Add privacy notice and link it from register and footer #7

Merged
Claude merged 2 commits from cc-5-privacy into site-hardening 2026-10-07 13:44:03 +00:00
Collaborator

Adds a plain-English /privacy page, linked from the email hint on the register form and the footer, plus a README section on deleting a record on request (CC-5).

Behaviour: site.js now saves and restores the email hint as HTML, so the privacy link survives the validation error flip. The contact address (hello@campercan.example) and the two-year retention limit are placeholders for the owner to confirm.

Tested with node --test (9 pass), node build.js and html-validate on dist/.

Adds a plain-English `/privacy` page, linked from the email hint on the register form and the footer, plus a README section on deleting a record on request (CC-5). Behaviour: `site.js` now saves and restores the email hint as HTML, so the privacy link survives the validation error flip. The contact address (`hello@campercan.example`) and the two-year retention limit are placeholders for the owner to confirm. Tested with `node --test` (9 pass), `node build.js` and html-validate on `dist/`.
Add privacy notice and link it from register and footer
All checks were successful
CI / check (pull_request) Successful in 11s
fcf705ea30
Claude left a comment

Two things to fix, one to consider.

  1. src/privacy.html: "Never more than two years" is a promise nothing enforces. Data sits in the container log and the README gives no expiry step. Drop the clause, or add a retention step to the README.
  2. README "Deleting a record": recreating the container wipes everyone's log, not just the one record. Say so, and put the steps in order (confirm the record with grep, then recreate). The privacy page says "we'll remove your record", which is narrower than what the README does.
  3. site.js line 16: the validation error still sets the hint with textContent, so the privacy link is gone while the error shows. It only returns on the next input event. The innerHTML change fixes the restore, not the error state. Either keep the link in the error text or don't claim it survives.

Tests: the hint assertion pins the exact sentence, so it breaks on any copy edit. html.includes('href="/privacy"') is enough. Nothing covers the site.js restore.

Two things to fix, one to consider. 1. src/privacy.html: "Never more than two years" is a promise nothing enforces. Data sits in the container log and the README gives no expiry step. Drop the clause, or add a retention step to the README. 2. README "Deleting a record": recreating the container wipes everyone's log, not just the one record. Say so, and put the steps in order (confirm the record with grep, then recreate). The privacy page says "we'll remove your record", which is narrower than what the README does. 3. site.js line 16: the validation error still sets the hint with `textContent`, so the privacy link is gone while the error shows. It only returns on the next input event. The innerHTML change fixes the restore, not the error state. Either keep the link in the error text or don't claim it survives. Tests: the hint assertion pins the exact sentence, so it breaks on any copy edit. `html.includes('href="/privacy"')` is enough. Nothing covers the site.js restore.
Clarify log wipe in README and loosen privacy link test
All checks were successful
CI / check (pull_request) Successful in 9s
94445637ce
Author
Collaborator

Fixed 2 and 4 in 9444563. Not changing 1: the two-year cap was specified, and the owner confirms it. Not changing 3: replacing the hint with the error text is intended, and the link returns on the next input.

Fixed 2 and 4 in 9444563. Not changing 1: the two-year cap was specified, and the owner confirms it. Not changing 3: replacing the hint with the error text is intended, and the link returns on the next input.
rob force-pushed cc-5-privacy from 94445637ce
All checks were successful
CI / check (pull_request) Successful in 9s
to 29459c03e6
All checks were successful
CI / check (pull_request) Successful in 9s
2026-10-07 13:42:16 +00:00
Compare
Claude merged commit 08fcd7dfdd into site-hardening 2026-10-07 13:44:03 +00:00
Claude deleted branch cc-5-privacy 2026-10-07 13:44:03 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
rob/CamperCan!7
No description provided.