DC-061: claim for Hermes
CI / Test & Lint (push) Canceled after 0s
CI / Security audit (push) Canceled after 0s

This commit is contained in:
Hermes
2026-08-23 20:20:43 -07:00
parent 65a4d825fb
commit a7a2b70b2d
+6
View File
@@ -351,6 +351,12 @@ Sami explicitly stated he wants email auth as an OPTION alongside TOTP, not a re
### DC-056: ToS + Privacy Policy pages — GDPR-aware, no SOC2/HIPAA for v1.0
- **status:** done
- **owner:** hermes
### DC-061: Remove superseded status/pricing/index.html — dead weight since dashcaddy.net pricing page
- **status:** in-progress
- **owner:** hermes
- **details:** The in-repo `status/pricing/index.html` is served by the status.sami SPA catch-all but duplicates the canonical pricing page now living on the dedicated Next.js marketing site at `dashcaddy.net/pricing`. It has 0 Stripe refs in the current codebase (the marketing site handles checkout). Remove the file to avoid confusion and reduce surface area. No Caddy config change needed — the SPA fallback will serve index.html for /pricing, which is correct behavior (dashboard app handles unknown routes).
- **impact:** Cleaner repo, single source of truth for pricing. Eliminates a stale page that could mislead users who hit status.sami/pricing directly.
- **details:** Two static pages at `/legal/tos` and `/legal/privacy`. ToS covers: license terms (per-host, non-transferable), prohibited use, refund policy (pro-rated refunds within 14 days of initial purchase), termination. Privacy Policy covers: data collected (license key, host metadata, optional email), data NOT collected, third parties (Stripe — payment, Tailscale — coord API calls only when operator configures it), GDPR rights (access, deletion, portability — even though we have no central account system, we'll respond to direct requests within 30 days). No SOC2/HIPAA — that's a v2 conversation.
- **impact:** Legal compliance for taking money. Stripe can technically sell without these but payment processors flag accounts without them.
- **prerequisite:** None.