Privacy Rights and Cookie Operations
Understand how cookie consent, California rights, do-not-sell/share requests, and browser privacy signals are handled.
This guide is past its review date. Validate the workflow before relying on it operationally.
Ownership Model
Myrivo owns the privacy infrastructure that has to behave consistently across storefronts:
Stores own the storefront-facing policy details and the operational follow-through:
- cookie consent storage and analytics gating
- browser privacy signal handling, including Global Privacy Control
- shared request-routing and future suppression plumbing
- privacy contact details
- California/privacy addenda
- manual response handling for store-level privacy requests
- review of explicit opt-out states created from storefront requests
Shopper Information Architecture
Shoppers should encounter privacy controls in predictable places:
Global Privacy Control should be honored automatically when present. It is not a setting shoppers have to discover inside the cookie banner.
- collection notices at checkout, newsletter signup, and review submission
- store-scoped Privacy Policy and Terms pages
- a dedicated privacy request page for rights requests
- a do-not-sell/share entry point that routes into the privacy request flow when enabled
Operator Expectations
Open `Store Settings > Privacy` to manage:
Open `Admin > Legal` to manage:
When a do-not-sell/share request is submitted, Myrivo now keeps both:
If the shopper’s browser also sent Global Privacy Control, that context is shown to operators so support can understand why the opt-out was created.
If a shopper asks whether Myrivo honors browser privacy signals, the answer is `yes`: the platform is responsible for honoring supported signals consistently, while the store remains responsible for policy copy and operational response handling.
- privacy contact fields
- California/privacy addenda
- incoming privacy requests and status updates
- explicit do-not-sell/share states for shopper emails
- shared storefront privacy notice behavior
- California notice visibility
- do-not-sell/share entry-point visibility
- the original request history
- the current explicit opt-out state used for operator follow-through
Related Docs
- `/docs/legal-governance-and-consent-ops`
- `/docs/store-settings-and-policies`
- `/docs/support-operations-and-escalation`