1. Information collected
A production service may process account details, authentication records, rental history, payment references, support messages, security logs and technical usage metadata. Collect only what is necessary.
2. Payments
Use a payment provider for checkout and avoid storing card or banking credentials. Explain which payment metadata is retained and why.
3. How information is used
Data may be used to authenticate users, provision rentals, prevent fraud, provide support, maintain security, process refunds and comply with legal obligations.
4. Sharing and service providers
List the actual hosting, database, authentication, payment, analytics and support providers used in production. Do not publish this section until the architecture is finalized.
5. Retention and deletion
Define retention periods for accounts, billing records, logs, support tickets and workspace files. Provide a documented process for deleting user data where legally permitted.
6. Security
Use access controls, encryption in transit, secret management, least privilege, backups and incident response procedures. No system can guarantee absolute security.
7. User rights and contact
Explain the process for access, correction, deletion, consent withdrawal and complaints as applicable. Add the operator identity, privacy contact and effective date before launch.