Description
Cartlyra Revenue Recovery for WooCommerce helps you understand and recover revenue your store is losing. Every feature is included — there is no separate paid version, no license, and no upgrade to buy. Sensitive capabilities that reach outside your site (AI and outbound webhooks) are disabled by default and only run after you explicitly enable and configure them with your own credentials.
The plugin tracks abandoned carts and checkout signals, sends manual and automated recovery emails (with built-in safety cooldowns and per-cart locking), and gives you privacy-first controls: suppression, one-click unsubscribe, contact encryption, configurable retention, and Health diagnostics.
What’s included
- Abandoned cart and checkout tracking for guests and logged-in customers.
- Lost Carts screen: every tracked cart with status filters, cart value, items, and order links.
- Manual recovery emails for eligible abandoned carts (one-click “Send Recovery Now”), repeatable after a built-in anti-spam safety cooldown, with a secure, expiring recovery link and one-click cart restore.
- Automated recovery: scheduled abandoned-cart recovery so the first email can send automatically once your delay elapses (disabled by default).
- Multi-step follow-ups: Step 2 and Step 3 recovery sequences (disabled by default).
- Failed and pending payment recovery: emails with a secure retry-payment link, plus pending-payment reminders (disabled by default).
- Smart Offers: a rules-based engine that can add a static or unique (percentage, fixed, or free-shipping) coupon to recovery emails, with cart-value, sale-item, and category guardrails to protect margins (disabled by default).
- Revenue Intelligence: checkout-incident detection, affected-cart cohorts, Payment Health, merchant-approved recovery campaigns, baselines, rollups, funnel intelligence, revenue-leak investigation, change timeline, Action Cases, and Fix Verification. No customer is contacted until you explicitly approve a campaign.
- AI Studio (bring-your-own key): the AI Recovery Copywriter, AI Incident Analyst, and AI Revenue Operator. AI is disabled by default; when you enable it and add your own OpenAI key (stored in an encrypted vault), it uses a no-personal-data payload and a daily call cap, and always falls back to the default email.
- Webhooks & n8n: send privacy-safe, HMAC-signed events to automation tools such as n8n. Disabled by default; nothing is sent until you create and enable an endpoint.
- Reports and CSV export.
- Brand Kit: brand-aware recovery emails (logo from your Media Library, colors, footer, support email, voice) with safe fallbacks and a privacy-safe placeholder preview.
- Privacy-first controls: contact encryption and safe lookup, a suppression list, one-click unsubscribe, configurable data retention, and an opt-in “delete data on uninstall” preference.
- Health & Diagnostics: system, database, and cron status with scheduled-task self-healing and a repair action.
- Safe by design: no raw IP addresses or user agents are stored (optional salted hashes only, off by default); WooCommerce High-Performance Order Storage (HPOS) compatible; multisite-aware; translation-ready and RTL-ready; and idle (no errors) when WooCommerce is inactive.
By default the plugin makes no third-party API calls. The only features that can send data off your site — AI (OpenAI) and outbound webhooks/n8n — are disabled until you turn them on and supply your own key or endpoint. See “External Services” below.
Privacy
To power abandoned-cart recovery and checkout-signal monitoring, the plugin may process cart, contact, and recovery information needed for the recovery workflows you configure — for example a cart’s contents and value, the billing email/phone/name a shopper enters at checkout, and records of recovery emails you send and whether their links were clicked. It does not store payment card details.
Sensitive contact data is protected using the plugin’s privacy architecture (encryption with one-way lookup hashes). Recovery emails are sent using your store’s configured WordPress/WooCommerce mail setup. You control how long data is kept (data retention), and shoppers can be suppressed or can unsubscribe so they are no longer contacted.
As the store owner, you remain responsible for configuring the plugin lawfully and for providing your own customer-facing privacy notice. The plugin also adds suggested privacy-policy text to Settings Privacy Policy Guide that you can adapt for your store.
The plugin integrates with the built-in WordPress Personal Data Export and Erase tools (under Tools Export Personal Data / Erase Personal Data), so you can provide or remove the recovery data it holds for a customer’s email address. When data is erased, a minimum opt-out record may be retained solely to help prevent future recovery communications to that person.
External Services
By default the plugin makes no third-party API calls. It bundles no licensing, telemetry, or remote-account service, and there is no Cartlyra server involved in its operation. Two optional features can connect to an external service, and only after you explicitly enable and configure them:
OpenAI (AI Studio) — optional, off by default, bring-your-own-key.
When you enable AI and enter your own OpenAI API key, the plugin sends requests to the OpenAI API (https://api.openai.com) to generate recovery-email copy, to explain checkout incidents, and to produce store operating briefings. AI is disabled by default and makes no OpenAI call until you enable AI, add your own key, and tick the OpenAI external-service consent box. Consent applies to all three AI capabilities below. Removing consent disables AI. Requests happen only on your explicit action (or, if you enable automated AI copy, when a recovery email is generated), subject to a daily call cap you control. Your key is stored encrypted and never displayed after saving.
AI Recovery Copywriter — what is sent: only safe, non-personal context — store/brand configuration, your selected tone and language, cart total, currency, item count, a checkout-started flag, a safe offer type, and a safe expiry-in-hours value.
AI Incident Analyst and AI Revenue Operator — when you explicitly request an analysis or briefing, OpenAI may receive aggregate operational evidence such as: incident type, status, severity, and timestamps; aggregate sample sizes, rates, counts, and affected-cart value; aggregate campaign counts; checkout funnel stage counts; revenue and recovery aggregates; trend and change categories; and store-level operational metrics and safe labels.
