evoOrigin settings
Settings live in two places: the component options (Components → evoOrigin → Options) and the system plugin (System → Plugins → System - evoOrigin (visitor origin)).
Component options
Visit log (level 1)
One row per session with the origin. This is personal data: turn it on only if you have a legal basis and have mentioned it in your privacy policy.
| Setting | What it does | Default |
|---|---|---|
| Log visits | Turns on visit logging in the database. Session capture works the same without it. | No |
| How to store the IP | Truncated, salted hash or full (see below). | Truncated |
| Detail retention (days) | After this period the detail becomes anonymous monthly counters and is deleted. From 1 to 3650. | 90 |
| Store click identifiers | Stores gclid, gbraid, wbraid, msclkid and fbclid in visits and in lead attribution. |
No |
| Click identifier retention (days) | A separate period for click identifiers. From 1 to 3650. | 90 |
How to store the IP
| Option | What is stored |
|---|---|
| Truncated (last octet zeroed) | For IPv4, the IP with the last octet set to zero. For IPv6, only the first 48 bits. |
| Salted hash | An HMAC-SHA256 of the IP with a salt derived from the site secret. It lets you count visitors without storing the IP. |
| Full | The whole IP. It is full personal data; use a short retention. |
An invalid IP is never stored.
Lead attribution (level 2)
A summary of a lead's first and last origin. Another extension triggers it with the onEvooriginLead event. It does not store browsing.
| Setting | What it does | Default |
|---|---|---|
| Store lead attribution | Turns on level 2. | No |
| Summary retention (months since the last interaction) | After this period the summary is deleted. From 1 to 120. Set by the data controller. | 24 |
Consent
If the site has a cookie banner, logging can be limited to visitors who accepted it by reading the cookie where the banner stores their choice.
| Setting | What it does | Default |
|---|---|---|
| Log only with consent | When on, a visit is logged only when the banner cookie arrives with the expected value. | No |
| Banner cookie | Name of the cookie where the banner stores the visitor's choice. Letters, numbers, dot, hyphen and underscore only (up to 64 characters). | Empty |
| Value meaning "accepted" | If empty, it is enough for the cookie to exist and not be empty. | Empty |
The consent option affects database logging only. Session capture does not depend on it.
Uninstall
| Setting | What it does | Default |
|---|---|---|
| Delete the tables on uninstall | When on, uninstalling the component drops the three evoOrigin tables. | No |
Licence
The License tab manages the extension's licence. See Licences and updates.
Permissions
The component defines three actions: administer (core.admin), manage (core.manage) and delete (core.delete).
| Action | What it allows |
|---|---|
| Manage | View statistics, visits and attribution in the panel; read through the REST API and the MCP tools. |
| Delete | Delete visits and lead summaries from the panel and from the MCP tools. |
| Administer | Open the options from the toolbar. |
System plugin settings
| Setting | What it does | Default |
|---|---|---|
| Session key | Joomla session key where the origin is stored. Letters, numbers, dot, hyphen and underscore only. If it is not valid, the default is used. | evo_origin |
| Own domains | One domain per line or comma separated. Their subdomains also count as own and are not treated as an external origin. | Empty: the site domain |
Change the session key only if another extension already reads a specific key.
Warnings in the panel
evoOrigin shows a warning in the panel in these cases:
- Consent is required but no cookie is configured: no visit will be logged.
- The full IP is stored with a retention longer than 90 days.
- Click identifiers are kept for more than 90 days.