Title: UltimaTour Operator
Author: tesystems
Published: <strong>Dawout 2, 2026</strong>
Last modified: Dawout 26, 2026

---

Search plugins

![](https://ps.w.org/ultimatour-operator/assets/banner-772x250.png?rev=3632936)

![](https://ps.w.org/ultimatour-operator/assets/icon-256x256.png?rev=3632857)

# UltimaTour Operator

 By [tesystems](https://profiles.wordpress.org/tesystems/)

[Download](https://downloads.wordpress.org/plugin/ultimatour-operator.2.0.0.zip)

 * [Details](https://hat.wordpress.org/plugins/ultimatour-operator/#description)
 * [Reviews](https://hat.wordpress.org/plugins/ultimatour-operator/#reviews)
 *  [Installation](https://hat.wordpress.org/plugins/ultimatour-operator/#installation)
 * [Development](https://hat.wordpress.org/plugins/ultimatour-operator/#developers)

 [Support](https://wordpress.org/support/plugin/ultimatour-operator/)

## Description

#### Finally. A tour booking and operations platform built for tour operators.

Not restaurants. Not appointments. Not generic events.

**Tours. Activities. Excursions.**

UltimaTour Operator combines online booking with the daily operational tools a tour
operator needs, directly inside WordPress. It supports the complete journey from
the first tour booking to the final guest follow-up for businesses selling tours,
activities, excursions, charters, rentals, and experiences.

Your website. Your bookings. Your customers. No UltimaTour commission on direct 
bookings.

Operator connects a public booking calendar and activity booking flow with tours,
departures, capacity, availability requests, customer records, digital pre-check-
in, document review, QR tickets, mobile staff check-in, attendance, payments, communications,
reviews, temporary holds, coupons, incidents, Google Calendar export, and revenue
planning.

A booking is only the beginning. Your team still needs to know who is coming, who
has paid, who completed required information, who is ready, who checked in, and 
what happens next. Operator keeps that operational journey connected.

Customers can prepare before arrival. Staff can work from phones and tablets. Operators
can manage departures, participants, evidence, communications, and post-tour actions
from one place.

Use Operator for dive and snorkeling businesses, boat and sailing tours, fishing
charters, ATV and buggy tours, zipline parks, kayak and paddleboard rentals, walking
and food tours, eco and wildlife tours, museums, sightseeing businesses, adventure
parks, and other scheduled experiences.

Your operational data stays in your WordPress database. Optional external services
are disclosed below and remain governed by their respective settings. Operator remains
usable as a local WordPress operations platform.

The guided setup creates your business profile, opening hours, physical location,
and first Tour. Every choice can be refined later.

Install UltimaTour Operator, publish your first departure, and start taking direct
bookings.

### External Services

Operator displays a required-registration explanation after activation but sends
no UltimaTour Ecosystem registration request until an administrator intentionally
selects Create / Verify Ecosystem Records. Reviews and TrustEmporium are free but
remain disabled until an administrator enables them in Integrations. Other optional
services connect only after configuration or when a visitor chooses the configured
payment or anti-spam flow.

#### UltimaTour Reviews

Purpose: Create or verify the operator’s free UltimaTour Reviews listing for public
discovery and review collection.

Data sent: Operator/business profile data such as business name, site URL/domain,
public website URL, public contact email/phone when configured, logo URL, location/
geography fields, public description/story, public tour profile summaries, opening
hours, social links, and review/discovery settings. Booking, customer, participant,
payment, and operational records are not sent by this setup step.

When data is sent: During free ecosystem record creation/verification, a manual 
re-check, and later profile or review sync while UltimaTour Reviews remains enabled.
Before each outgoing exchange, Operator verifies its signed core-integrity manifest
and protected file hashes; exchange is paused if integrity is not clean. The administrator
can turn Reviews off independently in Integrations.

Service URL: `https://ultimatour.com/wp-json/ultimatour-review/v1/`.

