Legal

Privacy Policy

Effective DateApril 25, 2026
Last UpdatedMay 11, 2026
ProductCompliSync — Google Workspace Add-on

This Privacy Policy describes how CompliSync ("CompliSync," "we," "us," or "our") collects, uses, and protects information when you use our Google Workspace Add-on that synchronizes data between Jira, Google Sheets, and Monday.com (the "Service"). CompliSync is installed through the Google Workspace Marketplace and operates within Google Sheets as a native add-on. By installing or using CompliSync, you agree to the terms of this Privacy Policy.

Section 01

Information We Collect

1.1 Information You Provide

  • Account registration information (name, email address, organization name)
  • Billing information (processed securely by our payment provider; we do not store full credit card numbers)
  • Jira instance URL, Jira email address, and Jira API token (stored encrypted)
  • Monday.com API token (stored encrypted)
  • Configuration settings including field mappings, sync schedules, and column designations

1.2 Data Accessed from Connected Platforms

When you authorize CompliSync, the add-on accesses and processes the following data solely to provide the Service:

  • Google Sheets (read and write): Cell values, row data, and sheet structure in the active spreadsheet you have open when using the add-on. CompliSync reads this data to determine sync state and writes Jira ticket data into your designated sheets.
  • Jira (read and write): Ticket IDs, summaries, statuses, priorities, assignees, reporters, dates, custom field values, linked tickets, and comments. CompliSync reads ticket data to populate your sheets and, when you use the Notes Writeback feature, posts comments back to Jira issues on your behalf.
  • Monday.com (write): Board items and column values. CompliSync pushes synchronized Jira data to Monday.com boards you configure.
We do not access data from these platforms beyond what is necessary to provide the synchronization service you have configured. For Google Sheets specifically, CompliSync only accesses the spreadsheet that is active when you open the add-on — it does not browse or index your Google Drive.

1.3 Usage Data

  • Sync logs including timestamps, record counts, and error messages
  • Feature usage patterns to improve the Service
  • Browser type and version when accessing our web dashboard
Section 02

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Synchronize data between your connected platforms as configured
  • Send transactional emails including sync status notifications and error alerts
  • Respond to support requests and troubleshoot issues
  • Process billing and manage your subscription
  • Improve and develop new features based on usage patterns
  • Comply with legal obligations
We do not sell, rent, or share your data with third parties for marketing purposes.
Section 03

Google API Limited Use Disclosure

CompliSync's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, CompliSync commits to the following with respect to data obtained via Google APIs:

  • Use is limited to providing the Service. Google user data is used only to perform the synchronization functions you have explicitly configured. We do not use Google data for any secondary purpose.
  • No data transfer to third parties. We do not transfer Google user data to third parties except as necessary to provide the Service (e.g., storing encrypted data on our hosting infrastructure), or as required by law.
  • No use for advertising. We do not use Google user data to serve advertisements, including retargeted, personalized, or interest-based advertising.
  • No use to train AI or ML models. We do not use Google user data to train machine learning or artificial intelligence models, whether generalized or specific to your organization.
  • No sale of data. We do not sell Google user data under any circumstances.
  • No use for credit scoring or lending decisions. We do not use Google user data for determining creditworthiness or for use in connection with lending products.
CompliSync's access to Google user data is limited to reading and writing the specific spreadsheet cells you designate for synchronization. We do not access your broader Google Drive, Gmail, Google Calendar, or any other Google services.
Section 04

Google OAuth Scopes

As a Google Workspace Add-on installed via the Google Workspace Marketplace, CompliSync requests the following OAuth permission scopes during installation. We request only the minimum permissions necessary to perform the functions you configure.

Scope Purpose Why It's Needed
spreadsheets.currentonly Read and write the active spreadsheet Required to read existing sheet data and write Jira ticket data into the spreadsheet currently open in your browser. This scope restricts the add-on to the active file only — it cannot access any other spreadsheets in your Drive.
script.external_request Make external HTTP requests Required to connect to the Jira REST API and the Monday.com API to fetch ticket data and push updates.
script.scriptapp Create and manage time-based triggers Required to set up the optional scheduled auto-sync trigger that runs your sync automatically once per day at the hour you configure. If you use manual sync only, this scope is still requested but no trigger is created.
userinfo.email View your email address Used to associate your add-on session with your account for settings storage and audit log attribution.
CompliSync does not request access to your full Google Drive, Gmail, Google Calendar, Google Contacts, or any other Google service. The spreadsheets.currentonly scope means the add-on is strictly limited to the spreadsheet you have open — it cannot scan or access any other files. If you are ever prompted to grant permissions beyond those listed above, please contact us immediately at hello@complisync.io.

4.1 Scheduled Trigger Disclosure

If you enable auto-sync, CompliSync uses Google Apps Script's time-based trigger system (ScriptApp.newTrigger) to run the sync function once per day at the hour you specify, on weekdays only. This trigger runs under your Google account's authorization and accesses the same spreadsheet and Jira credentials you configured. You may disable or remove the trigger at any time from within the CompliSync settings panel, or by visiting your Apps Script triggers page.

4.2 Revoking Access

You may revoke CompliSync's access to your Google account at any time by visiting your Google Account permissions page and removing CompliSync from the list of connected apps, or by uninstalling the add-on from the Google Workspace Marketplace. Revoking access will stop all sync operations including any scheduled triggers.

