plugin-icon

Cartlyra Revenue Recovery for WooCommerce

Recover abandoned carts and failed payments with automated emails, Smart Offers, checkout Revenue Intelligence, and reports. Privacy-first.
Version
1.0.2
Last updated
Jul 20, 2026
Cartlyra Revenue Recovery for WooCommerce

Cartlyra Revenue Recovery for WooCommerce helps you understand and recover revenue your store is losing. Every feature is included — there is no separate paid version, no license, and no upgrade to buy. Sensitive capabilities that reach outside your site (AI and outbound webhooks) are disabled by default and only run after you explicitly enable and configure them with your own credentials.

The plugin tracks abandoned carts and checkout signals, sends manual and automated recovery emails (with built-in safety cooldowns and per-cart locking), and gives you privacy-first controls: suppression, one-click unsubscribe, contact encryption, configurable retention, and Health diagnostics.

What’s included

  • Abandoned cart and checkout tracking for guests and logged-in customers.
  • Lost Carts screen: every tracked cart with status filters, cart value, items, and order links.
  • Manual recovery emails for eligible abandoned carts (one-click “Send Recovery Now”), repeatable after a built-in anti-spam safety cooldown, with a secure, expiring recovery link and one-click cart restore.
  • Automated recovery: scheduled abandoned-cart recovery so the first email can send automatically once your delay elapses (disabled by default).
  • Multi-step follow-ups: Step 2 and Step 3 recovery sequences (disabled by default).
  • Failed and pending payment recovery: emails with a secure retry-payment link, plus pending-payment reminders (disabled by default).
  • Smart Offers: a rules-based engine that can add a static or unique (percentage, fixed, or free-shipping) coupon to recovery emails, with cart-value, sale-item, and category guardrails to protect margins (disabled by default).
  • Revenue Intelligence: checkout-incident detection, affected-cart cohorts, Payment Health, merchant-approved recovery campaigns, baselines, rollups, funnel intelligence, revenue-leak investigation, change timeline, Action Cases, and Fix Verification. No customer is contacted until you explicitly approve a campaign.
  • AI Studio (bring-your-own key): the AI Recovery Copywriter, AI Incident Analyst, and AI Revenue Operator. AI is disabled by default; when you enable it and add your own OpenAI key (stored in an encrypted vault), it uses a no-personal-data payload and a daily call cap, and always falls back to the default email.
  • Webhooks & n8n: send privacy-safe, HMAC-signed events to automation tools such as n8n. Disabled by default; nothing is sent until you create and enable an endpoint.
  • Reports and CSV export.
  • Brand Kit: brand-aware recovery emails (logo from your Media Library, colors, footer, support email, voice) with safe fallbacks and a privacy-safe placeholder preview.
  • Privacy-first controls: contact encryption and safe lookup, a suppression list, one-click unsubscribe, configurable data retention, and an opt-in “delete data on uninstall” preference.
  • Health & Diagnostics: system, database, and cron status with scheduled-task self-healing and a repair action.
  • Safe by design: no raw IP addresses or user agents are stored (optional salted hashes only, off by default); WooCommerce High-Performance Order Storage (HPOS) compatible; multisite-aware; translation-ready and RTL-ready; and idle (no errors) when WooCommerce is inactive.

By default the plugin makes no third-party API calls. The only features that can send data off your site — AI (OpenAI) and outbound webhooks/n8n — are disabled until you turn them on and supply your own key or endpoint. See “External Services” below.

Privacy

To power abandoned-cart recovery and checkout-signal monitoring, the plugin may process cart, contact, and recovery information needed for the recovery workflows you configure — for example a cart’s contents and value, the billing email/phone/name a shopper enters at checkout, and records of recovery emails you send and whether their links were clicked. It does not store payment card details.

Sensitive contact data is protected using the plugin’s privacy architecture (encryption with one-way lookup hashes). Recovery emails are sent using your store’s configured WordPress/WooCommerce mail setup. You control how long data is kept (data retention), and shoppers can be suppressed or can unsubscribe so they are no longer contacted.

As the store owner, you remain responsible for configuring the plugin lawfully and for providing your own customer-facing privacy notice. The plugin also adds suggested privacy-policy text to Settings Privacy Policy Guide that you can adapt for your store.

The plugin integrates with the built-in WordPress Personal Data Export and Erase tools (under Tools Export Personal Data / Erase Personal Data), so you can provide or remove the recovery data it holds for a customer’s email address. When data is erased, a minimum opt-out record may be retained solely to help prevent future recovery communications to that person.

External Services

By default the plugin makes no third-party API calls. It bundles no licensing, telemetry, or remote-account service, and there is no Cartlyra server involved in its operation. Two optional features can connect to an external service, and only after you explicitly enable and configure them:

OpenAI (AI Studio) — optional, off by default, bring-your-own-key. When you enable AI and enter your own OpenAI API key, the plugin sends requests to the OpenAI API (https://api.openai.com) to generate recovery-email copy, to explain checkout incidents, and to produce store operating briefings. AI is disabled by default and makes no OpenAI call until you enable AI, add your own key, and tick the OpenAI external-service consent box. Consent applies to all three AI capabilities below. Removing consent disables AI. Requests happen only on your explicit action (or, if you enable automated AI copy, when a recovery email is generated), subject to a daily call cap you control. Your key is stored encrypted and never displayed after saving.

AI Recovery Copywriter — what is sent: only safe, non-personal context — store/brand configuration, your selected tone and language, cart total, currency, item count, a checkout-started flag, a safe offer type, and a safe expiry-in-hours value.

AI Incident Analyst and AI Revenue Operator — when you explicitly request an analysis or briefing, OpenAI may receive aggregate operational evidence such as: incident type, status, severity, and timestamps; aggregate sample sizes, rates, counts, and affected-cart value; aggregate campaign counts; checkout funnel stage counts; revenue and recovery aggregates; trend and change categories; and store-level operational metrics and safe labels.

None of the following are sent to OpenAI by any AI capability: customer names, emails, phone numbers, addresses, product names, product categories, cart line items, SKUs, coupon codes, order or cart identifiers, recovery URLs, tokens, raw gateway payloads, raw error messages, or API keys.

  • OpenAI Terms of Use: https://openai.com/policies/terms-of-use — OpenAI Privacy Policy: https://openai.com/policies/privacy-policy

Outbound Webhooks / n8n — optional, off by default. When you create and enable a webhook endpoint, the plugin sends HMAC-signed event notifications to the endpoint URL you configure (for example an n8n workflow you host). Webhooks are disabled by default; nothing is sent until you create and enable an endpoint, and test deliveries occur only when you explicitly trigger them. The destination is whatever URL you enter (validated against SSRF). There is no Cartlyra server involved.

An enabled endpoint receives an event envelope containing: your site URL, a generated event ID, the event name, the event timestamp, the payload schema version, and the plugin version — plus an event-specific data object with, where relevant, internal reference IDs (such as cart, message, incident, campaign, or campaign-recipient IDs) and safe aggregate fields (status and reason codes, amount and currency, counts, rates, and revenue/recovery aggregates).

No raw customer personal data, secrets, API keys, coupon codes, recovery URLs, message bodies, or the full endpoint URL are ever sent or exposed in the admin (the admin shows the endpoint host only).

Support

Free support is provided through this plugin’s WordPress.org support forum after publication.

Ownership

Cartlyra is the product brand behind this plugin. The official plugin contact is plugins@cartlyrai.com.

Freeon paid plans
Tested up to
WordPress 7.0.2
This plugin is available for download for your site.