Worklog360 Docs
Breadcrumbs

Worklog360: Data Security and Privacy Statement

Overview

This is a data security and privacy statement for Worklog360 app.

Privacy

Worklog360 processes limited personal data required to provide its functionality. This may include user identifiers (such as account IDs), worklogs, and project-related data retrieved from Jira.

We do not collect or store Atlassian account credentials (such as passwords or API tokens).

The app may log error details for diagnostics purposes. Logging is performed via Papertrail on  Heroku and does not intentionally include sensitive data such as credentials or tokens.

We also receive usage statistics and licensing information via Atlassian Marketplace APIs.

Data Storage

Worklog360 processes and stores application data necessary for its functionality on secure infrastructure hosted on Heroku.

This may include configuration settings, worklogs, and billing-related information required to provide reporting, budgeting, and invoicing features.

We store only the minimum personal and operational data required to operate the application. We do not store highly sensitive data such as user passwords, authentication credentials, or API tokens. Where possible, data remains within Atlassian systems.

Application logs (e.g. error logs) may be temporarily stored using logging services (such as Papertrail) for debugging and operational purposes. Logs do not intentionally include sensitive data such as credentials, tokens, or API keys.

Permissions Scope

Worklog360 requires permissions to read Jira issues, worklogs, and limited user-related data in order to provide time tracking, reporting, budgeting, billing, and invoicing features. The app also requires permissions to create and update worklog-related data where needed. Additional permissions, such as access to email addresses, are used only for specific features like notifications and only where permitted.

Hosting

Our application is hosted on Heroku Cloud Application Platform.

Data Retention

We retain only the data necessary to provide the service. Data is retained while the app is installed and may be deleted upon uninstall or customer request.

Security

All communication between the app and external services is performed over HTTPS (TLS 1.2 or higher). Sensitive data is not exposed in client-side code and is securely handled in the backend infrastructure. If you have found a security vulnerability, please email us mailto:contact@worklog360.com .

Email Addresses Privacy.

Our application uses Jira REST APIs to access user email addresses where permitted. Email addresses are processed only as needed for specific functionality, such as sending notifications (e.g., when a timesheet is submitted, approved, or rejected).

Email addresses are not stored beyond what is necessary for these operations and are not used for any other purposes.

Notifications are sent using third-party email services such as MailJS and Mailjet. These services process email data only for delivery purposes and in accordance with their respective privacy policies.

Our application is hosted on Heroku Cloud Application Platform.


References