WooCommerce accounts and privacy settings affect two connected parts of an online store: how customers place orders and how the store manages personal data afterward. The main configuration area is WooCommerce > Settings > Accounts & Privacy, where store owners can review guest checkout, login, account creation, privacy notices and retention options.
These settings should not be treated as a universal legal-compliance solution. They are operational controls that need to match the store’s customer journey, products, extensions and documented privacy process. Before changing them, review applicable legal, accounting, tax, payment-provider, fraud-prevention and contractual obligations, as well as data held outside WordPress.
What WooCommerce Accounts & Privacy Settings Control
The configuration areas to review
The Accounts & Privacy area brings several decisions together. Store owners can decide whether customers may order as guests, log in during checkout, create an account during checkout, create one after checkout or register from the My Account page. The same area also supports privacy-related notices and retention controls for accounts and orders.
A useful first step is to separate customer-journey settings from data-lifecycle settings. Guest checkout and account creation determine how an order begins. Retention periods determine what happens later to inactive accounts and orders in particular statuses.
- Checkout controls: guest orders, login during checkout and account creation.
- Account controls: registration during checkout, after checkout and from My Account.
- Retention controls: inactive accounts and pending, failed, canceled and completed orders.
Why store context matters
The same configuration will not suit every store. A business focused on one-time purchases may prefer a low-friction checkout, while a store built around repeat purchases or customer self-service may place more value on accounts. Products, subscriptions and downloadable products can also affect the customer journey.
Extensions may change the practical effect of these settings. In particular, stores using WooCommerce Subscriptions should review subscription-specific behavior before applying general account-retention rules. Privacy-related plugins and other extensions may also have their own export, eraser or retention handling.
WooCommerce Guest Checkout vs Customer Accounts
Guest checkout and login
Guest checkout allows a customer to place an order without creating or using a WordPress user account. A guest order is not tied to a WordPress user account. This can reduce the account-creation step for customers who do not need an ongoing relationship with the store.
Login during checkout is a separate choice. A store can allow existing customers to sign in while still making a different decision about whether new customers may check out as guests. Review these controls separately rather than treating guest checkout and customer login as opposite versions of one setting.
To configure the experience, open WooCommerce > Settings > Accounts & Privacy and decide whether guest orders are permitted. Then review the option for login during checkout. The appropriate choice depends on the store’s products, customer journey and extension requirements; neither guest checkout nor mandatory accounts is universally preferable.
When to offer account creation
WooCommerce provides several account-creation points. Customers may be allowed to create an account during checkout, after checkout or from the My Account page. These choices can be combined with guest checkout, allowing a customer to complete an order without an account and create one later.
Account creation can be useful when customers are expected to return, review their orders or use customer self-service. It may also be relevant to subscriptions or downloadable products. However, disabling guest checkout before checking the requirements of connected extensions can create an unsuitable customer journey. Configure each option according to the store’s actual workflow, not according to an assumed best practice.
- Review whether first-time customers need to purchase without an account.
- Decide whether account creation should be offered during checkout or after the order.
- Check whether registration from My Account supports the intended self-service process.
- Verify extension-specific requirements before restricting guest orders.
How to Configure WooCommerce Personal-Data Retention
Retention categories and time units
WooCommerce allows store owners to configure retention for inactive accounts and several order statuses: pending, failed, canceled and completed. Each period can be expressed in days, weeks, months or years. A blank retention field means that the relevant data is retained indefinitely.
Retention values should therefore be reviewed deliberately. Do not leave a field blank merely because no decision has been made, and do not enter a duration because it appears to be a general WooCommerce default. The available control is technical; the suitable period depends on the store’s circumstances.
- Inactive accounts: define how long inactive user accounts are retained.
- Pending, failed and canceled orders: review their separate retention periods.
- Completed orders: define when the configured cleanup should anonymize them.
- Blank fields: retain the relevant data indefinitely.
Choosing values without inventing a universal rule
WooCommerce documentation does not prescribe one retention period for every store. A practical process is to document the reason for each category, compare the planned periods with applicable legal, accounting, tax, invoicing, payment-provider, fraud-prevention and contractual obligations, and then enter matching values.
Before enabling automatic cleanup, confirm that removing or anonymizing records will not conflict with obligations to retain particular information. The relevant requirements may depend on jurisdiction, business model and sector. Appropriate legal or accounting advice may be needed for the store’s context.
