Data the final policy must address
The production service is expected to need limited contact and order information, policy acceptances, payment-review records, support messages, subscription dates, and security logs. Optional payment proofs require a separate, clearly explained private-upload process.
This draft does not state that every category is already collected. The final policy must reflect the deployed system and omit data that is not actually needed.
Purposes and lawful basis
The approved policy must connect each data category to a specific purpose such as creating an order, reviewing a manual transfer, delivering access, handling support, preventing abuse, meeting recordkeeping duties, or sending a requested renewal reminder.
Applicable legal bases and jurisdiction-specific wording require qualified review. Marketing consent, if introduced, must remain separate and optional.
Payment proofs and sensitive information
Receipt files, if enabled, must be validated, stored privately, accessed only by authorized staff, and retained only for an approved period. PDF acceptance remains disabled unless the hosting and security plan can handle it safely.
Customers should never send bank login credentials, card data, unrelated identity documents, or a full bank statement. Public URLs and analytics must not contain personal details, bank references, proof filenames, or private tracking tokens.
Choices, rights, and contact
The production policy must explain applicable access, correction, deletion, restriction, objection, portability, consent-withdrawal, and complaint options without claiming rights that do not apply in the confirmed jurisdiction.
A verified privacy contact and identity-check process must be published before requests are accepted. The current Contact page does not invent an email address or response deadline.
Cookies and privacy-aware analytics
Essential session and security cookies may be required for forms, checkout, and administration. Optional third-party analytics must remain disabled until the owner approves the provider, consent approach, data map, retention, and public disclosure.
Funnel measurement must exclude names, email addresses, phone numbers, order numbers, banking information, message bodies, receipt metadata, and subscription credentials.