Describe the bug
NotificationX stores personal data in its own {$prefix}nx_entries table but registers no WordPress privacy exporters or erasers, so that data is invisible to Tools → Export Personal Data and Tools → Erase Personal Data.
A repo-wide search for wp_privacy_personal_data_exporters, wp_privacy_personal_data_erasers, and wp_add_privacy_policy_content across includes/, blocks/, and notificationx.php returns zero results.
What's stored
Entry data payloads routinely include, depending on source:
name, first_name, last_name
email
ip
- postal fields —
city, country, state, line_1, line_2, postal_code (e.g. includes/Extensions/SureCart/SureCart.php#L166-L209)
This is personal data under GDPR/CCPA, and for some integrations it is linked to purchase or enrollment history.
Compounding: uninstall doesn't clean up
uninstall.php is a boilerplate stub — it contains only the WP_UNINSTALL_PLUGIN guard and no cleanup — so nx_entries and its personal data survive plugin deletion entirely.
Not covered by the existing GDPR/CCPA extensions
includes/Extensions/GDPR/ and includes/Extensions/CCPA/ are consent-banner notification sources. They help site owners display a cookie notice; they do nothing about data subject rights over NotificationX's own stored data.
Steps to reproduce
- Install NotificationX and any source that captures customer data (WooCommerce Sales, SureCart, EDD…).
- Let a few notifications accumulate so
{$prefix}nx_entries has rows containing a customer's name and email.
- Go to Tools → Export Personal Data, enter that customer's email, and run the export.
- Repeat with Tools → Erase Personal Data.
Expected: the export includes the customer's NotificationX entries; the erasure removes or anonymizes them.
Actual: neither tool sees the data. It is not exported, and it is not erased — the customer's name and email continue to appear in public social-proof popups after they have exercised their right to erasure.
Suggested fix
Register a single exporter/eraser pair keyed on data.email. Because every source funnels through the same nx_entries table and a common data shape, one implementation covers all integrations at once — this doesn't need per-extension work.
add_filter( 'wp_privacy_personal_data_exporters', [ $this, 'register_exporter' ] );
add_filter( 'wp_privacy_personal_data_erasers', [ $this, 'register_eraser' ] );
Erasure should probably anonymize rather than hard-delete, so notification counts and campaign history stay intact.
Separately, uninstall.php should drop the plugin's tables (ideally behind an opt-in "delete data on uninstall" setting, which is the common convention).
Impact
Compliance. A site owner cannot fulfil a GDPR Article 17 erasure request with the tools WordPress provides, and in the worst case the erased individual's name keeps being displayed publicly on the site.
The exposure scales with how sensitive the source is. It is one thing for a T-shirt purchase; it is quite another for appointment, donation, or health-adjacent booking data — which is what prompted this report.
Environment
Found on master @ 55f62f10.
Describe the bug
NotificationX stores personal data in its own
{$prefix}nx_entriestable but registers no WordPress privacy exporters or erasers, so that data is invisible to Tools → Export Personal Data and Tools → Erase Personal Data.A repo-wide search for
wp_privacy_personal_data_exporters,wp_privacy_personal_data_erasers, andwp_add_privacy_policy_contentacrossincludes/,blocks/, andnotificationx.phpreturns zero results.What's stored
Entry
datapayloads routinely include, depending on source:name,first_name,last_nameemailipcity,country,state,line_1,line_2,postal_code(e.g.includes/Extensions/SureCart/SureCart.php#L166-L209)This is personal data under GDPR/CCPA, and for some integrations it is linked to purchase or enrollment history.
Compounding: uninstall doesn't clean up
uninstall.phpis a boilerplate stub — it contains only theWP_UNINSTALL_PLUGINguard and no cleanup — sonx_entriesand its personal data survive plugin deletion entirely.Not covered by the existing GDPR/CCPA extensions
includes/Extensions/GDPR/andincludes/Extensions/CCPA/are consent-banner notification sources. They help site owners display a cookie notice; they do nothing about data subject rights over NotificationX's own stored data.Steps to reproduce
{$prefix}nx_entrieshas rows containing a customer's name and email.Expected: the export includes the customer's NotificationX entries; the erasure removes or anonymizes them.
Actual: neither tool sees the data. It is not exported, and it is not erased — the customer's name and email continue to appear in public social-proof popups after they have exercised their right to erasure.
Suggested fix
Register a single exporter/eraser pair keyed on
data.email. Because every source funnels through the samenx_entriestable and a common data shape, one implementation covers all integrations at once — this doesn't need per-extension work.Erasure should probably anonymize rather than hard-delete, so notification counts and campaign history stay intact.
Separately,
uninstall.phpshould drop the plugin's tables (ideally behind an opt-in "delete data on uninstall" setting, which is the common convention).Impact
Compliance. A site owner cannot fulfil a GDPR Article 17 erasure request with the tools WordPress provides, and in the worst case the erased individual's name keeps being displayed publicly on the site.
The exposure scales with how sensitive the source is. It is one thing for a T-shirt purchase; it is quite another for appointment, donation, or health-adjacent booking data — which is what prompted this report.
Environment
Found on
master@55f62f10.