=== WhitPay ===
Contributors: whitcombpayments
Tags: woocommerce, payments, checkout, reporting, merchant services
Requires at least: 5.6
Tested up to: 6.6
Requires PHP: 7.4
Stable tag: 2.5.5
License: GPLv2 or later

One plugin for your Whitcomb account: your checkout and your sales reporting, switched on to match
what Whitcomb placed you on.

== Description ==

This is the only Whitcomb plugin you need. It replaces the four we used to publish — a reporting
plugin and one per payment program — because a merchant should not have to work out which of them
is theirs, and a merchant on two programs should not install two.

**What it does for every account**

Reports each WooCommerce order to your Whitcomb portal as a short summary, whatever gateway took
the payment. Your sales, refunds and account health show up on the Transactions tab of
whitcombpayments.com/portal without you doing anything.

**What it adds only if your account has it**

* **Whitcomb Payments checkout** — a hosted, fully branded checkout. Your customers see Whitcomb
  Payments and nothing else; the money settles into your own account.
* **Stripe** — a card checkout on your own Stripe account, if Whitcomb placed you there.
* **Whitcomb Pay** — the same, on your own account, if Whitcomb placed you there instead.

You do not choose this and there is no module to buy. The plugin asks Whitcomb what your account is,
using your brand code, and switches on what belongs to you. If your desk later adds you to another
program, the matching checkout appears on its own within a day.

**What is sent, per order:** order id and number, status, currency, total, tax, shipping, refunded
amount, the gateway WooCommerce recorded and its transaction reference, item count and lines, and
the dates. Customer email, name, phone and billing address only if you switch that on.

**What is never sent:** card details (WooCommerce never holds them), and payment keys of any kind.
Every credential you enter — your checkout API key, your Stripe or Whitcomb Pay keys — stays on your own
server and is never transmitted to Whitcomb.

**How reporting is authenticated:** every report is signed with an HMAC-SHA256 keyed on the store
secret Whitcomb issued you, so nobody else can post sales into your books. Payment results coming
back into your store are signed too, so nothing can mark an order paid that did not actually pay.

== Installation ==

1. WordPress Admin → Plugins → Add New → Upload Plugin → choose `whitpay.zip`.
2. Activate, then open **Whitcomb** in the left-hand admin menu.
3. Press **Connect this store to Whitcomb**. You are taken to your own Whitcomb portal, you sign in
   as yourself and approve this shop, and you are brought straight back — connected. There is no
   code to copy and nothing to type, and your past orders start coming over on their own.
4. That is the whole setup. The panel then shows which parts are switched on for your account.
   (Prefer to do it by hand? The **Brand code** and **Store secret** fields are still there, on the
   Integrations tab of your portal.)
5. If a checkout is part of your account, finish it under WooCommerce → Settings → Payments: enable
   it and paste the credentials shown on that screen. For Whitcomb Pay, that is your **Application ID**
   and **Access Token** from developer.squareup.com — both are required, no webhook step needed.
   Other checkouts may ask for additional keys shown on their own settings screen.
6. Optional: **Save & send past orders** backfills your existing orders in the background.

== Upgrade Notice ==

= 2.5.0 =
There is nothing to copy any more. Open **Whitcomb** in your WordPress menu and press **Connect
this store to Whitcomb** — you sign in to your own portal, approve this shop, and the connection
completes itself. Your past orders are sent automatically once it connects. Already set up by
hand? Nothing changes; you do not need to reconnect.

= 2.4.0 =
No change for almost every account. Where Whitcomb has already provisioned the checkout for you,
the Whitcomb Pay settings screen no longer asks for an Application ID or Access Token — there is
nothing left for you to enter.

= 2.3.0 =
The Square-based checkout is now called Whitcomb Pay throughout — your own WooCommerce settings
screen, order notes and error messages no longer say "Square," though your credentials still come
from developer.squareup.com as before. Nothing about setup or how charges work changed, only names
and labels did. If you're already on 2.2.0 there is nothing new to configure.

= 2.2.0 =
Square checkout now happens right on your own checkout page instead of redirecting to Square — and
it now requires your Square **Application ID** in addition to the Access Token you already had
saved. If you use Square, add it under WooCommerce → Settings → Payments → Whitcomb Payments —
Square right after upgrading, or that payment method will stop appearing at checkout until you do.
A saved webhook signature key is no longer used and can be ignored.

