{"type":"BuyerProtectionDataLifecycleRegister","schemaVersion":"1.0.0","registerVersion":"2026-08-17.1","publishedAt":"2026-08-17T00:00:00.000Z","stage":"pre_pilot","scope":"Purpose, storage, lifecycle, deletion capability, backup consequence and unresolved approval state for BuyerProtection-held data.","summary":{"datasets":41,"transientDatasetsWithGuardedSweep":4,"datasetsWithoutApprovedAutomaticSchedule":37,"legalHoldConfigurationValid":true,"productionAutomaticPurgeScheduled":false,"accountableScheduleFullyApproved":false,"backupDeletionPropagationVerified":false},"datasets":[{"id":"merchant_accounts","name":"Merchant accounts","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_merchants","dataCategories":["email","name","company","domain","ABN","phone","password hash","account metadata"],"subjects":["merchant principals"],"purpose":"Operate the merchant account and bind its business identity.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"controlled_privacy_rights_execution_after_verified_identity_scope_human_decision_and_evidence","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_sessions","name":"Merchant sessions","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_sessions","dataCategories":["hashed session token","merchant ID","principal and role metadata","timestamps"],"subjects":["merchant principals"],"purpose":"Authenticate a bounded merchant session.","classification":"personal_and_confidential","lifecycle":"expires_at","enforcement":"expiry_checked_on_read_and_guarded_sweep_available","deletionCapability":"automatic_expiry_or_session_revocation","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"login_links","name":"One-time login and verification links","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_login_links","dataCategories":["email","hashed token","merchant ID","purpose","timestamps","bounded metadata"],"subjects":["merchant principals"],"purpose":"Verify signup email or recover account access.","classification":"personal_and_confidential","lifecycle":"expires_at_plus_7_days","enforcement":"single_use_expiry_and_guarded_sweep_available","deletionCapability":"automatic_guarded_transient_sweep","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"login_attempts","name":"Authentication attempts","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_login_attempts","dataCategories":["email","IP hash","success state","reason","user-agent metadata"],"subjects":["merchant principals"],"purpose":"Detect and throttle authentication abuse.","classification":"personal_and_confidential","lifecycle":"90_days_from_creation","enforcement":"guarded_sweep_available","deletionCapability":"automatic_guarded_transient_sweep","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_consents","name":"Merchant consents","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_consents","dataCategories":["principal email","document version and digest","acceptance time","IP and user-agent hashes"],"subjects":["merchant principals"],"purpose":"Prove the exact terms, scope and principal accepted.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"retain_or_redact_only_after_legal_and_contract_review","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"domain_authority_challenges","name":"Domain-authority challenges","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_domain_authority_challenges","dataCategories":["merchant ID","domain","challenge state","evidence digest","timestamps"],"subjects":["merchant organisations"],"purpose":"Prove authority over the claimed store domain.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"challenge_history_schedule_pending","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"captchas","name":"CAPTCHA challenges","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_captchas","dataCategories":["hashed challenge code","expiry and consumption timestamps"],"subjects":["anonymous users"],"purpose":"Bound automated form abuse.","classification":"personal_and_confidential","lifecycle":"expires_at_plus_1_day","enforcement":"guarded_sweep_available","deletionCapability":"automatic_guarded_transient_sweep","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_sites","name":"Merchant sites","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_merchant_sites","dataCategories":["merchant ID","domain","business name","verification state and reason"],"subjects":["merchant organisations"],"purpose":"Bind a merchant to its official domain and public verification decision.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"merchant_or_maintenance_workflow_required","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_certificates","name":"Merchant certificate records","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_merchant_certificates","dataCategories":["merchant ID","domain","certificate state","evidence and metadata"],"subjects":["merchant organisations"],"purpose":"Retain the evidence state behind a merchant certificate.