Why your SaaS needs a privacy policy
What to include in your SaaS privacy policy
Types of personal data you collect
- Data provided directly by users:
- Names
- Email addresses
- Billing and payment details
- Job titles and organisation names
- Contact numbers
- User-generated content (e.g., support requests, reviews)
- Automatically collected data:
- IP addresses
- Device information (type, operating system, identifiers)
- Browser types and versions
- Location data (based on IP addresses)
- Cookie and usage data (page views, interactions, duration)
- Data from third parties:
- Information received via integrations (e.g., analytics platforms like Google Analytics)
- Payment processors (e.g., Stripe, PayPal)
- Authentication providers (e.g., Google, Facebook sign-in)

How you collect user data
- Direct submissions by users:
- Account registration forms
- Subscription or billing information forms
- Contact and support request forms
- Feedback and survey responses
- Automated data collection:
- Cookies, pixels, and web beacons
- Analytics tools and scripts (e.g., Google Analytics, Hotjar)
- Server logs tracking website/app usage and performance
- Third-party data integrations:
- APIs or embedded services from payment gateways, marketing tools, CRM software
- Social media integrations providing user profile data


Legal basis for processing data (GDPR)
Salesforce explicitly cites performance of contract, compliance with legal obligations and legitimate interests (such as platform security and analytics) as its GDPR bases.

Why or how you use collected data
- Service delivery and improvement:
- Providing account functionality and customer support
- Enhancing user experience based on feedback and analytics
- Maintaining and securing your platform
- Marketing and communication:
- Informing users of service updates or new features
- Promotional campaigns and targeted advertising (with user consent)
- Analytics and research:
- Understanding user behaviour and preferences
- Identifying usage patterns to improve your offerings
Datadog’s privacy policy exemplifies this structure, stating that it uses personal data “to provide the Datadog Products,” “for research and to improve and create new Datadog Products,” “to communicate with you,” “for security,” “to market and promote the Datadog Products,” “to comply with legal obligations,” and “with your consent” (e.g., as a Featured Customer).

Data sharing with third parties
- Payment processors (e.g., Stripe, PayPal):
- For secure payment processing and fraud prevention
- For secure payment processing and fraud prevention
- Analytics and tracking tools (e.g., Google Analytics, Mixpanel):
- To gain insights into user interactions and enhance the service
- To gain insights into user interactions and enhance the service
- Customer support systems (e.g., Zendesk, Intercom):
- Managing and resolving customer inquiries efficiently
- Managing and resolving customer inquiries efficiently
- Marketing and email services (e.g., Mailchimp, HubSpot):
- Sending emails, newsletters, and personalised communication
- Sending emails, newsletters, and personalised communication
- Cloud hosting providers (e.g., AWS, Azure):
- Securely storing and managing user data
Zoom’s policy transparently outlines every third-party category, such as resellers, vendors, legal disclosures, marketing partners, affiliates, acquirers, and developers, along with the precise reasons and safeguards for each type of data sharing.

Data retention and deletion policies
- Retention periods:
- Account and billing data retained as long as users maintain active accounts
- Usage logs and analytics data typically retained for 12-24 months
- Legal and financial records retained as per regulatory requirements
- Deletion processes:
- Provide clear instructions for users to request data deletion
- Confirm data deletion within specified time frames (usually within 30 days)
- Circumstances requiring longer retention:
- Compliance with legal obligations
- Resolution of disputes
- Prevention of fraud or abuse
Atlassian's data retention policy keeps account data as long as your account is active and for a short grace period afterward, retains shared content (with identifying details removed on request) to preserve team workflows, and holds marketing and cookie-derived data only for a reasonable time after your last engagement before anonymising or deleting it.

User rights regarding their data
- Right to access personal data: Users can request a copy of their stored data.
- Right to rectify data inaccuracies: Users can request corrections to incorrect information.
- Right to delete personal data ("right to be forgotten"): Users can request deletion of their personal data under specific circumstances.
- Right to object to processing: Users can opt-out or restrict certain data processing activities (e.g., marketing communications).
Ahrefs presents a concise “Rights of the Data Subject” section that briefly explains each right in plain language and then points users to a single contact for submitting requests, outlining any verification steps and expected timelines. This clear, streamlined approach makes it easy for individuals to exercise their data rights.

Cookie usage and management
- Types of cookies used:
- Essential cookies (authentication, session management)
- Functional cookies (user preferences, settings)
- Analytics cookies (user behaviour insights)
- Advertising cookies (targeted ads, remarketing)
- User control options:
- Cookie consent banners allowing granular consent preferences
- Detailed cookie policy providing clear explanations and management instructions

Data security measures
- Encryption standards:
- Secure data transfers (SSL/TLS)
- Encryption at rest (AES)
- Access controls and restrictions:
- Limited internal access to user data based on roles
- Two-factor authentication for accessing sensitive information
- Regular security audits and testing:
- Periodic penetration testing
- Continuous monitoring of systems for suspicious activities
- Incident response procedures:
- Established processes for managing data breaches swiftly and transparently
- User notifications within legally mandated timelines (e.g., 72 hours under GDPR)
Slack emphasises its commitment to data security by detailing robust measures, such as internationally recognised certifications and safeguards against loss, misuse, and unauthorised access, and directing users to a dedicated Security Practices page for full details. It also clearly notes that, while it strives for the highest protection, absolute security cannot be guaranteed for data in transit or at rest.

International data transfers
- Clearly state countries or regions where user data may be transferred.
- Describe safeguards and compliance measures used, such as:
- GDPR-approved standard contractual clauses
- Adequacy decisions recognised by regulatory authorities
- Security certifications (e.g., ISO 27001, SOC 2 compliance)
Stripe transfers personal data worldwide, including to the United States, under EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework (with UK and Swiss extensions), and APEC Cross-Border Privacy Rules and Privacy Recognition for Processors. Details and copies of its Data Transfers Addendum are available in Stripe’s Privacy Center.

Privacy policy updates
GitHub handles privacy statement updates by committing to notify users of material revisions at least 30 days in advance. They do this either by prominently updating the Privacy Statement page on their website or by emailing the primary address on a user’s account. This approach ensures users have ample time to review changes before they take effect.

How users can contact you
- Dedicated privacy contact:
- Clearly list email addresses or online forms specifically for privacy queries (e.g., [email protected])
- Data protection officer (DPO) (if applicable):
- Provide name and contact details of your DPO for GDPR compliance
- User support channels:
- Links or instructions for contacting customer support regarding privacy concerns or rights requests
monday.com’s privacy policy lists its Data Protection Officer, EU representative , UK representative, and a general support email so users always know exactly where to direct any privacy inquiries.