#### UltimaTour Ecosystem / Partner Registry

Purpose: Administrator-authorized, free integrity registration of this Operator 
installation; signed Operator-core integrity protection; connection-health monitoring;
and authentication context for administrator-enabled Reviews and TrustEmporium exchanges.
This is an integrity and trust-service connection, not a commercial licensing or
payment service.

Data sent during initial registration or a manual registration refresh: Operator/
site name, WordPress administrator email, site URL and canonical domain, Operator
REST API base URL, generated installation identifier, plugin slug/type/version, 
WordPress version, PHP version, registry URL, registration mode, and connection-
health status. The registry returns a signed registration credential. Some internal
compatibility fields retain “license” names, but that credential authenticates integrity
and trust-service requests only; it does not represent a purchase or commercial 
entitlement.

Data sent in the six-hour integrity heartbeat: plugin slug/type/version, installation
identifier, site URL and canonical domain, registry URL, report time, WordPress 
version, PHP version, connection health, and Operator-core integrity results. Core
integrity results contain the signed-manifest payload hash and signature status,
scan time, clean/tampered state, counts of official/scanned/mismatched/missing/unexpected
protected files, and the relative paths of affected files. The heartbeat does not
send WordPress administrator URLs, server fingerprints, file contents, booking or
tour records, customer or participant data, payment data, or unrelated plugin inventory.

When data is sent: Only after an administrator selects the disclosed Create / Verify
Ecosystem Records action. Registration may then be retried manually and the integrity
heartbeat runs every six hours. An administrator can also select “Run Integrity 
Heartbeat Now” to send the same disclosed payload on demand. Operator stores the
last heartbeat attempt, last successful heartbeat, result, HTTP code, error, next
scheduled run, and current local integrity summary so they remain visible on the
Ecosystem Participation screen. Operator also performs the same local core-integrity
scan before outgoing UltimaTour Reviews or TrustEmporium exchange, but those exchanges
remain off unless an administrator enables them in Integrations. A failed scan pauses
only those optional trust-service exchanges and reports the failure on the next 
heartbeat; it does not disable local Operator pages, administration, bookings, tours,
customers, calendars, check-in, closures, or stored records. A registry outage likewise
never blocks local functionality. Registration and heartbeat never check payment,
a subscription, a purchase, or a commercial entitlement and never unlock a paid 
Operator-core feature.

Service URL: `https://partner.ultimatour.com/`.

Privacy policy and terms: https://trustemporium.com/privacy-terms/

#### Google Calendar API

Purpose: Optional one-way export of future departures to an administrator-selected
Google Calendar.

Data sent: OAuth client credentials supplied by the administrator, OAuth authorization
data, departure title, date/time, capacity, booked count, status, location, public
booking link when configured, and Operator admin deep links.

When data is sent: During OAuth authorization, when the administrator lists calendars,
when the administrator manually syncs future departures, and when enabled departure
changes are mirrored.

Service URLs: `https://accounts.google.com/`, `https://oauth2.googleapis.com/`, 
and `https://www.googleapis.com/calendar/v3/`.

Privacy policy: https://policies.google.com/privacy

Terms: https://policies.google.com/terms

#### Stripe

Purpose: Optional Stripe Checkout payment processing.

Data sent: Booking reference, amount, currency, selected tour/departure description,
customer contact details needed for checkout, and booking metadata.

When data is sent: Only when Stripe is enabled and a guest selects Stripe Checkout,
or when Stripe webhooks notify this site about payment status changes.

Service URLs: `https://api.stripe.com/` and `https://checkout.stripe.com/`.

Privacy policy: https://stripe.com/privacy

Terms: https://stripe.com/legal

#### PayPal

Purpose: Optional PayPal Checkout payment processing.

Data sent: Booking reference, amount, currency, selected tour/departure description,
customer contact details needed for checkout, and booking metadata.

When data is sent: Only when PayPal is enabled and a guest selects PayPal Checkout,
or when PayPal return/webhook flows notify this site about payment status changes.

Service URLs: `https://api-m.paypal.com/`, `https://api-m.sandbox.paypal.com/`, 
and `https://www.paypal.com/`.

