Draft for privacy review

Privacy policy outline matching PrepPort's portal, automation, and fulfillment data flows.

This draft maps what data is collected, why it is used, who may process it, and which analytics data must never include customer-sensitive content.

Operational data categories

Review these against target customer jurisdictions and payment/platform requirements.

Customer and commerce data

  • Company, contact, role, support mailbox, store URL, country, sales channels, and onboarding answers
  • SKU, barcode, bundle, label, packaging, supplier, quote, invoice, wallet, and product RFQ records
  • Order, recipient, address, tracking, ASN, fulfillment, inventory, and exception status

Operations evidence

  • Warehouse photos, QC evidence, counts, defect notes, carton data, label files, and inspection reports
  • Support messages, email/WhatsApp conversations, call summaries, service desk notes, and customer action states
  • Shopify/API/webhook events and customer-uploaded payment evidence status

Provider categories

  • Warehouse staff, suppliers, carriers, inspection partners, payment providers, communication providers, ecommerce platforms, hosting, and analytics providers
  • Data sharing is limited to service delivery, support, compliance, fraud prevention, accounting, and platform operation.

Analytics boundary

GA4/Search Console can be enabled only after privacy-safe event checks pass.

Allowed metadata

  • Page path, CTA, language, service category, UTM source/medium/campaign/content/term
  • Quantity bucket, platform category, coarse funnel step, anonymous session hash, event name, and timestamp

Never send

  • Email, phone, WhatsApp, name, company, full address, customer token, API key, payment reference, receipt URL, raw message text, product document, supplier private data, or secrets
  • Exact quote values, bank details, payment links, legal decisions, refunds, or customer-specific operational notes

Approval questions

Resolve these before publishing a final privacy policy.

Retention

Set retention periods for RFQs, QC photos, warehouse records, support messages, call summaries, payment evidence, and Shopify/order data.

Rights process

Confirm export, correction, deletion, accounting retention, legal hold, and identity verification process for target customer jurisdictions.

Consent notice

Confirm cookie/analytics notice and whether GA4 requires additional consent or opt-out wording before activation.

APP policy completeness

Final policy should cover access, correction, deletion/export request handling, complaint handling, overseas recipients/countries where practical, collection methods, and high-level storage/security practices without exposing security details.