WooCommerce Smart COD PRO – Your favourite, 5 star rated, WooCommerce COD plugin, now enhanced with a ton of new features!

Cancelled COD Data Sharing

COD Protection and cancelled COD data sharing are optional and off by default. They operate only after a store administrator explicitly enables “Enable COD protection and cancelled COD data sharing” in WooCommerce → Settings → Payments → Cash on Delivery. Enabling the option allows Smart COD to collect eligible cancelled Cash on Delivery (COD) order events and transmit them over HTTPS to api.woosmartcod.com. Turning it off stops future collection, transmission and checkout checks.

What this feature does

The feature considers WooCommerce orders that were cancelled and paid by Cash on Delivery. Eligibility is based on available shipment or fulfilment information and order timing; a cancelled order alone does not prove that a customer refused delivery. The information supports the operation and improvement of COD reliability and risk-prevention features.

When COD Protection is enabled, the plugin can check the email address or telephone entered during checkout against eligible dispatched-then-cancelled COD events from the same participating shop. If a match is returned, Cash on Delivery is hidden for that checkout. This is an automated checkout rule affecting the availability of COD only; the shopper can still use the shop’s other available payment methods. The current checkout decision does not use records from other shops or countries. The plugin does not contact courier APIs.

Information transmitted

For eligible cancelled COD events, the service receives a generated installation identifier, shop domain, plugin/version and operating country; a non-reversible order reference; cancellation time; currency; order, shipping and discount amounts; item count; customer type; shipping-method slug; and elapsed order time.

Where available, it also receives courier name, tracking code and shipment or fulfilment evidence. Each eligible event may include a capped count of earlier completed COD orders with tracking for the same shopper at that shop, as known at the time of cancellation. Normalised email, telephone, postcode, city and region are transformed into deterministic tokens before transmission. The receiving service applies an additional secret-keyed transformation before storing them.

During an enabled checkout lookup, the plugin sends the generated installation identifier, operating country and locally generated SHA-256 tokens for the available email address and telephone number. The service returns an allow-or-disable signal and a capped same-shop match count. Checkout lookup requests are not added to the event database or used to create a checkout customer profile.

Smart COD does not transmit raw customer names, postal addresses, email addresses, telephone numbers, product names, payment-card details, account passwords or WooCommerce order IDs for this feature.

How information is used

Received events are stored in a protected service environment. COD Protection uses eligible records belonging to the same installation to determine whether COD should remain available for a matching checkout. Received events may also be analysed in aggregate across participating shops in the same operating country to develop and improve COD reliability features. Pseudonymised identifiers allow recurring records to be recognised without storing the raw email address or telephone number.

Pseudonymised information can still be personal data. Store owners remain responsible for assessing their own privacy obligations, including whether and how this processing and the COD Protection rule should be described in their customer-facing privacy information.

Reliability and security

Data is transmitted over HTTPS. Requests are signed and protected against replay. The central database stores an additional secret-keyed representation of received identity tokens rather than the tokens submitted by the plugin. Checkout requests use a short timeout and fail open: if the service is unavailable, times out or returns an invalid response, Cash on Delivery remains available.

How to enable or disable the feature

The feature remains off unless a store administrator checks “Enable COD protection and cancelled COD data sharing” and saves the COD settings. Enabling it starts eligible historical and future event collection and enables same-shop checkout checks. Unticking it stops future local collection, transmission and checkout checks, cancels pending collection and delivery jobs, and returns the shop to its normal COD availability rules.

Disabling the setting does not automatically remove events already received by the service. For a request concerning information already held by the service, contact info@woosmartcod.com and include enough information to identify the relevant shop and request safely.

Retention

Eligible cancelled COD event records currently do not have an automatic expiry period. Checkout lookup requests are not stored as new event records. Requests concerning deletion, access or other privacy rights can be sent to info@woosmartcod.com.

Important information for merchants

This page describes product behaviour. It is not legal advice and does not replace a merchant’s own privacy notice, legal-basis assessment, contracts or other compliance obligations. Merchants should obtain appropriate legal advice for their circumstances.

100% Satisfaction Guaranteed — 14-day refund policy Check out our refund policy