Collabound Collabound
Product Pricing Docs Security
Sign in Get it on Marketplace ›
Product Pricing Docs Security Sign in Get it on Marketplace ›

Legal

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Shinetech Software Inc. ("Collabound", "we", "us", or "our") collects, uses, stores, shares, and protects information when you use Collabound, including the Collabound for Jira app, the Collabound Portal, our documentation, support services, and related websites or services (collectively, the "Services").

Collabound is designed for business-to-business work sharing and partner collaboration. If you use Collabound on behalf of an organization, your organization may control the workspace, Jira site connection, partner access, sharing templates, and data shared through the Services. This Privacy Policy should be read together with the Collabound Terms of Use and our Security Overview.

This Privacy Policy applies only to the Collabound Services. The Shinetech corporate website (www.shinetechsoftware.com) and other Shinetech products or services are governed by their own separate terms and privacy policies, which do not apply to the Collabound Services. Where those documents differ from this Privacy Policy, this Privacy Policy governs the Collabound Services.

With respect to Customer Data — such as Jira work item content, comments, and attachments submitted or shared through the Services — we act as a service provider (or "processor" under applicable data protection laws) on behalf of the customer organization that controls the workspace. That organization determines what data is submitted and shared through the Services and is responsible for having a lawful basis and any required notices or consents for that data. Where we determine the purposes and means of processing — such as for Collabound Portal account administration, security, billing, and service communications — we act as an independent controller.

Information We Collect

We collect information needed to provide, secure, support, and improve the Services. The categories of information may include:

  • Account and profile information — Names, email addresses, account identifiers, workspace membership, role assignments, invitation status, login records, and related account settings for Collabound Portal users.
  • Atlassian and Jira information — Atlassian site identifiers, cloud IDs, account IDs, Jira project or space metadata, issue keys, issue summaries, issue descriptions, statuses, priorities, labels, comments, attachments, request metadata, issue update events, and other Jira work item fields that are shared, synchronized, or otherwise accessed through Collabound according to configured permissions.
  • Workspace and collaboration information — Workspace names, partner relationships, collaboration status, site connections, sharing permission templates, shared content access templates, partner access settings, link share settings, and audit records.
  • Authentication and security information — Login attempts, session metadata, token issuance and revocation events, IP addresses, user agent data, device/browser metadata, and other records used to secure accounts and detect abuse.
  • Support and communication information — Information you provide when contacting support, reporting a problem, requesting deletion, asking a privacy question, or submitting feedback.
  • Usage and diagnostic information — Application events, feature usage, error logs, performance data, and operational logs used to keep the Services reliable and secure.
  • Optional website analytics information — If you allow analytics on www.collabound.com, Google Analytics processes page URLs and titles, referring website and permitted campaign parameters, outbound-link destination domains and URLs, approximate location, browser and device information, event time, and a pseudonymous client identifier. We do not send your name, email address, Collabound account information, Jira content, form contents, or other direct identifiers to Google Analytics.
  • Billing and Marketplace information — If the app is purchased through Atlassian Marketplace or another approved channel, we may receive subscription, license, billing status, organization, and contact information needed to administer the subscription. Payment processing may be handled by Atlassian or another payment provider according to their applicable terms.

We do not intentionally collect sensitive personal information unless it is included by you or your users in Jira work items, comments, attachments, support requests, or other content shared through the Services.

How We Use Information

We use information for the following purposes:

  • To provide, operate, maintain, and secure Collabound.
  • To connect Jira sites to Collabound workspaces and process app installation, lifecycle, and site-binding events.
  • To enable users to share selected Jira work items with partners, invite collaborators, revoke access, and manage shared work.
  • To enforce workspace, role, partner, field-level, and template-based access controls.
  • To synchronize shared work item data and keep shared views current where synchronization is enabled.
  • To provide partner portal views, Jira app pages, issue panels, comments, attachments, status transitions, and related collaboration features.
  • To create audit logs and security records for accountability, troubleshooting, fraud prevention, and compliance.
  • To send operational notices, invitations, account emails, security alerts, support responses, and service-related communications.
  • To administer subscriptions, licensing, billing status, trials, and Marketplace-related account information.
  • To monitor, debug, analyze, and improve service reliability, security, and performance.
  • With your consent, to measure visits to www.collabound.com, understand which pages visitors find useful, evaluate outbound-link journeys, and improve the website and its content.
  • To comply with legal obligations, enforce our terms, and protect the rights, safety, and security of Collabound, customers, users, partners, and the public.

