Legal

Read-only REST surface for policy documents.

PolicyDocument is a global, non-tenant-scoped model (privacy policy, terms of use, SMS-messaging consent). This viewset intentionally does not build on the *VintaScheduleModelViewSet family: those bases mix in TenantScopedViewMixin (irrelevant — no organization here) and GenericVirtualModelViewMixin (requires a VirtualModelSerializer with a virtual_model, which this flat, no-N+1 serializer doesn't need). A plain DRF ReadOnlyModelViewSet mirrors the existing precedent in organizations.views.ServiceAccountViewSet for this shape.

Auth split:

  • latest / latest_by_type are public (AllowAny) — the frontend must be able to render policy text before a session exists (mid-signup, pre-OAuth-completion).
  • list (full history) / retrieve (by id) require authentication — these expose the full version history rather than just the currently-relevant text, so they stay behind the default auth gate.

No write surface is exposed anywhere on this viewset.

get/policy-documents/{id}{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required
idstring required

Response

idinteger required
document_type'privacy_policy' | 'terms_of_use' | 'sms_consent' required
  • privacy_policy - Privacy Policy
  • terms_of_use - Terms of Use
  • sms_consent - SMS Messaging Consent
versioninteger required

Monotonically increasing per document_type.

titlestring required
body_markdownstring required

Raw markdown body, rendered client-side.

published_atstring date-time required

Changes