How to implement P3P policies for Virtual/ Multiple Domains

"Gregory, Trevor" <[email protected]> Mon, 24 Feb 2003 14:07:57 -0500
Newsgroups gmane.comp.web.p3p.policy
Message-ID <A3345112699FD41188AC00D0B782CFC70456BBCF@NYC-EX11.doubleclick.net>
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C2DC38.0AE0F730
Content-Type: text/plain;
	charset="iso-8859-1"

Hi,
I'm investigating an issue for a client that is trying to record e-commerce
transactions that uses a cookie to pass info back to our system.
Basically the client sends out an email from our DARTmail application.
Let's say the the domain that the client uses to send the email is
news.examplelv.com.
Our system uses this domain to mask/ track urls that lead back to the
clients main web page.  Let's say it is www.client.com
<http://www.client.com> .
 
So when the user gets the email, the link www.client.com
<http://www.client.com>  is masked with news.examplelv.com.  When the user
clicks on the link, a cookie is set on the user's system for
news.examplelv.com and the client is then redirected to
www.client.com/examplelv/ <http://www.client.com/examplelv/>  
 
Once at this site, the user has the option to browse the site and purchase
the clients services.  So assume the user purchases the client's services,
they then get taken to a Thank you page which contains an image tag that
references the cookie from the email domain - news.examplelv.com.  When the
page makes the image call, the information from the cookie is transferred
and our system records the transaction for the client.  If the user does not
allow cookies to be set, then our system cannot record the purchase.
 
The problem is that the email domain is being blocked because it does not
contain a compact privacy policy.  The client uses many virtual domains that
redirect back to a folder off of their main html page.. so for example they
might use examplelv.com, examplenv.com, testat.com, etc.. all of these
domains redirect back to client.com/examplelv/ or client.com/examplenv,
etc... 
 
I was wondering if anyone can shed light on the following questions:
1) If the client owns the third party domain - news.examplelv.com - but this
domain is a virtual domain and gets redirected to the clients main site, is
there a way to include the privacy policy for news.examplelv.com in the
privacy policy being used on the main page?
 
2) If there isn't a way to do the above, and seeing as the second level
domains, examplelv.com, examplenv.com, testat.com, etc.. do not go to a page
for those domains, but get redirected back to a folder off of the clients
main page .. client.com/examplelv/ , client.com/testat/ .. etc .. Would it
be possible to include the privacy policy on the page that is doing the
redirection .. 
 
I'm not an HTML expert, and I know very little about P3P so I hope my
scenario and questions make sense.  I've read the P3P implementation guide,
but it does not provide me with the information that I need to give back to
the client (or at least I cannot make sense of it).  I have not used the
name of the actual client domains, but if it helps I can supply them.. just
let me know if they are needed.  Any assistance would be greatly
appreciated.
Thank you in advance for you help.
 
Regards,
Trevor Gregory
Technical Services Specialist
DART Mail Technology Solution
Double Click Inc.
Telephones-
Tech Support:  416-847-3220
Toll Free:           800-793-6320<?xml:namespace prefix = o ns =
"urn:schemas-microsoft-com:office:office" />

http://www.doubleclick.net <http://www.doubleclick.net> 

DoubleClick builds profitable customer relationships for marketers and
publishers through integrated email technology solutions!

 

------_=_NextPart_001_01C2DC38.0AE0F730
Content-Type: text/html;
	charset="iso-8859-1"

