Bouzin Pay

Description

Bouzin Pay connects WordPress to Stripe and brings the essential commerce tools into one clear administration interface.

Main features:

  • Stripe OAuth connection, with separate TEST and LIVE modes.
  • Dashboard, products, prices, Checkout and Payment Links.
  • Payment-method management from WordPress.
  • Customers, invoices, subscriptions, refunds and promotion codes.
  • Customer account with purchases, invoices and subscription access.
  • Optional stock management.
  • Optional Digital Files for protected downloads.
  • Optional Protected Content for pages, posts, blocks and supported custom fields.
  • Optional Licences & private updates.
  • Optional Booking and photo-selling tools.
  • French translations included.

Optional modules are disabled by default, so each site can enable only the features it needs.

Bouzin Pay does not store full card or bank details. Payments remain processed by Stripe.

Security

  • Separate test and live keys.
  • Server-side validation of products, prices, status, associations, and mode.
  • WordPress access is granted only after confirmation of a paid and trusted Checkout Session.
  • Signed webhooks with atomic deduplication and controlled retries.
  • Idempotency keys for Stripe creation and action requests.
  • Separate WordPress capabilities for sensitive operations.
  • Redacted technical logs that exclude API keys, webhook secrets, signatures, client secrets, and payment methods.
  • Signed checkout configuration and ownership checks before protected digital content is displayed.
  • Authenticated, rate-limited digital delivery from encrypted containers whose storage path is never exposed to customers.

External service

This plugin connects to Stripe to create and manage payment-related objects and to process checkout and customer portal requests. Data sent to Stripe can include customer contact information, product and price identifiers, transaction details, subscription details, and request metadata required to perform the selected operation.

Stripe is an external service. Its use is subject to the Stripe Services Agreement and Stripe Privacy Policy.

If the administrator explicitly clicks Connect Stripe with Bouzin Pay, the plugin also contacts https://bouzin.ch/wp-json/bouzin-pay-connect/v1/. This optional connection service receives the WordPress site URL, a random installation identifier, the selected TEST/LIVE mode, the Stripe account identifier returned by OAuth, and an OAuth refresh token encrypted at rest on the service. Stripe App connected-account events are received centrally on bouzin.ch, verified with Stripe’s signing secret, then forwarded to the matching WordPress installation with a per-installation HMAC. If a site is temporarily unavailable, the raw event payload is encrypted while queued for retry and removed after successful delivery. Customer, payment, invoice, subscription, product and checkout API operations are not proxied through bouzin.ch; they continue directly from the merchant WordPress site to Stripe. Administrators can instead keep using manual Stripe credentials and never call this service.

If an administrator adds a product image hosted by another provider, visitors’ browsers contact that image host when the shop is displayed. The administrator is responsible for disclosing that provider where required.

Cart browser requirements

The central cart requires HTTPS, enabled first-party local storage and Web Locks support (current Chrome, Edge, Firefox and Safari). It stores a random attempt identifier, mode and public order reference, without contact details, so a reload or another tab can resume the same payment. Do not clear browser storage while a payment is unresolved. Legacy integrations calling the cart Checkout REST endpoint must send a 64-character random hexadecimal attempt_id and the selected mode; retries keep that identifier.

Development

Readable, uncompressed JavaScript and CSS source for every generated frontend asset is included in the source directory. The source-to-bundle mapping and build instructions are documented in source/README.md; the exact npm dependency and build commands are declared in package.json and locked in package-lock.json.

The catalogue assets in catalogue/assets are readable runtime source and require no bundling. Its PHP source, CSV examples and gettext generation script are included.

Credits and licenses

Bouzin Pay is derived from WPMarmite Pay 1.5.5. The original work is Copyright (C) 2024 WPMarmite, and the Bouzin Pay modifications are Copyright (C) 2026 Bouzin. WPMarmite is not affiliated with and does not provide support for Bouzin Pay.

Third-party copyright and license notices for Stripe PHP, Composer, Terser, and the included CA certificate bundle are provided in THIRD-PARTY-NOTICES.txt.

Privacy

Bouzin Pay can store Stripe identifiers, customer contact details, payment states, invoices, subscriptions, related object summaries, redacted logs, and webhook processing history in the WordPress database. It does not store full card numbers or full bank details.

When the optional one-click Stripe connection is used, the WordPress site stores an encrypted short-lived OAuth access token plus the Stripe account/connection identifiers. The central Bouzin Pay connection service at bouzin.ch stores the corresponding OAuth refresh token encrypted at rest and the minimum installation metadata needed to return refreshed access. It also receives signed Stripe App connected-account events and forwards them to the matching WordPress installation. Event payloads are encrypted only while queued for retry and are removed after successful delivery. The service is not used as a proxy for payment, customer, product, invoice, subscription or checkout API calls. Manual credentials remain available and do not require this service.

Protected digital content is linked to a Stripe product and remains subject to a server-side ownership check on each request. The plugin stores encrypted file metadata, purchase entitlements, refund state and an aggregate download count, but no IP address in digital download records. Invoice files and hosted invoice pages are delivered by Stripe and are not copied into the WordPress media library.

