1) Scope
This policy covers the TrackMate Forge app for Jira Cloud distributed through the Atlassian Marketplace and provided by Önder Yazılım (“we”, “us”). The separate TrackMate browser extension has its own privacy policy. Cookies and measurement on this website are described in the website privacy policy. Atlassian’s own processing of your data is governed by Atlassian’s privacy policy.
2) Information the app processes
| Information | Why | Where |
|---|---|---|
| Your Atlassian account ID, display name, avatar URL, Jira profile time zone and site address | Identify you, date worklogs in your time zone and build links to your site. Refreshed at most every 12 hours while you use the app. | Forge storage |
| Settings and preferences (language, appearance, working schedule, timer preferences, saved JQL filters, column choices, project colours) | Configure the app for you. | Forge storage |
| Team members you select: their account IDs, display names, avatar URLs and the schedule you set for them | Show the Team view. Their worklogs are read from Jira only as far as your Jira permissions allow. | Forge storage (your settings) |
| Timer state: issue key, start time, duration and the ID of the worklog being saved | Keep a timer running when your browser is closed and save it to Jira. | Forge storage |
| Jira configuration visible to you (statuses, issue types, field definitions, projects) | Populate settings and status options. Refreshed at most every 12 hours. | Forge storage |
| Jira issues and worklogs | Show calendars, reports and statistics, and create, edit or delete worklogs under your own Jira identity and permissions. | Read from and written to Jira |
| TrackMate extension compatibility data | If you also use the TrackMate browser extension, the app reads its settings and exchanges timer state through a Jira user property on your own account. | Jira user property |
| Diagnostic logs (errors and operational events; may include account IDs, issue keys, worklog IDs and timestamps; e-mail addresses and tokens are redacted) | Detect and fix problems. | Atlassian Forge logging |
The app never asks for your password or API token, and it does not store e-mail addresses.
3) Where information is stored
App data is kept in Atlassian Forge hosted storage, which encrypts data at rest, separates it per installation and keeps it in the location of your Atlassian product. The app declares no external network access: no information is transferred to us or to other third parties.
4) Who can access it
- You, through the app. Other users of your site see worklogs only where Jira permissions allow it.
- Atlassian, as the provider of the Forge platform.
- Us: we have no direct access to the app’s stored data. Diagnostic logs are available to us through Atlassian’s developer tools; your site administrator can turn off log sharing for your site at any time.
Reports you export (CSV, JSON or PDF) are created in your browser at your request. You decide where they go.
5) Retention and deletion
- Jira issues and worklogs remain Jira records. Uninstalling the app does not delete them.
- App data is kept while the app is installed. According to Atlassian’s Forge documentation, Forge hosted storage is retained for 28 days after uninstallation.
- Every week the app reports the account IDs it stores to Atlassian’s Personal Data Reporting API. When an account is closed, all app data for it is erased and it is removed from other users’ team lists. When a profile has changed, the app’s copies are refreshed or erased.
- You can remove team members and reset your settings in the app’s Settings at any time.
- Diagnostic logs are retained according to Atlassian’s Forge logging retention.
6) Permissions the app requests
| Permission | Used for |
|---|---|
read:jira-work | Read issues, projects, statuses and the worklogs you can see. |
write:jira-work | Create, edit and delete your worklogs and apply the issue status changes you choose. |
read:jira-user | Read your profile and time zone, search users you add to Team and refresh their names. |
write:user.property:jira | Share timer state with the TrackMate browser extension on your own account. |
storage:app | Store timer state, settings and preferences in Forge. |
report:personal-data | Report stored account IDs to Atlassian so closed or changed accounts are handled. |
Timers keep running and can be autosaved while your browser is closed. For this, Atlassian lets the app act on your behalf when it writes worklogs, so the worklog author is you, not the app.
7) Your choices and rights
You can ask us about the information described here or ask us to delete it by writing to mustafa@onderyazilim.com. We may need your site administrator’s involvement, because the app’s data belongs to your organisation’s installation. If your organisation needs a data processing agreement, contact us.
8) Security
The app runs only on Atlassian’s Forge platform and uses the minimum permissions listed above. To report a security issue, write to mustafa@onderyazilim.com.
9) Children
The app is a business tool and is not directed to children.
10) Changes
We will update this page when the app’s data handling changes and revise the “Last updated” date above.
11) Contact
Önder Yazılım — mustafa@onderyazilim.com
This document is provided for information and does not constitute legal advice. Where local regulations apply (for example GDPR or KVKK), consult a qualified legal professional.
← Back to TrackMate for Jira