Privacy policy
DRAFT for review. Not yet in effect. Prepared 2026-10-02 for Jon Martin's review. It is not legal advice and must be reviewed (ideally by counsel) before it is published or used in a HubSpot Marketplace listing. Items in [brackets] need a decision.
Last updated: [date of publication]
This policy explains what data the Portal Audit app ("Portal Audit", "we", "us") accesses, stores and shares when you connect it to your HubSpot account, and the choices you have. Portal Audit is operated by [legal entity name, e.g. Jon Martin / The Jon Martin company], [business address], reachable at jon@thejonmartin.com.
Who this applies to
This policy covers the HubSpot account ("portal") owners and users who install Portal Audit, and the people whose details appear in the portal settings we read (for example HubSpot users and record owners). It does not cover HubSpot itself; HubSpot's own privacy policy applies to your HubSpot account.
What we access
Portal Audit reads your HubSpot configuration through HubSpot's API, with the permissions ("scopes") you approve during install. It is read-only: it never creates, changes or deletes anything in your portal.
Required permissions:
| HubSpot data | Scope | What the audit reads |
|---|---|---|
| Account | oauth | Account details: portal ID, time zone, currency, data hosting location |
| Contacts | crm.objects.contacts.read | Record counts and field-completeness checks (counts only; no contact records are copied) |
| Companies | crm.objects.companies.read | Record counts and field-completeness checks |
| Deals | crm.objects.deals.read | Record counts, field completeness, deal pipelines and stages |
| Tickets | crm.objects.tickets.read | Record counts, field completeness, ticket pipelines and stages |
| Contacts | crm.schemas.contacts.read | Property definitions (names, types, groups, usage flags) |
| Companies | crm.schemas.companies.read | Property definitions |
| Deals | crm.schemas.deals.read | Property definitions |
| Tickets | crm.schemas.tickets.read | Property definitions |
| Line items | crm.objects.line_items.read | Record counts |
| Line items | crm.schemas.line_items.read | Property definitions |
| Quotes | crm.objects.quotes.read | Record counts |
| Quotes | crm.schemas.quotes.read | Property definitions |
| Users | crm.objects.owners.read | Record owners (name, email, active/archived) to find unassigned or departed owners |
| Users | settings.users.read | Users and roles (name, email, role, super admin flag) for the access review |
| Users | settings.users.teams.read | Teams and team membership |
| Segments (lists) | crm.lists.read | Segment names, types, sizes and last-updated dates |
| Account security | account-info.security.read | Login history, security activity and audit-log summaries (last 90 days); private-app API usage |
Optional permissions (only if your plan includes the tool and you leave them checked):
| HubSpot data | Scope | What the audit reads |
|---|---|---|
| Forms | forms | Form names, types and settings (submissions are not read) |
| Marketing email | marketing-email | Marketing email names, states and settings (nothing is sent) |
| Workflows | automation | Workflow names, status, object type, enrollment settings and actions (no workflow is changed) |
| Marketing email | content | Marketing email inventory when the marketing-email scope is not enough (some portals require content) |
| Custom objects | crm.objects.custom.read | Custom object record counts and field completeness |
| Custom objects | crm.schemas.custom.read | Custom object schemas and property definitions |
| Website | cms.domains.read | Connected domains, to find the company website for the business profile |
We do not read form submissions, email content sent to contacts, conversations, files, or payment data, and we do not copy contact, company, deal or ticket records. Data-quality checks use counts of records with missing or inconsistent fields.
What we store
- Connection data: your portal ID, HubSpot account domain, the ID of the user who installed the app, the permissions granted, and a refresh token. The refresh token is encrypted (AES-256-GCM). Short-lived access tokens are kept in memory only.
- Audit reports: the report files we generate (JSON, Markdown, HTML, PDF) and the fix plan. Reports contain configuration details and counts. They can include names and email addresses of your HubSpot users and record owners, because the access review lists, for example, super admins and inactive users.
- Business profile: your company's industry, size band and website, which you confirm with us, plus a short strengths/weaknesses summary generated from the audit.
- Schedule and history: your monthly audit settings and a record of past runs.
- Operational logs: request counts, errors and timings. Logs do not contain tokens or record data.
How we use it
Only to provide the service: run audits, produce reports and fix plans, compare month over month, and support you. We do not sell your data, use it for advertising, or use it to train AI models.
AI processing
Parts of the report narrative (summary, strengths/weaknesses, priorities) may be drafted with an AI assistant. Only aggregated audit results are used for this, and before any AI processing we remove email addresses, IP addresses, phone numbers, URLs (other than your public website) and known person names. [List the AI provider(s) actually used, e.g. "xAI (Grok)" or "none", and their data-retention terms.]
Who we share it with
We share data only with service providers that help us run Portal Audit, under contracts that limit their use of it:
| Provider | Purpose | Data |
|---|---|---|
| [Railway Corporation (railway.com)] | Hosting the app, database and report files [region: to confirm] | Everything listed under "What we store" |
| [AI provider, if any] | Drafting the report narrative | Redacted, aggregated audit results only |
| [Email provider used to send reports, e.g. Google Workspace] | Delivering reports to you | The report you receive |
We may disclose data if required by law. If Portal Audit is sold or transferred, this policy continues to apply to the data.
Where data is stored
Data is stored with our hosting provider in [region, e.g. the United States]. If you are outside that region, your data is transferred there. [If you serve EU/UK customers: name the transfer mechanism, e.g. Standard Contractual Clauses, and offer a data processing agreement.]
How long we keep it
- While installed: we keep reports and history so we can show month-over-month progress. [Optional: reports older than 24 months are deleted.]
- When you disconnect: our access ends and the refresh token is deleted immediately; scheduled audits stop.
- 30 days after you disconnect: we delete your reports, business profile, schedule, audit history and connection record. Encrypted backups expire within [the backup retention period, e.g. 30] days after that.
- On request: we delete your data sooner. Email jon@thejonmartin.com from an address on your HubSpot account.
Security
Encrypted connections (HTTPS) in transit; refresh tokens encrypted at rest; least-privilege, read-only API access enforced in code; admin functions protected by a secret token; data separated by portal ID. No method of storage or transmission is completely secure, but we work to protect your data and will tell you without undue delay if a breach affects it.
Your rights
Depending on where you live, you may have rights to access, correct, delete or export your personal data, or to object to or restrict its processing. Email jon@thejonmartin.com and we will respond within 30 days. For HubSpot users listed in a report, we act on behalf of the portal owner (as a processor/service provider), so we may refer your request to them. [If applicable: you can complain to your data protection authority.]
Children
Portal Audit is a business tool and is not directed at children under 16.
Changes
We will post changes on this page and update the date above. For material changes we will email the contact on file before they take effect.
Contact
[Legal entity name], [address]. Email: jon@thejonmartin.com.