None of the following are sent to OpenAI by any AI capability: customer names, emails, phone numbers, addresses, product names, product categories, cart line items, SKUs, coupon codes, order or cart identifiers, recovery URLs, tokens, raw gateway payloads, raw error messages, or API keys.
- OpenAI Terms of Use: https://openai.com/policies/terms-of-use — OpenAI Privacy Policy: https://openai.com/policies/privacy-policy
Outbound Webhooks / n8n — optional, off by default.
When you create and enable a webhook endpoint, the plugin sends HMAC-signed event notifications to the endpoint URL you configure (for example an n8n workflow you host). Webhooks are disabled by default; nothing is sent until you create and enable an endpoint, and test deliveries occur only when you explicitly trigger them. The destination is whatever URL you enter (validated against SSRF). There is no Cartlyra server involved.
An enabled endpoint receives an event envelope containing: your site URL, a generated event ID, the event name, the event timestamp, the payload schema version, and the plugin version — plus an event-specific data object with, where relevant, internal reference IDs (such as cart, message, incident, campaign, or campaign-recipient IDs) and safe aggregate fields (status and reason codes, amount and currency, counts, rates, and revenue/recovery aggregates).
No raw customer personal data, secrets, API keys, coupon codes, recovery URLs, message bodies, or the full endpoint URL are ever sent or exposed in the admin (the admin shows the endpoint host only).
Support
Free support is provided through this plugin’s WordPress.org support forum after publication.
Ownership
Cartlyra is the product brand behind this plugin. The official plugin contact is plugins@cartlyrai.com.
Installation
- Make sure WooCommerce 8.2 or higher is installed and active.
- In your WordPress admin, go to Plugins Add New Upload Plugin.
- Upload the plugin ZIP file and click Install Now.
- Click Activate to activate the plugin.
- Open the new Cartlyra menu and complete the guided setup under Cartlyra Settings.
FAQ
-
Does this plugin require WooCommerce?
-
Yes. The plugin is built for WooCommerce stores. If WooCommerce is not active, the plugin stays idle and shows an admin notice — it will never break your site.
-
Is every feature really included for free?
-
Yes. There is no separate paid version, no license key, no plan, no quota, and no upgrade to buy. Every feature described above ships in this one plugin. Some features that act on their own or reach outside your site — automated/scheduled sending, payment recovery, Smart Offers, AI, and outbound webhooks — are turned off by default so nothing happens until you configure it.
-
Does the plugin make any external/remote calls by default?
-
No. Out of the box the plugin runs entirely on your site and makes no third-party API calls during activation, admin use, the front end, cron, or uninstall. Two optional features can send data off-site only after you explicitly enable them: AI (to OpenAI, using your own key) and outbound Webhooks/n8n (to the endpoint URL you configure). There is no Cartlyra server involved in either.
-
How does the AI work, and is my data sent anywhere?
-
AI uses your own OpenAI API key (bring-your-own-key). It is disabled by default and makes no calls until you enable it and enter your key, which is stored encrypted. Requests carry aggregate, no-personal-data payloads, are rate-limited by a daily call cap, and always fall back to the default email if the AI is unavailable. Nothing is sent to any Cartlyra server.
-
How do webhooks work?
-
Webhooks are disabled by default. Nothing is sent until you create and enable an endpoint. Deliveries are HMAC-signed, validated against SSRF, retried safely, and carry privacy-safe payloads; the endpoint URL is stored encrypted. Test deliveries only happen when you explicitly trigger them. There is no Cartlyra server involved.
-
Is the plugin compatible with WooCommerce High-Performance Order Storage (HPOS)?
-
Yes. The plugin declares full compatibility with WooCommerce custom order tables.
-
Does the plugin work on multisite?
-
Yes. Activation, deactivation, and uninstall are multisite-aware.
-
Will my data be deleted if I uninstall the plugin?
-
Only if you enable the “Delete all plugin data when the plugin is uninstalled” option under Cartlyra Settings. By default, your settings are kept so you can reinstall without losing configuration.
-
Is this a finished, production-ready release?
-
This is an early 1.0.x release. We recommend testing on a staging copy of your store first and reporting any issues before relying on it in production.
Reviews
Contributors & Developers
“Cartlyra Revenue Recovery for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Cartlyra Revenue Recovery for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.2
- All-inclusive edition: every feature — automated recovery, multi-step follow-ups, payment recovery, Smart Offers, Revenue Intelligence, AI Studio (bring-your-own key), Webhooks & n8n, reports, and CSV export — is now included in this single plugin. There is no separate paid version, license, plan, quota, or upgrade.
- AI and outbound webhooks remain disabled by default and require your own key or endpoint before anything is sent off-site. No Cartlyra server is involved.
- Added clear OpenAI and Webhooks/n8n external-service disclosures.
- No customer-facing recovery behavior changes without your configuration; all safety controls (nonce/capability checks, privacy masking/encryption, suppression/unsubscribe, cooldowns, per-cart locking, Emergency Stop, SSRF protection, webhook signing, audit logs, retention/delete-data) are retained.
1.0.1
- Public rebrand to Cartlyra Revenue Recovery for WooCommerce.
- Admin CSS/JS is delivered through the standard WordPress enqueue APIs (no inline style/script tags).
- Added the “Requires Plugins: woocommerce” header and made the WP-Cron guidance URL construction install-safe.
1.0.0
- Initial WordPress.org distribution release candidate.