We do not sell customer data. We do not use Customer Data, Jira issue content, or Collabound users' personal information for third-party advertising, and we do not share Collabound users' personal information with advertising platforms.

Where the GDPR or similar laws apply to processing for which we act as a controller, we rely on the following legal bases: performance of a contract (providing the Services you or your organization request), legitimate interests (securing, operating, supporting, and improving the Services and preventing abuse), compliance with legal obligations, and consent where required. For Customer Data processed on behalf of a customer organization, that organization is responsible for its own legal basis.

How Information Is Shared

We share information only as needed to provide and support the Services, as directed by workspace administrators and users, or as legally required. This may include:

  • Within your organization — Workspace administrators and authorized users may access workspace settings, user membership, audit logs, and shared work according to their permissions.
  • With partner workspaces and invited users — Jira work item content selected for sharing may be made available to partner workspaces and invited partner users according to sharing permission templates, shared content access templates, and active collaboration settings.
  • With Atlassian — Collabound interacts with Atlassian services, APIs, Forge, Jira, and Atlassian Marketplace to provide app functionality, installation, licensing, and account-related processes. Atlassian processes information under its own applicable terms and policies.
  • With service providers — We use third-party service providers to host, operate, secure, support, and communicate about the Services. These providers may process information on our behalf subject to contractual obligations.
  • For legal and safety reasons — We may disclose information when required by law, legal process, regulation, government request, or to protect rights, property, safety, security, or prevent abuse.
  • Business transfers — If Collabound is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction subject to appropriate protections.

Subprocessors and Service Providers

Collabound uses subprocessors and service providers to deliver the Services. These may include cloud hosting, database, storage, email delivery, operational logging, diagnostics, support, security, and deployment providers. Collabound is hosted on Amazon Web Services (AWS). Additional service providers may be used as our operations evolve.

Our current service providers include:

  • Atlassian — Jira Cloud, Forge, Atlassian Marketplace, Jira Service Management, and Confluence services used for app functionality, installation, licensing, support, and documentation.
  • Amazon Web Services (AWS) — Cloud hosting, infrastructure, deployment, storage, database-related services, operational logging, and security services.
  • Amazon Simple Email Service (AWS SES) — Delivery of transactional emails such as invitations, verification messages, account notices, and security alerts.
  • Bitbucket Pipelines — Build, security scanning, and deployment automation for Collabound software. This service is not used to process Jira work item content as part of normal product use.
  • Google Analytics — Optional measurement of visits to www.collabound.com and outbound-link interactions, only after a visitor allows analytics. We disable Google Signals and advertising personalization and do not use analytics information for remarketing.

We require service providers to use information only for the purposes of providing services to Collabound and to protect information using appropriate security measures. You may contact us for current subprocessor information.

Data Storage and International Transfers

Collabound is operated as a cloud service. Collabound currently hosts and stores Service data in the United States. If you access or use the Services from outside the United States, information may be transferred to, processed in, and stored in the United States, where data protection laws may differ from those in your location.

Collabound and its service providers may also access or process information from other locations as needed to provide, support, secure, and operate the Services. We protect international transfers of personal information through contractual protections with our service providers. If your organization requires specific transfer safeguards, contact us at support@collabound.com.

Data Retention

We retain information for as long as reasonably necessary to provide the Services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, support auditability, and preserve business records.

