Conformitico – Recesso 54-bis

تفصیل

From 19 June 2026, EU Directive 2023/2673 requires every online retailer in the European Union to offer a digital withdrawal function that is at least as easy to use as the purchase flow. This plugin ships the complete set of building blocks an EU store needs to put that function in place — and works as a self-contained tool with or without WooCommerce.

It is built with Italian e-commerce in mind (the "diritto di recesso” rules of art. 52 ff. of the Codice del Consumo and the new art. 54-bis), but the interface is in English and the plugin is fully translation-ready, so a shop that also sells across the EU can deliver the same workflow in several languages.

Multilingual by design

  • Base UI in English, the source language, with a bundled Italian (it_IT) translation ready out of the box.
  • Designed for Italian online shops that may also sell abroad: translation-ready for EN/FR/DE and any other locale.
  • Compatible with WPML, Polylang and Loco Translate. Texts you enter in the settings (form intro, consent texts, excluded-notice texts, status-email bodies) are registered for translation through the bundled wpml-config.xml, so multilingual sites can translate them per language.
  • Links generated by the plugin (withdrawal page button, printable Annex I.B form, excluded-product link, the [r54b_link] shortcode) resolve to the correct page translation on WPML and Polylang sites.

Core features

  • Two-step confirmation flow (Art. 11a(3)): the public form leads to a read-only review screen with a dedicated "Confirm withdrawal” button. The request is registered only when that button is pressed, which avoids the unintended exercise of the right. The intermediate state is held server-side in a single-use token, so it also works without JavaScript.
  • Durable-medium acknowledgement (Art. 11a(4)): the confirmation email reproduces the full content of the declaration (name, order, order date, scope, affected products) plus the exact date and time of submission, carrying a verifiable SHA-256 receipt hash as tamper-evident proof — recomputable from the stored fields if a dispute arises.
  • Model withdrawal form (Annex I.B, Directive 2011/83/EU) generated dynamically from your shop data, shown as a collapsible block below the public form, with a printable view on the same URL. Helps meet the pre-contractual information obligation of Art. 6(1)(h).
  • Checkout consent checkboxes for the two consents the directive expects when applying specific exceptions:
    • Mandatory consent for digital content (Art. 16(m)) — blocks the place-order step until accepted.
    • Optional consent for services started within the 14-day window (Art. 14(4)(a)) — enables pro-rated billing if the customer later withdraws.
      Each consent is stored on the order with the exact text shown, accepted/declined state, timestamp, IP and user agent, as durable proof.
  • Article 16 exclusions per product and per category with full subcategory inheritance, driven by a single "Withdrawal status” dropdown (Standard, Digital content, Service started early, Other Article 16 exception) that also sets the matching checkout consent.
  • Configurable excluded-product notice, rendered between price and add-to-cart on single product pages, with separate title and body for digital content and for other Article 16 exceptions.
  • Request log stored as a private custom post type with a status lifecycle (pending accepted rejected completed), customer details, scope (full / partial), IP, user agent and UTC submission timestamp for legal traceability.
  • Role-based access: choose which user roles, besides the administrator, may view and manage requests, because each request holds personal data.
  • Status emails on a durable medium: an acknowledgement email on confirmation and a follow-up email on every status transition, with editable bodies and a configurable sender. A notification email is also sent to the shop admin, with reply-to set to the customer.
  • Native GDPR integration: a suggested Privacy Policy snippet plus a personal-data exporter and eraser, keyed on the customer email — no second GDPR plugin required.

WooCommerce features (auto-enabled when WooCommerce is active)

  • My Account Right of withdrawal endpoint with a per-order "Withdraw” button while the order is in an eligible status, deep-linked to the form with the order pre-filled.
  • Withdrawal notice injected into transactional emails (processing, completed, customer invoice) with a direct link to the pre-filled form. Eligible statuses are configurable; admin emails never receive the notice.
  • Order/email verification: the request is matched to a real order and gated by the configured eligible statuses. The 14-day deadline is surfaced as an advisory flag for the admin rather than an automatic rejection, since the period legally runs from delivery.
  • Private order notes added at every lifecycle step (received, accepted, rejected, completed), including any admin comment.
  • HPOS support, declared via FeaturesUtil::declare_compatibility().