Section 05

Human Review of Google User Data

5.1 Our Commitment

CompliSync does not allow any employee, contractor, or agent to read, view, or otherwise access the contents of your Google Sheets data except in the following limited circumstances:

  • With your explicit consent. If you request hands-on technical support and explicitly authorize a team member to access your data to diagnose an issue, we may do so solely to resolve your support request. You may revoke this consent at any time.
  • For security incident response. In the event of a detected security incident or data breach, authorized personnel may access the minimum data necessary to investigate, contain, and remediate the incident.
  • As required by law. We may be required by applicable law, regulation, legal process, or enforceable governmental request to access or disclose data. We will notify you to the extent permitted by law when such requests are received.

5.2 Automated Processing Only

Under normal operating conditions, your Google Sheets data is processed entirely by automated systems running within Google Apps Script's infrastructure. Our sync engine reads and writes spreadsheet data programmatically without any human involvement in the content of your data.

5.3 Apps Script Execution Logs

CompliSync uses Google Apps Script's built-in Logger service to record operational events such as sync completion, ticket counts, and error messages. These logs are stored by Google in your Apps Script project and are accessible to the script owner (your Google account). Log entries record metadata about sync operations — such as "Synced 12 tickets" or "Sync error: could not connect" — and are not designed to capture the content of your spreadsheet data. However, error messages may occasionally include partial data values when diagnosing a specific row or field. Logs are retained according to Google Apps Script's standard retention policy. CompliSync team members do not have access to your Apps Script logs unless you explicitly share your script project with us for support purposes.

5.4 Jira Comments Writeback

When you use the Notes Writeback feature, CompliSync reads the content of your designated Notes column and posts that text as a comment on the corresponding Jira ticket. This is a deliberate, user-initiated action. The content you write in Notes cells will be transmitted to your Jira instance and will be visible to anyone with access to that Jira ticket. CompliSync prepends a [CompliSync] tag to posted comments by default so they are identifiable; this tag can be disabled in project settings.

5.5 Support Access Controls

When support access is granted with your consent, it is subject to the following controls:

  • Access is logged in our audit system with a timestamp, the team member's identity, and your authorization record
  • Access is time-limited and scoped to the minimum data needed to resolve your issue
  • Access is revoked automatically when the support case is closed
  • Team members with support access are subject to confidentiality obligations and data handling training
If you ever have concerns about how your Google data has been accessed or handled, you may request a full audit log of all access events by emailing hello@complisync.io.
Section 06

Protected Health Information (PHI) and HIPAA

6.1 Our Approach to PHI

CompliSync is designed to help compliance-focused teams handle sensitive data responsibly. We acknowledge that some customers, particularly in healthcare and healthcare-adjacent industries, may process data that constitutes Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA).

6.2 Compliance Tier Customers

Customers on the Compliance tier of CompliSync may execute a Business Associate Agreement (BAA) with us. The BAA governs our obligations with respect to any PHI that may be processed through the Service. To request a BAA, contact hello@complisync.io with "BAA Request" in the subject line.

6.3 PHI Safeguards

CompliSync provides the following features to help customers manage PHI risk:

  • PHI Column Designation: Customers can mark specific columns as containing PHI
  • PHI Wipe: One-click or scheduled removal of data from designated PHI columns
  • Audit Log: A record of all sync, wipe, and share operations with timestamps and user attribution
  • Data Retention Controls: Automatic removal of records older than a customer-configured threshold
Customers are responsible for correctly designating PHI columns and for ensuring their use of CompliSync complies with applicable laws including HIPAA. CompliSync provides tools to assist with compliance but does not guarantee compliance independently of proper customer configuration.
Section 07

Data Storage and Security

7.1 Storage

Customer data is stored on servers located in the United States. API tokens and credentials are encrypted at rest using AES-256 encryption. Data in transit is protected using TLS 1.2 or higher.

7.2 Security Measures

  • Encryption of credentials and sensitive configuration data at rest
  • TLS encryption for all data in transit
  • Access controls limiting employee access to customer data
  • Regular security reviews and updates
  • Audit logging of all data access and modification events

7.3 Data Retention

We retain your account data for the duration of your subscription and for 30 days following termination, after which it is permanently deleted. Sync logs are retained for 90 days. You may request immediate deletion of your data by contacting hello@complisync.io.

Section 08

Third-Party Services

CompliSync integrates with the following third-party platforms. Your use of these platforms is governed by their respective privacy policies. We are not responsible for the privacy practices of these third-party services.

Google Workspace policies.google.com/privacy
Formspree formspree.io/legal/privacy-policy — contact forms
Stripe stripe.com/privacy — payment processing
Section 09

Your Rights

Depending on your location, you may have the following rights with respect to your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Portability: Request a machine-readable export of your data
  • Restriction: Request that we limit processing of your data
  • Objection: Object to certain types of processing

To exercise any of these rights, contact us at hello@complisync.io. We will respond within 30 days.

Section 10

Cookies

Our web dashboard uses essential cookies necessary for authentication and session management. We do not use tracking cookies or third-party advertising cookies. You may disable cookies in your browser settings, but this may affect your ability to log in to the dashboard.

Section 11

Children's Privacy

CompliSync is a business-to-business service not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately at hello@complisync.io.

Section 12

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on our website with a new effective date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

Section 13

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us. For HIPAA-related inquiries or to request a Business Associate Agreement, please include "BAA Request" in your email subject line.

CompliSync

Questions about privacy? We're here to help.