# evoOrigin settings

> Every evoOrigin 1.1.6 setting: component options, system plugin settings, permissions, default values and the warnings shown in the admin panel.

# evoOrigin settings

Settings live in two places: the component options (*Components → evoOrigin → Options*) and the system plugin (*System → Plugins → System - evoOrigin (visitor origin)*).

## Component options

### Visit log (level 1)

One row per session with the origin. This is personal data: turn it on only if you have a legal basis and have mentioned it in your privacy policy.

| Setting | What it does | Default |
| --- | --- | --- |
| Log visits | Turns on visit logging in the database. Session capture works the same without it. | No |
| How to store the IP | Truncated, salted hash or full (see below). | Truncated |
| Detail retention (days) | After this period the detail becomes anonymous monthly counters and is deleted. From 1 to 3650. | 90 |
| Store click identifiers | Stores `gclid`, `gbraid`, `wbraid`, `msclkid` and `fbclid` in visits and in lead attribution. | No |
| Click identifier retention (days) | A separate period for click identifiers. From 1 to 3650. | 90 |

**How to store the IP**

| Option | What is stored |
| --- | --- |
| Truncated (last octet zeroed) | For IPv4, the IP with the last octet set to zero. For IPv6, only the first 48 bits. |
| Salted hash | An HMAC-SHA256 of the IP with a salt derived from the site secret. It lets you count visitors without storing the IP. |
| Full | The whole IP. It is full personal data; use a short retention. |

An invalid IP is never stored.

### Lead attribution (level 2)

A summary of a lead's first and last origin. Another extension triggers it with the `onEvooriginLead` event. It does not store browsing.

| Setting | What it does | Default |
| --- | --- | --- |
| Store lead attribution | Turns on level 2. | No |
| Summary retention (months since the last interaction) | After this period the summary is deleted. From 1 to 120. Set by the data controller. | 24 |

### Consent

If the site has a cookie banner, logging can be limited to visitors who accepted it by reading the cookie where the banner stores their choice.

| Setting | What it does | Default |
| --- | --- | --- |
| Log only with consent | When on, a visit is logged only when the banner cookie arrives with the expected value. | No |
| Banner cookie | Name of the cookie where the banner stores the visitor's choice. Letters, numbers, dot, hyphen and underscore only (up to 64 characters). | Empty |
| Value meaning "accepted" | If empty, it is enough for the cookie to exist and not be empty. | Empty |

The consent option affects database logging only. Session capture does not depend on it.

### Uninstall

| Setting | What it does | Default |
| --- | --- | --- |
| Delete the tables on uninstall | When on, uninstalling the component drops the three evoOrigin tables. | No |

### Licence

The *License* tab manages the extension's licence. See [Licences and updates](https://evoaddons.com/en/documentation/licences-and-updates).

### Permissions

The component defines three actions: administer (`core.admin`), manage (`core.manage`) and delete (`core.delete`).

| Action | What it allows |
| --- | --- |
| Manage | View statistics, visits and attribution in the panel; read through the REST API and the MCP tools. |
| Delete | Delete visits and lead summaries from the panel and from the MCP tools. |
| Administer | Open the options from the toolbar. |

## System plugin settings

| Setting | What it does | Default |
| --- | --- | --- |
| Session key | Joomla session key where the origin is stored. Letters, numbers, dot, hyphen and underscore only. If it is not valid, the default is used. | `evo_origin` |
| Own domains | One domain per line or comma separated. Their subdomains also count as own and are not treated as an external origin. | Empty: the site domain |

Change the session key only if another extension already reads a specific key.

## Warnings in the panel

evoOrigin shows a warning in the panel in these cases:

- Consent is required but no cookie is configured: no visit will be logged.
- The full IP is stored with a retention longer than 90 days.
- Click identifiers are kept for more than 90 days.

---

https://evoaddons.com/en/documentation/evoorigin-settings