Standalone mode

The form, shortcode, request log, email notifications, SHA-256 receipt hash, Annex I.B model and GDPR integration all run without WooCommerce. The plugin always lives under its own top-level Withdrawals menu with a Settings submenu — the same path with or without WooCommerce. Activating WooCommerce later lights up the store features; deactivating it leaves the standalone features intact.

Shortcodes

  • [r54b_form] — embeds the withdrawal form anywhere.
  • [r54b_link] — a permanent link to the withdrawal page for any footer, widget area or template part, helping meet the "clearly identifiable” requirement of Article 11a.
  • [r54b_avviso_esclusione] — places the excluded-product notice with page builders (Divi, Elementor, Bricks, ShopLentor) that render their own product template and skip the standard WooCommerce hooks.

Built for production

  • Conditional asset loading: CSS only loads on the withdrawal page, on single-product pages that actually show the excluded notice, and on the plugin admin screens.
  • Escaped output, sanitized input, capability checks and nonces on every admin action; honeypot anti-spam and CSRF nonces on the public form.
  • Documented filters and actions so developers and agencies can extend the plugin without forking.
  • PHP 7.4+, WordPress 6.0+, WooCommerce 7.0+ (optional).

A note on legal compliance

This plugin is a technical tool, not legal advice. It provides building blocks to help you implement the right-of-withdrawal function, but it cannot guarantee compliance on its own: that depends on your business model, your catalogue and your jurisdiction. Review the texts and the workflow with a consumer-law advisor before relying on them.

About Conformitico

Recesso 54-bis is built and maintained by Conformitico, a team of lawyers and technicians specialised in e-commerce legal compliance. Beyond this free plugin, Conformitico offers professional review of the withdrawal texts the plugin generates and drafting of your store’s Terms & Conditions. Learn more at https://www.conformitico.it/. These services are entirely optional — the plugin is and remains free and fully functional on its own.

Credits

This plugin builds on the foundations of "EU Withdrawal Compliance” by Fernando Tellado, released under the GPLv2 or later. Recesso 54-bis is an independent, restructured and Italian-specialised work, distributed under the same licence in the spirit of the GPL.

اسکرین شاٹس

بلاکس

یہ پلگ ان 1 بلاک مہیا کرتی ہے۔

  • Recesso 54-bis — Withdrawal form Displays the right-of-withdrawal form (the same output as the [r54b_form] shortcode).

انسٹالیشن

  1. Upload the plugin folder to /wp-content/plugins/, or install the ZIP from Plugins Add New Upload Plugin.
  2. Activate the plugin from the Plugins screen.
  3. The plugin creates a "Right of withdrawal” page automatically with a sample template. Review and edit it from Pages.
  4. Go to Withdrawals Settings to set the notification email address and the page that hosts the form.
  5. Add the URL of the withdrawal page to your footer or legal-links section so it is reachable from any page.

عمومی سوالات

Does the form reject requests after the 14-day deadline?

No, not by default. The 14-day period legally starts when the goods are delivered (or, for digital content, when the download begins) — a date the shop cannot detect automatically — so auto-rejecting on the order or completion date could turn away customers who are still within their legal window. Instead the plugin flags requests that look past the approximate window in the admin notification and lets you check the real delivery date and decide. You can tune the advisory calculation (order date vs. completion date, plus grace days) under Withdrawals Settings. If your start date is reliable (services, digital content, shop pickup, predictable carriers) you can switch the Deadline enforcement setting from Advisory to Strict, which hides the button and blocks new requests once the deadline plus grace days has passed. Advisory is the default and the safe choice for goods with unpredictable delivery.

How do I mark products excluded from the right of withdrawal (Article 16)?

