AlmaLinux / AlmaLinux/almalinux.org

Make AlmaLinux.org more privacy friendly

オープン
#409 コメント 4 件 リアクション 2 件 担当者 2 名 @bennyvasquez が担当を希望しています GitHub で見る
enhancement
主要言語
HTML
スター
53
フォーク
70
平均マージ
19時間 19分
マージ済み PR(30日)
5

説明

### Change the following Matomo settings to increase the privacy of visitors by restricting & anonymizing the data we collect

**Proposed changes:**

* Anonymize Visitors' IP addresses
* Force tracking without cookies
> Enabling this option will automatically update matomo.js, so it contains some additional code to ensure all trackers won't use cookies. Additionally Matomo will ignore all tracking cookies on server side.
* Remove query parameters from referrer (ex, visiting from hawkhost.com/some-secret-portal?sid=12983719kawdkjaweq would strip the latter portion)
* Regularly delete old raw data from the database (proposed: 90 or 180)
* Delete old aggregated report data (proposed: 90 or 180)
* Anonymize previously tracked raw data
* IP Addresses
* Locations (Re-evaluates the location based on the anonymized IP (at least 2 bytes of the IP will be anonymized))

### Cookie consent

While they're annoying, we should display a cookie consent banner if we are setting any cookies (EX, Matomo [1]). We should consider if we want this to be a global change or only be displayed for individuals in countries with GDPR, etc).

We can utilize some of Matomos' built-in functionality for this, as well as instructions using other consent managers: https://developer.matomo.org/guides/tracking-consent.

It is worth noting that if we implement the anonymization changes proposed above, French visitors don't need to be offered a tracking consent popup: https://matomo.org/faq/how-to/how-do-i-configure-matomo-without-tracking-consent-for-french-visitors-cnil-exemption/

[1] We need to verify what cookies are being set. We need to re-evaluate this if we opt to set `Force tracking without cookies`

### Create a privacy policy & tell users exactly what data is collected and how it is utilized

The scope of this is beyond just AlmaLinux.org, but this is a good starting point. Here is a list of data Matomo collects by default (which would be far less if we implement the changes above).

https://developer.matomo.org/guides/tracking-consent

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。