=== Circumflex Booking Pro ===
Stable tag: 1.1.4
Requires at least: 6.8
Requires PHP: 8.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Adds controlled public availability, automatic approval per service, SMS confirmations and reminders
through Sendberry, one-way Telegram and web notifications for practitioners,
manual follow-ups after completed visits, and anonymous booking statistics to
Circumflex Booking.
Administrators can choose when SMS is sent, set a daily limit, send an agreed
test message, and see where visitors progress or stop in the booking form.

== Installation ==

1. Install and activate a compatible Circumflex Booking version.
2. Download Circumflex Booking Pro from the public product page.
3. In WordPress, choose Plugins > Add Plugin > Upload Plugin, select the ZIP,
   and activate Circumflex Booking Pro. No license key is required.
4. Open CF Booking > SMS (Pro) and enter the API key, access name, and access
   password from Sendberry.
5. Choose the approved sender, the name shown in the SMS, and the daily limit.
6. Send one agreed test message and then turn on SMS.
7. Open CF Booking > Statistics (Pro) to review and optionally enable anonymous
   booking statistics.
8. Edit a service under CF Booking > Services to turn on automatic approval for
   future bookings of that service, if wanted.
9. Open CF Booking > Follow-up (Pro) to add a review link and enable manual
   follow-ups, if wanted.
10. Open CF Booking > Telegram (Pro) to save the shared bot token. Then edit a
   practitioner, send a personal invitation, and enable either notification
   type. The practitioner only opens the link and presses Start in Telegram.
11. To use web notifications instead, open CF Booking > Web notifications (Pro)
    and activate it for the site. Then edit a practitioner, send the personal
    invitation, connect one or more devices, send a test, and enable either
    notification type. No external push-service account is required.
12. To limit genuine public availability, open CF Booking > Public availability
    (Pro), review the safeguards, choose the target and fade-out period, and
    enable it.

Saved Sendberry connection details are hidden. Customer phone numbers and
message text are not stored in the SMS status overview.

== Free early access, updates, and support ==

Version 1.1.4 is available at no cost during free early access. It requires no
account, payment, license key, activation, or external entitlement check. The
included features have no time limit. Circumflex Booking Pro is licensed under
GPL-2.0-or-later.

During free early access, download the current ZIP from the product page and
upload it again in WordPress to update an existing installation. The package
is published together with its SHA-256 checksum. Support is best-effort while
usage remains limited.

There is no fixed end date. If paid distribution is introduced later, already
installed Pro features and booking data keep working. A future subscription
may cover later Pro releases and commercial support. The planned paid launch
price remains USD 29 per year for its first 90 days and USD 49 per year
afterward; that window does not start during free early access.

== Controlled public availability ==

Controlled public availability is off by default. When enabled under CF Booking >
Public availability (Pro), it can hold some otherwise available service intervals
back from new public bookings. Every overlapping start is withheld under the
same interval rules as a real reservation. The administrator sets a target
share of possible public start times to show as unavailable near today, a
gradual fade to zero further ahead, and a minimum number of first-available
choices to keep per date.

The percentage applies to the start choices visitors actually see. Pro still
holds only complete, mutually non-overlapping treatments with their buffers,
then chooses the combination closest to the target. Equivalent results avoid
leaving an isolated public start time.

The defaults are a 60% nearby target, a 14-day fade-out, and two remaining
first-available choices. The supported ranges are 0–80%, 1–90 days, and 1–20
remaining choices respectively.

Existing bookings and genuine unavailability count first. A held time cannot
be booked through the public availability or booking API, but Pro creates no
fake booking or reservation row. The public form describes the time only as
unavailable. Administration, existing bookings, and customer change links keep
using the actual calendar. Do not describe held times as booked or use this
option to make unsupported claims about demand.

== Automatic approval ==

Automatic approval is off for every service until an administrator turns it
on in the service editor. A new public booking is confirmed immediately only
when every selected service allows automatic approval. If one selected service
still needs review, the complete booking remains pending.

The customer receives the ordinary confirmation email and, when configured,
the confirmation SMS. Email and SMS reminders continue as configured. Existing
bookings are not changed, and customer requests for a new time still require
manual review.