When the optional Protected content module is enabled, Bouzin Pay stores the selected product identifiers in page/post metadata and, where used, protected Gutenberg/ACF/Meta Box configuration. Access is evaluated from the same confirmed purchase and active-subscription records already associated with the signed-in WordPress account. The customer My content library lists only published destinations currently unlocked for that account.

Optional inventory stores product/session identifiers, quantities, revisions and durable deduplication records. A pending checkout creation request, which can include an email/customer identifier and return URLs, is encrypted locally until its session is recovered. Once the session is known, this payload is cleared. Unknown payments retain their reservation and recovery data for administrator review; no browser cancellation or local time limit silently releases them. Terminal stock attempts and paid/released reservation records are removed after 180 days in bounded daily batches; pending and uncertain payments are never removed automatically.

When the optional Licences & private updates module is enabled, Bouzin Pay stores licence identifiers and status, related product and purchase/subscription references, the associated WordPress user ID, and activation information such as site/home URLs, instance identifiers and plugin/WordPress versions. Manually granted licences can additionally store an optional recipient email address and a short administrator note; they do not create a Stripe payment or fake order. Activation tokens are kept as one-way hashes; a recoverable copy of the full licence key can be stored encrypted. The licence module does not use the visitor IP address as its licence identity. Private plugin releases additionally store release metadata and guarded ZIP packages locally. Eligible customers can download the current release from their Bouzin Pay account while the associated licence is valid.

When the optional Booking module is enabled, Bouzin Pay stores the service, appointment start/end time, booking status and, when applicable, payment/order linkage. Booking contact data such as email, customer name, phone number and an internal note are encrypted at rest when they are collected. Paid slot holds expire automatically; no-payment, manual, confirmed or cancelled booking records remain under the site administrator’s control and follow the plugin’s explicit full-removal setting on uninstall.

The plugin adds suggested privacy-policy text in the WordPress privacy guide. Site administrators remain responsible for adapting that text to their actual configuration and legal obligations.

The WordPress personal-data tools export local customer snapshots and purchase access, including customer records without a remaining WordPress account. Erasure removes contact details, free text, metadata and invoice download URLs from the local cache and removes the WordPress purchase/subscription associations. The same cleanup runs on account deletion. Unresolved encrypted checkout recovery must be resolved first; the eraser reports retained data instead of deleting payment recovery state.

Once a successful refund has revoked purchase access, a later refund delivery or bank refund failure does not automatically restore that access; the merchant must resolve the failed refund with the buyer.

Minimal financial identifiers and amounts, revoked purchase tombstones and keyed erasure fingerprints remain locally until explicit full removal of plugin data. These pseudonymous records prevent duplicate settlement, delayed webhook access restoration and reimport of erased contact details. The privacy eraser explicitly reports this retention. The suppression key is stored separately from WordPress authentication salts. Regular synchronization keeps other customer summaries until erasure or complete plugin-data removal; the merchant must define any further retention required for their business. No local privacy operation cancels billing or deletes Stripe’s records. A fresh authorized Stripe lookup in the administration can still retrieve records retained by Stripe.

Blocks

This plugin provides 4 blocks.

  • Bouzin Pay – Shop Automatically display synchronized products in a responsive shop.
  • Bouzin Pay – Stock remaining Display the live remaining stock for one Bouzin Pay product.
  • Bouzin Pay Add Stripe checkout to your website.
  • Bouzin Pay Customer Account Display a complete professional customer account with purchases, downloads, subscriptions, invoices, profile, account deletion, support, and Stripe billing.

Installation

  1. Upload and activate Bouzin Pay.
  2. Open Bouzin Pay > Settings.
  3. Connect Stripe with OAuth, or configure manual Stripe credentials if required.
  4. Start in TEST mode and verify the connection.
  5. Open Bouzin Pay > Modules and enable only the optional features you need.
  6. Test checkout, Stripe events, refunds, subscriptions and customer emails before switching to LIVE mode.

TEST and LIVE settings remain separate. Existing Stripe processing stays on Stripe; Bouzin Pay provides the WordPress interface and synchronization.

FAQ

How do product images, delivery and service fees work?

Create or edit a product to choose a public Media Library image and add its first price. Existing prices remain unchanged; create another price to change its amount. Protected downloads remain separate from the public product image.

Optional delivery is charged once per order and is supported for one-time purchases only. Enter delivery country codes (for example CH, FR or DE). Use a separate product without shipping for subscriptions.

Optional fixed service fees are charged once per order, or on the initial subscription invoice only. Percentage and card-payment surcharges are not provided. Name the actual service being charged. Costs and the selected price must use the same currency. Stripe discounts can also reduce service fees; tax treatment follows the price. Checkout displays the final total before payment confirmation.

