Privacy and visitor choices

Privacy Policy

This policy describes Lawscope’s current public-site data practices, including what visitors provide, what the site receives automatically, why information is used, and how visitors can exercise available choices.

Effective
Last updated

1. Scope and responsible entity

This notice applies to the public pages at getlawscope.com, including articles, category pages, search, preferences, and the Contact page. It does not govern a third-party site reached through an external link or an administrator’s separate account with a hosting or content-management provider.

Lawscope is the public publication name used by this notice. The responsible legal operator and postal address have not been supplied or confirmed, so this pre-launch version is kept out of search indexes rather than inventing those facts.

Lawscope publishes general U.S. legal information and does not provide legal advice. Sending a privacy or contact request does not create an attorney-client relationship.

2. Information visitors provide

Lawscope may receive information only when a visitor chooses to provide it:

  • Contact and correction requests: name, email address, subject, message, and an optional article URL.
  • Privacy requests: contact details, the right requested, residence or jurisdiction information needed to assess the request, and limited verification information.
  • Newsletter signup: an email address and confirmation status if that feature is activated.
  • Other voluntary details: information a visitor includes in a message. Visitors should not send legal secrets, government identifiers, financial details, health records, passwords, or time-sensitive case facts.

The current Contact form and newsletter controls do not transmit or store information while their monitored providers are unconfigured. The interface explains when a form is unavailable rather than silently collecting a submission.

3. Information collected automatically

When a browser requests a Lawscope page, normal internet delivery can expose the IP address, date and time, requested URL, referring page, browser and device information, approximate location inferred from an IP address, response status, and security or reliability events to the hosting and network providers. These facts may appear in infrastructure logs even when optional analytics and advertising are off.

The site’s search index is a static file fetched by the browser. Search matching runs locally: Lawscope does not intentionally transmit or retain the search phrase as an analytics event. A click on a third-party link causes a separate request to that third party under its own practices.

5. Cookies and similar technologies

Lawscope’s current first-party controls use browser local storage rather than a first-party tracking cookie. The key lawscope-theme stores only an explicit light or dark choice. The key lawscope:consent stores a revision number and essential, analytics, and advertising booleans. It contains no name, email, visitor ID, timestamp, IP address, page history, or search phrase.

Theme information remains until the visitor changes it, clears browser storage, or the browser removes it. Consent information remains until it is changed, cleared, or made obsolete by a policy revision. If storage is unavailable, the site uses conservative session defaults and does not treat optional categories as approved.

Manage privacy choices

Review or withdraw optional analytics and advertising choices at any time on this device.

6. Advertising and partners

Current status: inactive. Lawscope includes a local consent-aware Google AdSense adapter, but this build does not request Google’s advertising script, create an ad unit, or set an advertising cookie. Public identifiers remain inert placeholders, and advertising components are omitted from this legal page.

The planned provider is Google AdSense. Depending on the visitor’s choices, location, Google’s account controls, and applicable law, Google may serve personalized, non-personalized, or limited ads and may use cookies or similar storage for delivery, frequency control, measurement, security, and invalid-traffic prevention. Review Google’s advertising technologies notice, Google’s Privacy Policy, and My Ad Center. Lawscope also requires a Google-certified CMP where Google requires one. Advertising will not load unless the production, approval, identifier, policy, canonical-host, CMP-readiness, and visitor-consent gates are all satisfied.

7. Analytics

Current status: inactive. Lawscope includes a local consent-aware GA4 integration, but this build will not request Google’s tag or send analytics data. Production activation remains off, and the all-X measurement ID is inert.

The provider is Google Analytics 4. Lawscope’s strict opt-in implementation makes no Google Analytics request, sets no GA4 cookie, and sends no consent-mode ping before analytics permission is granted. Development and Preview builds cannot activate the production measurement ID. Advertising storage and signals remain denied, and Google Signals and advertising personalization are disabled.

After permission, the limited measurement set is: one page view; confirmed newsletter signup and Contact-form success events with no form values; category-link activation with a controlled category slug; and an article-read event after 30 foreground seconds and 75% of the article prose. Page locations and referrers omit query strings and fragments. Lawscope does not send names, email addresses, message or search text, contact subjects, form content, or other direct identifiers in event parameters.

The GA4 property must use a two-month event-data retention period, keep enhanced measurement features off unless separately reviewed, apply tested internal- and developer-traffic filters, and enable data redaction as defense in depth before routine production collection. Withdrawing analytics permission stops future collection on that browser; it does not erase information already processed by Google. See Google’s Privacy Policy and Google’s browser opt-out add-on.

