Legal
Privacy Policy
Last updated 29 August 2026
This policy explains what personal data the Snitch application and the hosted Org Chart collect, why that data is processed, who it is shared with, and the rights available to the people it describes.
1. Introduction and scope
1.1 This Privacy Policy (the “Policy”) describes how Snitch processes Personal Data in connection with the Slack application and the hosted Org Chart made available at snitchforslack.com and snitch.team (together, the “Service”). Snitch is a product operated by Boon IT SRL, a company registered in Romania under CUI 45987107, with its registered office in Cluj-Napoca, Romania, and references in this Policy to “Snitch”, “we” and “us” are to that company.
1.2 This Policy applies to Personal Data processed through the Service. It does not apply to any third-party service that a Customer elects to use alongside the Service, which is governed by that third party's own terms.
1.3 This Policy forms part of, and is incorporated by reference into, the Terms of Service.
2. Definitions
2.1 In this Policy, the following terms have the meanings given:
- “Customer” means the organisation that installs the Service into a Slack workspace.
- “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
- “Personal Data” means any information relating to a Data Subject, as defined in Applicable Data Protection Law.
- “Applicable Data Protection Law” means Regulation (EU) 2016/679 (the “GDPR”), the UK GDPR and the Data Protection Act 2018, and any other data protection or privacy legislation applicable to the processing.
- “Sub-processor” means a third party engaged by Snitch to process Personal Data in the course of providing the Service.
- “Workspace Data” means Personal Data originating from, or submitted through, a Customer's Slack workspace.
2.2 The terms “controller”, “processor”, “processing” and “personal data breach” have the meanings given to them in the GDPR.
3. Roles of the parties
3.1 In respect of Workspace Data, the Customer is the controller and Snitch acts as a processor, processing such data only on the Customer's documented instructions, which include the instructions given through configuration of the Service.
3.2 In respect of data processed for its own account administration, billing and security purposes, Snitch acts as a controller, that role being held by the company identified in clause 1.1.
3.3 Snitch shall not process Workspace Data for any purpose other than the provision of the Service, and shall not sell Personal Data under any circumstances.
3.4 Snitch shall ensure that personnel authorised to process Personal Data are bound by an appropriate duty of confidentiality.
4. Categories of Personal Data
4.1 Installation Data. On installation, Snitch receives from Slack: the Slack team identifier, workspace name and workspace domain, which determine the address of the chart; the Slack identifier of the installing user, used for setup, trial and billing communications; a bot access token, encrypted at rest using AES-256-GCM with a key held outside the database; and the workspace member directory, comprising Slack user identifier, full name, display name, email address, avatar URL and job title. Bot users, deactivated accounts and guest accounts are excluded.
4.2 Response Data. Snitch processes the response given by each Data Subject to the question “who do you report to?”, together with the times at which the question was sent and answered; the profile details a Data Subject elects to provide, comprising title, team, location, start date, pronouns and an “ask me about” entry; and the text of questions submitted to the bot, processed in order to answer them.
4.3 Authentication Data. Where a Data Subject signs in to view a chart, Snitch receives through Sign in with Slack (OpenID Connect) that person's Slack identifier, name, email address and avatar, which are held in a signed, HttpOnly session cookie for seven days.
4.4 Billing Data. Snitch stores a Stripe customer identifier, a subscription identifier, and the applicable plan and its status. Payment card details are collected and processed by Stripe and are at no point received or stored by Snitch.
4.5 Technical Data. Snitch generates server logs containing IP address, user agent, timestamps and error traces, retained for the periods stated in clause 9.
4.6 Usage Data. Snitch measures the use of its websites and of the hosted Org Chart through the analytics described in clause 8. Where a Data Subject is signed in to the Org Chart, the data transmitted to the analytics provider includes a workspace identifier and a stable user identifier, each derived from the Slack identifiers already held under clause 4.1. Names and email addresses are not transmitted to the analytics provider.
5. Data not processed
5.1 Snitch does not access channels, files, huddles, or any direct message other than a message sent to Snitch itself. Snitch has not requested, and does not hold, the Slack permissions that would render such access possible.
5.2 Snitch does not process salary, compensation, performance, disciplinary, health or other special category data, and the Service provides no field in which such data may be recorded.
5.3 Snitch operates product analytics as described in clause 8. Snitch does not sell Personal Data, and operates no advertising trackers and no cross-site advertising trackers on its websites or within the Service.
6. Purposes and lawful bases
6.1 Snitch processes Personal Data for the following purposes and on the following lawful bases:
- Provision of the Service, comprising construction and maintenance of the Org Chart, answering questions and keeping the chart current: processing is necessary for the performance of the contract with the Customer (Article 6(1)(b) GDPR), and is carried out on the Customer's instructions.
- Billing and account administration: necessary for the performance of that contract (Article 6(1)(b) GDPR).
- Security, abuse prevention and diagnostics: necessary for the purposes of Snitch's legitimate interests in operating a secure and available service (Article 6(1)(f) GDPR).
- Administrative communications to the installing administrator: necessary for the performance of that contract (Article 6(1)(b) GDPR).
- Analytics, comprising the measurement of the websites and of the Service described in clause 8.2: necessary for the purposes of Snitch's legitimate interests in understanding how the Service and the website are used and how they may be improved (Article 6(1)(f) GDPR). This processing is not carried out on the basis of consent. A Data Subject may object to it as described in clause 10.1, and may prevent it as described in clause 8.3.
