Renew Forge → Journal is the evidence of every cancellation: who, when, from which screen, and whether the confirmation email was sent. Filter by type, subscription, customer and dates; export to CSV exactly as stored.
Each record holds the event type, the subscription and customer numbers, the date and time (UTC), which button or screen was used, the status before and after, the date access ends, whether the email was sent and which version of its wording, and keyed hashes of the IP address and the browser. A refused cancellation is recorded with the reason. No card details, no raw IP address: the hashes are HMAC-SHA256 with the site’s own secret (its WordPress auth salt), so they prove “the same address as that other record” without revealing it, and hashes from two sites never match.
Record types of the free plugin: Cancellation requested; Cancellation confirmed; Cancellation refused; Cancellation withdrawn (reactivated); Cancellation requested: ends at the end of the minimum term; Confirmation email retried; Compliance check recorded. Renew Forge Pro adds its own (reminders sent or not sent, cooling-off periods, notices, cancellations and refunds, checkout acknowledgements, retention deletions).
The journal only ever adds: nothing in the free plugin edits or deletes a record, and the CSV export writes each record as it was stored. CSV columns: id, created_at_utc, type, subscription_id, order_id, customer_id, channel, ip_hash, user_agent_hash, payload_json. A cell that would start like a spreadsheet formula is prefixed with an apostrophe.
Why keep it: under s. 272(6) it is for the trader to prove that a notice was given. The only deletions happen in Pro, and both are recorded themselves — retention after the period you choose, and erasure of personal data on request (see Retention and personal data).
The plugin adds suggested wording about the journal to the privacy policy guide under Settings → Privacy. When the plugin is deleted, the journal and the settings stay by default, because the journal is your evidence; see Settings.