Privacy Policy

Privacy Policy for SharePoint Framework (SPFx) Applications

 

This Privacy Policy explains what personal and organisational information SharePoint Guru collects when customers use our SPFx apps purchased through the Microsoft Marketplace via our partner account, how that information is used and shared (including with Microsoft and other third parties), where it is stored, the security measures we apply, retention periods, and the rights available to users under UK data protection law. This policy applies to customers, end users and administrators of our applications and services. If you have questions, requests or a complaint about our handling of personal data, please use the contact form.

 

Effective Date: 02/Sept/2026

Provider: Ghost Machine Software

 

This Privacy Policy explains how [Your Company Name] (“Provider”, “we”, “us”, “our”) processes information when you install or use our SharePoint Framework (SPFx) applications (“Application”) within your Microsoft 365 tenant. By using the Application, you agree to the practices described in this policy.

 

1. Information We Process

 

The Application operates entirely within your Microsoft 365 tenant. Depending on configuration and features, the Application may process:

SharePoint site data (lists, libraries, pages, metadata)

User profile information (name, email, role, tenant ID)

Microsoft Graph data where permissions are granted

Operational telemetry (errors, performance metrics, usage patterns)

All processing occurs within your Microsoft 365 environment unless explicitly stated otherwise.

 

2. No External Data Collection

 

Unless the Application documentation specifically states otherwise:

We do not collect, store, transfer, or access your tenant data outside your Microsoft 365 environment.

We do not receive or retain any personally identifiable information (PII) from your tenant.

We do not use your data for analytics, marketing, profiling, or advertising.

If optional cloud services are used (e.g., external APIs), these will be clearly documented and require explicit consent.

 

3. Permissions & Access

 

The Application may require certain Microsoft 365 permissions to function, including SharePoint, Microsoft Graph, or Teams permissions. By installing the Application, you acknowledge:

Permissions are granted by your Microsoft 365 administrator.

The Application only uses permissions necessary for its core functionality.

The Provider cannot access your tenant unless you explicitly grant external access (e.g., support scenarios).

 

4. How We Use Processed Information

 

Information processed by the Application is used solely for:

Delivering core functionality

Improving user experience

Ensuring security and compliance

Troubleshooting issues within your tenant

Providing optional features (e.g., automation, reporting)

We do not sell, rent, or share any processed information with third parties.

 

5. Data Security

 

Your data remains protected by Microsoft’s enterprise‑grade security controls. We implement additional safeguards including:

Least‑privilege permission design

No external data extraction

Secure coding practices for SPFx and Microsoft Graph

Regular security reviews and updates

You are responsible for maintaining appropriate tenant‑level security, including conditional access, MFA, and governance policies.

 

6. Marketplace & Microsoft Relationship

 

The Application is distributed through the Microsoft Commercial Marketplace, but:

Microsoft is not responsible for the Application’s privacy practices.

Microsoft does not access or process data on our behalf.

All support and privacy inquiries must be directed to the Provider.

 

7. Cookies & Tracking

 

The Application does not use cookies, browser tracking, or external analytics unless explicitly stated in the product documentation.

 

8. Data Retention

 

Because the Application does not extract data externally, we do not retain tenant data. If optional cloud services are used, retention periods will be documented and configurable.

 

9. Your Rights

 

Depending on your jurisdiction, you may have rights to:

Access data processed by the Application

Request deletion of externally stored data (if applicable)

Request correction of inaccurate information

Request details about third‑party processors (if any)

Requests can be submitted via the contact form

 

10. Children’s Privacy

 

The Application is intended for business use within Microsoft 365 and is not designed for children under 16. We do not knowingly process children’s data.

 

11. Changes to This Policy

 

We may update this Privacy Policy to reflect changes in features, legal requirements, or security practices. Updates will be published in the Marketplace listing and/or our website. Continued use of the Application constitutes acceptance of the updated policy.

 

12. Contact Information

 

For privacy inquiries, data protection questions, or support requests please use the contact form

 

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.