{
  "schemaVersion": 1,
  "lastVerified": "2026-07-30",
  "summary": {
    "firstPartyCookies": "none",
    "trackingOrAdvertisingStorage": "none",
    "analytics": "none",
    "notice": "VoxFrame uses an informational privacy notice, not a consent banner. The acknowledgement preference is written only after the visitor chooses the acknowledgement button."
  },
  "browserStorage": [
    {
      "name": "voxframe.privacy.notice.v1",
      "surface": "customer-facing VoxFrame web origins",
      "medium": "localStorage",
      "status": "active-after-acknowledgement",
      "classification": "functional",
      "contents": "schema version and acknowledgement time",
      "purpose": "avoid repeating the informational privacy notice on the same origin",
      "createdWhen": "only after the visitor selects the acknowledgement button",
      "retention": "180 days; stale data is ignored and removed on the next page load",
      "clearedWhen": "after 180 days on the next page load, or manually through browser site-data controls",
      "recipient": "VoxFrame page on the same origin only"
    },
    {
      "name": "voxframe.ui.language",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "active",
      "classification": "functional",
      "contents": "one of en, nl, de or fr",
      "purpose": "keep the selected account-page language within the current tab",
      "createdWhen": "a supported lang query parameter is used",
      "retention": "until the browser tab closes",
      "clearedWhen": "the browser tab closes or site data is cleared",
      "recipient": "VoxFrame account page on the same origin only"
    },
    {
      "name": "voxframe.account.token",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "active",
      "classification": "strictly-necessary security",
      "contents": "short-lived bearer account-session token",
      "purpose": "authenticate account, device and billing-management requests",
      "createdWhen": "account login succeeds",
      "retention": "until sign-out or tab close; the server accepts an account session for no more than 4 hours",
      "clearedWhen": "explicit sign-out, rejected session, tab close or site-data clearing",
      "recipient": "VoxFrame API"
    },
    {
      "name": "voxframe.account.email",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "active",
      "classification": "functional",
      "contents": "account e-mail address supplied at login",
      "purpose": "prefill the optional account e-mail during the current signed-in tab flow",
      "createdWhen": "account login succeeds with an e-mail address",
      "retention": "until sign-out or tab close",
      "clearedWhen": "explicit sign-out, rejected session, tab close or site-data clearing",
      "recipient": "VoxFrame account page on the same origin; sent to the VoxFrame API during login"
    },
    {
      "name": "voxframe.purchase.delivery-token",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "dormant-checkout-implementation",
      "classification": "strictly-necessary security",
      "contents": "short-lived checkout delivery token",
      "purpose": "retrieve a completed purchase without placing the token in a query string",
      "createdWhen": "only if the dormant web checkout is explicitly re-enabled and checkout creation succeeds",
      "retention": "until checkout success, cancellation, page exit or tab close",
      "clearedWhen": "success, cancellation, page exit, tab close or site-data clearing",
      "recipient": "VoxFrame API"
    },
    {
      "name": "voxframe.purchase.checkout-session",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "dormant-checkout-implementation",
      "classification": "strictly-necessary transaction",
      "contents": "Stripe checkout-session identifier",
      "purpose": "correlate the browser return with the checkout session",
      "createdWhen": "only if the dormant web checkout is explicitly re-enabled and checkout creation succeeds",
      "retention": "until checkout success, cancellation, page exit or tab close",
      "clearedWhen": "success, cancellation, page exit, tab close or site-data clearing",
      "recipient": "VoxFrame account page and VoxFrame API"
    },
    {
      "name": "voxframe.purchase.checkout-request-id",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "dormant-checkout-implementation",
      "classification": "strictly-necessary transaction",
      "contents": "random UUIDv4 request identifier",
      "purpose": "make a retried checkout request idempotent",
      "createdWhen": "only if the dormant web checkout is explicitly re-enabled and a purchase attempt starts",
      "retention": "until checkout success, cancellation, page exit or tab close",
      "clearedWhen": "success, cancellation, page exit, tab close or site-data clearing",
      "recipient": "VoxFrame API"
    },
    {
      "name": "voxframe.purchase.checkout-request-email",
      "surface": "account.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "dormant-checkout-implementation",
      "classification": "strictly-necessary transaction",
      "contents": "normalized account e-mail used for the checkout attempt",
      "purpose": "reuse an idempotency identifier only for the same e-mail address",
      "createdWhen": "only if the dormant web checkout is explicitly re-enabled and a purchase attempt starts",
      "retention": "until checkout success, cancellation, page exit or tab close",
      "clearedWhen": "success, cancellation, page exit, tab close or site-data clearing",
      "recipient": "VoxFrame account page; sent to the VoxFrame API with checkout creation"
    },
    {
      "name": "voxframe.admin.token",
      "surface": "admin.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "active-admin-only",
      "classification": "strictly-necessary security",
      "contents": "short-lived signed admin session token",
      "purpose": "authenticate VoxFrame administration requests",
      "createdWhen": "username, password and TOTP login succeeds, or an explicitly gated break-glass exchange creates a server session",
      "retention": "until sign-out or tab close; the registered server session lasts no more than 60 minutes and an API restart invalidates it",
      "clearedWhen": "sign-out, rejected or expired session, tab close or site-data clearing",
      "recipient": "VoxFrame API"
    },
    {
      "name": "voxframe.admin.username",
      "surface": "admin.voxframeplayer.com",
      "medium": "sessionStorage",
      "status": "active-admin-only",
      "classification": "strictly-necessary administration",
      "contents": "admin username",
      "purpose": "identify and prefill the current admin login within the tab",
      "createdWhen": "an MFA-protected admin session is activated",
      "retention": "until sign-out, a rejected session or tab close",
      "clearedWhen": "sign-out, rejected or expired session, tab close or site-data clearing",
      "recipient": "VoxFrame admin page only"
    }
  ],
  "conditionalThirdParties": [
    {
      "party": "Cloudflare Turnstile",
      "status": "loaded only on support and cancellation forms when server-side bot protection is enabled",
      "when": "when a visitor opens a protected support or cancellation form; an additional challenge result is processed if the check is completed",
      "purpose": "prevent automated form and e-mail abuse",
      "storage": "no VoxFrame tracking or advertising storage; Cloudflare processes the limited browser, network and challenge-result data needed to validate the one-time token"
    },
    {
      "party": "Stripe",
      "status": "not loaded by the current fail-closed account purchase and success pages",
      "when": "only after a future explicit reactivation of embedded checkout, or after the user navigates to Stripe Billing Portal",
      "purpose": "payment, billing, fraud prevention and transaction security",
      "storage": "Stripe may use its own necessary cookies or browser technologies under Stripe's privacy information"
    }
  ],
  "serverProcessingNotes": [
    {
      "surface": "support and cancellation forms",
      "browserStorage": "none",
      "data": "request type, e-mail, optional order reference and date, message, locale and abuse-prevention metadata",
      "note": "form data is submitted directly to the VoxFrame API and is not browser storage"
    },
    {
      "surface": "VoxFrame web servers and API",
      "browserStorage": "none",
      "data": "security logs can contain IP address, request time, route, browser identifier and technical status",
      "note": "server logs are not cookies or browser storage"
    }
  ]
}
