Legal

Read-only REST surface for policy documents.

PolicyDocument is a global, non-tenant-scoped model (privacy policy, terms of use, SMS-messaging consent). This viewset intentionally does not build on the *VintaScheduleModelViewSet family: those bases mix in TenantScopedViewMixin (irrelevant — no organization here) and GenericVirtualModelViewMixin (requires a VirtualModelSerializer with a virtual_model, which this flat, no-N+1 serializer doesn't need). A plain DRF ReadOnlyModelViewSet mirrors the existing precedent in organizations.views.ServiceAccountViewSet for this shape.

Auth split:

  • latest / latest_by_type are public (AllowAny) — the frontend must be able to render policy text before a session exists (mid-signup, pre-OAuth-completion).
  • list (full history) / retrieve (by id) require authentication — these expose the full version history rather than just the currently-relevant text, so they stay behind the default auth gate.

No write surface is exposed anywhere on this viewset.

get/policy-documents{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required

Query parameters

document_type'privacy_policy' | 'sms_consent' | 'terms_of_use'

Filter by document type

  • privacy_policy - Privacy Policy
  • terms_of_use - Terms of Use
  • sms_consent - SMS Messaging Consent
limitinteger

Number of results to return per page.

offsetinteger

The initial index from which to return the results.

Response

countinteger required
nextstring uri nullable
previousstring uri nullable

Example response

{
  "count": 123,
  "next": "http://api.example.org/accounts/?offset=400&limit=100",
  "previous": "http://api.example.org/accounts/?offset=200&limit=100"
}

Changes