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"merchant_or_maintenance_workflow_required","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"trustedsite_events","name":"TrustedSite operational events","storeType":"sqlite_table","storeRef":"trustedsite_state:trustedsite_au_events","dataCategories":["merchant ID","domain","event type","order reference","amount","bounded payload"],"subjects":["merchant organisations","orders"],"purpose":"Support current merchant proof and order-state decisions.","classification":"personal_and_confidential","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"merchant_or_maintenance_workflow_required","backupConsequence":"A live-table deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"product_analytics","name":"Product analytics events","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-events.jsonl","dataCategories":["pseudonymous session ID","IP hash","user agent","page and action metadata"],"subjects":["site visitors"],"purpose":"Measure product use and diagnose funnel failures.","classification":"pseudonymous_personal_information","lifecycle":"90_day_schedule_proposed_not_approved","enforcement":"not_automatically_enforced","deletionCapability":"atomic_rewrite_not_yet_scheduled","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_applications","name":"Merchant applications and decisions","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-applications.jsonl","dataCategories":["merchant contact and business identity","commercial volume","operational evidence","human decision"],"subjects":["merchant principals","merchant organisations"],"purpose":"Review a merchant application without automatically activating protection.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"enterprise_inquiries","name":"Enterprise inquiries","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-enterprise-inquiries.jsonl","dataCategories":["contact identity","organisation","commercial problem","validation question"],"subjects":["prospective partner contacts"],"purpose":"Route a named institutional inquiry.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"enterprise_pipeline","name":"Enterprise ownership and pilot pipeline","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-enterprise-pipeline.jsonl","dataCategories":["inquiry digest","accountable owner","response proof metadata","next action","deal stage","authority and agreement references","hash-chain evidence"],"subjects":["prospective partner contacts","operators","institutional counterparties"],"purpose":"Own enterprise demand, distinguish routing from response and prevent a pilot or commercial outcome being recorded without evidence.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_commercial_decision_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"enterprise_authority","name":"Enterprise authority artifact ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-enterprise-authority.jsonl","dataCategories":["inquiry ID","document digest and controlled storage reference","issuer","authority scope","merchant scope","effective window","revocation evidence","operator identity"],"subjects":["prospective partner contacts","merchant organisations","operators","institutional counterparties"],"purpose":"Prevent an enterprise pilot or agreement stage from relying on an invented reference by binding the exact document digest, scope, current state and revocation history.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_authority_and_revocation_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"trust_inquiries","name":"Trust, privacy, security and complaint inquiries","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-trust-inquiries.jsonl","dataCategories":["contact identity","organisation","relationship","request details and references"],"subjects":["requestors"],"purpose":"Route privacy, security, complaint, accessibility and procurement requests.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"privacy_rights","name":"Privacy rights case ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-privacy-rights.jsonl","dataCategories":["requestor identity and authority claim","record scope","evidence references and digests","human decisions","provider/backup task state","response and closure evidence"],"subjects":["buyers","merchant principals","authorised representatives","operators"],"purpose":"Separate privacy-request intake, identity, scope, decision, execution evidence, response and closure.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"case_record_schedule_pending_preserve_decision_and_legal_hold_evidence","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"partner_referrals","name":"Partner referral events","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-partner-referrals.jsonl","dataCategories":["partner and cohort references","merchant milestone","aggregate consent metadata"],"subjects":["partners","merchant organisations"],"purpose":"Attribute a consented merchant-introduction milestone.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"order_passports","name":"Order Passport records","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-order-passports.jsonl","dataCategories":["merchant and order references","field-minimised order evidence","status history","access expiry"],"subjects":["orders","merchant organisations"],"purpose":"Give the authorised buyer a private time-bounded order evidence view.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"resolution_cases","name":"Resolution cases","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-resolution-cases.jsonl","dataCategories":["case and order references","merchant evidence","decision and resolution history"],"subjects":["buyers","orders","merchant organisations"],"purpose":"Reconstruct and resolve an order problem.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"value_ledger","name":"Commercial value ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-value-ledger.jsonl","dataCategories":["merchant/cohort references","measured values","method and reviewer evidence"],"subjects":["merchant organisations","partners"],"purpose":"Retain only independently reconcilable commercial outcome evidence.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"reviewer_attestations","name":"Independent reviewer attestations","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-reviewer-attestations.jsonl","dataCategories":["reviewer identity","method","evidence digests","finding and outcome claims"],"subjects":["reviewers","merchant organisations"],"purpose":"Verify an independent review against an exact evidence packet.