This is a working draft prepared to describe what Zyncit's code actually does. The sections marked [PLACEHOLDER] need real values filled in, and the whole document should be reviewed by a qualified lawyer before it is relied on for compliance (GDPR, CCPA, Slack App Directory review, Atlassian Marketplace review, etc.) or published as final.

1. Who this policy covers

This Privacy Policy explains how [LEGAL ENTITY NAME, e.g. "Zyncit Ltd"] ("Zyncit", "we", "us") collects, uses, stores, and shares information when an organization ("you", "your company") connects its Slack workspace and Jira site to Zyncit, and when individual users of that organization interact with Zyncit through Slack, the Control Center dashboard, or our website.

Zyncit is a business-to-business tool. It is intended to be used by employees of an organization that has connected its own Slack workspace and Jira site — not by members of the public directly.

2. Information we collect

Account information

Slack information

When your organization connects Slack, Zyncit receives and stores an OAuth access token scoped to your workspace, along with the workspace and channel identifiers needed to operate. Depending on the workflows your organization builds, Zyncit may read and store message content, file attachments, and user identifiers (names, emails, Slack user IDs) that are submitted through Zyncit's forms or exchanged in the Slack threads Zyncit manages.

Jira information

When your organization connects Jira, Zyncit receives and stores OAuth access and refresh tokens scoped to your Jira site, along with project, issue type, and custom field metadata needed to build forms. Ticket content, comments, statuses, and attachments that flow through a Zyncit workflow are read and, where the workflow requires it, stored or cached by Zyncit so they can be kept in sync between Slack and Jira.

Usage and audit information

We keep an audit log of actions taken inside the Control Center (for example, workflows created or edited, users added, and settings changed) so that Owners and Admins can see who did what, and when. We also keep aggregate usage statistics (ticket volume, sync counts) shown on the Analytics page.

Cookies

Zyncit sets a single essential, HttpOnly authentication cookie used to keep you signed in. We do not use third-party advertising or tracking cookies.

3. How we use information

We do not sell personal information, and we do not use the content of your Slack messages or Jira tickets to serve advertising.

4. Who we share information with

Zyncit shares information only with the service providers ("sub-processors") needed to run the product:

We do not share your organization's data with any other third party except where required by law, or with your explicit consent.

5. Data retention

We retain account, workflow, and synced content data for as long as your organization's Zyncit account remains active. If your organization disconnects Slack or Jira, or closes its Zyncit account, we will delete or anonymize the associated data within [RETENTION PERIOD, e.g. "30 days"], except where we are required to retain it for longer to comply with law.

6. Security

We take reasonable technical measures to protect information, including: encrypting traffic to and from Zyncit in transit (HTTPS), hashing passwords with bcrypt, storing OAuth tokens server-side rather than in the browser, and scoping every database query to your organization so that one customer's data is never visible to another. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete the personal information we hold about you, or to object to or restrict certain processing. Your organization's Owner or Admin can also directly remove your account or edit your role at any time from the Manage Users page. To exercise these rights, contact us at [PRIVACY CONTACT EMAIL, e.g. [email protected]].

8. International data transfers

Zyncit's infrastructure is currently located in [HOSTING REGION, e.g. "the United States" / "the European Union"]. If you access Zyncit from another region, your information will be transferred to and processed in that location.

9. Children's privacy

Zyncit is a business tool and is not directed at, or knowingly used by, children under the age of 16.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, notify Owners and Admins directly.

11. Contact us

Questions about this policy or how Zyncit handles your data can be sent to [PRIVACY CONTACT EMAIL, e.g. [email protected]].

Have a question about your data?

Reach out and we'll get back to you as soon as we can.

Explore Zyncit →