1. Cookies and similar technologies
Cookies are small files stored by a website in a browser. Similar technologies include local storage, scripts, pixels and software identifiers. Spanish rules can apply to storing or accessing information on a device even when the information is not personal data. This policy covers the cookies, storage keys and analytics requests observed in a clean-browser production audit, together with application behaviour verified in the source code.
2. Responsible publisher
The responsible publisher is THE BUSINESS DOER LLC. Its remaining tax, address, registry and working privacy-contact details are visibly pending. This draft is public so that the gap is visible; it is not presented as a final disclosure.
3. Technology inventory detected
| Name | Provider / domain | Purpose | Category | Duration / type | Party | When activated |
|---|---|---|---|---|---|---|
| __cf_bm | Cloudflare thebusinessdoer.com | Bot detection and protection against malicious traffic | Necessary — security | 30 minutes of inactivity / HttpOnly cookie | Set by an infrastructure provider in first-party context | Initial production response, before a consent decision |
| __dpl | Lovable hosting layer thebusinessdoer.com | Observed value matches the deployment identifier and appears to keep a visit on a consistent deployment. Exact provider documentation remains pending. | Necessary — provisional classification pending confirmation | 24 hours observed / cookie | Set by an infrastructure provider in first-party context | Production visit, before a consent decision |
| session-id | Lovable project analytics thebusinessdoer.com | Groups page-view analytics events into a browser session | Analytics — consent required | 30 minutes / cookie | Hosting provider in first-party context | Currently injected before consent; this is an unresolved launch blocker |
| /~flock.js → /~api/analytics | Lovable project analytics / first-party endpoint | Sends session ID, user agent, locale, inferred country, referrer, path and full URL for a page hit | Analytics — consent required | Per page view / script and network request | Hosting provider | Currently injected before consent; not controlled by the repository CMP |
| the-business-doer:consent | The Business Doer / current origin | Stores categories, policy version, decision time, expiry and decision method | Necessary — remember the privacy choice | 12 months / localStorage | First party | When the visitor accepts, rejects or saves a selection |
| sb-[project-ref]-auth-token | Lovable Cloud / Supabase-compatible authentication | Maintains and refreshes an authorised editorial session | Necessary — authentication | Until sign-out, session expiry or browser-data removal / localStorage | Provider key stored on the current origin | Only after successful administrator authentication |
No cf_clearance cookie was observed in this audit, so it is not listed as active; Cloudflare may set it only if a visitor completes a security challenge. Exact durations above are either technically observed or linked to provider documentation and are not inferred from generic cookie databases.
The application also emits typed in-page events through CustomEvent. Its own analytics adapter is not configured and sends nothing to a third party. That is separate from the hosting analytics injected by Lovable and described above.
4. Categories and legal basis
- Necessary: security, deployment consistency, consent memory and authentication only where needed. These rely on providing the requested service and, for related personal-data processing, legal obligation or legitimate interest in secure operation. They are not used as permission for advertising.
- Preferences: optional experience choices. No application service in this category is active.
- Analytics: audience or product measurement. Consent is required. The repository adapter is inactive, but Lovable currently injects project analytics before a decision and must be disabled or properly gated at hosting level.
- Advertising and marketing: ad delivery, personalisation or campaign measurement. The AdSense account verification meta tag and
/ads.txtdeclaration load no Google code. Advertising and the Google script remain hard-blocked pending a certified CMP.
5. Accept, reject, configure or withdraw
On a first visit, optional categories are off. Accept all, Reject all and Configure are presented together. Scrolling, navigating, inactivity or closing settings does not signal consent. Saving a selection with every optional category off has the same technical effect as rejecting all.
The decision is stored for 12 months and can be replaced at any time. Rejecting optional categories does not block the public publication. Blocking necessary storage at browser level may sign an administrator out or cause the consent panel to reappear.
6. Technical blocking and current limitation
Google Funding Choices and its fallback have been removed. AdSense is blocked by a code-level launch gate and is not mounted globally. The account-verification meta tag and/ads.txt declaration are passive: they do not load Google code, store data or render ads. The reusable content gate blocks future third-party embeds, and the local analytics adapter checks analytics consent before transmitting to any future adapter.
The hosting platform nevertheless injects /~flock.js after the application response. It currently writes session-id and posts a page event before the repository consent panel can decide. No documented project-level disable switch was available during the audit. This draft does not call that behaviour compliant: the site owner must have Lovable disable it or provide an officially supported consent integration, then repeat the clean-browser audit.
7. Renewal and material changes
The local consent record expires after 12 months. A policy-version, purpose, category or provider change invalidates the record and asks for a new decision. A choice recorded while an optional service is absent never authorises an undisclosed provider; adding one requires a new inventory, policy-version change and renewed consent.
8. Providers, transfers and Google advertising
Lovable Cloud/Supabase-compatible services process application, authentication, database and storage requests. Lovable hosting and Cloudflare also deliver and protect the site. Their exact entities, contractual roles, processing regions, subprocessors and transfer safeguards remain to be verified: [LOVABLE CLOUD/SUPABASE AND CLOUDFLARE ENTITIES, ROLES, DPAS, REGIONS, SUBPROCESSORS AND TRANSFER SAFEGUARDS PENDING VERIFICATION]. Google authentication is contacted only when an administrator chooses “Continue with Google”.
AdSense is not active. Before any launch for visitors in the EEA, United Kingdom or Switzerland, the publisher must implement one Google-certified CMP integrated with IAB Europe TCF v2.3, publish the configured vendors and purposes, test Google’s dashboard message and verify the real cookies and requests. This first-party panel is not represented as sufficient for Google advertising, and Consent Mode would not replace valid consent.
9. Browser controls and deletion
Browsers let you inspect, block or delete cookies and site data through privacy settings. Consult the official help for Chrome, Safari, Firefox, Edge or your browser. Deleting this site’s local data removes its consent record, so the panel appears again. The application can remove its own accessible storage but cannot promise immediate deletion of HttpOnly or provider-controlled cookies; those may require expiry, provider action or browser deletion.
10. Questions
Cookie and privacy questions should be sent to [PRIVACY EMAIL ADDRESS PENDING]. A working privacy address remains a mandatory legal-completion blocker.