A page can send private information before a user submits a form. Remote scripts, embeds, pixels, and analytics calls can receive URLs, referrers, identifiers, and event properties. Browser storage behavior changes across contexts, so an embedded tool cannot assume unrestricted cookies. This track uses a case-review product with optional analytics and a support widget. The engineering task is to identify each external data path, keep the core review flow usable without it, and apply the product’s approved preference and retention policy consistently.
Topics in this track
- Third-Party Request and Script Inventory — Record what external code and embeds receive before deciding whether they belong on a page.
- Optional Analytics Event Boundaries — Separate operational signals from optional measurement and constrain event fields before collection.
- Embedded Widget Storage and Fallback — Design embeds that work when third-party storage is partitioned or unavailable.
- Preference Change Propagation and Audit — Make optional-data choices take effect across tabs, queues, server events, and later sessions.
Prerequisite paths
Browser Security and Data Stewardship; Data Retention, Export, and Erasure.
Neighbor track
Practice path
Build Project: privacy-safe support and measurement and check decisions in Web Development: accessible content and privacy decisions quiz.
Further connections
Web Push and Notification Delivery.
Further connections
Human Challenges, Accessible Alternatives, and Signal Retention.
