=== WaLine Notifications for WooCommerce ===
Contributors: line, waline-team
Tags: woocommerce, whatsapp, notifications, widgets, otp
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Requires Plugins: woocommerce
Stable tag: 1.0.15
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Connect your WooCommerce store to WhatsApp Line for automated notifications, quick OTP login, reviews, and restock alerts.

== Description ==

WaLine Notifications for WooCommerce enables WooCommerce notifications and customer tools through WhatsApp. Keep customers informed about order updates and provide additional customer-facing features such as OTP login, restock notifications, reviews, and a WhatsApp support widget.

=== Key Features ===

* **Automated Order Notifications**: Send order status updates such as created, processing, completed, refunded, and other enabled order events to customers through WhatsApp.
* **WhatsApp OTP Quick Login**: Enable passwordless registration and login using verification codes sent to the customer's WhatsApp number.
* **Restock Notifications**: Display a "Notify Me When Available" option on out-of-stock product pages and allow customers to subscribe for availability notifications.
* **Order & Product Reviews**: Collect product and store ratings through the plugin's review functionality.
* **Interactive Chat Widget**: Display a customizable floating WhatsApp widget for customer support.

=== External / 3rd Party Service Notice ===

This plugin connects to the WhatsApp Line third-party service to provide WhatsApp messaging and related WooCommerce integration functionality.

* **Service Name:** WhatsApp Line Platform
* **Service Website:** https://line.sa
* **API Service:** https://whats.line.sa
* **Terms of Service:** https://line.sa/%D8%B4%D8%B1%D9%88%D8%B7-%D8%A7%D9%84%D8%A7%D8%B3%D8%AA%D8%AE%D8%AF%D8%A7%D9%85/
* **Privacy Policy:** https://line.sa/%D8%B3%D9%8A%D8%A7%D8%B3%D8%A9-%D8%A7%D9%84%D8%AE%D8%B5%D9%88%D8%B5%D9%8A%D8%A9

**Why does this plugin connect to an external service?**

The external service is required to provide WhatsApp messaging and related WooCommerce integration functionality that cannot be provided by WordPress alone.

**What data may be transmitted to WhatsApp Line?**

Depending on the features enabled by the store administrator, the plugin may transmit:

* **Store & Account Information:** Store URL, store name, administrator email address, merchant mobile phone number, and a unique store identifier.
* **Customer & Order Data:** Customer phone number, customer name, order number, order total, currency, order status, and relevant ordered product information when order notifications are enabled.
* **Cart Recovery Data:** Customer contact information, cart contents, cart totals, and checkout recovery information when cart recovery is enabled.
* **OTP Verification Data:** The destination mobile phone number and verification code when the OTP login feature is enabled and requested.

**When is data sent?**

* **No external requests during activation:** Activating the plugin does not make external HTTP requests or transmit customer data.
* **Disabled by default:** Notification features and store event notifications are disabled by default on a new installation.
* **Administrator action required:** External communication begins after the store administrator connects the store to the WhatsApp Line service and enables the relevant functionality.
* **Revocable:** Administrators can disable individual notification features or disable message sending from the plugin settings.
* **Event-driven communication:** Once a feature is connected and enabled, data is transmitted only when required by the enabled functionality, such as an enabled order notification, OTP request, restock subscription, or enabled cart recovery process.

**How is the data transmitted and processed?**

Communication between the WordPress site and WhatsApp Line uses HTTPS with TLS certificate verification enabled.

The service processes transmitted information to provide the enabled messaging and WooCommerce integration features, including message delivery and related merchant logs and reporting.

=== Installation ===

1. Upload the plugin folder to the `/wp-content/plugins/` directory, or install the plugin directly through the WordPress admin screen.
2. Activate the plugin through the 'Plugins' screen in WordPress.
3. Go to the "WhatsApp Line" settings menu in your WordPress dashboard.
4. Review the external service information and connect your store to your WhatsApp Line account.
5. Enable the notification features and customer tools you want to use.

=== Frequently Asked Questions ===

= Is a WhatsApp Line platform account required? =

Yes. An active merchant account on https://line.sa is required to use the WhatsApp messaging and integration features provided by the plugin.

= Does the plugin make external requests during activation? =

No. Plugin activation does not make external HTTP requests to the WhatsApp Line service or transmit customer data.

= Does the plugin send data to WhatsApp Line without administrator authorization? =

External communication is not performed during plugin activation. The store administrator must connect the store to WhatsApp Line and enable the relevant functionality before the plugin transmits data required for that functionality.

= Can I disable the connection or individual features? =

Yes. Administrators can disable individual notification features or disable message sending from the plugin settings.

= Where can I review the Terms and Privacy Policy? =

You can review the Terms of Service at https://line.sa/%D8%B4%D8%B1%D9%88%D8%B7-%D8%A7%D9%84%D8%A7%D8%B3%D8%AA%D8%AE%D8%AF%D8%A7%D9%85/ and the Privacy Policy at https://line.sa/%D8%B3%D9%8A%D8%A7%D8%B3%D8%A9-%D8%A7%D9%84%D8%AE%D8%B5%D9%88%D8%B5%D9%8A%D8%A9.

= Are the frontend scripts compiled or minified? =

No build pipeline or transpilation is used. The JavaScript and CSS assets included with the plugin are provided as human-readable source files.

= How does the OTP login work? =

Customers enter their mobile number, receive a verification code through WhatsApp, and enter the code to complete registration or login without using a password.

== Changelog ==

= 1.0.15 =

* Updated the plugin for compatibility with supported PHP and WordPress versions.
* Formatted JavaScript and CSS assets into clean, human-readable source code.
* Added comprehensive third-party external service, privacy policy, and terms disclosures.
* Added explicit external service connection and administrator opt-in flow.
* Enhanced REST API authentication with secret token validation.
* Implemented multi-layer rate limiting, brute-force protection, and lockout defenses for OTP login.
* Added nonces and capability checks across admin actions, AJAX handlers, and metaboxes.
* Ensured that plugin activation does not make external HTTP requests.
* Notification features remain disabled by default until enabled by the administrator.

= 1.0.0 =

* Initial public release with OTP Quick Login, Order Notifications, Reviews, and Restock alerts.
