Warning |
---|
WARNING: This document is outdated. OUTDATED. See Data Security and Privacy Statement v.2 instead (effective since ). List of changes in Data Security and Privacy Statement: v1 to v2 describes changes between two versions of this statement. |
On this page:
|
---|
Introduction
This Privacy Policy supplements the Appfire Privacy Policy and explains what information Appfire Technologies, LLC ("Vendor") collects about you and why, what we do with that information and how we handle the content you place in Planning Poker ("Add-On"). In the event of a conflict between the terms of this Privacy Policy and the Appfire Privacy Policy, the terms of this Privacy Policy shall control.
Scope of Privacy Policy
This Privacy Policy applies to the information that we obtain through your use of the "Planning Poker". By using "Planning Poker" you consent to the collection, processing, storage, disclosure and other uses described in this Privacy Policy.
Definitions
Add-On: a bundle of code, resources and configuration files that can be used with an Atlassian product to add new functionality or to change the behavior of that product's existing features, which is the "Planning Poker" in the scope of this document.
Content: any information or data that you upload, submit, post, create, transmit, store or display in an Atlassian Service.
Information: all of the different forms of data, content, and information collected by us as described in this Privacy Policy.
Personal Information: information that may be used to readily identify or contact you as an individual person, such as: name, address, email address, or phone number. Personal Information does not include information that has been anonymized such that it does not allow for the ready identification of specific individuals.
Changes to our Privacy Policy
We may change this Privacy Policy from time to time. If we make any changes, we will notify you by revising the "Effective Starting" date at the top of this Privacy Policy. If you disagree with any changes to this Privacy Policy, you will need to stop using Atlassian Services and deactivate your account(s), as outlined below.
Information available to us
Atlassian Marketplace
...
information
Contact information such as name, email address, mailing address, and phone number
Billing information such as credit card details and billing address
Jira host details (as prescribed by the Atlassian Connect Guidelines)
description
eventType
productType
baseUrl
pluginsVersion
serverVersion
sharedSecret
publicKey
clientKey
Content
We collect and store Content that you create, input, submit, post, upload, transmit, store or display in the process of using our SaaS Products or Websites. Such Content includes any Personal Information or other sensitive information that you choose to include ("incidentally-collected Personal Information").
Other submissions
We collect other data that you submit to us, such as surveys, activity or event, request customer support, communication with us via third party social media sites or any other form of communicating with us. For example, information regarding a problem you are experiencing with the Add-On could be submitted to our issue tracker or sent via email.
Information we collect from your use of
...
the add-
...
on
Web
...
logs
As is true with most websites and services delivered over the Internet, we gather certain information and store it in log files when you interact with the Add-On. This information includes internet protocol (IP) addresses as well as browser type, internet service provider, URLs of referring/exit pages, operating system, date/time stamp, information you search for, locale and language preferences, identification numbers associated with your Devices, your mobile carrier, and system configuration information, the URLs you accessed (and therefore included in our log files) include usernames as well as elements of Content (such as Jira project names, project keys, status names, and JQL filters) as necessary for the Add-On to perform the requested operations. Occasionally, we connect Personal Information to information gathered in our log files as necessary to improve Add-On Services for individual customers. In such a case, we would treat the combined Information in accordance with this privacy policy.
Analytics
...
information
We collect analytics information when you use our Add-On to help us improve our products and services. This analytics information consists of the feature and function of the Add-On being used, the associated license identifier (SEN) and domain name, the username and user data available from the Jira REST API. The analytics information we collect includes elements of Content related to the function the user is performing. As such, the analytics information we collect may include Personal Information or sensitive business information that the user has included in Content that the user chose to upload, submit, post, create, transmit, store or display in the Add-On.
...
As of the date this policy went into effect, we use Google Analytics and keen.io as analytics providers. To learn more about the privacy policy of Google Analytics, refer to Google's Policies and Principles. Use the Google Analytics Opt-out Browser Add-on to prevent analytics information from being sent to Google Analytics. To learn more about the privacy policy of keen.io, refer to keen.io Privacy Policy.
Analytics
...
information derived from
...
content
Analytics information also consists of data we collect as a result of running queries against Content across our user base for the purposes of generating Usage Data. "Usage Data" is aggregated data about a group or category of services, features or users that does not contain Personal Information.
Though we may happen upon sensitive or Personal Information as we compile Usage Data from Content across user instances, this is a byproduct of our efforts to understand broader patterns and trends. It is not a concerted effort by us to examine the Content of any particular customer.
