Draft for owner/legal review

Privacy placeholder

Not production legal text. The owner must review and replace this page before enabling measurement or provider correction intake.

Current repository defaults

Custom conversion measurement, advertising, and provider correction intake are disabled by default. Each endpoint fails closed unless its separate server release gate and required Cloudflare binding are present. Local drafts stay in this browser. A successful correction submission replaces the local draft with a browser receipt containing only the provider ID, opaque reference, pending state, and submission time.

Correction data when intake is approved

The pending-review queue stores the catalog provider identity, work email, requestor role, first-party evidence URL, factual correction text, idempotency digest, timestamps, and review audit state. The response does not return those form values. The deletion deadline is 90 days, subject to a documented legal hold; intake must remain disabled until an operator verifies the deletion process. Identity-free global and provider rate buckets do not derive or store an IP address, cookie, user agent, advertising ID, or visitor identifier.

Data this project must not use for analytics

Do not collect raw searches, selected pregnancy or postpartum stages, trimester or due date, health details, names, contact details, precise location, form values, full URLs or referrers, raw IP or user agent, advertising IDs, or persistent visitor identifiers. Evidence-source clicks and schedule/availability intent remain separate aggregate events; neither proves a booking.

Production decisions required

Before enabling measurement or correction intake, document the operator identity, purpose and lawful basis, processors, actual Cloudflare configuration, enforced retention/deletion, security practices, user rights, contact method, browser storage, and jurisdiction-specific disclosures. Obtain owner/legal approval and align the deployed behavior with that reviewed text.