Privacy policy: https://www.paypal.com/privacy

Terms: https://www.paypal.com/legalhub/useragreement-full

#### OpenStreetMap Nominatim

Purpose: Optional reverse geocoding for derived geography from operator coordinates.

Data sent: Coordinates entered or saved by the administrator.

When data is sent: Only when the administrator uses geography derivation features.

Service URL: `https://nominatim.openstreetmap.org/`.

Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy

Usage policy: https://operations.osmfoundation.org/policies/nominatim/

#### OpenStreetMap Map Tiles

Purpose: Optional administrator-facing location picker map display for Operator 
Profile coordinates.

Data sent: Browser requests for map tiles around the viewed coordinates or map viewport,
plus ordinary request metadata handled by the tile provider such as IP address and
browser headers.

When data is sent: Only when an administrator opens the location picker map in Operator
Profile/settings and the browser loads the map tiles.

Service URL: `https://tile.openstreetmap.org/`.

Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy

Tile usage policy: https://operations.osmfoundation.org/policies/tiles/

#### Cloudflare Turnstile

Purpose: Optional anti-spam protection for public booking, availability request,
notify-me, request-departure, and local customer submission forms.

Data sent: Visitor browser verification data handled by Cloudflare and the site 
key configured by the administrator.

When data is sent: Only when Turnstile is enabled, configured, and displayed on 
a protected public form before that form is submitted.

Service URL: `https://challenges.cloudflare.com/`.

Privacy policy: https://www.cloudflare.com/privacypolicy/

Terms: https://www.cloudflare.com/website-terms/

#### Google reCAPTCHA

Purpose: Optional anti-spam protection for public booking, availability request,
notify-me, request-departure, and local customer submission forms. Operator supports
Google reCAPTCHA v3 score checks and Google reCAPTCHA v2 checkbox challenges.

Data sent: Visitor browser verification data handled by Google and the site key 
configured by the administrator.

When data is sent: Only when reCAPTCHA is enabled and configured for a protected
public form. reCAPTCHA v3 executes before submission to obtain a verification score;
reCAPTCHA v2 sends data when the visitor completes the checkbox challenge.

Service URL: `https://www.google.com/recaptcha/`.

Privacy policy: https://policies.google.com/privacy

Terms: https://policies.google.com/terms

#### UltimaTour Partner Information

Purpose: Provide the mandatory free UltimaTour Ecosystem registration, installation-
integrity, and ecosystem connection services described above.

Data sent: The site, installation, version, connection-health, and Operator-core
integrity information listed in the UltimaTour Ecosystem disclosure above. Operator
does not inventory, authorize, download, install, update, repair, or activate add-
on plugins.

When data is sent: After the administrator authorizes the required free registration,
during manual registration retries, and during the six-hour operational heartbeat.
Reviews and TrustEmporium exchanges require their own administrator-enabled settings.

Service URL: `https://partner.ultimatour.com/`.

Privacy policy and terms: https://trustemporium.com/privacy-terms/

#### TrustEmporium

Purpose: Create or verify the operator’s free TrustEmporium business record for 
verified business, incident, and post-tour event infrastructure. Background customer
lookups, operational TrustEmporium lookups, and intentional post-tour customer record
submissions remain controlled by their own settings or administrator actions.

Data sent: Operator/business identity such as business name, site URL/domain, public
contact email/phone where available, and registration identifiers needed to match,
link, or create the business record. When TrustEmporium is configured, customer 
submissions such as bookings, availability requests, notify-me requests, and request-
departure requests may queue a background lookup using the customer name, email,
phone, request context, booking reference, tour/departure, date/time, and guest 
count where available. Intentional post-tour customer record submissions may send
customer name, email, phone, tour name, departure date/time, booking reference, 
record type, and the operator-entered note. Payment card or funding-source data 
is never sent.