Use the single Withdrawal status dropdown, available per category and per product:

  1. By category: edit a category under Products Categories and pick a status — for example Other Article 16 exception for perishable or custom-made goods, or Digital content (Art. 16(m)) for sealed digital content. Every product in that category and its descendants inherits it.
  2. By product: edit the product, open the General tab and pick a status. The default is Inherit from category; pick any other value (including Standard) to override for that product only.

When a request lands on an order with excluded items, the plugin flags it but never auto-rejects it, because a partial withdrawal over the non-excluded items can still be valid — the admin reviews and decides.

The excluded-product notice does not appear with my page builder. What can I do?

Page builders such as Divi, Elementor, Bricks or ShopLentor render their own single-product template and skip the standard WooCommerce hook where the notice is injected. Drop the [r54b_avviso_esclusione] shortcode into your product layout (most builders have a "Shortcode” element) and the notice will print for the current product whenever it is flagged as excluded. With no attributes it resolves the product being viewed; pass id="123" to target a specific product.

How do the checkout consent checkboxes work (Art. 16(m) and Art. 14(4)(a))?

When the cart contains flagged products, the plugin can inject two consent checkboxes at checkout:

  • Mandatory (Art. 16(m)) for digital content: the customer must accept it to complete the order; without it recorded, the customer keeps the 14-day right even after accessing the content.
  • Optional (Art. 14(4)(a)) for services started within the window: if accepted, the trader may charge a pro-rated amount on an early withdrawal; without it, an early withdrawal forces a full refund.

The exact text shown, the accepted/declined state, timestamp, IP and user agent are stored on the order. Both checkboxes can be enabled or disabled and fully re-worded under Withdrawals Settings Checkout consent.

I sell to businesses (B2B). Can I exclude them?

The right of withdrawal protects consumers (natural persons acting outside their trade or profession), not business buyers, but the plugin never decides that for you. Enable Consumer self-declaration under Withdrawals Settings and the form shows a required checkbox where the buyer declares they purchased as a consumer; a business that cannot declare it self-excludes, and the declaration is stored with the request as proof. It is off by default. The r54b_show_consumer_check filter lets you decide per order (VIES validation, a customer-type field, etc.).

Does it include the Annex I.B model withdrawal form?

Yes. It is generated dynamically from your shop name, address and contact email, with an optional trader phone from settings. It appears as a collapsible block below the public form and has a printable view on the same page. Providing this model is a pre-contractual information obligation under Art. 6(1)(h) of Directive 2011/83/EU; the online function added by Directive 2023/2673 complements but does not replace it.

What is the verification code in the customer email?

It is a SHA-256 hash computed from the request data (post ID, customer name, email, order reference, scope, order date and submission timestamp). The customer keeps the email as tamper-evident proof on a durable medium. If a dispute arises later, recompute the hash from the stored fields with the r54b_compute_receipt_hash() helper and confirm the original submission was not altered.

Where are requests stored and who can manage them?

Each request is a private custom post type entry (r54b_richiesta), not publicly accessible from the frontend, managed under the top-level Withdrawals menu. Because each request holds personal data (name, email, IP), you choose under Withdrawals Settings Permissions which roles, besides the administrator, may view and manage them. The administrator always has access.

Does it support HPOS (High-Performance Order Storage)?

Yes. The plugin declares HPOS compatibility on load.

Does the plugin work without WooCommerce?

Yes. The form, shortcode, request log, email notifications, SHA-256 receipt hash, Annex I.B model and GDPR integration all run as a standalone tool under their own Withdrawals menu. When WooCommerce is active, the plugin adds order/email validation, the My Account endpoint, the email notice, private order notes and the Article 16 product/category exclusions on top.

Can I customise the emails?

Yes. Under Withdrawals Settings you can set the sender ("From name” and "From address”) and edit the body of the accepted, rejected and completed status emails; left empty, each falls back to the bundled default. All strings remain translatable through the text domain. Emails are sent in plain text.

Which hooks does the plugin expose for developers?

