← Files ClaraARCHIVED FILE
privacy/hosted-services/retail-data.json
5.76 KB · Oct 4, 2026 · 12:28 UTC
{
"schema_version": 1,
"service_id": "retail-data",
"display_name": "Mparanza Retail Data and Mapping Service",
"provider_or_recipients": [
"Mparanza Attribute Reporting service"
],
"workflows": [
"attribute-reporting",
"brand-fit"
],
"governed_paths": [
"skills/attribute-reporting/SKILL.md",
"skills/brand-fit/SKILL.md",
"modules/attribute-reporting/skills/attribute-reporting/SKILL.md",
"modules/attribute-reporting/skills/attribute-reporting/references/server-boundary.md",
"modules/attribute-reporting/skills/brand-fit/SKILL.md",
"modules/attribute-reporting/scripts/server_bridge_client.py",
"modules/attribute-reporting/scripts/project_pipeline.py",
"repository/modules/hosted_services/api.py",
"repository/modules/pdp/attribute_reporting_api.py",
"repository/modules/pdp/attribute_reporting_bridge.py",
"repository/modules/pdp/legal_content.py"
],
"trigger": "The user selects the installed current-database Retailer Signals workflow, the downstream Brand Fit workflow, or an explicit development fresh-scrape persistence path.",
"automatic": false,
"data_sent": [
{
"id": "authentication",
"when": "When requesting or consuming a magic link or using a persisted authenticated session",
"content": "Authorized email and redirect path, consumed magic link or Mparanza session cookie, and ordinary connection metadata"
},
{
"id": "retailer-signals-job",
"when": "When requesting taxonomy, evidence packages, or mapping worksets",
"content": "Retailer, category, taxonomy version and hash, evidence job and mapping submission identifiers, mapping mode, and explicit correction reason when used"
},
{
"id": "reviewed-mapping-submission",
"when": "At the explicit authenticated server-write checkpoint",
"content": "Pinned mapping workset identity and hash, idempotency key, complete mapping tasks, Codex decisions, validated mappings, and independent mapping review"
},
{
"id": "brand-fit-job",
"when": "When creating a downstream Brand Fit package",
"content": "Actor-owned source evidence-job identifier, brand source retailer, brand name, source Retailer Signals report SHA-256 and verdict, and optional owned or retailer category aliases; the local report file is not sent"
},
{
"id": "development-scrape-persistence",
"when": "Only when an app_files development run explicitly requests a fresh scrape",
"content": "Structured locally captured retailer listing and product-detail records written to the server-backed database; this upload path is not available in the installed Clara plugin"
}
],
"data_returned": [
{
"id": "taxonomy-and-worksets",
"when": "During Retailer Signals preparation and mapping",
"content": "Published category taxonomy, immutable public mapping worksets, task coverage, source identifiers, mapping acceptance receipts, and sanitization/provenance receipts"
},
{
"id": "retailer-evidence-packages",
"when": "After actor-owned evidence jobs are ready",
"content": "Checksum-bound structured retail records, cohort comparisons, accepted mapping state, package provenance, and public image URLs; packages contain no server paths or image bytes"
},
{
"id": "brand-fit-package",
"when": "After an actor-owned Brand Fit job is ready",
"content": "Checksum-bound current retailer-presence rows, brand-owned catalogue rows, accepted mapping-state snapshot, scope metrics, candidate-product evidence, timestamps, and public image URLs"
}
],
"access": {
"arrangement": "The installed bridge uses an authenticated Mparanza session. Artifacts and jobs are actor-owned and another authenticated user receives no information about whether an artifact exists. The plugin receives no database credentials. Development persistence uses the app_files runtime rather than the installed plugin.",
"controls": [
"The remote bridge accepts only HTTPS mparanza.com or www.mparanza.com outside local tests.",
"A supplied cookie is attached only to the exact approved origin; a persistent cookie jar must be a private 0600 regular file outside run and repository folders.",
"Downloads are size-limited, origin-pinned, content-type checked, checksum-verified, and safely extracted.",
"Mapping writes are transactional, idempotent, and require the complete independently reviewed artifact set."
]
},
"retention": {
"status": "documented",
"statement": "The bridge retains Retailer Signals and Brand Fit evidence jobs, mapping worksets, mapping submissions, central structured product records, taxonomy, accepted mappings, retailer-presence data, and owned-catalogue data as durable service data. The reviewed runtime has no age-based or event-triggered automatic deletion path for these artifacts. Count and byte limits reject new work without deleting retained artifacts."
},
"security_controls": [
{
"id": "report-not-uploaded",
"control": "Local Retailer Signals and Brand Fit HTML, report models, semantic reviews, browser QA, and hydrated image bytes are not uploaded by the installed workflows."
},
{
"id": "source-report-hash-only",
"control": "Brand Fit sends the source report hash, verdict, and actor-owned evidence-job identifier rather than the report file."
},
{
"id": "no-direct-database-access",
"control": "The installed plugin uses the authenticated bridge and never receives direct database credentials."
}
],
"review": {
"reviewed_at": "2026-09-30",
"reviewed_by": "privacy-surface-review",
"basis": "hosted_service_boundary_review_of_source",
"source_fingerprint": "ff4f30f2dfdfcc2e92d0f7dbd1fa895156ec8c68e2951737fe5220643e5d55e8"
}
}
SHA-256: 7eadd761a8c6f8dadbd0f98efa0e8d15596139cfe93c4a3b25dfdbec57c2d3af