Cookies and
...
other tracking technologies
We use various technologies to collect information, such as cookies and web beacons. Cookies are small data files stored on your hard drive or in device memory. We use cookies to improve and customize Add-On and your experience; to allow you to access and use the Add-On without re-entering your username or password; and to count visits and understand which areas and features of the Add-On are most popular. You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from websites you visit. If you do not accept cookies, however, you may not be able to use all aspects of the Add-On. We may also collect information using web beacons (also known as "tracking pixels"). Web beacons are electronic images that may be used in the Add-On or in emails that help us to deliver cookies, count visits, understand usage and campaign effectiveness and determine whether an email has been opened and acted upon.
We also use javascript, e-tags, "flash cookies", and HTML5 local storage to collect information about your online activities over time and across different websites or online services. Many browsers include their own management tools for removing HTML5 local storage objects. To manage "flash cookies" please click here.
How we use the information we collect
General
...
use
We use the Information we collect about you (including Personal Information to the extent applicable) for a variety of purposes, including to:
...
Notwithstanding the foregoing, we will not use Personal Information appearing in our Analytics Logs or Web Logs for any purpose. The use of Information collected through our Atlassian Services shall be limited to the purposes disclosed in this policy.
Compiling aggregate analytics information
To better comply with the Atlassian Marketplace, we make extensive use of analytics information (including log and configuration data) to understand how Add-On is being configured and used, how it can be improved for the benefit of all of our users, and to develop new products and services. As such we generate Usage Data (as defined above) from the web logs and analytics logs described above, including the Content elements captured in such logs, as well as from the Content stored in the Add-On.
Information sharing and disclosure
We will not share or disclose any of your Personal Information or Content with third parties except as described in this policy. We do not sell your Personal Information or Content.
Your
...
use
When you use Add-On, Content you provide will be displayed back to you.
Collaboration
As a natural result of using Add-On, you may create Content that other users of your Jira instance can access for the purposes of collaboration. Some of the collaboration features of Add-On display your profile information, including Personal Information included in your profile, to users with whom you have shared your Content
Service
...
providers, business partners, and others
We work with third-party service providers to provide website, application development, hosting, maintenance, back-up, storage, virtual infrastructure, payment processing, analysis and other services for us. These service providers may have access to or process your Information for the purpose of providing those services for us. This list includes:
Digital Ocean — SSD Cloud Hosting
Mandrill — For sending transactional emails
Mailchimp — For sending newsletters and release notes
Google Analytics — For collecting analytics
Keen.io - For collecting analytics
CloudFlare — DNS proxy
Information we do not share
We do not share Personal Information about you with third parties for their marketing purposes (including direct marketing purposes).
Data storage, transfer, and security
Add-On hosts data with hosting service providers in numerous countries. The servers on which Personal Information is stored are kept in a controlled environment. While we take reasonable efforts to guard your Personal Information, no security system is impenetrable and due to the inherent nature of the Internet as an open global communications vehicle, we cannot guarantee that information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others, such as hackers. In addition, we cannot guarantee that any incidentally-collected Personal Information you choose to store in Add-On is maintained at levels of protection to meet specific needs or obligations you may have relating to that information.
Where data is transferred over the Internet as part of the Add-On, the data is encrypted using industry-standard SSL (HTTPS).
Data flow
The app installs a "connector" into the customer Jira, which then communicates with our APIs (via an iframe basically).
...
When the user loads the game from the Planning Poker API, they receive all relevant Game Session information represented by the IDs (issue IDs and user IDs). After that, JavaScript code in the user's browser executes a call to the Jira REST API to fetch all the information about the Issue and to populate it into the Number 1 on the screenshot. This communication happens only between the user browser and the Jira REST API.
Same logic applies to the population of Game Players section — Number 2 on the screenshot
Estimation context (Number 3) is basically just a search from the current user browser against the Jira REST API
Estimation Backlog and Archive (Number 4) is represented by the issue IDs. When a used user clicks on any of the IDs, the required data is pulled via the current user browser JavaScript from the Jira REST API (no outgoing requests)
There are also other views in the Planning Poker where the issues information is displayed (such as Estimation Backlog Details), but the logic there is the same as described above.
Therefore, the only outgoing information from Jira is the anonymised anonymized IDs, the rest happens between the user browser and Jira REST API (within the same network).
A rough illustration of this communication is attached below.
...