Org Sentinel
Privacy Policy
Last updated: August 13, 2026
Data we process
- Account data: name, email, password hash, workspace membership and preferences.
- Service data: plan, billing status, audit events and security logs.
- Salesforce analysis: data read with the permissions granted to the current Salesforce user. Free and Pro history stays local. Team and Enterprise may synchronize normalized operational snapshots, health-model coverage, aggregate factor counts, area scores and risk counts encrypted at rest.
- Data-platform connections: encrypted access credentials and configured mappings when an authorized administrator enables the connector.
Data we do not collect
We do not request or store Salesforce passwords, Salesforce session cookies, payment-card details, raw health-factor evidence, Salesforce user names or emails, IP addresses or raw Salesforce business tables in the Org Sentinel cloud service. Card data is processed by Paddle.
Purpose and legal basis
We process data to provide the requested service, secure accounts, administer subscriptions, communicate important service events and meet legal obligations. Where consent is required, notification preferences can be changed in the extension.
Storage and sharing
Cloud data is hosted in protected infrastructure and shared only with service providers needed for hosting, email delivery, security and billing. Paddle acts as Merchant of Record for paid purchases. We do not sell personal data.
Retention and deletion
Local data can be removed from the extension at any time. Cloud account data can be exported or permanently deleted from Account settings. Active subscriptions must first be canceled; workspace owners may need to transfer ownership. Deletion removes the workspace, snapshots, integrations and memberships from the live database. Encrypted disaster-recovery backups expire automatically within 90 days and are used only to restore the service after an incident, not to recreate a closed account. Paddle may retain billing records as required for tax, accounting, fraud prevention or legal compliance.
Your rights
Depending on your location, you may request access, correction, deletion, portability, restriction or objection. Use the self-service controls first, or contact support for assistance.
Security and international use
We use HTTPS, tenant isolation, encryption at rest for sensitive payloads, short-lived access tokens, audit logging and least-privilege design. Data may be processed outside your country with appropriate contractual and legal safeguards.
Contact
Privacy questions: send a private support request.