7. Sub-processors
7.1 Snitch engages the following Sub-processors, each bound by a written agreement imposing data protection obligations no less protective than those set out in this Policy:
- Slack Technologies (Salesforce): the platform on which the application operates.
- Vercel Inc.: application hosting.
- Neon Inc.: the PostgreSQL database in which chart data is stored.
- Stripe, Inc.: subscription payment processing. Stripe acts as merchant of record for subscriptions to the Service and issues the invoices and receipts for them.
- Anthropic PBC: where a question is submitted in natural language, the question and a compact extract of the organisation data required to answer it are transmitted to the Anthropic API. Anthropic does not use API inputs to train its models.
- PostHog Inc.: product analytics and session replay for the websites and the Service, hosted in the European Union, receiving page views, interaction events, session recordings in which form inputs are masked, and, for a signed-in user of the Org Chart, a workspace identifier and a stable user identifier. No name and no email address is transmitted to PostHog.
7.2 Snitch shall inform Customers of any intended addition or replacement of a Sub-processor, and shall remain liable for the acts and omissions of its Sub-processors.
8. Cookies and analytics
8.1 Strictly necessary cookies. Snitch sets a signed session cookie following Slack sign-in, and a short-lived state cookie which secures the sign-in exchange. These cookies are strictly necessary for the delivery of the Service and are set without consent, as permitted by Applicable Data Protection Law.
8.2 Analytics cookies and local storage. Snitch operates product analytics on its websites and within the hosted Org Chart. An analytics cookie and a local storage entry are written to the device and read from it on later visits, in order to recognise the same browser across sessions. This processing is carried out on the basis of the legitimate interests stated in clause 6.1, and not on the basis of consent.
8.2.1 The data collected comprises the pages viewed; the clicks and other interactions with elements of a page, such as the links and buttons activated on it; the referring address; an approximate location derived from the IP address; the device, browser and screen type; and recordings of the session, in which the contents of form fields are masked before the recording leaves the browser. It is used only to understand how the Service and the website are used and how they may be improved, and it is never sold.
8.2.2 Where a session recording is made of a page within the Org Chart, that recording will show the organisation information which was displayed on the page, such as names and reporting lines. It is processed as Workspace Data, on the same basis and subject to the same obligations as the rest of clause 4.
8.3 Controlling analytics. A visitor who does not wish to be measured may prevent the analytics cookie and local storage entry described in clause 8.2 through the settings of their browser, or by using a tracking blocker. Doing so has no effect whatsoever on the availability or the functionality of the Service.
8.3.1 On request to hello@snitchforslack.com, Snitch shall delete the analytics data associated with a person. Clause 10 applies to such a request as it applies to any other.
9. Retention and deletion
9.1 Workspace Data is retained for so long as the Service remains installed in the Customer's workspace.
9.2 Where a trial expires without a subscription being taken, no data is deleted and the chart becomes read-only. Where the application is removed from Slack, processing ceases immediately and data is retained so that the Customer may reinstall without loss.
9.3 On the written request of a workspace administrator, Snitch shall delete Workspace Data within 30 days, and shall procure its removal from backups within a further 30 days.
9.4 Server logs are deleted within 30 days of creation.
10. Rights of Data Subjects
10.1 Subject to Applicable Data Protection Law, a Data Subject has the right to request access to, rectification of, erasure of, or restriction of the processing of their Personal Data, the right to data portability, and the right to object to processing carried out on the basis of legitimate interests.
10.2 Certain rights may be exercised directly within the Service: a Data Subject may update their own profile through the bot, and a workspace administrator may correct a reporting line.
10.3 Any other request should be addressed to hello@snitchforslack.com. Snitch shall respond within 30 days. Where Snitch acts as processor, a request concerning a live chart may be referred to the Customer as controller, and Snitch shall provide the Customer with reasonable assistance in responding to it.
10.4 A Data Subject in the European Economic Area or the United Kingdom has the right to lodge a complaint with their competent supervisory authority.
11. Security measures
11.1 Snitch implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including:
- transmission of all traffic over TLS;
- encryption of Slack bot tokens at rest using AES-256-GCM, with the encryption key held outside the database;
- access control by which a chart may be viewed only following Slack sign-in, with verification on each request that the authenticated person is a member of the workspace concerned. No chart is publicly accessible or accessible by unguessable link.
11.2 No security measure is absolute. In the event of a personal data breach affecting Workspace Data, Snitch shall notify the affected Customer's administrators without undue delay and shall provide the information reasonably required for the Customer to comply with its own notification obligations.
12. International transfers
12.1 Hosting and database infrastructure are located in the United States. Where Personal Data of Data Subjects in the European Economic Area or the United Kingdom is transferred to that jurisdiction, such transfer is made pursuant to the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where applicable.
13. Children
13.1 The Service is a workplace tool supplied to organisations. It is not directed at persons under the age of 16, and Snitch does not knowingly process their Personal Data.
14. Amendments
14.1 Snitch may amend this Policy from time to time. The date stated above shall be updated on each amendment.
14.2 Where an amendment is material, workspace administrators shall be notified in Slack before the amendment takes effect.
15. Contact
15.1 Enquiries, requests and complaints concerning this Policy should be addressed to hello@snitchforslack.com.