When data is sent: TrustEmporium remains disabled until an administrator enables
it in Integrations. Data is then sent during free ecosystem record creation/verification,
a manual re-check, configured background enrichment after a customer submission,
an operator-requested lookup retry, or an intentional post-tour customer-record 
submission. Before each exchange, Operator verifies its signed core-integrity manifest
and protected file hashes; exchange is paused if integrity is not clean. Background
results are operator-only and never block booking, payment, availability-request,
or notify-me submission.

Service URL: `https://trustemporium.com/`.

Data and responsibility: https://trustemporium.com/data-responsibility/

Privacy policy and terms: https://trustemporium.com/privacy-terms/

## Screenshots

[⌊Operator dashboard with daily operations overview.⌉⌊Operator dashboard with daily
operations overview.⌉[

Operator dashboard with daily operations overview.

[⌊Public booking calendar.⌉⌊Public booking calendar.⌉[

Public booking calendar.

[⌊Departure management.⌉⌊Departure management.⌉[

Departure management.

[⌊Booking pipeline.⌉⌊Booking pipeline.⌉[

Booking pipeline.

[⌊Temporary holds.⌉⌊Temporary holds.⌉[

Temporary holds.

[⌊Payment settings.⌉⌊Payment settings.⌉[

Payment settings.

[⌊Google Calendar integration settings.⌉⌊Google Calendar integration settings.⌉[

Google Calendar integration settings.

[⌊Operator Profile and integration settings.⌉⌊Operator Profile and integration settings
.⌉[

Operator Profile and integration settings.

[[

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/` or install the plugin zip through
    WordPress.
 2. Activate “UltimaTour Operator” from the Plugins screen.
 3. Open Operator in the WordPress admin menu.
 4. Configure Operator Profile, tours, departures, payment settings, and public booking
    pages.

## FAQ

### Does UltimaTour Operator use UltimaTour’s hosted ecosystem?

Operator asks an administrator to register free of charge with the UltimaTour Ecosystem
for installation identity, integrity, and connection health. Registration starts
only after the administrator uses the disclosed Create / Verify Ecosystem Records
action. Until then, Operator remains fully usable for local tours, bookings, customers,
calendars, closures, check-in, and administration. UltimaTour Reviews and TrustEmporium
exchanges remain off until an administrator enables them in Integrations. None of
these services sells, unlocks, meters, blocks, or disables the Operator core.

### How does Operator protect Reviews and TrustEmporium from altered Operator code?

The official package contains a signed integrity manifest with SHA-256 checksums
for Operator’s protected core files. Operator verifies the manifest signature and
re-hashes those files locally before trust-service data exchange and during its 
heartbeat. Modified, missing, or unexpected protected files cause a visible integrity
warning, are reported to the UltimaTour Ecosystem, and pause outgoing UltimaTour
Reviews and TrustEmporium exchanges. Bookings and other local operational data remain
available and are never deleted by an integrity failure. Reinstalling the official
package restores the protected files; the next successful scan and heartbeat restores
trusted exchange.

### Does the plugin store credit card data?

No. Stripe and PayPal payments use provider-hosted checkout flows. Operator stores
payment status, amount, gateway, and provider reference data only.

### Can I use manual or offline payments only?

Yes. Manual/offline payments can be used without Stripe or PayPal.

### Does Google Calendar update Operator records?

No. Base provides one-way export from Operator to Google Calendar. Operator remains
the editable source of operational records.

### Does this plugin acquire other plugins?

No. Operator does not download, purchase, install, update, repair, or activate other
plugins. Separately installed modules can attach to Operator later through its integration
interfaces.

## Reviews

![](https://secure.gravatar.com/avatar/a4bd7f702ccf3bf3945029e17281335b946db8a24cb6a05dce1b728c8a8375e6?
s=60&d=retro&r=g)

### 󠀁[Honestly, this is pretty good](https://wordpress.org/support/topic/honestly-this-is-pretty-good/)󠁿

 [snubasxm](https://profiles.wordpress.org/snubasxm/) Dawout 14, 2026

I do not really like writing reviews, but this plugin really deserves one. We tried
it for our tour business and honestly did not expect this much from a free plugin.
It feels like it was made by people who actually understand tour operators. It took
a little time to set everything up, but once it was running, everything just made
more sense. Bookings, guest information, tickets and check-in are all in one place.
We are definitely keeping it.