8. Newsletter and contact providers

Newsletter: Newsletter signup is inactive, so Lawscope does not currently transmit or retain subscriber email addresses.

Contact: The Contact form is visibly unavailable until a monitored server-side delivery destination and credential are configured; it does not accept messages in this state.

When newsletter delivery is activated, signup will use double opt-in. A subscriber can unsubscribe using the link in each message. Lawscope will identify the sender and state how active subscriptions, unsubscribes, and suppression records are retained before collecting addresses.

The Contact endpoint validates fields again on the server, uses a hidden trap and request throttling, does not write messages to Git, and forwards an accepted message only to a configured server-side HTTPS destination. Delivery credentials never appear in browser code. Downstream provider retention must be confirmed before the form is enabled.

9. Disclosure of information

Lawscope may disclose limited information:

  • to infrastructure and other processors that provide hosting, content delivery, security, communications, or a visitor-requested feature;
  • when reasonably necessary to comply with law or valid process, protect rights and safety, investigate abuse, or defend a legal claim;
  • as part of a merger, financing, reorganization, or transfer of the publication, subject to applicable notice and safeguards; or
  • with the visitor’s direction or consent.

Lawscope does not sell personal information. If this build’s Section 6 status says advertising is available, consented Google AdSense processing may constitute targeted advertising, sharing, or another regulated practice in some jurisdictions. Visitors can deny or withdraw Lawscope’s advertising permission through Privacy Choices and can use the provider controls linked in Section 6. Google Analytics 4 is available only under the production and consent conditions in Section 7, with this build’s status shown there. Lawscope will add any further legally required notice or opt-out method before a covered practice begins.

Current service inventory

The statuses below are generated from the versioned privacy configuration used for this build.

  • Vercel

    Configured dependency Owner confirmation pending

    Purpose: Public-site hosting, delivery, reliability, and security logging

    Retention: No repository-defined period; confirm the production account and provider settings before launch.

    Provider notice: Vercel privacy information

  • Google Fonts

    Configured dependency Owner confirmation pending

    Purpose: Delivery of the Inter and Merriweather font files used by the public interface

    Retention: Controlled by the provider under its terms; Lawscope does not receive a font-request profile.

    Provider notice: Google Fonts privacy information

  • Cloudflare cdnjs

    Configured dependency Owner confirmation pending

    Purpose: Delivery of the Font Awesome 6 icon stylesheet

    Retention: Controlled by the provider under its terms; Lawscope does not receive a CDN-request profile.

    Provider notice: Cloudflare cdnjs privacy information

  • Not selected

    Inactive

    Purpose: Forwarding Contact form messages to a monitored Lawscope support destination

    Retention: No downstream period can be stated until the monitored delivery provider is selected.

    Provider notice: Not selected

  • Google Analytics 4

    Inactive Owner confirmation pending

    Purpose: Consent-based audience measurement using a deliberately limited event set

    Retention: The production GA4 property must be confirmed at the two-month event-data retention setting before activation; aggregated reports may persist until deleted under the account policy.

    Provider notice: Google Analytics 4 privacy information

  • Google AdSense

    Inactive Owner confirmation pending

    Purpose: Consent-based responsive advertising, delivery measurement, frequency controls, and invalid-traffic protection after separate approval

    Retention: No AdSense request is made while inactive. Before activation, the owner must confirm Google’s current account controls, partner disclosures, consent configuration, retention practices, and applicable opt-out routes.

    Provider notice: Google AdSense privacy information

  • Not selected

    Inactive

    Purpose: Optional double-opt-in newsletter delivery

    Retention: No subscriber email is collected while the feature remains inactive.

    Provider notice: Not selected

10. U.S. state privacy rights

Depending on residence, the type and amount of processing, and whether a law applies to Lawscope, a visitor may have rights to know or access information, correct inaccuracies, delete information, receive a portable copy, opt out of sale, sharing, or targeted advertising, limit certain sensitive-data uses, and appeal a denied request. Some laws also protect visitors from discriminatory treatment for exercising a right.

This list does not claim that every state right applies in every situation. Lawscope will evaluate a request under the law that applies, explain a material denial where required, and provide an appeal route where available. An authorized agent may submit a request if legally permitted and if authority can be verified.

11. California notice at collection

Identifiers

IP address and, only when submitted, name and email address. Used for site delivery, security, responses, and activated subscriptions.

Internet or network activity

Requested page, referrer, browser/device facts, service logs, and local preference state. Used for delivery, security, reliability, and consented measurement if activated.

