=== VendMizer ===
Contributors: vendmizer
Tags: ecommerce, online-store, shop, payments, store
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

A complete standalone e-commerce platform for WordPress — products, cart, checkout, payments, orders, shipping, and analytics.

== Description ==

VendMizer is a self-contained e-commerce platform for WordPress. It runs on its own custom database tables and a REST API with a fast, dependency-free JavaScript admin, so it does not require any other e-commerce plugin to work.

The free plugin is fully functional on its own. It includes:

* Product catalog with categories, attributes, brands, and product tags
* Cart and a complete checkout flow
* Order management and a customer directory
* Coupons and discounts
* Inventory tracking
* Shipping rates and tax rates
* Reviews, wishlist, and digital downloads
* A built-in storefront with editable Home, About, Contact, and Announcement pages, plus a blog
* Analytics dashboard with revenue and order reporting
* A privacy-first cookie consent banner that blocks Google Analytics and the Meta Pixel until the visitor agrees (granular categories, bilingual, first-party only — no IP tracking)
* Contact inbox, media library, staff roles, and outgoing webhooks
* Multilingual interface — ships with English and Arabic (with full right-to-left support), and you can add and translate additional languages

VendMizer integrates with a number of third-party payment, shipping, and anti-spam services. These integrations are optional and only contact an external service after you configure and enable them. See the "External services" section below for the full list and what each one sends.

A separate commercial add-on, VendMizer Pro, adds further modules (point of sale, subscriptions, returns, loyalty, gift cards, marketing, affiliates, multi-branch, AI tools, and more). The Pro add-on is not required to use this plugin, and this plugin does not lock, disable, or nag about any of its own features.

== External services ==

VendMizer can connect to the third-party services listed below. None of them are contacted unless you enable and configure the corresponding feature (for example, entering API keys for a payment gateway, enabling a shipping carrier, or turning on an additional currency). No data is sent to any of these services during normal browsing or admin use unless that feature is active.

**Payment gateways.** When you enable a gateway and a customer pays with it, order and payment details (such as amount, currency, order reference, and the billing information required to process the charge) are sent to that provider to create and confirm the transaction. Supported providers and their terms/privacy policies:

* Stripe — https://stripe.com/legal — https://stripe.com/privacy
* PayPal — https://www.paypal.com/legalhub — https://www.paypal.com/privacy
* Square — https://squareup.com/legal — https://squareup.com/privacy
* Authorize.Net — https://www.authorize.net/about-us/terms.html — https://www.authorize.net/about-us/privacy.html
* 2Checkout (Verifone) (API hosts: api.2checkout.com, and api.avangate.com in sandbox mode) — https://www.2checkout.com/legal/ — https://www.2checkout.com/policies/privacy-policy/
* Klarna — https://www.klarna.com/international/terms-and-conditions/ — https://www.klarna.com/international/privacy-policy/
* Moyasar — https://moyasar.com/en/resources/terms/ — https://moyasar.com/en/resources/privacy-policy/
* Tamara — https://tamara.co/en-sa/terms-and-conditions — https://tamara.co/en-sa/privacy-policy
* Tabby — https://tabby.ai/en-AE/legal/terms-and-conditions/latest — https://tabby.ai/en-AE/legal/privacy-policy/latest
* Payoneer Checkout (hosted payment page; API host: oscato.com) — https://www.payoneer.com/legal/ — https://www.payoneer.com/legal/privacy-policy/

**Shipping carriers.** When you enable a carrier and create a shipment or request a rate, the recipient address, parcel weight/dimensions, and sender details are sent to that carrier to generate rates, labels, and tracking:

* Aramex — https://www.aramex.com/us/en/terms-of-use — https://www.aramex.com/us/en/legal-details/privacy-policy
* SMSA Express — https://www.smsaexpress.com/terms-and-conditions — https://www.smsaexpress.com/privacy-policy
* Naqel Express — https://www.naqelexpress.com/en/About/TermsCondition — https://www.naqelexpress.com/Privacy/PrivacyPolicy
* USPS — https://about.usps.com/termsofuse.htm — https://about.usps.com/who/legal/privacy-policy/full-privacy-policy.htm
* EasyPost (multi-carrier rating & label generation) — https://www.easypost.com/terms — https://www.easypost.com/privacy-policy
* Shippo (multi-carrier rating & label generation) — https://goshippo.com/legal — https://goshippo.com/privacy

(UPS, FedEx, DHL, OnTrac, and AfterShip are referenced only to build public package-tracking links; no data is sent to them by the plugin.)

