Data care

Privacy Policy

Owner and legal review required before publication.

Status
Draft — not published
Version
1
Effective date
Not yet approved

Data the final policy must address

The production service is expected to need limited contact and order information, policy acceptances, payment-review records, support messages, subscription dates, and security logs. Optional payment proofs require a separate, clearly explained private-upload process.

This draft does not state that every category is already collected. The final policy must reflect the deployed system and omit data that is not actually needed.

Purposes and lawful basis

The approved policy must connect each data category to a specific purpose such as creating an order, reviewing a manual transfer, delivering access, handling support, preventing abuse, meeting recordkeeping duties, or sending a requested renewal reminder.

Applicable legal bases and jurisdiction-specific wording require qualified review. Marketing consent, if introduced, must remain separate and optional.

Payment proofs and sensitive information

Receipt files, if enabled, must be validated, stored privately, accessed only by authorized staff, and retained only for an approved period. PDF acceptance remains disabled unless the hosting and security plan can handle it safely.

Customers should never send bank login credentials, card data, unrelated identity documents, or a full bank statement. Public URLs and analytics must not contain personal details, bank references, proof filenames, or private tracking tokens.

Processors, transfers, and retention

The final policy must name or accurately categorize the hosting, email, support, analytics, and other processors actually configured, along with relevant international-transfer information.

Retention periods, deletion or anonymization rules, backup behavior, and audit-record exceptions are not yet approved. No retention promise is made by this fixture.

Choices, rights, and contact

The production policy must explain applicable access, correction, deletion, restriction, objection, portability, consent-withdrawal, and complaint options without claiming rights that do not apply in the confirmed jurisdiction.

A verified privacy contact and identity-check process must be published before requests are accepted. The current Contact page does not invent an email address or response deadline.

Cookies and privacy-aware analytics

Essential session and security cookies may be required for forms, checkout, and administration. Optional third-party analytics must remain disabled until the owner approves the provider, consent approach, data map, retention, and public disclosure.

Funnel measurement must exclude names, email addresses, phone numbers, order numbers, banking information, message bodies, receipt metadata, and subscription credentials.