Data security and Privacy

Data security and Privacy

Overview

Capacity Tracker has three different implementations depending on your Jira platform:

  • Jira Cloud (Forge)

  • Jira Cloud (Connect) - Deprecated

  • Jira server and Data Center

Jira Cloud (Forge)

Running on Atlassian Forge means your data never leaves Atlassian's infrastructure. It also means Atlassian is handling Authentication and Authorization so the overall security is improved.

We do not have the "Runs on Atlassian" badge because in order to ensure a smooth transition from Connect to Forge, we need to make an API call to the old infrastructure to move your old settings to Forge when you update the app. Because of this external link, the app is not compatible with the "Runs on Atlassian" requirements at this time. However, this is strictly temporary and will be removed as soon as all our existing clients have moved to the Forge version.

Jira Cloud (Connect) - Deprecated

Capacity Tracker for Jira Cloud uses the Atlassian Connect framework and works by exposing a multitude of REST APIs. The app is hosted in our own infrastructure and your Jira instance interacts with it by calling those APIs.

Data storage

To provide the best possible service, some data will be stored in our own storage layer for versions 2.2.X-AC (AWS DynamoDB) which is being deprecated. For version 2.1.0 (Forge) and up it is stored on Atlassian’s cloud infrastructure.


The data stored includes:

  • Jira instance details (base URL, date of installation / modification, etc). This allows us to use the Atlassian Connect framework.

  • Board settings

    • Team settings (working days, holidays)

    • For every user in your board: user account ID, role, daily capacity

  • User days off

  • Multi-project report settings:

    • Project Keys

    • Board IDs

  • Templates

    • User account IDs, role, daily capacity

  • API Refresh tokens & keys

Security

All API calls use HTTPS for security.

Capacity Tracker is part of the Atlassian Cloud Fortified program which includes strict security requirements.

Endpoints

If you use a firewall, you may need to white-list our production endpoints:

Data Residency and Processing

Your configuration data will be stored in our internal storage layer located in US-East region.

Our processing servers are distributed in two regions (US-East and EU-West), so the actual server being used will depend on your location.

Jira Server and Data Center

Capacity Tracker for Jira Server and Data Center is a self-contained application that will be downloaded and installed on your own Jira instance. Your data will stay on your instance and will never be sent anywhere else.