← Files ClaraARCHIVED FILE

privacy/hosted-services/retail-data.json

5.76 KB · Oct 4, 2026 · 12:28 UTC

↓ Download file

{
  "schema_version": 1,
  "service_id": "retail-data",
  "display_name": "Mparanza Retail Data and Mapping Service",
  "provider_or_recipients": [
    "Mparanza Attribute Reporting service"
  ],
  "workflows": [
    "attribute-reporting",
    "brand-fit"
  ],
  "governed_paths": [
    "skills/attribute-reporting/SKILL.md",
    "skills/brand-fit/SKILL.md",
    "modules/attribute-reporting/skills/attribute-reporting/SKILL.md",
    "modules/attribute-reporting/skills/attribute-reporting/references/server-boundary.md",
    "modules/attribute-reporting/skills/brand-fit/SKILL.md",
    "modules/attribute-reporting/scripts/server_bridge_client.py",
    "modules/attribute-reporting/scripts/project_pipeline.py",
    "repository/modules/hosted_services/api.py",
    "repository/modules/pdp/attribute_reporting_api.py",
    "repository/modules/pdp/attribute_reporting_bridge.py",
    "repository/modules/pdp/legal_content.py"
  ],
  "trigger": "The user selects the installed current-database Retailer Signals workflow, the downstream Brand Fit workflow, or an explicit development fresh-scrape persistence path.",
  "automatic": false,
  "data_sent": [
    {
      "id": "authentication",
      "when": "When requesting or consuming a magic link or using a persisted authenticated session",
      "content": "Authorized email and redirect path, consumed magic link or Mparanza session cookie, and ordinary connection metadata"
    },
    {
      "id": "retailer-signals-job",
      "when": "When requesting taxonomy, evidence packages, or mapping worksets",
      "content": "Retailer, category, taxonomy version and hash, evidence job and mapping submission identifiers, mapping mode, and explicit correction reason when used"
    },
    {
      "id": "reviewed-mapping-submission",
      "when": "At the explicit authenticated server-write checkpoint",
      "content": "Pinned mapping workset identity and hash, idempotency key, complete mapping tasks, Codex decisions, validated mappings, and independent mapping review"
    },
    {
      "id": "brand-fit-job",
      "when": "When creating a downstream Brand Fit package",
      "content": "Actor-owned source evidence-job identifier, brand source retailer, brand name, source Retailer Signals report SHA-256 and verdict, and optional owned or retailer category aliases; the local report file is not sent"
    },
    {
      "id": "development-scrape-persistence",
      "when": "Only when an app_files development run explicitly requests a fresh scrape",
      "content": "Structured locally captured retailer listing and product-detail records written to the server-backed database; this upload path is not available in the installed Clara plugin"
    }
  ],
  "data_returned": [
    {
      "id": "taxonomy-and-worksets",
      "when": "During Retailer Signals preparation and mapping",
      "content": "Published category taxonomy, immutable public mapping worksets, task coverage, source identifiers, mapping acceptance receipts, and sanitization/provenance receipts"
    },
    {
      "id": "retailer-evidence-packages",
      "when": "After actor-owned evidence jobs are ready",
      "content": "Checksum-bound structured retail records, cohort comparisons, accepted mapping state, package provenance, and public image URLs; packages contain no server paths or image bytes"
    },
    {
      "id": "brand-fit-package",
      "when": "After an actor-owned Brand Fit job is ready",
      "content": "Checksum-bound current retailer-presence rows, brand-owned catalogue rows, accepted mapping-state snapshot, scope metrics, candidate-product evidence, timestamps, and public image URLs"
    }
  ],
  "access": {
    "arrangement": "The installed bridge uses an authenticated Mparanza session. Artifacts and jobs are actor-owned and another authenticated user receives no information about whether an artifact exists. The plugin receives no database credentials. Development persistence uses the app_files runtime rather than the installed plugin.",
    "controls": [
      "The remote bridge accepts only HTTPS mparanza.com or www.mparanza.com outside local tests.",
      "A supplied cookie is attached only to the exact approved origin; a persistent cookie jar must be a private 0600 regular file outside run and repository folders.",
      "Downloads are size-limited, origin-pinned, content-type checked, checksum-verified, and safely extracted.",
      "Mapping writes are transactional, idempotent, and require the complete independently reviewed artifact set."
    ]
  },
  "retention": {
    "status": "documented",
    "statement": "The bridge retains Retailer Signals and Brand Fit evidence jobs, mapping worksets, mapping submissions, central structured product records, taxonomy, accepted mappings, retailer-presence data, and owned-catalogue data as durable service data. The reviewed runtime has no age-based or event-triggered automatic deletion path for these artifacts. Count and byte limits reject new work without deleting retained artifacts."
  },
  "security_controls": [
    {
      "id": "report-not-uploaded",
      "control": "Local Retailer Signals and Brand Fit HTML, report models, semantic reviews, browser QA, and hydrated image bytes are not uploaded by the installed workflows."
    },
    {
      "id": "source-report-hash-only",
      "control": "Brand Fit sends the source report hash, verdict, and actor-owned evidence-job identifier rather than the report file."
    },
    {
      "id": "no-direct-database-access",
      "control": "The installed plugin uses the authenticated bridge and never receives direct database credentials."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-30",
    "reviewed_by": "privacy-surface-review",
    "basis": "hosted_service_boundary_review_of_source",
    "source_fingerprint": "ff4f30f2dfdfcc2e92d0f7dbd1fa895156ec8c68e2951737fe5220643e5d55e8"
  }
}

SHA-256: 7eadd761a8c6f8dadbd0f98efa0e8d15596139cfe93c4a3b25dfdbec57c2d3af