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">


<META content="MSHTML 6.00.2800.1141" name=GENERATOR></HEAD>
<BODY>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003>Hi,</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I'm investigating an 
issue for a client that is trying to record e-commerce transactions that uses a 
cookie to pass info back to our system.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Basically the client 
sends out an email from our DARTmail application.&nbsp; Let's say the the domain 
that the client uses to send the email is 
news.examplelv.com.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Our system uses this 
domain to mask/ track urls that lead back to the clients main web page.&nbsp; 
Let's say it is <A 
href="http://www.client.com">www.client.com</A>.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>So when the user 
gets the email, the link <A href="http://www.client.com">www.client.com</A> is 
masked with news.examplelv.com.&nbsp; When the user clicks on the link, a cookie 
is set on the user's system for news.examplelv.com and the client is then 
redirected to <A 
href="http://www.client.com/examplelv/">www.client.com/examplelv/</A> 
</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Once at this site, 
the user has the option to browse the site and purchase the clients 
services.&nbsp; So assume the user purchases the client's services, they then 
get taken to a Thank you page which contains an image tag that references the 
cookie from the email domain - news.examplelv.com.&nbsp; When the page makes the 
image call, the information from the cookie is transferred and our system 
records the transaction for the client.&nbsp; If the user does not allow cookies 
to be set, then our system cannot record the purchase.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>The problem is that 
the email domain is being blocked because it does not contain a compact privacy 
policy.&nbsp; The client uses many virtual domains that redirect back to a 
folder off of their main html page.. so for example they might use 
examplelv.com, examplenv.com, testat.com, etc.. all of these domains redirect 
back to client.com/examplelv/ or client.com/examplenv, etc... 
</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I was wondering if 
anyone can shed light on the following questions:</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>1) If the client 
owns the third party domain - news.examplelv.com - but this domain is a virtual 
domain and gets redirected to the clients main site, is there a way to include 
the privacy policy for news.examplelv.com in the privacy policy being used on 
the main page?</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>2) If there isn't a 
way to do the above, and seeing as the second level domains, examplelv.com, 
examplenv.com, testat.com, etc.. do not go to a page for those domains, but get 
redirected back to a folder off of the clients main page .. 
client.com/examplelv/ , client.com/testat/ .. etc .. Would it be possible to 
include the privacy policy on the page that is doing the redirection .. 
</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>I'm not an HTML 
expert, and I know very little about P3P so I hope my scenario and questions 
make sense.&nbsp; I've read the P3P implementation guide, but it does not 
provide me with the information that I need to give back to the client (or at 
least I cannot make sense of it).&nbsp; I have not used the name of the actual 
client domains, but if it helps I can supply them.. just let me know if they are 
needed.&nbsp; Any assistance would be greatly appreciated.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN class=637124818-24022003>Thank you in advance 
for you help.</SPAN></FONT></DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2><SPAN 
class=637124818-24022003>Regards,</SPAN></FONT></DIV>
<DIV><B><SPAN 
style="FONT-SIZE: 10pt; COLOR: #000099; FONT-FAMILY: Helvetica">Trevor 
Gregory</SPAN></B><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><I><SPAN 
style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: Helvetica">Technical Services 
Specialist</SPAN></I><SPAN style="FONT-SIZE: 10pt"><BR></SPAN><B><SPAN 
style="FONT-SIZE: 10pt; COLOR: #cc0000; FONT-FAMILY: Helvetica">DART</SPAN></B><SPAN 
style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica"> Mail Technology 
Solution<BR><B>Double<SPAN style="COLOR: red"> Click</SPAN> Inc.</B></SPAN><SPAN 
style="FONT-SIZE: 10pt"><BR></SPAN><SPAN 
style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica">Telephones-<BR>Tech 
Support:<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>416-847-3220<BR>Toll 
Free:<SPAN 
style="mso-tab-count: 1">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
</SPAN>800-793-6320<?xml:namespace prefix = o ns = 
"urn:schemas-microsoft-com:office:office" /><o:p></o:p></SPAN></DIV>
<DIV class=Section1>
<P class=MsoNormal><SPAN 
style="FONT-SIZE: 10pt; FONT-FAMILY: Helvetica"><U><SPAN style="COLOR: blue"><A 
href="http://www.doubleclick.net">http://www.doubleclick.net</A></SPAN></U></SPAN><SPAN 
style="FONT-SIZE: 10pt"><BR></SPAN><SPAN 
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-bidi-font-size: 12.0pt"><BR><SPAN 
style="COLOR: black">DoubleClick builds profitable customer relationships for 
marketers and publishers through integrated email technology 
solutions!</SPAN></SPAN></P></DIV>
<DIV>&nbsp;</DIV></BODY></HTML>

------_=_NextPart_001_01C2DC38.0AE0F730--