DRAFT — Privacy Policy Not Approved

LEGAL_DRAFT_NOT_APPROVED: project facts and legal-owner approval are required before publication.

LEGAL_DRAFT_NOT_APPROVED

This is a mother-template worksheet, not an approved privacy policy. It contains no project-specific privacy promises. Replace every PROJECT_BRIEF_REQUIRED item with verified facts from the Project Brief, obtain approval from the responsible legal owner, and remove this marker before launch.

Document status

FieldRequired project fact
Product or servicePROJECT_BRIEF_REQUIRED: product_name_and_scope
Privacy controller/operatorPROJECT_BRIEF_REQUIRED: privacy_controller_or_operator
Privacy contactPROJECT_BRIEF_REQUIRED: privacy_contact
Effective datePROJECT_BRIEF_REQUIRED: privacy_effective_date
Last updatedPROJECT_BRIEF_REQUIRED: privacy_last_updated_date
Approved byPROJECT_BRIEF_REQUIRED: legal_approver_and_approval_record

Operator and scope

PROJECT_BRIEF_REQUIRED: identify the reviewed privacy controller or responsible operator, the product covered by this policy, the production domain, the intended audience or markets, and the verified contact route. Do not assume that this party is also the Terms contracting operator or the seller/merchant, and do not infer an entity, address, or jurisdiction from the domain or source-code vendor.

Data inventory and purposes

PROJECT_BRIEF_REQUIRED: list only data the launched product actually receives, creates, derives, or stores. For each item record the exact fields or category, source, purpose, whether it is required, storage system, recipients or processors, and retention or deletion rule.

The completed inventory must separately verify any applicable data from:

  • accounts, authentication, email verification, and support;
  • product inputs, uploads, prompts, task records, generated outputs, and saved assets;
  • usage, diagnostics, device, network, security, and fraud-prevention records;
  • orders, subscriptions, invoices, credits, and the site's payment metadata;
  • analytics, advertising, attribution, affiliate, and customer-service tools.

Do not state that this site collects or stores card numbers, billing addresses, or other processor-held payment data unless the implemented checkout flow and the selected provider contract confirm that fact.

Cookies and browser storage

PROJECT_BRIEF_REQUIRED: copy the verified production inventory from the Project Brief. Include each cookie, local-storage key, session-storage key, SDK or tag; its provider, purpose, trigger, duration, data sent, and enabled markets. Record the actual consent or preference behavior, if any. Do not claim that a consent manager exists unless it has been implemented and tested.

Service providers and disclosures

PROJECT_BRIEF_REQUIRED: identify only vendors and other recipients enabled for this project, what data each receives, why it receives it, and where the supporting configuration or contract is recorded. Do not copy the mother template's list of supported integrations as if all were active.

Storage, retention, and deletion

PROJECT_BRIEF_REQUIRED: state the verified storage locations or systems, retention periods or decision rules, backup treatment, deletion behavior, and the operational owner for each applicable data category. Do not promise encryption, access controls, deletion timing, or a particular hosting location without evidence.

User requests and account deletion

PROJECT_BRIEF_REQUIRED: describe the tested request channel, identity-verification process, account-deletion flow, applicable request types, response owner, and any product-specific effect on inputs, outputs, orders, invoices, or required records.

Regional disclosures, cross-border transfers, and rights

PROJECT_BRIEF_REQUIRED_LEGAL_REVIEW: based only on the confirmed target markets, actual data locations and transfers, and legal-owner review, add any applicable legal basis, regional disclosure, cross-border transfer information, user rights, exercise process, and regulator or complaint route. Do not add a jurisdiction, transfer mechanism, statutory right, or regulator by default.

Children or age conditions

PROJECT_BRIEF_REQUIRED_OR_NOT_APPLICABLE: record the approved age or audience position for the actual product and target markets. Do not add a default age threshold.

Policy changes

PROJECT_BRIEF_REQUIRED: state the approved update and notice process. Keep the visible effective and last-updated dates aligned with the approved document; do not use a content creation date as either date.

Contact

PROJECT_BRIEF_REQUIRED: provide the verified privacy or support contact and any additional contact details approved for publication.


Release check: this page must continue to display LEGAL_DRAFT_NOT_APPROVED until all applicable facts above are complete and the responsible legal owner has approved the final text. The marker is a searchable procedural safeguard; it is not a runtime publication gate.