WordPress purchase links and Gutenberg buttons read the product’s current costs for new sessions. Previously created Stripe Payment Links and pending Checkout sessions remain unchanged: create a new Stripe Payment Link after changing costs. Direct Stripe Payment Links containing a product with costs support a single main product in this release.

Does this update migrate my Stripe webhooks?

Manual-key installations can keep using the existing per-site signed webhook and guided webhook migration. OAuth Stripe App installations do not create, modify or delete merchant webhook endpoints: they use the central signed event destination on bouzin.ch. This removes the need for the sensitive webhook_write Stripe App permission.

What happens when an optional module is disabled?

On a fresh installation, Digital Files, Protected content and Licences & private updates are off. Bouzin Pay only keeps a tiny module-state option so it can know what to load. Protected content is independent from Digital Files. Enabling Licences automatically enables Digital Files. Disabled optional features do not register their business hooks, REST routes, cron jobs or public assets. When Protected content is disabled, its Gutenberg blocks, ACF/Meta Box filters, page/content protection and the customer My content tab are not registered. Existing module data is retained so switching a module back on is safe. Complete removal happens only when the global complete-data-deletion option is selected before uninstalling Bouzin Pay.

How do I sell protected PDF access as a subscription?

Open Bouzin Pay > Products and create or select a product. Use Add a price, select a Subscription sale type, then choose the period and enter 1, 2, or 3. Attach the PDF from Protected Files to that same product, then create a Purchase Link or copy the price’s buy button. A value of 3 with Month bills every three months until cancellation; it is not a one-time three-month pass. The PDF is displayed and served only while the synchronized subscription is active or trialing and its known paid period has not ended. Select One-time payment for a non-recurring charge. Licence duration is configured separately in the Licences module.

Can customers cancel a subscription from their WordPress account?

Yes. The Subscriptions tab displays each synchronized subscription and its next renewal or access-end date. Manage or cancel my subscription first asks the customer to continue, then opens Stripe directly on the cancellation flow for that exact subscription. Stripe displays the final consequences and collects the final confirmation. Subscription cancellation must be enabled in the matching TEST or LIVE Stripe customer-portal configuration.

Can customers delete their WordPress account?

Yes. Eligible customer accounts have a protected deletion form in the Profile tab. The customer must enter the current password, type DELETE, and confirm the access warning. Staff accounts and multisite accounts cannot use this action. A renewing LIVE subscription must be canceled first. WordPress profile and protected-content access are removed immediately, while Stripe billing records, invoices, transactions, and legally required records remain in Stripe.

Does Bouzin Pay store card or bank details?

No. Full card numbers, full bank details, and legal identity data remain in Stripe’s secured interfaces.

What data is stored locally?

The plugin stores a limited administrative cache of selected Stripe objects, redacted technical logs, and event history needed to prevent duplicate webhook processing. Webhook history is retained for 180 days and technical logs for 90 days by default; both durations are configurable in Bouzin Pay settings. Failed webhook records are retained for up to twice the configured webhook duration to support diagnosis.

Can all plugin data be removed?

Enable the complete deletion option before uninstalling the plugin. Deactivation alone never deletes data. Resolve all pending payments first: unresolved stock attempts and their inventory ledger/account binding are deliberately preserved even during complete deletion. Reconcile them before a later full cleanup. No operation deletes products, sales or invoices from Stripe.

Where are paid digital files stored?

They are stored as encrypted .bpv containers in Bouzin Pay’s guarded vault under the WordPress uploads directory, never as public Media Library attachments. Back up both the WordPress database and the complete uploads directory together. The per-file keys are encrypted from the site’s WordPress authentication salts; changing those salts or restoring only one half of the backup makes existing protected files unreadable until they are uploaded again.

Reviews

Read all 1 review

Contributors & Developers

“Bouzin Pay” is open source software. The following people have contributed to this plugin.

Contributors

Translate “Bouzin Pay” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.1.2

  • Adds Stripe OAuth/Connect with separate TEST and LIVE modes.
  • Adds Stripe payment-method management directly from WordPress.
  • Expands catalogue, stock, cart, customer accounts, digital files and protected content.
  • Adds optional Booking, Photo Galleries, WPForms and Licence modules.
  • Improves Checkout reliability, subscriptions, refunds, privacy, security and recovery.
  • Adds French translations for France, Switzerland, Belgium and Canada.

0.1.1

  • Use an independent Checkout signing secret while preserving existing paid-session verification and vault encryption.
  • Enqueue inline styles through WordPress and prefix localized JavaScript globals.
  • Generate a non-executable vault index document.
  • Preserve the customer subscription display fix and separate client/webhook API versions.

0.1.0

  • Initial public release.
  • Added Stripe dashboard and management tools for products, prices, customers, invoices, subscriptions, refunds, disputes and payouts.
  • Added separate TEST/LIVE modes, signed webhooks, encrypted key storage and redacted logs.
  • Added the customer account, protected digital content and authenticated downloads.
  • Added CSV product import/export, the shop block and optional per-product stock.
  • Added privacy, security, retention and reproducible source/build documentation.