Credential custody, webhook signatures, secrets rotation, abuse prevention, retries/idempotency, human approvals, third-party store content, source mapping, robots/directives, DNS/domain owner obligations, intellectual property licenses, usage cap and external provider boundaries.
Functional scope: site/pages, blog, forms, storefront, checkout experience, branding, domains and publishing.
Primary public legal pages: Terms; Privacy; Cookie Policy; AUP; Messaging & Consent.
Legal position: Customer is publisher/merchant. It is responsible for own consumer/store policies, products, claims, cookies, accessibility and lawful form/marketing consent.
Mandatory product controls: Form consent mapping; cookie controls; publish history/rollback; checkout revalidation; deep links to canonical Products/Orders/Payments/SEO.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: customer account, orders, bookings, payments, returns, support and loyalty self-service.
Primary public legal pages: Privacy; Terms; Security; DPA.
Legal position: Strong authentication and tenant/customer isolation. Merchant-specific consumer policies must be shown where relevant; Noxtill policies do not replace merchant terms.
Mandatory product controls: Account verification; privacy controls; session security; lawful invoice/payment display; request history; consent preferences.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
