CPRA + hold
Privacy & discovery
Public privacy policy, notice at collection, GPC, and where bytes actually live when counsel sends a subpoena.
Public: /privacy (notice + categories), /cookies (device snapshots), /privacy/request (CPRA form), /disclosures, /licenses, /tax. Desk: /admin/compliance.
| Control | Where |
|---|---|
| Notice at collection | components/legal/notice-banner.tsx |
| Telemetry opt-out / GPC | components/telemetry/beacon.tsx |
| Data inventory | lib/compliance/catalog.ts |
| CPRA intake | actions/privacy.ts → .data/privacy-requests.json |
| Discovery map | DISCOVERY_SOURCES in the catalog |
Legal hold: do not purge contracts, Stripe objects, or telemetry. Export from Stripe Dashboard, Postgres/Supabase, GitHub audit log, and .data/ — the admin desk is not a vault and never holds card PAN.