Security & data handling
Union intake can be sensitive. Treat it that way.
Grievance facts, member contact details and workplace reports can contain personal or sensitive information. Deployment and access should match the workflow.
This website build
Keep credentials server-side. Keep the claims specific.
HTTPS deployment
Deploy through Netlify HTTPS. Production security still depends on the final domain, account settings and deployment configuration.
Server-side email
The Resend API key is read by a Netlify Function and is not placed in browser JavaScript.
Input controls
The contact endpoint restricts accepted request types, constrains input lengths and uses a honeypot field for basic bot filtering.
No ad tags by default
This build does not include an advertising or analytics tag by default.
Recording / consent notice
A dedicated notice page is included, but the final wording and call behavior must match the jurisdictions and workflow actually used.
Procurement pages
DPA and sub-processor pages are included as review material and must be kept aligned with the final production architecture.
For grievance or organizing intake: decide who can access the information, how long it is retained, and which details are truly necessary before launch.