Privacy Policy — AS Team Hub Jira Integration
This privacy policy explains how the AS Team Hub application ("the Application") handles data when you connect your Atlassian (Jira Cloud) account to it using Atlassian OAuth 2.0 (3LO). Connecting is optional and is initiated by you from within the Application.
Who this applies to
The Application is an internal tool used by authorized staff of First Line Software. Connecting your Atlassian account lets the Application perform Jira actions from the Application as you, limited to your own Jira permissions.
Data the Application accesses
When you authorize the connection, the Application uses your Atlassian OAuth token to access, on your behalf and within your existing Jira permissions:
- Jira projects, issues, comments, and related work items you are permitted to view or modify.
The Application performs actions you or the Application's workflows initiate (for example: creating issues, adding comments, transitioning issues). It never accesses more than your own Jira permissions allow.
Data the Application stores
For each connection, the Application stores in its own database only the information required to maintain the authorized connection:
- The OAuth access token and refresh token, the token expiry time, and the scopes you granted.
- The Jira Cloud site identifier and site URL for the connection.
The Application does not store your Atlassian account identifier, email address, or name, and does not copy or store the content of your Jira issues, comments, or attachments. Where your Atlassian account identity is needed for an action, it is obtained from Atlassian at the time of the request using your token and is not retained.
Why the Application stores this data
Solely to maintain your authorized connection and to perform Jira actions from the Application as you. Access tokens are short-lived and refreshed automatically; refresh tokens are rotated on each use.
How the data is protected
- Tokens are stored with access restricted to system administrators and are not exposed to other users of the Application.
- Each user can only access their own connection.
- Tokens and authorization codes are never written to application logs.
- Data is transmitted to Atlassian over encrypted (HTTPS) connections.
Data sharing
The Application does not sell or share this data with third parties. The data is used only to call Atlassian's APIs on your behalf.
Retention and deletion
- Connection data is retained until you disconnect the integration (in the Application, via your user preferences) or an administrator removes your connection.
- You can revoke the Application's access at any time from your Atlassian account settings (Account settings → Connected apps); revoking invalidates the stored tokens.
- On disconnection or revocation, the stored tokens are cleared.
Your choices
- Connecting your Atlassian account is voluntary.
- You may disconnect or revoke access at any time using the options above.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date.
Contact
For questions or data requests regarding this integration, contact [email protected].