Agile Gauge for Azure DevOps — Privacy Policy
Last updated: [date — not published yet]
Overview
Agile Gauge ("the Extension") is an Azure DevOps extension published by AlestaSoftware ("AlestaSoftware", "we", "us"). It processes Azure DevOps data inside the customer's browser to render dashboards and reports. This policy explains what data the Extension touches, where it goes, and what AlestaSoftware stores on its own systems.
1. Data the Extension reads from Azure DevOps
The Extension uses read-only Azure DevOps scopes (vso.project, vso.work, vso.graph). With those scopes, the Extension reads, on demand:
- project, team, sprint, and iteration metadata
- work item fields and revision history needed for analytics
- group and membership info needed for Access Control
This data stays in the customer's browser. It is not sent to AlestaSoftware.
2. Data persisted in the customer's Azure DevOps tenant
Configuration and per-user preferences are persisted via Microsoft's Azure DevOps Extension Data Service. This storage is hosted by Microsoft and scoped to the customer's organization. AlestaSoftware does not host or have access to it. This includes:
- extension configuration (access control, notification settings)
- per-user UI preferences
- license activation token and license summary (cached locally so the Extension can revalidate)
3. Data AlestaSoftware stores on its own systems
AlestaSoftware operates a backend at [domain — registration pending] that handles licensing and a small set of telemetry events. This backend runs on infrastructure shared with AlestaSoftware's other products, but Agile Gauge's data lives in its own isolated database schema — never mixed with any other product's records. The following data is stored on AlestaSoftware-controlled systems:
- License records: Azure DevOps organization name, ADO organization ID, plan, expiry, status, activation tokens issued by AlestaSoftware
- Seat roster: opaque Azure DevOps identity descriptors of the users assigned a seat. No names or email addresses — the descriptor format used cannot decode to one. Used only to enforce seat assignments. Agile Gauge enforces seat limits strictly — a user without an assigned seat cannot access the Extension's data and is shown a message directing them to their organization administrator. There is no limited "starter" or unlicensed viewing mode.
- Usage and error telemetry (opt-out available): event types covering which view was opened, which feature was used, error categories (never error text itself), session-start markers, license activation, and purchase-flow events — plus extension version, the Azure DevOps organization ID, and a pseudonymous user identifier (the Azure DevOps user GUID, never a name or email) — used to count distinct active users per organization and to enforce seat limits. Any licensed user can turn this off for the whole organization (Configuration → Privacy). Never work item content.
- Payment metadata via [payment processor] (sub-processor): the processor holds payment instrument data; AlestaSoftware never receives raw card numbers.
- Anonymous website metrics (this website only): standard privacy-first page-view/referrer counters, no cookies, no IP address, no user or organization identifier.
AlestaSoftware does not receive Azure DevOps work item content, AI prompts, AI responses, or AI provider API keys.
4. AI integrations
Not available in v1. Agile Gauge does not currently offer any AI-powered features or third-party AI integrations. A future bring-your-own-key (BYOK) AI capability is under discussion — if built, this policy will be updated before that feature ships. Customer-supplied API keys would stay in the customer's own environment and would never be stored by AlestaSoftware.
5. Sub-processors
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Microsoft Azure DevOps | Hosts the customer's tenant + Extension Data Service | Customer-controlled |
| [payment processor] | Payment processing | Billing details for purchasers only |
| [cloud host] | Hosts backend (database and runtime) | License records, activation tokens, telemetry |
| [email provider] | License-key delivery, billing emails | Recipient email address and organization name |
6. Data retention
[retention periods — not yet finalized]
7. Security controls
- HTTPS required for all outbound traffic
- Read-only Azure DevOps scopes — the Extension cannot modify work items, pipelines, or repository content
- License activation tokens are bearer credentials and are not logged
- Seat enforcement is verified server-side on every request that serves real data — not just a client-side screen
8. Your rights and choices
You can:
- switch off usage telemetry (Configuration → Privacy)
- request deletion of any license-related contact data by emailing support
- uninstall the Extension; this removes it from the ADO tenant. License records are retained per the retention policy above
9. Contact
- Email: [support email]
- Company: AlestaSoftware
- See our support page and the İletişim / Contact page for our registered company details
10. Data protection rights (GDPR / CCPA)
If you are in the EU/EEA, UK, or California, you have rights under GDPR, UK GDPR, and CCPA, including access, rectification, erasure, restriction, portability, and objection. Most of these can be exercised by uninstalling the Extension or emailing support for deletion of any AlestaSoftware-held license record. AlestaSoftware responds to verified requests within 30 days as required by applicable law.