Privacy — draft operational copy

Only collect what the membership portal needs.

This internal-staging privacy copy is conservative and not approved for public production. Business-owner and counsel review are required before real public supporter payments or public media-access claims.

Information used for membership

The portal should collect only the information needed to operate membership, billing support, account status, optional private-access provisioning, audit logs, security, abuse prevention, and support requests.

Payment data

Stripe handles payment method entry, card details, invoices, and billing portal actions. This portal stores membership and billing-status references needed to reconcile supporter status; it must not store card numbers.

Support and safety

Supporters should not send passwords, API keys, payment-card numbers, setup tokens, private links, or unrelated personal information through support requests. Support and audit records should contain only fields needed to resolve membership, billing, safety, abuse-prevention, or operational issues.

Launch review boundary

Public privacy language, retention rules, account deletion handling, provider disclosure, and legal-rights processes remain launch gates. Public supporter payments are not approved by this staging copy.

Related policies: Terms, refunds and cancellation, and acceptable use.