Draft — Not Legal Advice — Requires Founder and Solicitor Review
This page is a structural placeholder, not a finished legal document. Nothing on it should be published, relied upon, or shown to a real customer or business as if it were RAIEX's actual Terms, Privacy Policy, or any other binding document until the founder has reviewed it and, for anything with real legal weight, a qualified solicitor has reviewed it too. RAIEX makes no claim of legal compliance anywhere on this page.
[Not yet written. Real, current answer (not to be invented - re-derive from the live schema before publishing): guest checkout name/phone/email (transactions), staff account email (auth.users), staff profile name (profiles, not yet applied), a business's own customer records including marketing_consent (customers), stock request contact details (stock_requests), employee task activity/tokens (tasks/task_token_ledger). See 11_RAIEX_LEGAL_TRUST_FOUNDATION.md Section 5 for the fuller, already-audited list.]
[Not yet written. child_profiles (schema only, not a working feature yet) may eventually hold a child's name/DOB/gender/height, entered by a parent/guardian about their own child - never collected directly from a child, never public. State this plainly once the feature is real; today it holds no live data and nothing reads or writes it.]
[Not yet written. Order fulfilment, staff task administration, and (only where explicitly opted in) marketing - never collected for a purpose beyond what's stated.]
[Not yet written. Real retention periods - not yet decided anywhere in this codebase. Flag for founder decision, informed by UK GDPR's storage-limitation principle.]
[Not yet written. Access, correction, deletion, objection to marketing - UK GDPR data-subject rights. No self-service mechanism exists yet for any of these; today a request would need to be handled manually by the business. State this honestly rather than implying a working portal exists.]
[Not yet written. Only sent where marketing_consent (customers/transactions) is explicitly true - never inferred, never pre-ticked. See src/app/shop/checkout/page.tsx's own checkbox for the real, current mechanism.]
[Not yet written. SumUp (payment processing) and Supabase (hosting/database infrastructure) - the only two third parties this codebase actually integrates with today.]