Privacy-first runtime
Privacy is a runtime property, not a promise in a footer.
The site should avoid collecting personal data when aggregated operational information is enough. A feature that needs visitor-level tracking, third-party profiling, or a consent banner needs a clear reason before it belongs on these sites.
Rule#
Prefer server-side, aggregated, cookieless, and local behaviour. Do not ship third-party runtime code to the browser unless the feature is intentional, disclosed, and reviewed.
Runtime expectations#
- Do not use client-side analytics scripts when server-side measurement is enough.
- Do not set analytics cookies.
- Do not build visitor profiles.
- Do not send full query strings, form content, or personal data to analytics tools.
- Keep JavaScript local unless a third-party runtime dependency is deliberately accepted.
- Keep fonts, images, and core interface assets local.
- Disclose third-party packages that run in the visitor’s browser.
Analytics#
Analytics should answer operational questions: pageviews, referrers, paths, devices, and broad trends. Questions that require tracking a visitor across sessions or sites are out of scope.
Any analytics integration must satisfy these properties:
- Cookieless: no persistent cookies and no identifiers that track visitors across websites
- No personal data: no stored IP addresses, form content, or personally identifiable information
- Aggregated reporting: overall trends, never individual journeys
- Lightweight runtime: a small local script only when a script is required, and no script when server-side measurement is enough
- Data ownership: prefer tools that can be self-hosted or controlled directly
Implementation details belong in Analytics. This page owns the rule.
Review triggers#
Review the privacy rule before adding:
- a new script
- a new analytics event
- a new form integration
- a third-party embed
- a browser package that phones home
- a Cloudflare product that changes request logging, bot controls, or visitor identification