Information collected
The production policy should describe information submitted through the Exposure Review, contact requests, analytics, and any engagement intake. Do not publish this framework until the actual systems and providers are known.
Exposure Review data
Document the submitted domain, matching work email, verification tokens, report data, retention window, deletion behavior, and follow-up use. The policy must match the Railway implementation exactly.
How information is used
Limit use to delivering requested services, maintaining security, responding to inquiries, and lawful business operations. Document any marketing follow-up and consent mechanism.
Service providers
Identify hosting, email, analytics, error-monitoring, scheduling, and payment providers once selected. Avoid naming providers that are not actually used.
Security and retention
Describe reasonable safeguards and retention periods without making absolute security guarantees.
Your choices
Add verified contact information and applicable request procedures after counsel or the responsible business owner reviews the final policy.