| Seller authority | Use a non-sensitive status such as seller authority summary recorded by owner. | Signed seller approval, written authorization, seller agreement exhibit, or owner approval note. | Ask counsel before using this proof for paid seller onboarding, titled assets, broker authority, or indemnity language. | Do not store signed contracts, private IDs, title documents, private emails, or unredacted proof in public repo docs. |
| Source file or export | Use a source class, source channel, row count, and owner-reviewed status without private links or tokens. | Raw files, source export, field map, import validation output, and cleanup notes in the approved owner-controlled folder. | Review reuse permission when the source is a third-party platform, supplier feed, dealer website, or marketplace export. | Do not store tokenized links, passwords, private customer rows, vendor cost, buyer lists, or private operational exports in repo docs. |
| Photo and media rights | Use photo-rights status, media source class, and review state without exposing original private evidence. | Original photo folder, seller approval, media permission note, image-source map, and redaction notes. | Ask counsel before using media beyond listing/search pages, such as widgets, advertising, social previews, or seller reporting. | Do not store unapproved marketplace photos, customer paperwork, private documents, license-plate-sensitive images, or unredacted media proof in public docs. |
| Source URL and marketplace-export permission | Use source URL policy, source channel, and permission-confirmed summary without copying restricted content. | Owner export proof, source URL list, approved API/export note, platform-permission record, or seller reuse permission. | Review platform terms before production use of marketplace pages, supplier catalogs, scraped pages, API data, or feed reuse. | Do not crawl, scrape, or copy third-party marketplace pages for production imports without explicit permission and reuse rights. |
| Contact route and update owner | Use public business contact route, branch owner, and refresh cadence summary only. | Seller-approved lead recipient, branch routing note, update-owner note, stale review cadence, and owner approval. | Review consent and privacy language before sharing buyer details, wanted requests, call/SMS attribution, CRM delivery, or seller notifications. | Do not store private employee contacts, customer contacts, buyer PII, call recordings, SMS consent data, or CRM credentials in public docs. |
| Sensitive-data exclusions | Use a simple excluded-data status such as sensitive material excluded from repo and public pages. | Only store sensitive evidence in the approved owner-controlled location when the owner and policy allow retention. | Ask counsel or the owner before retaining contracts, buyer/customer records, employee contacts, payment records, bank data, or regulated documents. | Never store secrets, passwords, API keys, payment data, bank data, private buyer lists, private customer records, or unredacted permission evidence in repo docs. |