 [ Read all 1 review ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/)

## Contributors & Developers

“UltimaTour Operator” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ tesystems ](https://profiles.wordpress.org/tesystems/)

“UltimaTour Operator” has been translated into 1 locale. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/ultimatour-operator/contributors)
for their contributions.

[Translate “UltimaTour Operator” into your language.](https://translate.wordpress.org/projects/wp-plugins/ultimatour-operator)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ultimatour-operator/),
check out the [SVN repository](https://plugins.svn.wordpress.org/ultimatour-operator/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/ultimatour-operator/)
by [RSS](https://plugins.trac.wordpress.org/log/ultimatour-operator/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.0.0

 * Streamlined direct booking so capacity is reserved by guest count while participant
   identity can be completed later.
 * Added explicit primary-booker participation and lifecycle timing for Tour participant
   requirements.
 * Made Pre-Check-In the authoritative participant-completion stage without weakening
   document, waiver, medical, safety, or eligibility requirements.
 * Added immediate ticket issuance: one-person bookings receive an individual participant
   ticket and QR, while parties of two or more receive a group ticket and operational
   roster QR that never automatically checks in the party.
 * Preserved individual participant tickets for sufficiently identified participants
   and made participant delivery an explicit action.
 * Unified incomplete-participant readiness across direct, administrative, OTA, 
   concierge, and external booking sources.
 * Added safer manual OTA intake with duplicate protection and accurate capacity
   for bookings whose participant details are not complete yet.
 * Corrected Google Calendar duplication, identity recovery, occupancy totals, remaining
   capacity, and mixed-source booking summaries.
 * Simplified the Reviews workspace while retaining guest-specific review links 
   and QR codes in the appropriate booking and communication workflows.
 * Improved WordPress.org compliance, database safety, and onboarding presentation.

#### 1.3.17

 * Added operator-controlled availability-request payment reminders that stop automatically
   when payment, cancellation, expiry, or the booking cutoff resolves the request.
 * Improved booking-form accessibility, dialog labeling, loading feedback, theme
   compatibility, and general operational reliability.

#### 1.3.8

 * Added and stabilized guided first-run setup for business details, opening hours,
   location, timezone, a first Tour, and real future availability.
 * Improved onboarding progression, opening-hours persistence, optional map coordinates,
   setup recovery, and administrator guidance.
 * Added staff-confirmed departure closeout, participant document review actions,
   and clearer booking detail controls.
 * Added projected revenue planning and accurate OTA compensation forecasting while
   preserving settlement clarity.
 * Added governed extension points for eligible external commerce integrations.

#### 1.1.4

 * Fix AJAX-loaded public booking form initialization so calendar-launched bookings
   preserve the complete validation, pricing, participant, document, and Stripe 
   checkout path.
 * Add a governed Smart Commerce communication insertion point that renders empty
   unless a commerce module supplies eligible content.

## Meta

 *  Version **2.0.0**
 *  Last updated **4 jou ago**
 *  Active installations **40+**
 *  WordPress version ** 6.7 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.2 or higher **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/ultimatour-operator/) and [Lao](https://lo.wordpress.org/plugins/ultimatour-operator/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/ultimatour-operator)
 * Tags
 * [Activity Booking](https://hat.wordpress.org/plugins/tags/activity-booking/)[booking calendar](https://hat.wordpress.org/plugins/tags/booking-calendar/)
   [online booking](https://hat.wordpress.org/plugins/tags/online-booking/)[tour booking](https://hat.wordpress.org/plugins/tags/tour-booking/)
   [Tour Operator](https://hat.wordpress.org/plugins/tags/tour-operator/)
 *  [Advanced View](https://hat.wordpress.org/plugins/ultimatour-operator/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/ultimatour-operator/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/ultimatour-operator/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ultimatour-operator/reviews/)

## Contributors

 *   [ tesystems ](https://profiles.wordpress.org/tesystems/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ultimatour-operator/)