== Telegram notifications ==

Telegram is disabled for every practitioner until an administrator saves the
global bot token, connects that practitioner, and enables one or both
notification choices. A personal invitation can be emailed or copied and
shared. The practitioner opens it on a phone and presses Start in Telegram;
the Chat ID is connected automatically. Manual Chat ID entry remains available
under Advanced for shared groups. Pending-booking and automatic-approval
notices are independent. A later manual approval does not trigger the automatic
notice.

Messages contain only the original booking outcome, local appointment time,
internal booking number, and a link to the protected WordPress administration
page. They contain no customer, service, comment, or health details. Pro stores
only PII-free idempotency and delivery state; Chat IDs remain in a separate
practitioner-connection table and rendered messages are not stored. The
booking/event marker stays as the duplicate guard.

Telegram transport runs after the booking transaction. A missing configuration
or Telegram error never prevents the booking or existing email/SMS messages.
Easy invitations use one narrow authenticated webhook. It accepts only signed
Start invitations, which expire after 24 hours and work once in a private bot
chat. Ordinary messages are ignored; no conversations, general bot commands,
customer bot features, or automatic retry are included.

== Web notifications ==

Web notifications are off site-wide until an administrator explicitly activates
them under CF Booking > Web notifications (Pro). Only then can an administrator
change practitioner choices, send invitations, run tests, or deliver live
alerts. Turning it off stops queued and new alerts while preserving keys,
devices, invitations, and practitioner choices. Each practitioner remains off
until at least one device connects and one or both event choices are enabled.
The choices are independent and off by default. They cover only a new booking
that starts pending and a new booking that is approved automatically during its
original creation. A later manual approval does not trigger the automatic
notice.

No OneSignal, Firebase, or other push account is needed. Pro generates one
installation-wide VAPID key pair and stores its private key plus browser
subscriptions with authenticated encryption. The administrator can email or
copy/share a 24-hour one-time invitation. Android and supported computers can
activate directly. On iPhone and iPad, the page guides the practitioner through
Safari’s Share > Add to Home Screen flow. If email opens the invitation in
Brave or Chrome, one button copies the signed link for Safari. A short-lived
Secure, HttpOnly, SameSite cookie carries the valid invitation into the Home
Screen web app on current iOS versions; the one-time activation code remains a
collapsed fallback. The manifest and stable start URL contain no invitation
token. Several devices can be connected for one practitioner. Administration
shows the verified device count and provides test, add-device, cancel, and
disconnect controls.

Push payloads contain only the original booking outcome, local appointment
time, internal booking number, and a protected administration link. They
contain no customer, service, comment, or health details. Readable browser
endpoints and keys are not stored in tables; only keyed endpoint hashes and
encrypted subscription data are retained. A separate booking/event marker
prevents duplicate web notifications without interfering with Telegram.

Delivery runs after booking commit. Missing setup or push-service failure can
never block the booking or existing email, SMS, and Telegram notifications.
Expired device subscriptions are removed, while uncertain sends are not
retried automatically.

== Follow-up after visits ==

Follow-ups are disabled by default. When enabled, an administrator can open a
completed booking, review a personal thank-you, and send either email or SMS.
Nothing is sent automatically or in bulk, and only one follow-up can be
requested for each booking.

Before sending, Pro checks whether the same email address or phone number has
already received a review request. A booking manager is warned and must
explicitly confirm before sending again. A request that is still being sent
cannot be duplicated.

Email uses the site's ordinary WordPress mail setup. SMS uses the saved
Sendberry settings and counts toward the configured daily SMS limit. The
customer receives an honest-review invitation and can opt out of future review
requests. Pro stores booking and delivery pointers plus non-reversible opt-out
fingerprints, not a copy of the customer's contact details or message text.

A booking manager can also register that the customer has opted out of review
requests or is generally reserved against marketing. This is a firm block and
cannot be overridden during sending. Removing it requires confirmation that
the customer explicitly asked to receive such requests again. Reservations do
not stop confirmations, reminders, or other necessary appointment messages.

The email sender name and address can be set for follow-ups without changing
other WordPress email. An administrator can send the saved design as a clearly
marked test without creating a booking. The booking overview shows whether a
follow-up is being sent, was sent, or was not sent.

== Anonymous booking statistics ==

Collection is disabled by default. When enabled, Pro keeps one aggregate row
for each anonymous booking-form visit. It records the furthest booking step,
selected services, broad device and browser categories, whether no available
times were shown, and the category of any field that needed correction.

