Account, marketplace, safety, and product data should have a defined purpose instead of being collected “just because.”
Privacy controls should explain what ClaraWide knows—and give people useful choices.
This page separates public/profile visibility from private account data, commerce records, safety evidence, location preferences, communications, exports, and deletion requests. It is a product/privacy foundation and still requires final legal review before launch.
Nearby discovery uses user-selected approximate location/radius settings. Shipping or billing addresses are separate private commerce data.
Orders, refunds, disputes, payouts, and moderation decisions may require retained records even after a profile is changed or an account closes.
People should have a clear place to request copies of their data and account deletion without hunting through support pages.
Different data exists for different reasons.
These categories describe the intended launch architecture. Final production disclosures must match the systems ClaraWide actually operates.
Email, account identifiers, display name, profile bio, maker/shop role, profile visibility, follow settings, and account preferences.
Purpose: account access, identity within ClaraWide, personalization, and user controls.Orders, line items, shipping/pickup details, tax records, refunds, disputes, seller fees, payout states, tracking, and transaction snapshots.
Purpose: complete and support marketplace transactions and required financial records.Messages, posts, follows, Clara Hearts, comments/replies when added, reviews, reports, and attachments.
Purpose: user-requested communication, community features, marketplace support, and abuse prevention.Blocked content records, reports, surrounding context used in review, appeals, enforcement decisions, shop standing, payout-risk signals, and fraud indicators.
Purpose: prevent harm, fraud, circumvention, abuse, and protect users/platform integrity.User-selected nearby location and radius for local discovery. This is separate from private delivery or billing addresses.
Purpose: Nearby feed/search and event/shop discovery.Visits, clicks, conversion events, device/session diagnostics, and aggregate performance data when production analytics are enabled.
Purpose: reliability, security, marketplace measurement, and product improvement.Visibility and discovery settings belong to the user.
These controls are browser-local in this foundation and are not a substitute for production server enforcement.
Deleting a profile is not the same as erasing every historical record immediately.
Some information may need to remain for transactions, fraud prevention, legal obligations, chargebacks, tax/accounting records, safety investigations, or dispute history.
Production deletion should remove or de-identify eligible profile/social data according to the final retention policy and active obligations.
Completed transaction records may need to remain for accounting, tax, refund, chargeback, processor, and legal requirements even after account closure.
Serious abuse, fraud, threats, appeals, and moderation evidence may be retained long enough to investigate, enforce, prevent repeat harm, or satisfy legal obligations.
Minimal relationship data may need to remain so a deleted/recreated account cannot trivially bypass a safety block.
Production systems may retain limited backup/security records for defined periods. Final launch policy must state the real retention approach.
When ClaraWide no longer needs data for its stated purpose or a required retention reason, the production process should delete or de-identify it according to policy.
If a reported message sits inside a larger mutual conflict, review may pull surrounding conversation context so ClaraWide can evaluate both sides rather than assuming the reporter was automatically innocent.
Export what the prototype knows, or start an account-deletion request.
Production must verify identity before fulfilling privacy requests. These controls currently create browser-local demonstrations only.
Creates a JSON export from the ClaraWide browser-local records available in this build. This does not represent every future server-side production record.
Models a future verified privacy request for an accessible copy of account data rather than a developer-style raw export.
Starts a deletion request. It does not instantly erase orders, safety evidence, financial records, or other information that may have a valid retention requirement.