  • Active shares — Shared work item data is retained while the share is active and while needed to provide synchronized partner collaboration.
  • Revoked shares — When access is revoked, partner access to shared work is removed. Collabound may retain revocation metadata, audit logs, and related records for security and accountability.
  • Workspace and account data — Workspace, site, role, collaboration, and user records are retained while the account or workspace remains active and for a reasonable period afterward.
  • App uninstallation — If the Collabound for Jira app is uninstalled, associated workspace, site, sharing, and synchronized work item data is retained for at least 30 days and up to 365 days after uninstallation to support account recovery, reinstallation, customer support, security, and auditability, unless deletion is requested earlier. Audit, security, backup, and legally required records may be retained longer where required.
  • Audit and security logs — Audit logs and security records may be retained for longer periods to support accountability, compliance, abuse prevention, and investigation.
  • Deletion requests — Workspace administrators may contact support to request deletion of workspace data. Access may be removed and relevant records may be marked for deletion first, with final removal handled according to legal, security, backup, audit, operational retention, and purge requirements.

Security

We use administrative, technical, and organizational measures designed to protect information from unauthorized access, disclosure, alteration, and destruction. These measures include encryption in transit, encryption at rest, role-based access control, field-level access templates, audit logging, token-based authentication, and secure Forge app communication.

No method of transmission or storage is completely secure. For more detail about our security practices, see the Collabound Security Overview.

Cookies and Similar Technologies

The Collabound Portal may use cookies, local storage, or similar technologies that are necessary for authentication, session management, security, and service functionality. These product technologies are separate from the optional website analytics described below.

On www.collabound.com, we use the necessary collabound_analytics_consent cookie to remember whether you allowed or rejected optional analytics. It does not track website activity and expires after approximately 6 months.

If you allow analytics, Google Analytics uses the first-party _ga cookie to distinguish pseudonymous visitors and a _ga_<measurement-id> cookie to maintain session state. We configure these analytics cookies to expire after up to 13 months without extending their lifetime on later visits. They are not set unless you allow analytics.

You may reject analytics without affecting your use of the website. You may also allow, reject, or withdraw your choice at any time using the Cookie settings link in the website footer. Withdrawing consent stops future analytics collection and removes this website's Google Analytics cookies from your browser.

Google Analytics uses IP addresses at collection time to derive approximate location and states that it discards them before analytics information is logged. We do not use Google Analytics for advertising personalization or remarketing, and we do not associate website activity with your Collabound account or email address. For more information about Google's processing, see Google's Privacy Policy.

We do not use advertising cookies in the Services, and we do not use Jira issue content or Collabound users' personal information for third-party advertising.

Your Choices and Rights

Depending on your location and applicable law, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. In many cases, your organization controls the workspace and data processed through Collabound. If your request relates to data controlled by your organization, we may ask you to contact your organization or workspace administrator, or we may work with your organization as needed to handle the request.

You may contact us to request assistance with privacy rights, account deletion, workspace deletion, or data access requests. We may need to verify your identity and authority before fulfilling a request.

Atlassian Account Data

When Collabound processes Atlassian account information, such as account IDs, we use it to provide app functionality, enforce access controls, connect Jira actions to Collabound users, and support account lifecycle processes. If Atlassian notifies Marketplace apps of account closures or data requests, we will handle those notices according to applicable Atlassian Marketplace requirements and this Privacy Policy.

Children's Privacy

Collabound is a business service and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided personal information to Collabound, please contact us.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date above. If changes are material, we may provide additional notice through the Services, email, documentation, Marketplace listing, or other appropriate means.

Contact Us

If you have questions about this Privacy Policy, our privacy practices, data requests, or security matters, contact us at support@collabound.com.

Collabound Collabound

Securely share Jira work with partners outside your company.

Product

  • Overview
  • Pricing
  • Atlassian Marketplace
  • Portal sign in

Resources

  • Documentation
  • Security overview
  • Support

Legal

  • Privacy policy
  • Terms of use

© 2026 Shinetech Software Inc. . All rights reserved.

Help us improve Collabound

We use optional Google Analytics cookies to understand website visits and outbound-link clicks. We do not use this data for advertising or link it to your Collabound account. Privacy Policy