= 2.1.0 =
Adds the Whitcomb Payments hosted checkout for accounts placed on it, replacing the separate
multi-store gateway plugin. If you have that plugin installed, deactivate and delete it first — its
settings do not carry over, so have your API key and webhook secret to hand.

= 2.0.0 =
Replaces "Whitcomb Payments — Reporting", "— Stripe" and "— Square". Deactivate and delete any of
those before activating this one.

== Frequently Asked Questions ==

= Will this change my checkout? =
Only if Whitcomb placed you on a checkout program, and only once you enable that payment method and
enter your keys. Reporting on its own never touches checkout.

= Whose name do my customers see? =
Yours, and Whitcomb Payments. The hosted checkout is branded Whitcomb Payments throughout — no
third-party processor name appears at any point.

= Does it slow down checkout? =
No. Order reports are sent without waiting for a reply.

= What if the same order is reported twice? =
Whitcomb matches on your store's order id, so a repeat is an update to the same row, never a
duplicate sale. Payment results are de-duplicated too, and a paid order is never walked back by a
late message arriving out of order.

= Can I stop it? =
Untick "Report sales to Whitcomb" to stop reporting including the daily health check, or deactivate
the plugin.

== Changelog ==

= 2.5.4 =
* Orders are reported as Whitcomb's only when a Whitcomb gateway took them, so another processor's sales are never counted as Whitcomb's.

= 2.5.3 =
* Your store tells your Whitcomb portal which time zone it runs on, so an order shows the same date and time in your portal that you see here in WooCommerce.

= 2.5.2 =
* Housekeeping: the plugin's internal comments are tidied. No change in what the plugin does.

= 2.5.1 =
* Updates arrive inside WordPress — the Plugins screen offers each new version.
* Customer phone and billing address are reported with the order when customer details are switched on.
* The plugin now reports its real version to your portal.

= 2.5.0 =
* One-click store connect. The merchant presses one button, approves the shop as themselves in
  their Whitcomb portal, and the brand code and store secret are delivered to their own server —
  never shown, never emailed, never typed. The exchange is PKCE-protected: the verifier stays on
  the merchant's server, so a code lifted from browser history or a proxy log cannot be redeemed.
* Connecting now sends the first heartbeat and starts the order backfill on its own, so the desk
  sees the store and its history immediately instead of waiting for someone to press a second
  button.
* The brand code / store secret fields remain for anyone who prefers to enter them by hand.

= 2.4.0 =
* Whitcomb Pay can now be provisioned entirely from Whitcomb's side for accounts set up that way.
  Where it applies, the Application ID / Access Token / Location ID / test-mode settings are
  hidden — there is nothing to enter — and the charge is authorized over the same signed channel
  this plugin already reports sales on, never with a token stored on this server.

= 2.3.0 =
* The Square-based checkout is now presented as Whitcomb Pay everywhere a merchant sees it — the
  gateway name, settings screen, order notes and error messages. Where you get your credentials
  (developer.squareup.com) and how charges work are unchanged.

= 2.2.0 =
* Square: card is entered and tokenized right on your own checkout page with Square's Web Payments
  SDK — no more redirect to a Square-hosted page. The charge happens in the same request that places
  the order, so there is no window where a buyer has paid but the order hasn't caught up yet.
* Square: added required Application ID settings (Production and Sandbox).
* Square: removed the now-unnecessary hosted-checkout return and webhook handlers — the synchronous
  charge response is the confirmation, so there is nothing left for either to do.
* Square: the reference sent with each charge is trimmed to the plain order number, nothing else.

= 2.1.0 =
* Whitcomb Payments hosted checkout, white-labelled end to end, for accounts placed on it. Signed
  webhooks confirm payment; a paid order cannot be downgraded by a later message.
* Collapsed from the 20-slot multi-store gateway to the single account a merchant actually has:
  credentials sit on the payment method's own settings screen alongside Stripe and Square.

= 2.0.0 =
* One plugin per account. Reporting for everyone; each checkout loads only for the accounts
  Whitcomb placed on it, decided by the account rather than by which file you downloaded.
* Brand code, store secret, reporting settings, the daily health check and the connection test are
  shared by every part of the plugin instead of being repeated per gateway.
* New panel on the Whitcomb admin page showing exactly what is switched on for this account.

= 1.0.0 =
* The separate plugins this replaces.
