EU Withdrawal and Legal Guarantee Compliance
EU Withdrawal and Legal Guarantee Compliance

EU Withdrawal and Legal Guarantee Compliance

5/5 (17 ratings) 1K+ active installs Updated Sep 22, 2026
Public withdrawal form with all required fields.

Public withdrawal form with all required fields.

Two EU deadlines, one plugin. From 19 June 2026, Directive 2023/2673 obliges every online retailer in the EU to offer a digital withdrawal function at least as easy to use as the purchase flow. From 27 September 2026, Directive (EU) 2024/825 and Implementing Regulation (EU) 2025/1960 oblige every shop selling goods to display the harmonised notice on the legal guarantee of conformity. Most plugins in the directory stop at “a withdrawal button”. This one covers both, free and complete.

The legal guarantee notice

The official notice ships bundled in the 24 EU languages and is shown unedited, as the regulation requires: above the place-order button of both the classic and the block checkout, and in your order emails with the official PDF attached, so it survives the mail clients that block remote images. Three display modes (the whole notice, a disclosure, or a native popover for narrow columns), the Spanish three-year note where it applies, a shortcode for your own guarantee page, a footer link, and a private order note recording which notice each buyer saw. Only shown when the cart holds goods: the notice does not cover services or digital content.

The withdrawal function

  • Two-step confirmation (Art. 11a(3)): the form leads to a review screen with a read-only summary and a “Confirm withdrawal” button, and the request is registered only when that button is pressed. Held server-side in a single-use token, so it works without JavaScript.
  • Durable-medium acknowledgement (Art. 11a(4)): the confirmation email reproduces the full declaration and the exact date and time of submission, with a verifiable SHA-256 receipt hash recomputable from the stored fields if a dispute arises.
  • Annex I.B model withdrawal form generated from your shop data, collapsible below the public form and printable from the same URL. Meets the information obligation of Art. 6(1)(h), which the new directive does not replace.
  • Two consent checkboxes at the WooCommerce checkout: the mandatory one for digital content (Art. 16(m)), which blocks the order until accepted, and the optional one for services started inside the 14-day window (Art. 14(4)(a)), which enables pro-rated billing. Both are persisted on the order with the exact text shown, accepted or declined, timestamp, IP and user agent.
  • One “Withdrawal status” dropdown per product and per category, with four options, driving the Article 16 exclusion and the matching checkout consent at once, with full subcategory inheritance. Competing plugins gate this behind a paid tier.
  • Configurable notice on excluded products, between price and add-to-cart, with its own title and body per type of exception.
  • Native GDPR integration: Privacy Policy snippet, personal-data exporter and eraser, all keyed on the customer email.
  • Standalone mode: form, shortcode, request log, emails, receipt hash, Annex I.B and GDPR all run without WooCommerce, in the same Withdrawals menu on every install.

On the front end

  • A withdrawal page created on activation, with a neutral template ready to publish and the reminder to review it with a lawyer kept in the dashboard rather than in the page.
  • [ayudawp_withdrawal_form] for the form, [ayudawp_withdrawal_link] for a permanent link to it from any footer or widget area, [ayudawp_guarantee_notice] for the guarantee notice, [ayudawp_guarantee_link] for its page, and [ayudawp_withdrawal_excluded_notice] for page builders that skip the standard WooCommerce hooks.
  • Semantic form with HTML5 validation, honeypot, escaped output, sanitized input and CSRF nonces, plus a privacy-policy checkbox linked to your configured page.

With WooCommerce

  • My Account Right of withdrawal, with a per-order “Withdraw” button while the order is in an eligible status, deep-linked to the form with the order pre-filled.
  • Request tracking for the customer: the same screen lists their requests with date, order, scope, status, your resolution note and the receipt code, and the order row shows an open request instead of an empty slot.
  • Withdrawal notice in the transactional emails, with a direct link to the form. Eligible statuses configurable; admin emails never receive it.
  • Automatic verification of the order and email pair, gated by the configured statuses. The 14-day deadline is an advisory flag for you, not an automatic rejection, because the period runs from delivery. Basis and grace days configurable, with an optional strict mode.
  • Optional “Accept unmatched requests” mode: register what does not match an order as Unverified for manual review instead of rejecting it. Off by default.
  • Order-number compatibility with Sequential Order Numbers and Custom Order Numbers (Tyche and WPFactory), plus a filter for any other scheme.
  • “Withdrawal” column on the orders screen, private order notes at every step, and HPOS compatibility declared.

