Privacy Policy
- Zero Message Content Storage: We NEVER read, inspect, process, or store your private Slack channel messages.
- Military-Grade Token Encryption: All Slack OAuth bot tokens are encrypted at rest using authenticated AES-256-GCM.
- Strict GDPR & CCPA Compliance: Full user rights to data access, portability, and complete deletion.
1. Introduction
At TurnHero ("TurnHero", "we", "us", or "our"), we understand that you trust us with sensitive information when integrating our service with your Slack workspace. We are committed to maintaining the confidentiality, integrity, and security of all personal and corporate data entrusted to us.
This Privacy Policy explains what information we collect, how it is used, how it is encrypted and protected, our data retention periods, and your rights under global data privacy regulations including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Zero Message Content Storage Policy
We take a strict least-privilege approach to Slack platform permissions. TurnHero does NOT request, access, or store Slack conversation message history.
- We do not request
channels:history,groups:history,im:history, ormpim:historyscopes. - We cannot read any messages posted by users in your channels, private groups, or direct messages.
- Our Slack bot permissions are strictly limited to updating usergroup memberships (
usergroups:write), posting shift handover announcements and DMs (chat:write,im:write), and checking user availability status (users:read).
3. Information We Collect
When you install and use TurnHero, we collect only the minimal data necessary to provide automated rotation services:
A. Slack Workspace & Authorization Data
- Slack Workspace Identifiers: Team ID (e.g.,
T01234567), Team Name, Enterprise ID (if applicable), and Bot User ID. - OAuth Bot Access Tokens: Issued by Slack during OAuth authorization. These tokens are immediately encrypted using AES-256-GCM before writing to database storage.
B. Rotation & Duty Roster Data
- Rotation Configuration: Rotation name, usergroup ID (e.g.,
S01234567), target announcement channel ID, cadence, and configured timezone. - Roster Members: Ordered lists of Slack User IDs participating in the rotation.
- User Availability Status: When a rotation is evaluated, TurnHero calls
users.profile.getto inspect the user's current status text and status emoji solely to detect Out-of-Office (OOO), vacation, or sick leave indicators. We do not store historic status updates. - Shift Swaps: Requested date, requesting user ID, covering user ID, and swap status (pending, accepted, declined).
C. Billing & Payment Data
- Stripe Identifiers: Stripe Customer ID, Subscription ID, and subscription status (trialing, active, past_due, canceled).
- Payment Details: All credit card details and payment credentials are processed and held directly by our PCI-DSS Level 1 certified billing partner, Stripe. TurnHero never sees or stores full payment card numbers.
4. Token Security & AES-256-GCM Encryption
We implement industry-standard cryptographic practices to safeguard authentication tokens:
- Authenticated Encryption at Rest: All Slack bot access tokens are encrypted using AES-256-GCM (Advanced Encryption Standard in Galois/Counter Mode with 256-bit keys).
- Unique Initialization Vectors (IV): A cryptographically secure 12-byte initialization vector is generated randomly for every single encryption operation, eliminating ciphertext pattern recognition.
- Authentication Tags: 16-byte authentication tags ensure ciphertext integrity and protect against bit-flipping attacks.
- Transit Encryption: All data in transit between Slack, our backend services, and Firestore is encrypted using modern TLS 1.3.
5. Data Retention & Deletion Policy
We believe in data minimization and retain data only as long as required to deliver our Service:
- Active Workspaces: Roster configurations and rotation histories are retained while your workspace has an active or trial installation.
- Uninstallation: If TurnHero is uninstalled from your Slack workspace, our webhook immediately revokes access. Your encrypted bot token is permanently deleted from our primary database immediately.
- Complete Data Purge: All historical rotation records and workspace metadata are completely erased within 30 days of uninstallation, or within 72 hours upon receiving a written deletion request.
6. GDPR Compliance & Your Legal Rights
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, TurnHero processes your personal data as a Data Processor under Article 6(1)(b) of the General Data Protection Regulation (GDPR). You have the following rights:
- Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you.
- Right to Rectification (Article 16): You may update or correct your roster and configuration data at any time via the Slack App Home tab.
- Right to Erasure / "Right to be Forgotten" (Article 17): You may request the immediate, permanent deletion of all data associated with your user ID or workspace.
- Right to Data Portability (Article 20): You may request an export of your rotation configurations in a structured, machine-readable JSON format.
- Right to Object and Restrict Processing (Articles 18 & 21): You may object to or restrict certain types of data processing.
To exercise any of these rights, please email our Data Protection team at privacy@turnhero.app.
7. CCPA & California Privacy Rights
Under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):
- We Do Not Sell Your Data: TurnHero has never sold, rented, or monetized personal information to third parties, and will never do so.
- We Do Not Share for Cross-Context Behavioral Advertising: We do not track users across third-party websites or engage in behavioral advertising.
8. Third-Party Subprocessors
We partner with select, enterprise-grade cloud service providers to maintain the Service. Each subprocessor is vetted for security and signs a Data Processing Agreement (DPA) incorporating Standard Contractual Clauses (SCCs):
- Google Cloud Platform & Firebase: Cloud infrastructure, serverless execution (Cloud Run / Cloud Functions), and database storage (Cloud Firestore) located in the United States.
- Slack Technologies LLC / Salesforce, Inc.: Communication platform and API provider.
- Stripe, Inc.: Payment processing and subscription management.
- Sentry (Functional Software, Inc.): Crash diagnostics and error monitoring (configured with data scrubbers to prevent PII logging).
- PostHog, Inc.: Product analytics for feature usage and telemetry.
9. Contact Our Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us:
TurnHero Privacy & Data Protection Office
Email: privacy@turnhero.app
Security Inquiries: security@turnhero.app
Physical Address: TurnHero Cloud Services, San Francisco, CA, USA