Privacy policy draft — not effective

Cruz Casino Entertainment first-pilot privacy preparation.

This owner-approved business draft describes a minimized future invitation-only request workflow. Legal review and separate activation approval are still required.

DRAFT — NOT EFFECTIVE — NOT AUTHORIZATION FOR DATA COLLECTION. No effective privacy-policy identity has been assigned. This page does not activate collection, acknowledgment, accounts, quotes, or protected customer features.

1. Planned first-pilot information

If separately approved and activated later, the invitation-only workflow is planned to use only the information needed to review and respond to an event request:

  • Name, email, optional phone number, and contact preference
  • Event type and date, approximate guest count, and requested games or services
  • A planning description and optional budget, timing, duration, venue name, venue city, venue setting, organization, and logistics notes
  • Account and authentication records needed for protected invite-only access
  • Service communications, including a bounded response to a specific information request
  • Security and audit records needed to protect the service and document authorized activity

Unsubmitted planning information will not be persisted to the server. Merely typing into a future form must not create a customer record, autosave a draft, or place planning information in browser storage.

2. Excluded or deferred information

The first pilot will not collect a referral source, street address, customer event name, customer event timezone, payment-card or bank information, tax or government-identification information, contracts or signatures, unrestricted uploads, or other unapproved data.

Payment, employee, payroll, marketing, analytics, advertising, and other future features require their own review and explicit approval; they are not part of this first-pilot privacy draft.

3. Purpose and communications

Planned uses are responding to the request, preparing and discussing event options, providing protected account access, sending service communications, maintaining useful customer and event relationship history, and protecting the service. The first pilot has no analytics, advertising, remarketing, non-essential cookies, marketing email, or marketing SMS. Communications are service communications only.

4. Sensitive-information warning

Do not provide passwords, authentication or recovery codes, payment-card or bank information, government identification numbers, unnecessary medical information, or other credentials or sensitive information not needed for event planning.

The same warning must appear beside applicable free-text planning, logistics, and follow-up fields rather than only on this page.

5. Adults arranging events

The account and request workflow is intended for adults arranging events. This does not mean that the underlying event must be adults-only. Counsel must review the final age wording before this draft becomes effective.

6. Retention categories

Cruz Casino Entertainment expects repeat year-over-year clients and plans to retain useful structured customer and event relationship history while it serves that planning purpose. Follow-up and free-text communications may use a shorter purpose-based rule. Account and authentication records, security and audit records, and temporary or unsubmitted data are separate categories with separate purposes.

Exact measurable retention periods, legal holds, deletion exceptions, and immutable audit-record handling remain pending legal review. This draft does not establish a numeric retention period.

7. Draft manual privacy-request process

The planned initial operating model is a controlled manual process: verified intake; authenticated-account or email-challenge verification where appropriate; search of applicable systems; a hold check; delete, redact, or pseudonymize as permitted; minimal completion evidence; and a response to the requester. Sensitive identity documents must not be collected through ordinary text messages.

Jory Cross is the accountable privacy-policy owner and retention/deletion operations owner. Yolanda Flores is the backup and privacy escalation owner. Response timing will follow applicable law; this draft makes no voluntary fixed response-time promise.

8. Provider and cookie approach

The public draft uses provider and service categories, such as hosting, protected authentication and session services when configured, database, and prepared-but-disabled service communications. Mentioning a category does not mean that a provider or integration is active.

A separate versioned internal named-provider register is planned. Whether category-only public disclosure is legally sufficient, and the final essential-cookie disclosure, remain pending legal review.

9. Acknowledgment and activation boundary

Future protected quote submission and information responses are planned to require acknowledgment tied to the exact approved policy identity. Current controls are disabled presentation only: they collect no acknowledgment and have no handler, state, persistence, RPC, or database field. Legal review must determine whether acknowledgment is sufficient or affirmative consent is required.

An effective policy requires owner approval, legal review, immutable content and identity binding, an approved effective date, and separate public-data activation authorization. Environment variables alone can never supply those approvals. A future deterministic identity may use a Cruz format such as cruz-privacy-v<major>-<YYYY-MM-DD>-sha256-<digest-prefix>, with the full canonical SHA-256 stored and exact matches failing closed. No actual policy identity or effective date is assigned here.