In the admin

  • Full request log as a private post type with its status lifecycle, customer details, scope, IP, user agent and UTC timestamp.
  • CSV export for accounting and consumer-protection audits, by bulk action or filtered by status and date range, with cells escaped against formula injection.
  • Audit trail per request: resolution timestamp on every status change and whether the acknowledgement was accepted for delivery, in the detail screen and in the CSV.
  • Bulk actions, a status metabox with a required comment when rejecting, and the captured checkout consents on file.
  • Emails: acknowledgement to the customer, notification to the shop with reply-to set to the customer, and a follow-up on every status change.
  • Legal disclaimer in the settings page, and a Mandatory / Recommended / Optional tag on every setting.

Multilingual stores: WPML and Polylang

Compliance cannot depend on the language the customer was browsing in, so both are supported with nothing to configure. Set the withdrawal status once, on the product or category in your original language, and it holds across every translation, with an explicit status on a translation still winning. Every link follows the visitor’s language, and so does the guarantee notice. The bundled wpml-config.xml exposes your own editable texts to String Translation and marks the request log as non-translatable. See the FAQ for the current limitation on the plugin’s own emails.

Built for production

  • CSS only loads where it is needed: the withdrawal page, the checkout, product pages that actually show a notice, and the plugin’s own admin screens.
  • Delivered as language packs from translate.wordpress.org. Follows the WordPress Coding Standards, with escaped output, sanitized input, capability checks and nonces.
  • 19 documented filters and 4 actions, so agencies can extend it without forking.
  • PHP 7.4+, WordPress 6.0+, WooCommerce 7.0+ (optional).

Why this plugin?

  • Fully free, no paid tier. No premium add-on, no feature behind an upsell, no “Pro” version on the horizon.
  • The only plugin in the directory that issues a SHA-256 receipt hash as durable proof of each request, that ships the Annex I.B model form, that injects the two checkout consents with proof on the order, and that gives you Article 16 exclusions with subcategory inheritance without a paid tier.
  • The harmonised guarantee notice included, in the 24 languages, at the checkout and in the emails, which is the second obligation landing in 2026 and the one most plugins still ignore.
  • Real multilingual support with WPML and Polylang, and everything configurable from the settings screen without writing a line of code.
  • Maintained by a Spanish WordPress trainer with 20+ years on the platform, with the es_ES translation kept up to date by the author, replies on the support forum and an active roadmap of free improvements.

Roadmap

Planned for upcoming free versions: the GARAN durability label per product; the checkout consents inside the Checkout block; HTML emails inheriting the WooCommerce theme, and plugin emails in the customer’s language; a Gutenberg block and a widget for the withdrawal link; a custom “Withdrawal requested” order status; a PDF of the request with its receipt hash; and a dashboard widget.

Privacy

For each request the plugin stores the customer name and email, the order reference and date, the IP address and User-Agent, the UTC submission timestamp and the SHA-256 receipt hash. All of it serves the legal traceability the directive asks for and lets the shop handle the request.

Data lives in a private custom post type (ayudawp_withdrawal) reachable only by the roles you authorise. Nothing is sent to third-party services: everything happens between your shop and your customer through standard WordPress emails.

Add a section to your privacy policy describing this storage. The plugin contributes a suggested snippet you can paste from Settings Privacy Policy Guide, and withdrawal data is exposed to Tools Export Personal Data and Tools Erase Personal Data, filtered by customer email.

Support

Need private support or custom development?

Do you need one-on-one help, priority troubleshooting, or a custom feature, integration, or tweak built specifically for your site? I offer private support and custom development. Just contact me and tell me what you need.

Need help or have suggestions?

Love the plugin? Please leave us a 5-star review and help spread the word!

About AyudaWP.com

We are specialists in WordPress security, SEO, AI and performance optimization plugins. We create tools that solve real problems for WordPress site owners while maintaining the highest coding standards and accessibility requirements.