01 / PURPOSE
Connect storefront context to the verified workspace
The planned connector can establish tenant and store binding, improve authorized inventory coverage, request scans, and show current status without promising legal compliance.
02 / DATA SHEET
Publish exactly what leaves WordPress
The install experience must identify endpoints, purposes, authentication, data fields, frequency, retention, subprocessors, and disconnect/deletion behavior before consent.
- Store and site identifiers
- Approved catalog, page, policy, and configuration evidence
- Connector health and version diagnostics with redaction
- No customer card, health, or unnecessary order data
03 / INSTALL
Bind the right site to the right tenant
Installation requires an authenticated RUO Clear administrator, a short-lived signed handshake, explicit store selection, scope review, and a verifiable connection state.
04 / LIFECYCLE
Disconnect, uninstall, export, and deletion are distinct
Each action must explain what access stops, which authorized evidence remains, how retention works, and which action is reversible.
05 / SECURITY
Signed requests, rotation, and support-safe diagnostics
Use scoped credentials, request signatures, replay protection, rotation, tenant binding, rate limits, safe logging, version support, and compatibility testing.