Privacy Policy
Version 2026-10-02Effective
This policy explains what personal data Yalla Scrum keeps, why, who processes it for us, and how long we keep it. Yalla Scrum is run by Yalla Scrum, 1st settlement South Academy. For anything about your data, email [email protected].
1. The data we keep
- Account data: your name, email address, Atlassian account ID and avatar, your Yalla Scrum role, and, for an account login, a hashed password and an authenticator secret.
- Jira data you work with: the sites, boards, sprints, issues, estimates and people Yalla Scrum shows you, as read from Jira, and the plans, estimates, capacity and reports your team creates in Yalla Scrum.
- Sign-in data: encrypted Atlassian access tokens and session records, so you stay signed in.
- Billing data: your workspace's plan, seats, payment references and invoices. We do not store card numbers; card and wallet payments are handled by Paymob.
- Technical data: server logs with IP addresses and request details, used for security and to fix problems.
2. Why we use it
We use this data only to provide Yalla Scrum: to sign you in, to show and update your Jira work as you direct, to run your team's planning sessions and reports, to bill your workspace, to send the emails the service needs, and to keep the service secure. We do not sell your data and we do not use it for advertising.
3. Who processes it for us
- Atlassian: Jira sign-in (OAuth) and the Jira data Yalla Scrum reads and updates on your behalf.
- Resend: sends Yalla Scrum's emails (invites, sign-in help, reports).
- Paymob: card and wallet payments, when you pay that way.
- Our hosting provider: the servers and storage that run Yalla Scrum and keep its database and backups.
Each processes the data only to provide its part of the service. The Data Processing Addendum has the details.
4. How long we keep it
- While your workspace is active, we keep its data so the service works.
- If you cancel, we keep the data until the end of the last period you paid for, then erase it.
- Backups are kept for 14 days, so erased data leaves our backups within 14 days after it is erased.
- Server logs are kept only as long as needed for security and troubleshooting.
5. Security
Access tokens are encrypted at rest, sessions use secure cookies, and access to the data is limited to what is needed to run the service.
6. Your rights
You can ask us for a copy of your personal data, to correct it, or to erase it, by emailing [email protected]. If your workspace is managed by your employer, we may pass your request to them, since they decide how Yalla Scrum is used.
7. Changes
When we change this policy we update the version date and, for a change that matters to you, tell you before it applies.
8. Contact
Write to Yalla Scrum, 1st settlement South Academy. Email: [email protected].