Privacy Policy
Privacy Policy for SharePoint Framework (SPFx) Applications
This Privacy Policy explains what personal and organisational information SharePoint Guru collects when customers use our SPFx apps purchased through the Microsoft Marketplace via our partner account, how that information is used and shared (including with Microsoft and other third parties), where it is stored, the security measures we apply, retention periods, and the rights available to users under UK data protection law. This policy applies to customers, end users and administrators of our applications and services. If you have questions, requests or a complaint about our handling of personal data, please use the contact form.
Effective Date: 02/Sept/2026
Provider: Ghost Machine Software
This Privacy Policy explains how [Your Company Name] (“Provider”, “we”, “us”, “our”) processes information when you install or use our SharePoint Framework (SPFx) applications (“Application”) within your Microsoft 365 tenant. By using the Application, you agree to the practices described in this policy.
1. Information We Process
The Application operates entirely within your Microsoft 365 tenant. Depending on configuration and features, the Application may process:
SharePoint site data (lists, libraries, pages, metadata)
User profile information (name, email, role, tenant ID)
Microsoft Graph data where permissions are granted
Operational telemetry (errors, performance metrics, usage patterns)
All processing occurs within your Microsoft 365 environment unless explicitly stated otherwise.
2. No External Data Collection
Unless the Application documentation specifically states otherwise:
We do not collect, store, transfer, or access your tenant data outside your Microsoft 365 environment.
We do not receive or retain any personally identifiable information (PII) from your tenant.
We do not use your data for analytics, marketing, profiling, or advertising.
If optional cloud services are used (e.g., external APIs), these will be clearly documented and require explicit consent.
3. Permissions & Access
The Application may require certain Microsoft 365 permissions to function, including SharePoint, Microsoft Graph, or Teams permissions. By installing the Application, you acknowledge:
Permissions are granted by your Microsoft 365 administrator.
The Application only uses permissions necessary for its core functionality.
The Provider cannot access your tenant unless you explicitly grant external access (e.g., support scenarios).
4. How We Use Processed Information
Information processed by the Application is used solely for:
Delivering core functionality
Improving user experience
Ensuring security and compliance
Troubleshooting issues within your tenant
Providing optional features (e.g., automation, reporting)
We do not sell, rent, or share any processed information with third parties.
5. Data Security
Your data remains protected by Microsoft’s enterprise‑grade security controls. We implement additional safeguards including:
Least‑privilege permission design
No external data extraction
Secure coding practices for SPFx and Microsoft Graph
Regular security reviews and updates
You are responsible for maintaining appropriate tenant‑level security, including conditional access, MFA, and governance policies.
6. Marketplace & Microsoft Relationship
The Application is distributed through the Microsoft Commercial Marketplace, but:
Microsoft is not responsible for the Application’s privacy practices.
Microsoft does not access or process data on our behalf.
All support and privacy inquiries must be directed to the Provider.
7. Cookies & Tracking
The Application does not use cookies, browser tracking, or external analytics unless explicitly stated in the product documentation.
8. Data Retention
Because the Application does not extract data externally, we do not retain tenant data. If optional cloud services are used, retention periods will be documented and configurable.
9. Your Rights
Depending on your jurisdiction, you may have rights to:
Access data processed by the Application
Request deletion of externally stored data (if applicable)
Request correction of inaccurate information
Request details about third‑party processors (if any)
Requests can be submitted via the contact form
10. Children’s Privacy
The Application is intended for business use within Microsoft 365 and is not designed for children under 16. We do not knowingly process children’s data.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in features, legal requirements, or security practices. Updates will be published in the Marketplace listing and/or our website. Continued use of the Application constitutes acceptance of the updated policy.
12. Contact Information
For privacy inquiries, data protection questions, or support requests please use the contact form