[WordPress] 外掛分享: UltimaTour Operator

首頁外掛目錄 › UltimaTour Operator
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 6.7+ PHP 8.2+ v1.1.4 上架:2026-08-01

內容簡介

UltimaTour Operator 是一款專為旅遊業者設計的外掛,讓使用者能夠直接在 WordPress 中管理可預訂的行程。此外掛提供了必要的工作流程,無需額外的預訂平台,提升了操作效率。

【主要功能】
• 管理旅遊行程及公開資訊
• 提供公共預訂日曆與表單
• 支援手動及線上支付(Stripe、PayPal)
• 參與者票券及 QR 碼存取
• 客戶體驗時間線與自動升級
• 事件報告及操作備註

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「UltimaTour Operator」→ 直接安裝(推薦)

原文外掛簡介

UltimaTour Operator is an operations plugin for tour operators who want to manage bookable departures directly inside WordPress.
Base includes the practical workflows needed to operate without a separate booking platform:

Tours and public tour information.
Departures and sessions.
Public booking calendar and booking form.
Booking pipeline and customer records.
Manual/offline payments, Stripe Checkout, and PayPal Checkout.
Participant tickets, QR access, and pre-check-in.
Customer Experience Timeline with automatic upgrade backfill from provable Operator history.
Availability requests and temporary holds.
Coupons, reviews, and review request workflows.
Incident reporting and operational notes.
Printable day sheets and departure sheets.
Optional one-way Google Calendar export.

