PLACEHOLDER. REQUIRES LEGAL REVIEW BEFORE LAUNCH. This page is a structural placeholder outlining the sections a complete privacy policy needs for this site, based on its actual data flows (newsletter signups via MailerLite, contact form via WPForms, standard analytics, affiliate links). It is not a substitute for review by qualified legal counsel, and should not be published as a final policy without that review. Privacy law (GDPR, CCPA/CPRA, and similar) carries real compliance obligations that need to be verified against your actual hosting setup, analytics configuration, and target audience jurisdictions before this goes live.
*Last updated: [DATE. To be set at actual publish]*
Sections a complete policy needs, given this site's actual data collection
### 1. What data we collect
Newsletter signup: email address (via MailerLite embedded form)
Contact form submissions: name, email, subject, message (via WPForms Lite)
Standard site analytics: page views, referrer, approximate location, device type (specify actual analytics tool once selected, not specified in this build, since analytics platform choice needs a privacy-conscious decision and isn't in Inference's 7-plugin stack by default; recommend a privacy-focused option like Plausible or a self-hosted alternative over a data-broad option)
Cookies: specify which are strictly necessary (session, theme preference) versus optional (analytics), and confirm the cookie consent banner (see Cookie section below) accurately reflects this
### 2. How we use collected data
Newsletter emails: sending the newsletter and related account communications only, via MailerLite
Contact form data: responding to inquiries, routed internally per category
Analytics: understanding aggregate site usage to improve content and site performance, not individual user tracking beyond what the chosen analytics tool does by default
### 3. Third-party data processors List every third-party service that touches visitor data: MailerLite (newsletter), WPForms (contact form submissions, if using their cloud-connected features), your hosting provider, your analytics provider, and any ad-serving vendor once the monetization slots (see `docs/03-tech-plugins-cpt-monetization.md`) are activated with a live ad network.
### 4. Cookie policy Specify categories (strictly necessary, analytics, advertising) and confirm the consent mechanism matches actual cookie behavior. Required in most jurisdictions with EU/UK visitors, and increasingly required in various US states.
### 5. User rights Access, correction, deletion, and portability rights. Specify request process and confirm actual technical capability to fulfill deletion/export requests within your stack before promising them in the policy text.
### 6. Data retention How long newsletter subscriber data, contact form submissions, and analytics data are retained, and the deletion process when a user unsubscribes or requests deletion.
### 7. Children's privacy Standard statement that the site isn't directed at children under 13 (or the relevant age threshold in applicable jurisdictions) and doesn't knowingly collect their data.
### 8. Contact for privacy requests A specific contact path (can route through the general Contact page with a dedicated Subject option, or a dedicated privacy@ email address) for privacy-specific requests.
### 9. Changes to this policy Standard notice-of-changes language and how updates will be communicated.
Why this is a placeholder, not final text
Privacy law carries real regulatory and liability consequences, and the correct text depends on specifics (your actual hosting jurisdiction, your actual analytics and ad vendor choices, your actual target audience's locations) that should be confirmed and reviewed by qualified legal counsel before this page replaces this placeholder. See the launch checklist for this as a required pre-launch item.
