser and operating system |
| Timestamp | Date and time of consent (UTC) |
| Context | Where the consent was given: checkout, registration, review or pay-for-order |
Viewing consent logs
Section titled “Viewing consent logs”There is no admin screen for the checkout and registration consent records yet. They are stored in the database and included in the WordPress privacy tools (see below).
Cookie-banner decisions from the Consent Manager are a different list: they are shown, and can be exported to CSV, under Reports in the Polski admin.
IP anonymization
Section titled “IP anonymization”The plugin anonymizes IP addresses with WordPress’s own helper: the last octet of an IPv4 address and the last 80 bits of an IPv6 address are zeroed. This supports GDPR data minimization while preserving basic log usability.
Integration with WooCommerce Blocks
Section titled “Integration with WooCommerce Blocks”Consent checkboxes also work with the block checkout form, with two limits: the Terms and Privacy labels show as plain text without their links, and the conditional boxes (digital content waiver, category, country or payment rules) are not shown there. See Legal checkboxes.
Right to be forgotten
Section titled “Right to be forgotten”The plugin works with the WordPress tool Tools > Erase Personal Data. After approving a deletion request, the plugin automatically:
- Anonymizes data in consent logs
- Deletes personal data from withdrawal forms
- Preserves anonymized entries for accountability purposes
Right to data portability
Section titled “Right to data portability”The plugin works with Tools > Export Personal Data. The export includes:
- Consent history
- Form data (anonymized)
- Communication preferences
Troubleshooting
Section titled “Troubleshooting”Checkboxes do not display on the order page Check that the GDPR module is enabled in Polski > Modules. With the block checkout form you need WooCommerce 8.0+.
Customer reports inability to place an order Check that another plugin (e.g. Germanized, WPML) is not adding the same checkboxes. Disable consents from other plugins and use only the Polski for WooCommerce module.
Consent logs do not record the IP address
Check that the server passes the IP address. Behind a reverse proxy (e.g. Cloudflare) configure the X-Forwarded-For header in WordPress.
Next steps
Section titled “Next steps”- Report issues: GitHub Issues
- Discussions and questions: GitHub Discussions