Base also includes the reusable OTA Connector Framework for future separately approved adapters. The framework provides connector registration, canonical booking intake, field provenance, immutable dual references, policy decisions, communication classification, and operational-truth boundaries. It does not include live OTA API connectivity by itself.
UltimaTour Operator stores booking and operational data in this WordPress installation. This package contains the complete Operator core and no product storefront, paid feature gate, contact-forms add-on, historical-review-recovery add-on, or planned-closures add-on. Other plugins can integrate through Operator’s documented hooks and interfaces; Operator does not acquire or install their code.
External Services
Operator displays a required-registration explanation after activation but sends no UltimaTour Ecosystem registration request until an administrator intentionally selects Create / Verify Ecosystem Records. Reviews and TrustEmporium are free but remain disabled until an administrator enables them in Integrations. Other optional services connect only after configuration or when a visitor chooses the configured payment or anti-spam flow.
UltimaTour Reviews
Purpose: Create or verify the operator’s free UltimaTour Reviews listing for public discovery and review collection.
Data sent: Operator/business profile data such as business name, site URL/domain, public website URL, public contact email/phone when configured, logo URL, location/geography fields, public description/story, public tour profile summaries, opening hours, social links, and review/discovery settings. Booking, customer, participant, payment, and operational records are not sent by this setup step.
When data is sent: During free ecosystem record creation/verification, a manual re-check, and later profile or review sync while UltimaTour Reviews remains enabled. Before each outgoing exchange, Operator verifies its signed core-integrity manifest and protected file hashes; exchange is paused if integrity is not clean. The administrator can turn Reviews off independently in Integrations.
Service URL: https://ultimatour.com/wp-json/ultimatour-review/v1/.
UltimaTour Ecosystem / Partner Registry
Purpose: Administrator-authorized, free integrity registration of this Operator installation; signed Operator-core integrity protection; connection-health monitoring; and authentication context for administrator-enabled Reviews and TrustEmporium exchanges. This is an integrity and trust-service connection, not a commercial licensing or payment service.
Data sent during initial registration or a manual registration refresh: Operator/site name, WordPress administrator email, site URL and canonical domain, Operator REST API base URL, generated installation identifier, plugin slug/type/version, WordPress version, PHP version, registry URL, registration mode, and connection-health status. The registry returns a signed registration credential. Some internal compatibility fields retain “license” names, but that credential authenticates integrity and trust-service requests only; it does not represent a purchase or commercial entitlement.
Data sent in the twice-daily integrity heartbeat: plugin slug/type/version, installation identifier, site URL and canonical domain, registry URL, report time, WordPress version, PHP version, connection health, and Operator-core integrity results. Core integrity results contain the signed-manifest payload hash and signature status, scan time, clean/tampered state, counts of official/scanned/mismatched/missing/unexpected protected files, and the relative paths of affected files. The heartbeat does not send WordPress administrator URLs, server fingerprints, file contents, booking or tour records, customer or participant data, payment data, or unrelated plugin inventory.
When data is sent: Only after an administrator selects the disclosed Create / Verify Ecosystem Records action. Registration may then be retried manually and the integrity heartbeat runs twice daily. An administrator can also select “Run Integrity Heartbeat Now” to send the same disclosed payload on demand. Operator stores the last heartbeat attempt, last successful heartbeat, result, HTTP code, error, next scheduled run, and current local integrity summary so they remain visible on the Ecosystem Participation screen. Operator also performs the same local core-integrity scan before outgoing UltimaTour Reviews or TrustEmporium exchange, but those exchanges remain off unless an administrator enables them in Integrations. A failed scan pauses only those optional trust-service exchanges and reports the failure on the next heartbeat; it does not disable local Operator pages, administration, bookings, tours, customers, calendars, check-in, closures, or stored records. A registry outage likewise never blocks local functionality. Registration and heartbeat never check payment, a subscription, a purchase, or a commercial entitlement and never unlock a paid Operator-core feature.
Service URL: https://partner.ultimatour.com/.
Privacy policy and terms: https://trustemporium.com/privacy-terms/
Google Calendar API
Purpose: Optional one-way export of future departures to an administrator-selected Google Calendar.
Data sent: OAuth client credentials supplied by the administrator, OAuth authorization data, departure title, date/time, capacity, booked count, status, location, public booking link when configured, and Operator admin deep links.
When data is sent: During OAuth authorization, when the administrator lists calendars, when the administrator manually syncs future departures, and when enabled departure changes are mirrored.
Service URLs: https://accounts.google.com/, https://oauth2.googleapis.com/, and https://www.googleapis.com/calendar/v3/.
Privacy policy: https://policies.google.com/privacy
Terms: https://policies.google.com/terms
Stripe
Purpose: Optional Stripe Checkout payment processing.
Data sent: Booking reference, amount, currency, selected tour/departure description, customer contact details needed for checkout, and booking metadata.
When data is sent: Only when Stripe is enabled and a guest selects Stripe Checkout, or when Stripe webhooks notify this site about payment status changes.
Service URLs: https://api.stripe.com/ and https://checkout.stripe.com/.
Privacy policy: https://stripe.com/privacy
Terms: https://stripe.com/legal
PayPal
Purpose: Optional PayPal Checkout payment processing.
Data sent: Booking reference, amount, currency, selected tour/departure description, customer contact details needed for checkout, and booking metadata.
When data is sent: Only when PayPal is enabled and a guest selects PayPal Checkout, or when PayPal return/webhook flows notify this site about payment status changes.
Service URLs: https://api-m.paypal.com/, https://api-m.sandbox.paypal.com/, and https://www.paypal.com/.
Privacy policy: https://www.paypal.com/privacy
Terms: https://www.paypal.com/legalhub/useragreement-full
OpenStreetMap Nominatim
Purpose: Optional reverse geocoding for derived geography from operator coordinates.
Data sent: Coordinates entered or saved by the administrator.
When data is sent: Only when the administrator uses geography derivation features.
Service URL: https://nominatim.openstreetmap.org/.
Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy
Usage policy: https://operations.osmfoundation.org/policies/nominatim/
OpenStreetMap Map Tiles
Purpose: Optional administrator-facing location picker map display for Operator Profile coordinates.
Data sent: Browser requests for map tiles around the viewed coordinates or map viewport, plus ordinary request metadata handled by the tile provider such as IP address and browser headers.
When data is sent: Only when an administrator opens the location picker map in Operator Profile/settings and the browser loads the map tiles.
Service URL: https://tile.openstreetmap.org/.
Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy
Tile usage policy: https://operations.osmfoundation.org/policies/tiles/
Cloudflare Turnstile
Purpose: Optional anti-spam protection for public booking, availability request, notify-me, request-departure, and local customer submission forms.
Data sent: Visitor browser verification data handled by Cloudflare and the site key configured by the administrator.
When data is sent: Only when Turnstile is enabled, configured, and displayed on a protected public form before that form is submitted.
Service URL: https://challenges.cloudflare.com/.
Privacy policy: https://www.cloudflare.com/privacypolicy/
Terms: https://www.cloudflare.com/website-terms/
Google reCAPTCHA
Purpose: Optional anti-spam protection for public booking, availability request, notify-me, request-departure, and local customer submission forms. Operator supports Google reCAPTCHA v3 score checks and Google reCAPTCHA v2 checkbox challenges.
Data sent: Visitor browser verification data handled by Google and the site key configured by the administrator.
When data is sent: Only when reCAPTCHA is enabled and configured for a protected public form. reCAPTCHA v3 executes before submission to obtain a verification score; reCAPTCHA v2 sends data when the visitor completes the checkbox challenge.
Service URL: https://www.google.com/recaptcha/.
Privacy policy: https://policies.google.com/privacy
Terms: https://policies.google.com/terms
UltimaTour Partner Information
Purpose: Provide the mandatory free UltimaTour Ecosystem registration, installation-integrity, and ecosystem connection services described above.
Data sent: The site, installation, version, connection-health, and Operator-core integrity information listed in the UltimaTour Ecosystem disclosure above. Operator does not inventory, authorize, download, install, update, repair, or activate add-on plugins.
When data is sent: After the administrator authorizes the required free registration, during manual registration retries, and during the twice-daily operational heartbeat. Reviews and TrustEmporium exchanges require their own administrator-enabled settings.
Service URL: https://partner.ultimatour.com/.
Privacy policy and terms: https://trustemporium.com/privacy-terms/
TrustEmporium
Purpose: Create or verify the operator’s free TrustEmporium business record for verified business, incident, and post-tour event infrastructure. Background customer lookups, operational TrustEmporium lookups, and intentional post-tour customer record submissions remain controlled by their own settings or administrator actions.
Data sent: Operator/business identity such as business name, site URL/domain, public contact email/phone where available, and registration identifiers needed to match, link, or create the business record. When TrustEmporium is configured, customer submissions such as bookings, availability requests, notify-me requests, and request-departure requests may queue a background lookup using the customer name, email, phone, request context, booking reference, tour/departure, date/time, and guest count where available. Intentional post-tour customer record submissions may send customer name, email, phone, tour name, departure date/time, booking reference, record type, and the operator-entered note. Payment card or funding-source data is never sent.
When data is sent: TrustEmporium remains disabled until an administrator enables it in Integrations. Data is then sent during free ecosystem record creation/verification, a manual re-check, configured background enrichment after a customer submission, an operator-requested lookup retry, or an intentional post-tour customer-record submission. Before each exchange, Operator verifies its signed core-integrity manifest and protected file hashes; exchange is paused if integrity is not clean. Background results are operator-only and never block booking, payment, availability-request, or notify-me submission.
Service URL: https://trustemporium.com/.
Data and responsibility: https://trustemporium.com/data-responsibility/
Privacy policy and terms: https://trustemporium.com/privacy-terms/

延伸相關外掛

文章
Filter
Apply Filters
Mastodon