**Spam protection.** If you enable a CAPTCHA provider on forms, the visitor's challenge token and IP address are sent to that provider for verification:

* Google reCAPTCHA — https://policies.google.com/terms — https://policies.google.com/privacy
* Cloudflare Turnstile — https://www.cloudflare.com/website-terms/ — https://www.cloudflare.com/privacypolicy/
* hCaptcha — https://www.hcaptcha.com/terms — https://www.hcaptcha.com/privacy

**Currency exchange rates.** When you change your store's base currency, the plugin fetches reference exchange rates from Frankfurter (which sources European Central Bank data) to convert historical order amounts. Only currency codes are sent; no personal or store data is transmitted. The API host is api.frankfurter.app. Frankfurter is an open-source service that publishes no separate privacy policy; its terms are its licence, and its data-handling statement is on its home page. Service and privacy statement: https://frankfurter.dev/ — Licence/terms: https://github.com/lineofflight/frankfurter/blob/main/LICENSE

**Analytics & advertising.** If you enter a Google Analytics 4 / Google Tag Manager measurement ID or a Facebook (Meta) Pixel ID in the settings, the storefront loads that provider's script from their servers and sends visitor and e-commerce events (page views, product views, add-to-cart, checkout, purchases). Both are off until you enter an ID. If you also enable the optional Cookie Consent module, these scripts are held back until the visitor grants the matching consent category — no analytics or advertising script is loaded, and no request is made to Google or Meta, before consent (Google Consent Mode v2 signals are sent alongside).

* Google Analytics / Google Tag Manager — https://policies.google.com/terms — https://policies.google.com/privacy
* Facebook (Meta) Pixel — https://www.facebook.com/legal/terms — https://www.facebook.com/privacy/policy

**Maps & address lookup.** If you enable the map address picker, the storefront loads map tiles from OpenStreetMap and geocodes/reverse-geocodes the address a customer enters using OpenStreetMap's Nominatim service. The picker appears at checkout and in the customer account address book. These are only contacted when the map picker is enabled.

* OpenStreetMap (map tiles) — https://operations.osmfoundation.org/policies/tiles/ — https://wiki.osmfoundation.org/wiki/Privacy_Policy
* Nominatim (geocoding) — https://operations.osmfoundation.org/policies/nominatim/ — https://wiki.osmfoundation.org/wiki/Privacy_Policy

**Map embeds (Google Maps).** If you paste a map embed URL into your storefront's contact page or a homepage section, the storefront renders that provider's map in an iframe on the relevant public page. The admin help text points you to Google Maps, so that is the usual provider. This happens only for a map you add, and the plugin sends no customer data. https://policies.google.com/terms — https://policies.google.com/privacy

**Web fonts.** The plugin bundles its default storefront fonts locally and makes no external font request by default for the storefront. Fonts are loaded from Google Fonts in two cases: if you select a custom storefront font that is not bundled, and in the Arabic transactional email template, which links Noto Kufi Arabic so Arabic renders correctly in email clients. https://policies.google.com/terms — https://policies.google.com/privacy

**Video embeds (YouTube / Vimeo).** If you add a YouTube or Vimeo video URL to a product, blog post, or storefront section, the storefront embeds that provider's player and loads its thumbnail on the relevant public page so visitors can watch it. This happens only for videos you add, and the plugin sends no customer data. https://www.youtube.com/t/terms — https://policies.google.com/privacy — https://vimeo.com/terms — https://vimeo.com/privacy

**Outgoing webhooks.** If you create a webhook, the plugin sends the event data you configure to the destination URL you specify. The destination is entirely under your control.

**Search engine indexing (IndexNow).** If you turn on IndexNow in the SEO settings, the plugin notifies the IndexNow service when your store URLs change so that participating search engines (such as Microsoft Bing) can re-crawl them. Only public URLs from your own site are sent; no personal or customer data is transmitted. It is off by default and requires a key you generate in the settings. The API host is api.indexnow.org. IndexNow publishes no separate privacy policy; its terms document contains its privacy statement. Service: https://www.indexnow.org/ — Terms and privacy statement: https://www.indexnow.org/terms

== Third-party libraries ==

VendMizer bundles the open-source libraries and fonts listed below. Each is redistributed under its own licence, and a copy of that licence ships inside the plugin alongside the files it covers.

