LEGAL_DRAFT_NOT_APPROVED
This is a mother-template worksheet, not an approved privacy policy. It contains no project-specific privacy promises. Replace every
PROJECT_BRIEF_REQUIREDitem with verified facts from the Project Brief, obtain approval from the responsible legal owner, and remove this marker before launch.
| Field | Required project fact |
|---|---|
| Product or service | PROJECT_BRIEF_REQUIRED: product_name_and_scope |
| Privacy controller/operator | PROJECT_BRIEF_REQUIRED: privacy_controller_or_operator |
| Privacy contact | PROJECT_BRIEF_REQUIRED: privacy_contact |
| Effective date | PROJECT_BRIEF_REQUIRED: privacy_effective_date |
| Last updated | PROJECT_BRIEF_REQUIRED: privacy_last_updated_date |
| Approved by | PROJECT_BRIEF_REQUIRED: legal_approver_and_approval_record |
PROJECT_BRIEF_REQUIRED: identify the reviewed privacy controller or responsible operator, the product covered by this policy, the production domain, the intended audience or markets, and the verified contact route. Do not assume that this party is also the Terms contracting operator or the seller/merchant, and do not infer an entity, address, or jurisdiction from the domain or source-code vendor.
PROJECT_BRIEF_REQUIRED: list only data the launched product actually receives, creates, derives, or stores. For each item record the exact fields or category, source, purpose, whether it is required, storage system, recipients or processors, and retention or deletion rule.
The completed inventory must separately verify any applicable data from:
Do not state that this site collects or stores card numbers, billing addresses, or other processor-held payment data unless the implemented checkout flow and the selected provider contract confirm that fact.
PROJECT_BRIEF_REQUIRED: copy the verified production inventory from the Project Brief. Include each cookie, local-storage key, session-storage key, SDK or tag; its provider, purpose, trigger, duration, data sent, and enabled markets. Record the actual consent or preference behavior, if any. Do not claim that a consent manager exists unless it has been implemented and tested.
PROJECT_BRIEF_REQUIRED: identify only vendors and other recipients enabled for this project, what data each receives, why it receives it, and where the supporting configuration or contract is recorded. Do not copy the mother template's list of supported integrations as if all were active.
PROJECT_BRIEF_REQUIRED: state the verified storage locations or systems, retention periods or decision rules, backup treatment, deletion behavior, and the operational owner for each applicable data category. Do not promise encryption, access controls, deletion timing, or a particular hosting location without evidence.
PROJECT_BRIEF_REQUIRED: describe the tested request channel, identity-verification process, account-deletion flow, applicable request types, response owner, and any product-specific effect on inputs, outputs, orders, invoices, or required records.
PROJECT_BRIEF_REQUIRED_LEGAL_REVIEW: based only on the confirmed target markets, actual data locations and transfers, and legal-owner review, add any applicable legal basis, regional disclosure, cross-border transfer information, user rights, exercise process, and regulator or complaint route. Do not add a jurisdiction, transfer mechanism, statutory right, or regulator by default.
PROJECT_BRIEF_REQUIRED_OR_NOT_APPLICABLE: record the approved age or audience position for the actual product and target markets. Do not add a default age threshold.
PROJECT_BRIEF_REQUIRED: state the approved update and notice process. Keep the visible effective and last-updated dates aligned with the approved document; do not use a content creation date as either date.
PROJECT_BRIEF_REQUIRED: provide the verified privacy or support contact and any additional contact details approved for publication.
Release check: this page must continue to display LEGAL_DRAFT_NOT_APPROVED until all applicable facts above are complete and the responsible legal owner has approved the final text. The marker is a searchable procedural safeguard; it is not a runtime publication gate.