# DRAFT — FOR LEGAL REVIEW — NOT APPROVED FOR PUBLICATION

# Proposed PLOCAL Privacy Notice

**Status:** Working description of implemented systems, not counsel-approved, not effective, and not a claim of legal compliance.

## Scope and people covered

This draft addresses visitors, voters, Business submitters/representatives, payers, Businesses represented in Profiles, support reporters, and internal PLOCAL staff. Counsel must define controller/business identity, territorial scope, effective date, lawful bases, state-specific supplements and rights.

## Information PLOCAL processes

1. **Business Submission:** Business identity, category, city/state/ZIP, service areas, description, website, public contact information, online profiles, services/features, licenses/credentials and submitter role/contact/notes.
2. **Screenshots and evidence:** A server-validated website screenshot is stored privately under a non-public reference; authorized public Profile streaming may show the submission screenshot through an ownership/publication gate. PLOCAL may process submitted/public evidence for Evaluation.
3. **Public Profile and Evaluation:** Business identity/location/category, lifecycle, finalized Digital/Service/Trust results, public 0–10 PLOCAL Score, qualification progress, final outcome, Award identity/history and applicable screenshot.
4. **Voting/security:** A pseudonymous cookie identity, HMAC-derived digest, ballot/window relationship and vote-state data. Raw identity is not persisted as the voter identity. IP address may be processed transiently by HTTP infrastructure and rate limiting; security/logging/proxy providers may process network metadata. Counsel must align exact cookie notice and retention wording with production configuration.
5. **Payments:** Stripe-hosted Checkout processes payment method/card data. PLOCAL stores provider-safe Checkout Session, PaymentIntent, Refund, dispute and event references; base/tax/total/refunded minor-unit amounts; currency; payment/activation/refund-operation state and timestamps. PLOCAL does not store card number/CVC or Stripe secrets in staff views.
6. **Support Cases:** Name, email, optional phone, Business/Profile context, subject, message, source/type/status and timestamps for Contact, Support, Accessibility, Fraud, Billing/refund and Legal/privacy requests. These messages may contain sensitive information chosen by the reporter.
7. **Internal operations:** Staff account/role/permission, DB-backed session, assignment, safe audit actor/reference/action/outcome metadata and operational logs. Full sensitive Case/Evaluation messages are not duplicated into audit metadata.
8. **Technical data:** Server/application logs, request/security/rate-limit data, cookies/session data, configuration health and error diagnostics. Production details require deployment audit confirmation.

## Purposes

Operate Submission, Checkout and Evaluation; publish/maintain Profiles and Recognition; conduct D/S/T review; enable qualification voting and anti-abuse; reconcile payments/refunds/disputes; provide support/accessibility/safety/legal review; authenticate and authorize staff; prevent fraud; diagnose failures; keep audit/history; comply with legal duties; and protect rights/safety. Counsel must map lawful bases/notice-at-collection requirements.

## Public information

Approved Business/Profile, finalized Evaluation, voting progress, Recognition and Award history may be public and discoverable. Private submitter/staff/payment/support details are not public. Counsel must approve permanence, source/content rights, correction/removal and indexing language.

## Sharing/service providers

Potential recipients include Stripe, infrastructure/hosting/database/storage/backup, mail provider once configured, security/rate-limit/logging/monitoring, analytics if enabled, professional advisers, authorities/legal recipients when required, and public users for public Profile/Recognition data. Counsel must confirm actual vendors, contracts, transfers and sale/share/targeted-advertising disclosures.

## Retention

PLOCAL intends to retain information for appropriate periods needed for service delivery, security, dispute/financial/audit/history, legal compliance and approved Profile/Recognition purposes. **No fixed retention period is approved or implemented.** Counsel must determine categories, legal requirements, deletion/anonymization, backups, litigation holds and public-history exceptions before publication. No B3.2 purge scheduler exists.

## Security

Implemented controls include private screenshot storage, safe streaming, pseudonymous HMAC voter identity, rate limits, same-origin/honeypot/validation for static support intake, signed Stripe webhooks, local provider-event idempotency, DB-backed internal sessions, RBAC, CSRF for internal mutations, audit events, escaped untrusted text, and no raw card capture. No system can promise absolute security; counsel must finalize disclosure language and incident notice process.

## Choices and rights

Users may submit support/legal/privacy Cases for access, correction, deletion/removal or other requests, but submission does not automatically execute the request. Counsel must specify applicable rights, verification, authorized agents, appeal, timelines, non-discrimination, exceptions and jurisdictional contacts.

## Cookies and similar technologies

PLOCAL uses cookies for internal sessions and pseudonymous public voting identity; other production analytics/preferences must be inventoried. Counsel must approve cookie classification, consent/opt-out requirements, Do Not Track/GPC treatment and notice mechanics.

## Children

**COUNSEL PLACEHOLDER:** Determine intended audience/age rules and legally appropriate child/minor provisions.

## International/state-specific matters

**COUNSEL PLACEHOLDER:** Determine transfers, regional/state disclosures and addenda. No jurisdiction-specific conclusion is made here.

## Contact

Current established general contact: `info@plocal.com`. Counsel must approve privacy request address, verification and legal-notice details.