Approximate geolocation

A coarse area may be inferred by infrastructure providers from an IP address for delivery, security, or regional behavior. Lawscope does not request precise location.

Submission contents

A message and optional article URL submitted through Contact. Used to respond to the selected inquiry and maintain necessary request records.

Lawscope does not intend to collect sensitive personal information through public forms and asks visitors not to submit it. Current sale and sharing status is “none active.” Retention follows the criteria in Section 13. Requests use the process in Section 20.

12. EEA, UK, and Swiss rights

If data-protection law in the European Economic Area, United Kingdom, or Switzerland applies, a visitor may have rights of access, correction, erasure, restriction, objection, and portability, and may withdraw consent for future processing. A visitor may also complain to the competent supervisory authority. Rights can be limited by exemptions and the circumstances of a request.

The controller is the responsible Lawscope operator identified in Section 1. The purposes and possible legal bases are described in Section 4. Lawscope does not use solely automated decisions that produce legal or similarly significant effects in the current public-site configuration.

13. Data retention

Lawscope keeps information only for the period reasonably needed for the disclosed purpose, security, legal obligations, dispute handling, and request records. Where the final period depends on an account or provider that has not been selected, this policy states that limit rather than inventing a duration.

  • Theme and consent state: on the visitor’s device until changed, cleared, browser-removed, or invalidated by a revision.
  • Contact request in the endpoint: processed in memory for validation and forwarding; not written by the endpoint to Git or an application database.
  • Abuse-control key: a pseudonymous HMAC-derived rate-limit key held only in server memory for a ten-minute window; it is not exposed in a response.
  • Forwarded messages: provider and owner-approved period must be configured before monitored delivery is enabled.
  • Hosting and security logs: governed by confirmed production provider/account settings; the repository does not set a custom period.
  • Analytics: none is collected while inactive; after consent-based activation, the GA4 property must use a two-month event-data retention setting.
  • Advertising and newsletter data: no newsletter data is collected while that feature is inactive. AdSense makes no request while advertising is inactive; after a fully gated, consented activation, Google’s current provider terms and configured account controls govern its advertising-data retention.

14. Data security

Lawscope uses reasonable administrative, technical, and organizational measures suited to the site, including HTTPS deployment, server-side form validation, bounded requests, same-origin endpoints, abuse controls, environment-only secrets, limited data flows, dependency review, and separation of public content from submitted personal information.

No internet transmission, storage system, or security control is guaranteed to be completely secure. Visitors should avoid sending confidential legal facts or urgent information through public forms and should use an appropriate qualified professional or authority for legal and emergency matters.

15. Children’s privacy

Lawscope is a general-audience legal information publication and is not directed to children under 13. Lawscope does not knowingly collect personal information from a child under 13. A parent or guardian who believes a child supplied information may use the privacy-request process in Section 20 so Lawscope can investigate and delete information where appropriate.

16. Do Not Track and Global Privacy Control

Browser Do Not Track signals are not consistently defined, so the current preference controller does not assign them a separate state. Global Privacy Control is treated as a direction to keep advertising permission off on that device; the advertising control is disabled while the signal is active. Optional technologies also remain off until the visitor affirmatively chooses them.

17. International transfers

Lawscope is a U.S.-focused publication. Public-site information may be processed in the United States or other locations where hosting, network, font, icon, and future approved communications providers operate. Those locations may have data-protection rules that differ from a visitor’s jurisdiction.

Where law requires a transfer mechanism, the responsible operator will use an available safeguard such as an adequacy decision, contractual protection, or another lawful basis. Provider locations and safeguards must be confirmed before a data-collecting optional service is activated.

19. Policy changes

Lawscope will update the “Last updated” date when this notice materially changes. If a change materially expands collection or use, Lawscope will provide notice appropriate to the change and obtain consent where required before applying it. Prior versions and the reason for material revisions should be retained in publication records.

Material revision record

Initial pre-launch publication describing Lawscope’s implemented default data flows and activation safeguards.

20. Contact and rights requests

To ask a privacy question or request access, correction, deletion, portability, an applicable opt-out, or an appeal, use the Lawscope Contact page and choose Privacy request. Do not include passwords, government identifiers, complete financial account details, or confidential legal facts.

Lawscope may ask for information reasonably necessary to match a request with available records, confirm identity, protect against fraud, or verify an authorized agent. Any verification information will be limited to the request and handled under this policy. Lawscope will respond within the period required by applicable law or explain if an extension is permitted and needed.