diff --git a/BACKLOG.md b/BACKLOG.md index 262e299..39c6ba9 100644 --- a/BACKLOG.md +++ b/BACKLOG.md @@ -351,6 +351,12 @@ Sami explicitly stated he wants email auth as an OPTION alongside TOTP, not a re ### DC-056: ToS + Privacy Policy pages — GDPR-aware, no SOC2/HIPAA for v1.0 - **status:** done - **owner:** hermes + +### DC-061: Remove superseded status/pricing/index.html — dead weight since dashcaddy.net pricing page +- **status:** in-progress +- **owner:** hermes +- **details:** The in-repo `status/pricing/index.html` is served by the status.sami SPA catch-all but duplicates the canonical pricing page now living on the dedicated Next.js marketing site at `dashcaddy.net/pricing`. It has 0 Stripe refs in the current codebase (the marketing site handles checkout). Remove the file to avoid confusion and reduce surface area. No Caddy config change needed — the SPA fallback will serve index.html for /pricing, which is correct behavior (dashboard app handles unknown routes). +- **impact:** Cleaner repo, single source of truth for pricing. Eliminates a stale page that could mislead users who hit status.sami/pricing directly. - **details:** Two static pages at `/legal/tos` and `/legal/privacy`. ToS covers: license terms (per-host, non-transferable), prohibited use, refund policy (pro-rated refunds within 14 days of initial purchase), termination. Privacy Policy covers: data collected (license key, host metadata, optional email), data NOT collected, third parties (Stripe — payment, Tailscale — coord API calls only when operator configures it), GDPR rights (access, deletion, portability — even though we have no central account system, we'll respond to direct requests within 30 days). No SOC2/HIPAA — that's a v2 conversation. - **impact:** Legal compliance for taking money. Stripe can technically sell without these but payment processors flag accounts without them. - **prerequisite:** None.