Legal surface

Privacy for purchase and recovery.

The privacy route establishes how the storefront handles purchase email, token-based recovery, signed-in convenience, and release access without overselling identity or analytics complexity.

Email-only authHashed tokens

Privacy structure

The lane defines the major privacy topics now so later legal content can slot into a real route instead of a placeholder.

Customer data handled here

The direct storefront only collects the information required to sell, recover, and support the utility.

  • Purchase email and normalized email matching for post-purchase linking.
  • Hashed auth, success, manage, and download tokens instead of raw token storage.
  • Release metadata and delivery audit for entitled download access.

Operational boundaries

The site avoids pretending to be a broader identity platform.

  • Email magic links are convenience-only authentication for the customer portal.
  • Suite gateway workflows remain outside the direct storefront's data ownership.
  • Provider integrations are constrained to checkout, licensing, delivery, and support operations.