Guest purchasing / GDPR Non Compliance
-
Currently your plugin offers:
Require Login To Checkout?
If ticked then user needs to be logged in to view or pay invoice, can only view or pay their own invoice. If unticked then anyone can view or pay the invoice.
This means guests cannot purchase from payment forms unless signed in already to your website or if you untick the require login they can BUT ANYONE can view everyone’s invoices by changing the invoice ID in a url which shows personal data such as billing address etc. I’m pretty sure this is completely illegal and website owners risk being sued for GDPR Non Compliance unless the customer agreed for their personal information to be freely available on the Web (which nobody would).
Some changes needed..
1. Login to view invoices mandatory unless customers choose for guests to be able to view their invoice or some sort of share invoice option to specific people / emails.
2. Guest checkout option which creates a new account using their email like when you create an invoice for someone.
Sorry if this message comes on strong but it’s a brilliant plugin that I want to work and use without risk for myself and clients.
Regards
- The topic ‘Guest purchasing / GDPR Non Compliance’ is closed to new replies.