Create a data map

List every form field, uploaded document, API payload, database table, analytics event, and downstream provider. Classify sensitive and regulated information.

Use least privilege

Grant each integration only the records and actions required. Separate public keys, user tokens, administrative credentials, and service-role secrets.

Document consent and purpose

Explain why data is collected and how it is shared. Marketing consent should not be buried inside unrelated funding authorization.

Set retention and deletion

Define how long applications, documents, logs, analytics identifiers, and backups remain, plus how verified deletion requests are handled.

Design visible failure states

A failed webhook or upload should create an actionable alert and preserve the submission where possible. Never display success when the system cannot confirm delivery.