Jack for Craft CMS

Configuration

Settings

Open Jack → Settings, or Settings → Plugins → Jack. The screen is for admins only, and only appears where allowAdminChanges is on. Every setting can also be set in config/jack.php.

SettingConfig keyDefaultWhat it does
Recompile automaticallyautoCompileonRebuilds every document's draft when the profile, the inventory or these settings are saved. Off, drafts stay as they are and documents show as out of date instead
Give documents their own URLsenableDocumentUrlsonGives each document a front-end page. Turn it off if the site already publishes its legal texts through its own entries
Document templatedocumentTemplateblankYour template for a document's own page, rendered with a document variable. Blank means Jack's own plain page
Show a “last updated” lineshowLastUpdatedonPrints Stand: or Last updated: with the publish date at the foot of every rendered document
Restrict edited text to basic markuppurifyOutputonLimits text you've rewritten, and sections you've added, to basic text markup. Off allows more HTML; HTML Purifier runs either way, so scripts and javascript: links never pass. Library text is never touched

Recompile automatically only ever touches drafts. Turning it on or off doesn't change what visitors see. That moves only when someone publishes. See Usage.

Settings that change the output, like Show a “last updated” line, recompile every draft when you save them, if Recompile automatically is on.

Finding undeclared services (Pro)

These control what Find undeclared services and jack/inventory/detect read.

SettingConfig keyDefaultWhat it does
Directories to scandetectorPathstemplatesRelative to the project root. Add your build folder: a tag manager snippet often appears only in compiled JavaScript
File extensionsdetectorExtensionstwig, html, js, phpComma separated
Largest file to readdetectorMaxFileSize512In kilobytes, 1–10240. Larger files are skipped

The foot of the screen says when the bundled clause library was last reviewed.

The config file

<?php
// config/jack.php

return [
    'autoCompile' => false,
    'enableDocumentUrls' => true,
    'documentTemplate' => '_legal/document',
    'showLastUpdated' => true,
    'purifyOutput' => true,
    'detectorPaths' => ['templates', 'web/dist'],
    'detectorExtensions' => ['twig', 'html', 'js'],
    'detectorMaxFileSize' => 512,
];

detectorPaths and detectorExtensions also accept a comma-separated string, such as 'twig,html,js'.

User permissions

Jack adds four permissions under Jack in each user group's settings. Admins have all of them.

PermissionHandleWhat it allows
View legal documentsjack:view-documentsOpening Jack's screens: documents, profile, inventory and audit, read-only
Create and edit documents, the profile and the inventoryjack:manage-documentsCreating, editing, recompiling and deleting documents. Editing the profile and the inventory
Publish documentsjack:publish-documentsPublishing a document, which is what puts its text on the site
Edit the company profilejack:manage-profileEditing the profile without being able to touch documents or the inventory

The last three are nested under View legal documents.

Publish documents is separate from editing on purpose. Compiling a document produces a draft. Publishing it is the site's public legal position, and plenty of organisations want those to be different people. Give your editors Create and edit… and give whoever signs off Publish documents.

The profile

Jack → Profile holds the facts about the business. Each field is a fact some clause needs. Fill one in and it's right in every document, in every language, at once.

The fields are grouped into sections:

SectionWhat goes in it
CompanyLegal name, legal form, authorised representative, address, register court and number, VAT ID, economic ID
ContactEmail, phone, fax, contact form URL, and the person responsible for editorial content
ProfessionFor regulated professions: title, chamber, professional regulations, supervisory authority
Data protectionController, data protection officer, the supervisory authority, default retention
HostingYour host, their address, where the servers are, their privacy policy, whether a data processing agreement is in place
This siteSite name and URL, Primary audience, whether it's aimed at under-16s, sells online, or has accounts
SellingDelivery time, withdrawal period, returns address, governing law, place of jurisdiction
AccessibilityConformance, standard, known limitations, last assessed, feedback address

The hints under each field matter. Legal name wants the name exactly as registered, not the brand. VAT ID is the USt-IdNr., not your tax number. Legal form decides which imprint entries German law requires of you.

Primary audience sets the jurisdiction new documents are created with. You can change it per document afterwards.

Links must be web addresses

Every URL fact, such as Contact form URL, Authority website or Their privacy policy, only accepts an http:// or https:// link. Anything else is rejected when you save. The same goes for Privacy policy URL and Opt-out URL on an inventory entry.

Per-site overrides (Pro)

On a multi-site install, the profile screen links to each site under Per-site overrides:. A site's profile holds only the answers that differ from the global one. Anything left blank falls back to the global profile.

Blanking a field on a site's profile doesn't erase it. It stops overriding it. A German site and its English translation are usually one company, so you type the address once.

The inventory

Jack → Inventory lists everyone the site hands data to. This list is the privacy policy's services section. Add Stripe here and the Stripe paragraph appears in every language you publish in, with the right legal basis and the right transfer wording.

The inventory is global, not per site. The processors a business uses don't change between its German and English sites. Only the language does.

Adding a service

  • From the library: pick one of the 44 bundled services and press Add. Provider, address, legal basis, transfer wording and cookies all come with it.
  • Something else: type a key for a service Jack doesn't know, using lowercase letters, numbers and underscores, and press Add a custom service. You describe it on the next screen. Anything you leave blank won't appear.

Editing a service

Each field on a bundled service shows the library's value as a placeholder. Change one and this site stops following the library for that field. Change what your adviser told you to change, and leave the rest.

FieldWhat it is
Name, Provider, Provider addressWho the recipient is
Legal basisConsent, contract, legal obligation or legitimate interest. Jack's reading, not a ruling
Where the data goesStays in the EEA, or the transfer mechanism: an adequacy decision, the EU–US Data Privacy Framework, or standard contractual clauses
Purpose, Data processed, Retention, Extra noteIn German and English. Short phrases, not sentences: Jack supplies the grammar around them
Privacy policy URL, Opt-out URLhttp(s) links only
In useOff keeps the entry but leaves it out of every document. It's then listed under Switched off

Server log files and Session and security cookies are always on. They describe something the site does whether or not it's written down, so they can't be switched off or removed.