Privacy Policy
Shift Handover Log for Microsoft Teams · Effective 22 August 2026
This policy describes how J.P. Johnson Law LLC ("we", "us") handles information when you use the Shift Handover Log application for Microsoft Teams and Microsoft 365 (the "App"), including its Microsoft Marketplace purchase page at sl.maconapps.com.
The short version
- The App stores only what your own people type into it, plus the minimum identity information needed to know who typed it.
- It does not read your chats, channels, files, mail, meetings, calendar or
directory. It requests one Microsoft Graph permission:
User.Read, the ordinary sign-in permission. - We do not sell data, do not use advertising or analytics trackers, and do not use your content to train any model.
What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Your Microsoft Entra tenant ID and user object ID; your display name and sign-in name as carried on the sign-in token | The Microsoft Entra single sign-on token Teams provides when you open the App | To identify your organization and you, and to attribute each handover, item, note and acknowledgment to the person who made it |
| Handover log configuration (log name, shift names, shift length, start hour, time zone) | Entered by the person who configures the tab | To generate the shift grid and continuity reporting |
| Handover content: summaries, items, severities, references (for example a ticket or change number), notes, submission and acknowledgment timestamps | Typed by your operators | This is the product — the record your team keeps |
| Log membership and roles, and the names of people added to a log | Chosen by a log admin via the Microsoft people picker or by entering an object ID | To restrict each log to its team |
| Subscription state (plan, seat count, status, billing term) and, for the purchasing account, its email address | Microsoft's SaaS Fulfillment API and Microsoft Graph license information | To know which features your organization and each user are entitled to |
| An audit log of actions (who created, submitted, acknowledged, exported or changed membership, and when) | Generated by the App | Accountability; the audit log is append-only and cannot be edited |
What we do not collect
No content from Teams, Outlook, SharePoint, OneDrive or any other Microsoft 365 service. No directory listings — the people picker is drawn and searched by Microsoft, and the App receives only the people you chose. No device identifiers, location, or behavioral analytics. The App sets no cookies inside Teams; the purchase page sets one short-lived (15-minute) sign-in session cookie used solely to complete Microsoft sign-in.
How data is stored and protected
- Data is stored in Cloudflare's D1 database and Workers KV services, currently in Cloudflare's North American region, and is encrypted in transit (TLS) and at rest.
- Every request is authenticated with a signature-validated Microsoft Entra token; nothing asserted by the browser is trusted for identity.
- Data is isolated by organization (tenant) and, within an organization, by log membership.
- Credentials used to talk to Microsoft are held in an encrypted secret store and never sent to the browser.
- Entitlement decisions are cached for at most five minutes; the cache is cleared immediately when Microsoft notifies us of a subscription change.
Who can see your data
Members of a handover log can read that log. Log admins manage membership. Our staff do not access customer content except where strictly necessary to resolve a support request you have raised, or as required by law. Our sub-processors are Cloudflare, Inc. (hosting, database and cache) and Microsoft Corporation (identity, licensing and commerce). No other third party receives your data.
Retention and deletion
- Handover records are kept for as long as your organization uses the App, because a continuous chain is the point of a handover log. Archived logs remain readable and exportable.
- When your subscription ends, your data is retained for 90 days so that a reinstated subscription finds it intact, then deleted.
- You may request deletion of your organization's data, or of an individual's data, at any time using the contact below. We act on verified requests within 30 days.
- Paid plans include a CSV export so that you always hold your own copy.
Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or delete personal data, and to complain to a supervisory authority. Because the App is used within your employer's Microsoft 365 environment, your employer is normally the data controller and we act as its processor; requests are usually best routed through your organization's administrator, but you may also contact us directly.
Changes
We will post any change to this policy at this address and update the effective date above. Material changes will also be noted in the App.
Contact
J.P. Johnson Law LLC · support@maconapps.com