Hi Shahriar,
Thanks for your reply.
1. Surely all of this info (email address and Order ID) is posted back from the processor (e.g. PayPal) or available in the session, so it could authenticate without the user having to re-enter their email address? It’s a superfluous extra step.
2. Can the email templates be set up in my theme directory so that my changes aren’t lost during plugin updates?