sandywp / plugins / harvv-analytics

Harvv Analytics

Zero-PII behavioral analytics pixel with WooCommerce order sync. No cookies, no device storage, built for a simple consent posture.

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v1.0.8 WP 6.0+ PHP 7.4+

your-sandbox.sandywp.com/wp-admin
no screenshot published

About this plugin

Zero PII. No cookies. No device storage.

Harvv Analytics ships a lightweight (under 10 KB gzipped) behavioral tracker that captures how visitors interact with your pages — dead clicks, rage clicks, scroll depth, hover intent, JavaScript errors, engagement time — and syncs WooCommerce orders to your Harvv dashboard. It never reads cookies, never transmits names, emails, phone numbers, or addresses, and never stores personal data in your WordPress database.

The plugin is designed to avoid the things consent rules attach to: it sets no cookies, stores nothing on the visitor’s device, and transmits no names, emails, or other personal details. Many site owners find this removes the need for an analytics consent banner, but consent law varies by country and by what else your site runs, so make your own assessment for your site. Your visitors see no pop-ups from us, and your checkout flows are not slowed.

What this plugin does

  • Enqueues a vanilla-JS tracker (no jQuery, no external scripts) on your frontend.
  • Captures behavioral signals: scroll depth, click targets, dead/rage clicks, hover intent, page errors, engagement time.
  • Syncs WooCommerce orders on woocommerce_payment_complete (never blocks checkout).
  • Passes customer identity as a non-reversible hash derived from the site’s own salts — the raw email never leaves WordPress.
  • Works with WooCommerce HPOS (Custom Order Tables) out of the box.
  • Multisite-aware: one network API key, per-subsite Site IDs, per-subsite admin overrides.

What this plugin does NOT do

  • Does not set or read cookies.
  • Does not transmit email addresses, names, phone numbers, postal addresses, or IP addresses.
  • Does not load any JavaScript from external URLs — the tracker ships bundled with the plugin.
  • Does not create custom database tables on your WordPress site.
  • Does not record session replays or keystrokes.

Why you might want this

If you run a WooCommerce store and want to see the dead clicks, rage clicks, and broken checkout paths your visitors hit — without making them click through a GDPR banner — Harvv is designed for you. The behavioral signals are sent to your Harvv dashboard where they become a prioritized list of UX fixes with plain-English explanations.

External Services

This plugin relies on the Harvv analytics service (operated by Olivas Venture Capital LLC d/b/a Harvv) to store and analyze behavioral events. Data is transmitted to the following endpoint:

  • Endpoint: https://harvv.com/v1/track (overridable via the HARVV_API_BASE constant in wp-config.php for staging or self-hosted receivers)
  • When: Events are sent continuously while a visitor is on your site (batched every 5 seconds or on tab close, via navigator.sendBeacon when available). WooCommerce order events are sent once, on woocommerce_payment_complete.
  • What is sent (behavioral events): Session ID (random, in-memory, regenerated per browser tab — never a stable cookie), visitor ID (sessionStorage-scoped, cleared when the tab closes), event type, page path (no query string with sensitive params), referrer, viewport dimensions, CSS selectors of clicked/hovered elements (tag + id + first class name only, no text content), JavaScript error messages, engagement timestamps.
  • What is sent (WooCommerce events): Order ID, order status, order total, line-item product IDs and quantities, coupon codes, payment method name, shipping method name, non-reversible customer hash (derived via wp_hash() using your WordPress salts).
  • What is NOT sent: Names, email addresses, phone numbers, postal addresses, IP addresses, raw user IDs, cookies, session replays, keystroke data, form values.
  • Registration endpoint: https://harvv.com/v1/sites/register — called once per site (or subsite on Multisite) to obtain a Site ID. Transmits only the site URL, site name, WordPress version, PHP version, and plugin version.
  • Pixel script (canonical, 1.0.3+): https://harvv.com/px/<your_site_key>/pixel.js — enqueued on the frontend via wp_enqueue_script. This is the same canonical pixel served to every Harvv-installed site regardless of install channel (WP plugin, Laravel package, direct script-tag, Shopify integration). Loaded once per page, ~15.6 KB gzipped. The pixel itself transmits only the behavioral signals described above. Sites that need an offline-capable / self-hosted pixel can override the URL via define( 'HARVV_PIXEL_URL', '...' ); in wp-config.php, or via the harvv_pixel_url filter.
  • Connect flow: https://harvv.com/connect/wordpress — opened in a new browser tab when an admin clicks “Connect to Harvv” in the plugin settings. Harvv’s hosted signup page handles authentication; it then POSTs the API key back to your site’s own REST endpoint (/wp-json/harvv/v1/connect) with a nonce you generated locally.
  • Stack-inventory endpoint: https://harvv.com/v1/inventory — called once at site registration and refreshed weekly by WP-Cron. Sends a site-context snapshot: installed plugin slugs + versions, the active theme slug + version, WordPress version, PHP version, MySQL/MariaDB version, server software string (e.g. “nginx/1.24.0”), site language code, timezone, permalink-structure boolean, WP_DEBUG boolean, memory limit, max execution time, object cache backend, WP-Cron disabled boolean, multisite blog count, total user count (number only — no usernames, no emails, no per-role breakdown), aggregate post and page counts, custom post type slugs + publish counts, and (when WooCommerce is active) WooCommerce version, store currency, base country, and product count. No visitor data, no usernames, no email addresses, no post content, no comments, no IP addresses, no PII of any kind. Powers plugin-attribution and platform-specific UX diagnosis on the Harvv dashboard. Admins can preview the exact payload at Settings → Harvv Analytics → Preview the exact diagnostic snapshot we would send. Disabled by clearing the Settings → Harvv Analytics → Preferences → Share stack info checkbox, by adding define( 'HARVV_SHARE_INVENTORY', false ); to wp-config.php, or by returning false from the harvv_share_inventory filter.
  • Harvv terms of service: https://harvv.com/terms
  • Harvv privacy policy: https://harvv.com/privacy