Filters:

  • r54b_grace_days — extra days added to the advisory deadline.
  • r54b_allowed_statuses — order statuses (without the wc- prefix) for which the button and email notice are offered.
  • r54b_email_ids — WooCommerce email IDs where the withdrawal notice is injected (return an empty array to remove it).
  • r54b_allow_unverified_order — return true to accept submissions whose order number cannot be matched to a real order.
  • r54b_pre_resolve_wc_order — short-circuit the order resolver (return a WC_Order, false, or null to fall through).
  • r54b_resolve_wc_order — late filter receiving the resolved order and the raw reference, for auditing or last-chance overrides.
  • r54b_validation_result — the order/email validation result before the request proceeds; return valid => false with an error code to reject (e.g. a captcha integration).
  • r54b_show_consumer_check — whether the "bought as a consumer” checkbox is shown, with the current field values.

Actions:

  • r54b_after_status_change — fires after a status change (individual or bulk). Arguments: request ID, new status, optional admin comment.
  • r54b_after_form — fires inside the public form wrapper, right after </form>, so modules can inject content below the form. Used internally by the Annex I.B model form.
  • r54b_form_before_submit — fires inside the form, right before the submit button, so an integrator can render a captcha/anti-spam widget or an extra field posted with the form.

Is this plugin enough to comply with EU Directive 2023/2673?

It covers the functional building blocks the directive imposes EU-wide from 19 June 2026: a discoverable digital withdrawal function, eligibility by order status with an advisory deadline flag, Article 16 exclusions with subcategory inheritance, durable-medium proof via the SHA-256 receipt hash, the Annex I.B model form and the checkout consent checkboxes for the Art. 16(m) and Art. 14(4)(a) exceptions, plus operational tooling such as the status lifecycle and native GDPR integration. Legal compliance ultimately depends on your business model, catalogue and jurisdiction; the plugin provides the technical building blocks, not legal advice — consult a consumer-law specialist for your specific case.

Can I get my withdrawal texts reviewed by a lawyer?

Yes. The plugin generates sample legal texts (the withdrawal page, Article 59 exclusion notices, checkout consents and emails) and reminds you to have them reviewed before publishing. Conformitico — the team behind this plugin, lawyers and technicians — offers professional review and tailoring of those texts, and drafts your Terms & Conditions to match. See Withdrawals Legal services in the admin. These are optional paid services; the plugin stays free and fully functional on its own.

جائزے

There are no reviews for this plugin.

شراکت دار اور ڈیویلپرز

“Conformitico – Recesso 54-bis” اوپن سورس سافٹ ویئر ہے۔ مندرجہ ذیل لوگوں نے اس پلگ ان میں حصہ لیا:

شراکت دار

چینج لاگ

1.0.0

  • Initial public release.
  • Public two-step withdrawal form (Art. 11a(3)): read-only summary and a dedicated confirmation step, honeypot anti-spam, standalone or WooCommerce-aware.
  • Durable-medium customer acknowledgement email with SHA-256 receipt hash and an optional PDF receipt attachment.
  • Public, login-less verifiable-receipt link (HMAC-signed) with a self-contained verification page.
  • Annex I.B model withdrawal form rendered below the public form, with a printable view.
  • Checkout consents captured on both the classic checkout and the WooCommerce Checkout block (Store API), including the mandatory digital-content consent (Art. 16(m)).
  • Article 16 exclusions: per-product and per-category "Withdrawal status” with category inheritance and a product-page exclusion notice.
  • WooCommerce order-detail withdrawal button, status notice and an informational "days left” countdown; My Account withdrawal endpoint; withdrawal block in order emails.
  • Automatic refund recording from WooCommerce (Art. 56 reminder), surfaced on the request screen.
  • Immutable, append-only audit log with a SHA-256 hash chain and an admin integrity check.
  • Admin toolkit: requests log with status management, filters, bulk actions, overview KPIs, setup wizard, dashboard widget and CSV export (protected against formula injection).
  • Native GDPR integration (personal-data export/erase) and full translation readiness (bundled Italian translation).
  • HPOS compatible; standalone with optional WooCommerce integration.