**Chart.js 4.5.1** — MIT. Draws the charts on the admin dashboard and report screens. The plugin ships the project's official published UMD build, `assets/vendor/chartjs/chart.umd.min.js`. Its complete, unobfuscated source is public at https://github.com/chartjs/Chart.js/tree/v4.5.1 . Licence: `assets/vendor/chartjs/LICENSE.md`

**Leaflet 1.9.4** — BSD 2-Clause. Powers the optional map address picker. The full unminified source ships as `assets/vendor/leaflet/leaflet-src.js`. Licence: `assets/vendor/leaflet/LICENSE.txt`

**SheetJS (js-xlsx) 0.18.5** — Apache License 2.0. Used only in the admin, to read spreadsheet files during product import. The full unminified source ships as `assets/vendor/sheetjs/xlsx.js`. Licence: `assets/vendor/sheetjs/LICENSE`

Note on the Apache 2.0 licence: it is compatible with version 3 of the GNU GPL, but not with version 2. VendMizer is released as "GPLv2 or later", so any distribution of the plugin that includes SheetJS is taken under the GPLv3-or-later branch of that grant.

**Lucide icons** — ISC. The admin and storefront icons are inline SVG path data from the Lucide project; no Lucide script or stylesheet is bundled. Licence: `assets/js/lib/LICENSE-lucide.txt`

**Fonts** — SIL Open Font License 1.1. DM Sans, Noto Kufi Arabic, Outfit, and the Saudi Riyal symbol font ship as .woff2 files in `assets/fonts/`, each with its own `OFL-*.txt` licence file in that directory.

== Installation ==

1. Upload the `vendmizer` folder to the `/wp-content/plugins/` directory, or install the plugin through the WordPress Plugins screen.
2. Activate the plugin through the Plugins screen in WordPress.
3. Open VendMizer from the admin menu and follow the setup wizard to configure your store currency, pages, and basic settings.
4. Optionally configure payment gateways, shipping carriers, and other integrations under Settings. Each integration is off until you enable it.

== Frequently Asked Questions ==

= Does VendMizer require another e-commerce plugin? =

No. VendMizer is fully standalone and runs on its own database tables and REST API.

= Does the plugin send my data anywhere? =

Not during normal use. External services are only contacted when you enable and configure the matching feature. See the "External services" section for the complete list and what each one sends.

= Does it have a cookie consent banner? =

Yes. The free Cookie Consent module shows visitors a granular consent banner and holds Google Analytics and the Meta (Facebook) Pixel back until they agree, so no tracking script loads before consent. It is off by default — enable it under Settings → Modules, then customize it under Settings → Cookie Consent. Consent is stored in a single first-party cookie on the visitor's device; the plugin performs no IP lookup and keeps no server-side consent log.

= Is the plugin free to use? =

Yes. Every feature listed in the description works in the free plugin. An optional commercial add-on adds extra modules, but it is not required and the free plugin does not lock or disable any of its own features.

= Does it support languages other than English? =

Yes. English is the default language and Arabic is included out of the box (with full right-to-left layout). You can also add and edit additional languages and their translations from the admin.

== Changelog ==

= 1.0.0 =
* Initial public release.
* Product catalog with categories, attributes, brands, and product tags.
* Cart, a complete checkout flow, coupons, and discounts.
* Order management, a customer directory, and inventory tracking.
* Shipping rates and tax rates, with optional carrier integrations.
* Reviews, wishlist, and digital downloads.
* A built-in storefront with editable Home, About, Contact, and Announcement pages, plus a blog. The storefront does not take over your site's front page unless you turn that on in Settings.
* Analytics dashboard with revenue and order reporting.
* A privacy-first cookie consent banner that blocks Google Analytics and the Meta Pixel until the visitor agrees.
* Contact inbox, media library, staff roles, and outgoing webhooks.
* Multilingual interface, shipping with English and Arabic including full right-to-left support.

== Upgrade Notice ==

= 1.0.0 =
Initial public release.