By activating this plugin and supplying an API key, you consent to the transmission of the data described above to Harvv. You can disconnect at any time from the plugin’s settings page; uninstalling removes all plugin options from your database.

Questions

Does this require a cookie consent banner?

The plugin is built to avoid the things consent rules attach to: it sets no cookies, stores nothing on the visitor’s device, and transmits only behavioral signals (dead clicks, scroll depth, and similar) with no names, emails, or other personal details. Many site owners run it without an analytics banner for that reason. Consent law varies by country and by what else your site runs, so make your own assessment for your site.

If your legal counsel interprets the regulations more conservatively than we do, you can still add Harvv to your privacy policy’s third-party services section. The plugin provides suggested language at Settings → Privacy → Policy Guide.

Does this plugin work without WooCommerce?

Yes. The WooCommerce integration loads conditionally — on a non-Woo WordPress site, the plugin runs as a pure behavioral pixel.

Does this plugin slow down my checkout?

No. All outbound HTTP calls use wp_remote_post() with 'blocking' => false, and the browser tracker uses navigator.sendBeacon() or fetch with keepalive: true. Nothing in the plugin waits on a response from Harvv.

Is this plugin HPOS (Custom Order Tables) compatible?

Yes. The plugin declares compatibility with custom_order_tables and uses only the WC_Order CRUD API — never direct $wpdb access against order tables.

What happens if my site loses internet connectivity?

The browser tracker queues events locally and attempts to flush on each interval; unsent events are discarded silently when the browser tab closes. WooCommerce order events are fire-and-forget — if your site cannot reach harvv.com at the moment of payment_complete, the event is lost. We do not queue order events for retry on-site because doing so would require creating a custom database table, which this plugin intentionally does not do.

As of 1.0.1 the plugin records the timestamp of the most recent successful Woo sync and surfaces it on the settings page so an admin can spot a silently broken integration before reconciling Stripe and Woo manually.

How do I uninstall?

Delete the plugin from the Plugins screen. All plugin options (harvv_api_key, harvv_site_id, and related) are removed via uninstall.php. The plugin never creates custom database tables on your site, so nothing is left behind.

I use caching plugins — does this conflict?

No. The tracker is enqueued in the footer and is cache-friendly (same output for every visitor). The Connect-flow REST endpoint is under /wp-json/harvv/v1/* and is gated by a one-shot nonce, so caching that endpoint is harmless.

Is the Site key in my page source a secret?

No — the Site key is a public, per-site identifier. Think of it like a Stripe publishable key: it ships embedded in your page source so the browser tracker can authenticate its POSTs to Harvv. It can be used only to send events for the site it was issued for; it cannot be used to read your account data or events from any other site. If you ever need to rotate it, do so from the Harvv dashboard.

sandywp / also on the shelf

Try another plugin

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.