Privacy Policy
This Privacy Policy explains how we collect, use, and protect information when you use UndoEngine
("Service"), a Salesforce data management and recovery tool.
1. Information We Collect
- Account information such as name and email provided during registration or subscription;
- Payment information is processed directly by our payment provider (Creem) — we do not
collect, store, or have access to credit card data or other payment credentials;
- Technical and usage data related to product usage and system performance;
- Salesforce organization metadata, including Organization ID, Organization URL, and
Organization Name, stored in Airtable and used strictly to verify authorization to access
the Service: each time the package is used, an authenticated request is made to Airtable
to confirm that the installing organization's Organization ID is on the allowed list of
clients;
- We do not store or copy Salesforce business data, including records, record history, or any
CRM content, outside the customer's Salesforce organization, except for files for which the
customer may optionally connect their own Cloudflare R2 storage for backup and restore —
described in more detail in Section 4.
2. Legal Basis for Processing (for EU Users)
We process personal data on the following legal bases under the GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service and manage your subscription;
- Legitimate interest (Art. 6(1)(f)) — to ensure security, prevent fraud, and improve the Service;
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law, including tax and accounting requirements.
3. How We Use Information
- To operate and maintain the Service;
- To process payments and manage subscriptions;
- To provide customer support and communicate updates;
- To improve reliability, performance, and functionality of the Service;
- To comply with legal obligations.
4. Salesforce Data and File Storage
UndoEngine operates entirely within the customer's Salesforce environment via authorized API
access. All Salesforce business data remains stored in the customer's Salesforce organization,
except for files for which the customer has optionally connected their own Cloudflare R2
storage for backup and restore.
In this case:
- The customer independently creates and controls their own Cloudflare account and R2 bucket;
- The customer provides UndoEngine with access credentials (Access Key ID, Secret Key, Account ID)
solely to perform file backup and restore operations on the customer's behalf;
- Files are stored in the customer's bucket, isolated from other customers, with no shared
access or quotas;
- UndoEngine does not access the contents of the bucket outside of operations initiated by the
customer through the Service, and does not copy or retain copies of these files on its own
infrastructure;
- The customer remains the controller of the data stored in their Cloudflare R2 bucket and is
responsible for configuring their own Cloudflare account in accordance with applicable legal
requirements.
The customer remains the data controller for all Salesforce and file data. UndoEngine processes
this data only on behalf of the customer and solely for the purpose of executing requested
operations such as backup, restore, rollback, and synchronization.
5. Third Parties and Subprocessors
We engage the following subprocessors to process limited technical data and to process payments:
- Creem — payment processing; Creem independently collects, processes, and stores payment
data in accordance with its own privacy policy;
- Airtable — storage of customer account information and Salesforce organization metadata
(Organization ID, Organization URL, Organization Name) for licensing and access control
purposes;
- Cloudflare — provided by the customer as optional file storage on their own account;
Cloudflare in this case acts as the customer's subprocessor, not ours, since the account,
bucket, and data are fully owned and controlled by the customer.
6. Cookies and Analytics
Our website does not use analytics or marketing cookies that identify individual visitors.
7. Data Security
We implement reasonable technical and organizational security measures to protect our systems
and access credentials. Salesforce business data remains entirely within the customer's
Salesforce organization, except for files for which the customer has optionally configured
backup through their own Cloudflare R2 storage — in this case, the security of such data also
depends on the customer's own Cloudflare account configuration, as described in Section 4.
We do not process or store payment data — its protection is provided by Creem.
8. Data Retention
We do not store Salesforce business data and do not store payment data — its processing and
storage is handled solely by our payment provider, Creem, in accordance with its own privacy
policy. We retain only minimal account information (name, email) and Salesforce organization
metadata (Organization ID, URL, and Name) necessary to operate the Service and manage
subscriptions.
Files for which the customer has optionally connected their own Cloudflare R2 storage are
retained in the customer's account according to their own retention settings — we do not
control or determine the retention period for these files.
Account information and Salesforce organization metadata are retained for the duration of the
subscription and are deleted within a reasonable period after cancellation, unless longer
retention is required by applicable law (including tax law).
9. Data Breach Notification
In the event of a security incident affecting personal data, we will notify affected users and,
where required, the relevant supervisory authorities within the timeframes established by
applicable law.
10. Your Rights (for EU/GDPR Users)
You have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion of your data ("right to be forgotten");
- restrict processing;
- data portability;
- object to processing;
- lodge a complaint with a data protection supervisory authority in your country.
To exercise these rights, contact
support@undoengine.com.
11. Rights of California Residents (CCPA/CPRA)
If you are a California resident, under the CCPA/CPRA you have the right to:
- know what personal information we collect and how it is used;
- request deletion of your personal information;
- opt out of the sale/sharing of personal information — we do not sell or share personal
information with third parties for cross-context behavioral advertising or monetary
consideration;
- non-discrimination — we will not penalize you for exercising your privacy rights through
reduced service quality or changed pricing. This does not apply to data without which
providing the Service is technically impossible (in particular, the Organization ID
required to authorize access to the Service) — declining to provide such data means the
Service cannot be used.
To exercise these rights, contact
support@undoengine.com.
12. Right to Lodge a Complaint
In addition to contacting us directly, you have the right to lodge a complaint with the relevant
data protection supervisory authority in your jurisdiction.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page.
Last updated: 31.07.2026