I'm not too familiar with the extent of California's "long arm" with respect to websites, but CA tends to take the position that most any contact with the state gives CA jurisdiction (I'm probably a bit broad here). So, a website that collects info from CA residents could be seen as conducting business in the state and would be subject to this law. Physical presence is usually not a requirement.
Good lord, does nobody plan before they start hacking away? If someone wanted to watch me write software, they would see a bunch of scribbling on a notepad or whiteboard for most of the time.
There would be enough jurisdiction to arrest the guy if he happened to travel to France though. Maybe not enough to have any charges stick, but probably enough to make his life misérables.
I agree, and add that Scope of Work and the process to change the scope are the most important (followed by deliverables and cost) because those two areas seem to cause most contention.
I also love the idea of using existing and well understood licenses. On the surface, it seems much safer than rolling your own licensing schemes, or having a lawyer do the same (I'm a non-practicing lawyer and a current web developer. In my research on design/dev contracts, i've never heard anyone doing this, but it sounds like a brilliant idea!)