The statistics do not store names, email addresses, phone numbers, comments,
IP addresses, full browser details, cookies, persistent visitor identifiers,
or recordings of visitor activity. Logged-in WordPress users are excluded.
Data stays in the WordPress database and is deleted automatically after the
configured period, which defaults to 90 days. An administrator can delete all
statistics at any time.

== Changelog ==

= 1.1.4 =

* Improve plain-language guidance for controlled public availability,
  follow-ups, and related administration in English and Norwegian.
* Clarify how the target percentage counts genuine unavailability and keeps
  complete treatment intervals without creating fake bookings.

= 1.1.3 =

* Apply the configured percentage to public start choices while retaining only
  complete treatment intervals with buffers.
* Choose the closest reachable visible result and prevent long treatments from
  making a moderate target appear almost fully booked.

= 1.1.2 =

* Calculate filling from complete treatment capacity and avoid isolated public
  start times when an equivalent placement is available.

= 1.1.1 =

* Treat held starts as complete service intervals so every overlapping public
  choice is unavailable under the same rules as a real reservation.
* Choose deterministic, non-overlapping interval anchors by their actual
  effect on the target while preserving the configured public minimum.
= 1.1.0 =

* Add optional controlled online capacity with an administrator-defined nearby
  target, linear fade-out period, and minimum first-available choices per date.
* Count genuine unavailability first, select held starts deterministically, and
  enforce them during both availability reads and locked booking submission.
* Keep the feature off by default and create no fake bookings or reservation
  rows; administration and customer change flows retain the actual calendar.

= 1.0.0 =

* Initial stable release of Circumflex Booking Pro.
* Add optional automatic approval, SMS, Telegram and web notifications,
  manual follow-ups, and anonymous booking statistics.
* Publish free early access without checkout, license keys, activation, or
  external entitlement checks.

= 0.1.0-alpha.22 =

* Rename the practitioner channel to Web notifications throughout the English
  and Norwegian interfaces so it remains distinct from Telegram push alerts.
* Keep the Web Push protocol, storage, delivery behavior, and schema unchanged.

= 0.1.0-alpha.21 =

* Add an explicit site-wide browser-notification activation button, off by
  default, before practitioner controls and delivery can be enabled.
* Preserve devices, keys, invitations, and practitioner choices when browser
  notifications are turned off, while also cancelling already queued alerts.
* Simplify current iPhone activation to Safari Add to Home Screen followed by
  one activation tap, using a short-lived HttpOnly invitation handoff.
* Guide Brave and Chrome users to copy the signed invitation into Safari, and
  keep the one-time activation code as a collapsed fallback.

= 0.1.0-alpha.20 =

* Add optional standards-based browser push notifications for practitioners,
  with no external push-service account.
* Add personal one-time device invitations, Android/desktop direct activation,
  and a guided iPhone/iPad Home Screen flow with a short activation code.
* Support several encrypted devices per practitioner, verified status, safe
  test notifications, and self-service or administrator disconnect controls.
* Reuse only the PII-free original-booking event while keeping a separate
  idempotent Web Push queue so email, SMS, and Telegram remain independent.

= 0.1.0-alpha.19 =

* Show the site-wide SMS state in the practitioner editor and wherever an SMS
  action can be expected.
* Keep unavailable confirmation choices visible but disabled, with a precise
  explanation and a settings link for authorized administrators.
* Distinguish intentionally paused, missing, and broken SMS setup in booking
  confirmations and follow-up choices.

= 0.1.0-alpha.18 =

* Show Telegram and Sendberry connection status before configuration fields.
* Collapse saved credentials behind a clear change-setup action while keeping
  notification choices and other operating settings visible.
* Open the relevant setup automatically when configuration is missing, invalid,
  or needs correction, without requiring JavaScript.

= 0.1.0-alpha.17 =

* Verify the invitation endpoint with a signed Telegram-shaped request before
  activating the webhook.
* Repair the common empty-User-Agent block automatically on supported Apache
  and LiteSpeed sites with one narrow, reversible access rule.
* Add a connection check and Site Health status with understandable guidance
  when hosting or an external firewall still blocks invitations.

= 0.1.0-alpha.16 =

* Let administrators email, copy, or share a personal Telegram invitation
  instead of finding and entering a personal Chat ID manually.
* Connect the practitioner after one press on Start and refresh the
  administration status automatically.
* Protect invitations with a 24-hour signed one-time token, an authenticated
  narrow webhook, capability checks, and per-action nonces.
* Keep manual Chat ID entry under Advanced for shared Telegram groups and
  migrate existing practitioner connections without changing notification
  opt-ins.