The privacy policy should describe the resulting retention logic. It should distinguish inactive accounts from order categories and explain that completed orders may be anonymized rather than simply deleted. The policy should not imply that WooCommerce settings alone determine the store’s legal obligations.
What WooCommerce Cleanup Does to Orders
Scheduled retention cleanup
When retention settings are configured, WooCommerce runs retention cleanup daily. The outcome depends on the order status. Failed, pending and canceled orders are moved to the trash. Completed orders are anonymized so sales statistics remain accurate.
Trash handling and anonymization are not identical. Moving an order to the trash is different from anonymizing a completed order, and neither description should be replaced with a general promise of complete deletion. Store owners should understand these outcomes before setting automatic periods.
- Failed orders: moved to the trash after the configured period.
- Pending orders: moved to the trash after the configured period.
- Canceled orders: moved to the trash after the configured period.
- Completed orders: anonymized after the configured period so sales statistics remain accurate.
Manual and bulk personal-data removal
WooCommerce includes options to remove personal data from orders when processing an account-erasure request and to allow bulk removal of personal data from orders. This is separate from understanding the scheduled treatment of different order statuses.
Personal-data removal cannot be undone. Treat bulk removal as an irreversible operation: test the workflow on a staging site or use documented backups before applying it to production data. Also remember that removing data from WooCommerce orders does not automatically remove information stored by external services, non-participating extensions or other data systems.
Personal-Data Export and Erasure Requests
How the WordPress request workflow operates
WordPress privacy tools use verified email requests for exporting and erasing personal data. An administrator must process the confirmed request. WooCommerce data can be included through the WordPress privacy workflow and participating plugins, but coverage depends on how those plugins support the relevant privacy tools.
This means that a confirmed request should be reviewed rather than assumed to be complete automatically. Store owners should check which connected extensions provide privacy-exporter and eraser support, particularly when customer or order information is handled beyond standard WooCommerce data.
Limits beyond the WordPress database
WordPress states that confirmed erasure permanently removes data from the database, but it does not automatically remove data from backups or archive files. External services and other data stores may also require separate handling.
Include the broader data flow in the store’s privacy process. Review backups, staging copies, exports, email platforms, analytics systems, CRMs and payment-provider records separately. Do not imply that an erasure request in WordPress reaches every connected system or guarantees removal from all copies.
Align WooCommerce Retention Settings With the Privacy Policy
Create a settings-to-policy checklist
Start by listing the data categories controlled in WooCommerce: inactive accounts, pending orders, failed orders, canceled orders and completed orders. Record the period configured for each category, including the selected unit. If a field is blank, document that the relevant data is retained indefinitely rather than leaving the policy unclear.
Next, describe the processing outcome accurately. Explain that failed, pending and canceled orders are moved to the trash during configured cleanup, while completed orders are anonymized so sales statistics remain accurate. Document how verified export and erasure requests are handled and state that some data locations require separate review.
If WooCommerce Subscriptions is active, include its specific retention considerations. WooCommerce Subscriptions adds a setting for ended subscriptions, and customers with at least one subscription are exempt from inactive-user cleanup according to its documentation. Do not apply ordinary inactive-account logic without checking this behavior.
Audit extensions and connected systems
Compare the published privacy policy with the actual WooCommerce values after every significant configuration change. Then review the systems that WooCommerce settings do not control directly. This includes third-party extensions, payment providers, analytics, CRMs, email systems, backups, exports and staging copies.
- Check whether each relevant extension supports privacy export and erasure.
- Review whether external services retain customer or order information separately.
- Confirm how backups and archive files are covered by the broader process.
- Recheck subscription-specific retention when WooCommerce Subscriptions is active.
- Update the policy and configuration when products, integrations or obligations change.
Use cautious wording in the policy and internal documentation. The configuration can help support privacy processes, but it does not by itself establish GDPR compliance or compliance with any other law. Retention periods should be checked against the store’s jurisdiction and business context, with appropriate legal or accounting advice where needed.
Configuring WooCommerce accounts and privacy settings is a process of matching customer access, order handling and documented retention logic. Choose guest checkout and account-creation options based on the real customer journey. Set separate periods for inactive accounts and order statuses without assuming a universal duration. Understand the difference between trash handling, completed-order anonymization and irreversible personal-data removal. Finally, review WordPress privacy requests, extensions, external services and backups as separate parts of the data flow. Keep the privacy policy synchronized with the settings and revisit it when the store changes. Explore our WordPress plugins, WooCommerce extensions, themes and membership plans to find the right tools for your website.