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"security_assessments","name":"Independent security-assessment claims","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-security-assessments.jsonl","dataCategories":["assessor identity","candidate/scope/report digests","finding counts","signed decision"],"subjects":["assessors"],"purpose":"Verify an independent security decision against the current candidate.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"admin_audit","name":"Privileged-access audit ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-admin-audit.jsonl","dataCategories":["operator key ID and display name","scope","route","result","hash-chain evidence"],"subjects":["operators"],"purpose":"Make privileged access and decisions reconstructable.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_security_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"billing_events","name":"Billing event evidence","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-billing-events.jsonl","dataCategories":["provider object references","subscription/payment/refund/payout state","amount and currency","hash-chain evidence"],"subjects":["merchant organisations"],"purpose":"Apply signed provider events without treating them as bank settlement.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_financial_control_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"billing_settlements","name":"Billing payout settlement evidence","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-billing-settlements.jsonl","dataCategories":["payout event digest","amount and currency","bank-evidence references and digests","separate operator decision","reversal evidence","hash-chain evidence"],"subjects":["merchant organisations","operators"],"purpose":"Keep provider-paid, prepared bank evidence, separate reconciliation and later reversal as distinct states without storing statements or account numbers.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_financial_control_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"agent_quotes","name":"Agent quote and payment-intent evidence","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-agent-quotes.jsonl","dataCategories":["agent principal","merchant/order references","quote expiry","payment status"],"subjects":["agent principals","merchant organisations","orders"],"purpose":"Bind one agent request to a short-lived offer and its observed outcome.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"commerce_connections","name":"Controlled Shopify connections","storeType":"atomic_json","storeRef":"application_state:buyerprotection-commerce-connections.json","dataCategories":["merchant ID","shop domain","encrypted/scoped access credential","scope and lifecycle state"],"subjects":["merchant organisations"],"purpose":"Operate the controlled read-only Shopify source.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"revoke_then_redact_connection","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"commerce_source_events","name":"Field-minimised commerce source events","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-commerce-source-events.jsonl","dataCategories":["merchant and shop references","order/fulfilment/refund state","source timestamps","integrity metadata"],"subjects":["orders","merchant organisations"],"purpose":"Prove the observation window and current commerce evidence.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"shop_redact_physically_rewrites_store","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"descriptor_registry","name":"Merchant payment descriptors","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-descriptor-registry.jsonl","dataCategories":["merchant and shop references","asserted/approved descriptor","decision history"],"subjects":["merchant organisations"],"purpose":"Help a buyer recognise a merchant payment descriptor.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"shop_redact_physically_rewrites_store","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"pilot_cohort","name":"Pilot cohort and consent ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-pilot-cohort.jsonl","dataCategories":["merchant/shop references","pilot status","principal consent","withdrawal and review state"],"subjects":["merchant principals","merchant organisations"],"purpose":"Prove current authority for a bounded pilot.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"withdraw_then_shop_redact_or_reviewed_retention","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"shopify_public_connections","name":"Public Shopify app connections","storeType":"atomic_json","storeRef":"application_state:buyerprotection-shopify-public-connections.json","dataCategories":["merchant ID","shop domain","encrypted offline credential","billing and privacy lifecycle"],"subjects":["merchant organisations"],"purpose":"Operate the separately controlled public Shopify app candidate.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"uninstall_revoke_and_shop_redact","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"capacity_ledger","name":"Protection capacity ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-capacity-ledger.jsonl","dataCategories":["merchant/application references","capacity allocation and release evidence"],"subjects":["merchant organisations"],"purpose":"Prevent promises beyond backed and approved capacity.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"credential_revocations","name":"Merchant credential revocations","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-trust-credential-revocations.jsonl","dataCategories":["credential and merchant references","revocation time and reason"],"subjects":["merchant organisations"],"purpose":"Keep a revoked public credential from becoming valid again.