Skip to main content

Internal

Privacy Audit Summary

Last technical review: August 8, 2026

This page is a point-in-time technical inventory of the client-side behavior of this site as of the review date above. It is not legal advice, a certification, an audit opinion, or a guarantee of compliance with any law, regulation, or framework. Behavior may change when the site or a provider changes. The governing descriptions for visitors are in the Privacy Policy and the Cookie Policy.

Cookies observed

  • None set by application code.
  • Cloudflare network-security and bot-management cookies, such as __cf_bm, may be set by the network layer on any route. Strictly necessary. Not used for advertising or cross-site tracking.
  • Cloudflare Turnstile may set short-lived challenge cookies in connection with the widget rendered on /contact. Strictly necessary.

Local storage used by this site

  • dwc-cookie-consent-v2: stores the visitor preference record (analytics, marketing, personalization flags, detected GPC state, timestamp). Browser local storage, not a cookie. Persists until cleared by the visitor or the browser.

Third-party requests

  • Cloudflare Turnstile (challenges.cloudflare.com): bot protection script. Strictly necessary. Loaded only on /contact.
  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com): stylesheet and font file requests for the site typeface. These requests make the visitor internet protocol address and standard request headers visible to that service. Whether the provider sets any cookie is controlled by the provider. No analytics or advertising identifier is sent with these requests.

Backend recipients of form data

  • Contact form submissions are transmitted to the application backend and stored in a hosted database (Supabase).
  • Transactional confirmation and internal notification email is sent through the Lovable email infrastructure.
  • Application hosting is provided by Lovable, with Cloudflare in front for network delivery and security.

Scripts requiring consent

  • None at this time. Any future non-essential script must be registered with the consent manager and gated on the appropriate category before it loads.

Consent storage

Preferences are stored in browser localStorage under the key dwc-cookie-consent-v2. The consent manager emits a dwc-consent-changed window event that future script loaders must subscribe to. Because no optional vendor currently operates, an accept selection loads nothing and records a preference only.

Global Privacy Control

When navigator.globalPrivacyControl === true, the marketing and personalization categories are shown as off, are disabled in the preference dialog, and are persisted as off for a custom save and for the accept action. The dialog displays a notice acknowledging the signal.

Confirmations

  • Google Analytics is not used.
  • Meta Pixel is not used.
  • TikTok Pixel is not used.
  • Google Ads remarketing is not used.
  • Microsoft / Bing Ads tracking is not used.
  • Session replay, heatmaps, mouse tracking, scroll tracking, and behavior recording are not used.
  • Fingerprinting scripts are not used.
  • No chat widget is installed.
  • No non-essential cookies are set before consent.
  • Form contents are not sent to analytics or advertising platforms, and are not written to browser storage, URLs, or console output.
  • No first-party or proxied page-hit analytics script is loaded by application code, and no analytics session identifier is generated by application code.
  • Lovable Visitor Analytics is disabled in project settings as of August 8, 2026.
  • A live inspection of https://datawisec.com after the setting change did not observe a ~flock.js script or a /~api/analytics request.

Scope note: this inventory covers behavior produced by the application code in this project. Platform-level analytics were disabled in project settings as of the review date. A future platform, configuration, or deployment change could reintroduce such behavior and must be re-verified.