= 0.1.0-alpha.15 =

* Add opt-in one-way Telegram notices for new pending and automatically
  approved bookings, configured separately for each practitioner.
* Encrypt the shared bot token, add a saved-Chat-ID test action, and keep
  customer and service details out of messages and local queue state.
* Send only after booking commit and keep one idempotent marker per booking
  event so repeated hooks cannot send duplicates.

= 0.1.0-alpha.14 =

* Warn when a customer has received a review request through another booking,
  and require a booking manager to confirm before sending again.
* Prevent duplicate requests while another request to the customer is still
  being sent.
* Let booking managers register review-specific or general-marketing
  reservations, which can never be overridden when sending.
* Require explicit customer-request confirmation before a reservation is
  removed, and retain who registered the change and when.
* Backfill existing follow-up history using non-reversible contact
  fingerprints without storing readable email addresses or phone numbers.
* Keep booking confirmations, changes, decisions, and reminders independent
  from review-request reservations.

= 0.1.0-alpha.13 =

* Let administrators set the sender name and email address used for follow-up
  email without changing other WordPress email.
* Add a clearly marked test email using the saved subject, message, review
  button, and sender without creating a booking.
* Show follow-up delivery status directly in the booking overview.

= 0.1.0-alpha.12 =

* Keep the follow-up confirmation page hidden from the menu while allowing
  authorized administrators to open it from a completed booking.

= 0.1.0-alpha.11 =

* Add a manual follow-up action to completed bookings.
* Let administrators review and send either email or SMS, with a configurable
  preferred channel and editable neutral message text.
* Allow only one follow-up per booking and add a customer opt-out without
  storing readable contact details in Pro tables.
* Keep SMS follow-ups within the existing Sendberry setup, Norwegian-number
  policy, single-message limit, and daily sending limit.

= 0.1.0-alpha.10 =

* Let administrators enable automatic approval separately for each service.
* Confirm a multi-service booking only when every selected service allows it.
* Keep the setting off by default and leave existing bookings and time-change
  requests unchanged.
* Send the ordinary confirmation and configured reminders after automatic
  approval, including SMS when it is enabled.

= 0.1.0-alpha.9 =

* Add optional local booking-process statistics with a clear 7-, 30-, and
  90-day overview.
* Show step-by-step progress, services, broad device and browser groups, and
  general problem categories without storing customer details.
* Keep collection disabled by default, exclude logged-in users, delete old
  data automatically, and let administrators clear all statistics.

= 0.1.0-alpha.8 =

* Keep the full mobile-number label on the contact field.
* Use the shorter Phone label in the booking review.

= 0.1.0-alpha.7 =

* Label the Pro phone field as Mobile number.
* Keep the mobile-number check before review without permanent rule text below
  the field.

= 0.1.0-alpha.6 =

* Check Norwegian mobile numbers before customers review their booking.
* Keep the same mobile-number check at submission and manual booking entry.

= 0.1.0-alpha.5 =

* Make all Pro settings, help text, notices, and Site Health messages easier to
  understand.
* Simplify the SMS status overview.
* Show only the message type, planned time, and a clear status.
* Use a clearly fictional phone number format in the test field.

= 0.1.0-alpha.4 =

* Let administrators save, replace, and remove Sendberry connection details
  from the SMS settings.
* Hide saved connection details after they have been stored.
* Continue to support Sendberry connections managed by the website operator.

= 0.1.0-alpha.3 =

* Make the Pro SMS settings reliably available in WordPress administration.

= 0.1.0-alpha.2 =

* Support Norwegian mobile numbers, including spaces and an optional +47.
* Allow only ordinary eight-digit mobile numbers beginning with 4 or 9.
* Block other numbers before an SMS can be sent.
* Add a configurable daily limit of 100 SMS by default, including tests.
* Send remaining messages from the next day when the daily limit is reached.

= 0.1.0-alpha.1 =

* Add confirmation SMS selected by default with per-approval opt-out.
* Send SMS reminders at the same times as reminder emails.
* Show whether recent SMS messages are waiting, sent, delivered, or need
  attention.
* Add test messages, SMS settings, and a Site Health result.
* Keep customer phone numbers and message text out of the SMS status overview.
