Does anyone actually use the fake context menu that the editor creates? Or would people prefer it disabled so they can paste and use spell check as normal?
I cannot tell if it is because the information is sent without ssl, but from the console this is the url that is returning the 403 error, https://www.paypal.com/paymentwall/payment-selection
This might help, https://blog.stackpath.com/glossary/cross-origin-resource-sharing/ If you look in the console window of your browser you can see that the fonts are trying to load, but the sites CORs policy is stopping them.
This has been added in for the next release. https://github.com/thirtybees/community-theme-default/commit/32b8a6420d09a50b26f67b7ebf5135ebaf74f428#diff-ec7069dd8de504e21a20586ae9179834
There is no legal basis, you are confusing two very different things. GDPR has to do with data. The ToS has to do with something totally different and does need a checkbox. Think about it this way. Does agreeing to GDPR mean that you agree to my shop not allowing returns? Or to me charging you a restocking fee on your purchase? Or to me selling you used goods? Those are things covered in a ToS. Data policy is not and should not be covered in a ToS. This is why a ToS needs a checkbox.