How to implement P3P policies for Virtual/ Multiple Domains
"Gregory, Trevor" <[email protected]> Mon, 24 Feb 2003 14:07:57 -0500
| Newsgroups | gmane.comp.web.p3p.policy |
|---|---|
| Message-ID | <A3345112699FD41188AC00D0B782CFC70456BBCF@NYC-EX11.doubleclick.net> |
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C2DC38.0AE0F730 Content-Type: text/plain; charset="iso-8859-1" Hi, I'm investigating an issue for a client that is trying to record e-commerce transactions that uses a cookie to pass info back to our system. Basically the client sends out an email from our DARTmail application. Let's say the the domain that the client uses to send the email is news.examplelv.com. Our system uses this domain to mask/ track urls that lead back to the clients main web page. Let's say it is www.client.com <http://www.client.com> . So when the user gets the email, the link www.client.com <http://www.client.com> is masked with news.examplelv.com. When the user clicks on the link, a cookie is set on the user's system for news.examplelv.com and the client is then redirected to www.client.com/examplelv/ <http://www.client.com/examplelv/> Once at this site, the user has the option to browse the site and purchase the clients services. So assume the user purchases the client's services, they then get taken to a Thank you page which contains an image tag that references the cookie from the email domain - news.examplelv.com. When the page makes the image call, the information from the cookie is transferred and our system records the transaction for the client. If the user does not allow cookies to be set, then our system cannot record the purchase. The problem is that the email domain is being blocked because it does not contain a compact privacy policy. The client uses many virtual domains that redirect back to a folder off of their main html page.. so for example they might use examplelv.com, examplenv.com, testat.com, etc.. all of these domains redirect back to client.com/examplelv/ or client.com/examplenv, etc... I was wondering if anyone can shed light on the following questions: 1) If the client owns the third party domain - news.examplelv.com - but this domain is a virtual domain and gets redirected to the clients main site, is there a way to include the privacy policy for news.examplelv.com in the privacy policy being used on the main page? 2) If there isn't a way to do the above, and seeing as the second level domains, examplelv.com, examplenv.com, testat.com, etc.. do not go to a page for those domains, but get redirected back to a folder off of the clients main page .. client.com/examplelv/ , client.com/testat/ .. etc .. Would it be possible to include the privacy policy on the page that is doing the redirection .. I'm not an HTML expert, and I know very little about P3P so I hope my scenario and questions make sense. I've read the P3P implementation guide, but it does not provide me with the information that I need to give back to the client (or at least I cannot make sense of it). I have not used the name of the actual client domains, but if it helps I can supply them.. just let me know if they are needed. Any assistance would be greatly appreciated. Thank you in advance for you help. Regards, Trevor Gregory Technical Services Specialist DART Mail Technology Solution Double Click Inc. Telephones- Tech Support: 416-847-3220 Toll Free: 800-793-6320<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /> http://www.doubleclick.net <http://www.doubleclick.net> DoubleClick builds profitable customer relationships for marketers and publishers through integrated email technology solutions! ------_=_NextPart_001_01C2DC38.0AE0F730 Content-Type: text/html; charset="iso-8859-1" <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <META content="MSHTML 6.00.2800.1141" name=GENERATOR></HEAD> <BODY> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Hi,</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I'm investigating an issue for a client that is trying to record e-commerce transactions that uses a cookie to pass info back to our system.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Basically the client sends out an email from our DARTmail application. Let's say the the domain that the client uses to send the email is news.examplelv.com.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Our system uses this domain to mask/ track urls that lead back to the clients main web page. Let's say it is <A href="http://www.client.com">www.client.com</A>.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>So when the user gets the email, the link <A href="http://www.client.com">www.client.com</A> is masked with news.examplelv.com. When the user clicks on the link, a cookie is set on the user's system for news.examplelv.com and the client is then redirected to <A href="http://www.client.com/examplelv/">www.client.com/examplelv/</A> </SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Once at this site, the user has the option to browse the site and purchase the clients services. So assume the user purchases the client's services, they then get taken to a Thank you page which contains an image tag that references the cookie from the email domain - news.examplelv.com. When the page makes the image call, the information from the cookie is transferred and our system records the transaction for the client. If the user does not allow cookies to be set, then our system cannot record the purchase.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>The problem is that the email domain is being blocked because it does not contain a compact privacy policy. The client uses many virtual domains that redirect back to a folder off of their main html page.. so for example they might use examplelv.com, examplenv.com, testat.com, etc.. all of these domains redirect back to client.com/examplelv/ or client.com/examplenv, etc... </SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I was wondering if anyone can shed light on the following questions:</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>1) If the client owns the third party domain - news.examplelv.com - but this domain is a virtual domain and gets redirected to the clients main site, is there a way to include the privacy policy for news.examplelv.com in the privacy policy being used on the main page?</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>2) If there isn't a way to do the above, and seeing as the second level domains, examplelv.com, examplenv.com, testat.com, etc.. do not go to a page for those domains, but get redirected back to a folder off of the clients main page .. client.com/examplelv/ , client.com/testat/ .. etc .. Would it be possible to include the privacy policy on the page that is doing the redirection .. </SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I'm not an HTML expert, and I know very little about P3P so I hope my scenario and questions make sense. I've read the P3P implementation guide, but it does not provide me with the information that I need to give back to the client (or at least I cannot make sense of it). I have not used the name of the actual client domains, but if it helps I can supply them.. just let me know if they are needed. Any assistance would be greatly appreciated.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Thank you in advance for you help.</SPAN></FONT></DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003></SPAN></FONT> </DIV> <DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Regards,</SPAN></FONT></DIV> <DIV><B><SPAN style="FONT-SIZE: 10pt; COLOR: #000099; FONT-FAMILY: Helvetica">Trevor Gregory</SPAN></B><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><I><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: Helvetica">Technical Services Specialist</SPAN></I><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><B><SPAN style="FONT-SIZE: 10pt; COLOR: #cc0000; FONT-FAMILY: Helvetica">DART</SPAN></B><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica"> Mail Technology Solution<BR><B>Double<SPAN style="COLOR: red"> Click</SPAN> Inc.</B></SPAN><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica">Telephones-<BR>Tech Support:<SPAN style="mso-spacerun: yes"> </SPAN>416-847-3220<BR>Toll Free:<SPAN style="mso-tab-count: 1"> </SPAN>800-793-6320<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></SPAN></DIV> <DIV class=Section1> <P class=MsoNormal><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica"><U><SPAN style="COLOR: blue"><A href="http://www.doubleclick.net">http://www.doubleclick.net</A></SPAN></U></SPAN><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-bidi-font-size: 12.0pt"><BR><SPAN style="COLOR: black">DoubleClick builds profitable customer relationships for marketers and publishers through integrated email technology solutions!</SPAN></SPAN></P></DIV> <DIV> </DIV></BODY></HTML> ------_=_NextPart_001_01C2DC38.0AE0F730--