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"official_registry","name":"TrustedSite Official Registry","storeType":"append_only_jsonl","storeRef":"application_state:trustedsite-official-registry.jsonl","dataCategories":["merchant ID","official domains and assets","authority evidence","decision/revocation history"],"subjects":["merchant principals","merchant organisations"],"purpose":"Publish only merchant-authorised official-domain facts.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"brand_watch","name":"Private Brand Watch candidates","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-brand-watch.jsonl","dataCategories":["merchant/brand references","candidate domains","source and feature evidence","alert state"],"subjects":["merchant organisations","domain operators"],"purpose":"Privately surface candidates for human review without publishing a fraud verdict.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"incident_desk","name":"Brand incident decisions and actions","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-incident-desk.jsonl","dataCategories":["candidate/case references","human classification","evidence","appeal and action history"],"subjects":["merchant organisations","domain operators","reviewers"],"purpose":"Separate classification, appeal, merchant approval and authorised external action.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"merchant_assurance_queries","name":"Merchant Assurance queries","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-merchant-assurance-queries.jsonl","dataCategories":["partner principal","merchant/domain query","purpose","returned evidence digest"],"subjects":["partner principals","merchant organisations"],"purpose":"Audit a permissioned partner lookup without outsourcing the partner's decision.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"maintenance_window_rewrite_required","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"institutional_access","name":"Institutional tenant, subject and merchant-authority ledger","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-institutional-access.jsonl","dataCategories":["institution identity and exact OIDC issuer","HMAC-pseudonymised subject","purpose and role","merchant authority and consent digest","effective and expiry times","operator decision","hash-chain evidence"],"subjects":["institutional counterparties","institutional analysts","merchant organisations","operators"],"purpose":"Release a bounded merchant assurance response only when institution, named subject, purpose and merchant authority are all current.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_authority_revocation_and_security_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"data_lifecycle_receipts","name":"Data lifecycle deletion receipts","storeType":"append_only_jsonl","storeRef":"application_state:buyerprotection-data-lifecycle-receipts.jsonl","dataCategories":["operator key ID","reason","dataset counts","legal-hold state","hash-chain evidence"],"subjects":["operators"],"purpose":"Prove what a guarded transient purge did without retaining deleted identities.","classification":"confidential_operational","lifecycle":"schedule_pending_accountable_approval","enforcement":"not_automatically_enforced","deletionCapability":"append_only_control_record_schedule_pending","backupConsequence":"A live-store deletion does not remove an encrypted backup copy; backup expiry or beyond-use controls remain separate.","legalHoldEligible":true},{"id":"encrypted_local_backups","name":"Encrypted local state backups","storeType":"encrypted_archive_directory","storeRef":"application_state:backups","dataCategories":["encrypted copy of application state","manifest and checksum"],"subjects":["all subjects present in the backed-up state"],"purpose":"Recover the service after corruption or operator error.","classification":"encrypted_recovery_copy","lifecycle":"backup_expiry_and_beyond_use_schedule_not_approved","enforcement":"not_automatically_enforced","deletionCapability":"separate_backup_expiry_and_key_destruction_workflow_required","backupConsequence":"This is the backup copy itself; a live-store deletion remains recoverable here until expiry, destruction or verified beyond-use.","legalHoldEligible":true}],"transientSweep":{"mode":"guarded_operator_execution_only","confirmation":"DELETE EXPIRED TRANSIENT RECORDS","datasets":["merchant_sessions","login_links","captchas","login_attempts"],"publicExecutionEndpoint":false,"productionScheduleEnabled":false},"boundaries":["A published lifecycle is not a counsel-approved retention period or proof that every historic copy was destroyed.","A live-store deletion does not remove encrypted backup copies, provider-held copies or historic deployment artifacts.","Legal holds fail closed: invalid hold configuration blocks deletion execution.","Append-only evidence stores are not rewritten by an online cron because an uncoordinated rewrite could lose concurrent writes.","Access, correction, deletion, litigation hold, regulatory retention and incident response remain separate accountable decisions."],"links":{"privacy":"https://buyerprotection.com.au/privacy","dataProcessing":"https://buyerprotection.com.au/data-processing","serviceProviders":"https://buyerprotection.com.au/.well-known/buyerprotection/service-providers.json","evidenceIndex":"https://buyerprotection.com.au/.well-known/buyerprotection/trust-centre.json","schema":"https://buyerprotection.com.au/schemas/data-lifecycle-register/v1","contact":"https://buyerprotection.com.au/contact?intent=privacy"},"registerId":"bpdlr_199ee47474609dedbc7ccbe6","digestAlgorithm":"sha256_recursive_key_sort_json_v1","registerDigest":"sha256:199ee47474609dedbc7ccbe60ecbff169f61713a26ec5e28480237a3b7b1510b"}