Project Tracker is an internal application for the Bank Sinarmas Core Banking and Technical Product Management team. In this policy, “Project Tracker,” “we,” “us,” and “our” refer to the team and organization operating the application. This policy applies to the Project Tracker website and service, including its sign-in flow, dashboard, scheduled jobs, and configured integrations.
1. Information we receive
Account and sign-in information
Sign-in is provided through Google OAuth and Supabase Auth. We receive the identity details needed to authenticate an account and apply the company access rule, such as your name, email address, provider account identifier, and basic profile information made available by Google. We use this information to confirm that the account is a verified @banksinarmas.com identity, create or maintain a session, and associate activity with the correct authorized user.
Project Tracker does not request access to Gmail, Google Drive, Google Contacts, Google Calendar, Google Photos, or other Google content. The Google sign-in connection is used for identity and authentication only.
Tracker information
Authorized users and administrators may enter or manage operational information such as team member names and work email addresses, roles, groups, projects, Jira keys, project status, planned dates, activities, mandays, capacity overrides, holidays, worklogs, BAU entries, delivery-manager assignments, and project notes or custom fields. The tracker may also store derived utilization, sprint, capacity, and alert information calculated from those records.
Integration information
If an administrator configures an integration, the service may process information from or send information to:
- Jira: project, sprint, issue, assignee, issue-type, and worklog information needed for sprint and operational-work reporting. Jira credentials are stored and used only on the server.
- Google Chat: scheduled digest, alert, escalation, and mention content sent to the configured internal Chat space. Chat delivery is disabled until the application’s integration switch is intentionally enabled.
- Service providers: hosting, authentication/database, and error-monitoring providers may process technical information needed to run and secure the service.
Technical information
The service and its providers may receive ordinary technical information such as request timestamps, browser and device information, approximate network information, authentication events, and security or error records. Error-monitoring payloads are configured to exclude request bodies, cookies, headers, query strings, and credential-shaped values. Session replay is disabled.
2. How we use information
We use information to:
- authenticate authorized users and enforce the
banksinarmas.comaccess boundary; - provide project, capacity, worklog, sprint, archive, and reporting features;
- calculate utilization and other operational views from tracker records;
- run configured Jira synchronizations and internal Google Chat notifications;
- secure, troubleshoot, monitor, and improve the service; and
- comply with applicable law, internal controls, and legitimate administrative requests.
3. Google user data and limited use
Google user data is limited to the identity information described in this policy. We use it only to sign users in, verify their company-domain eligibility, maintain their session, and attribute authorized tracker activity. We do not sell Google user data, use it for advertising, or use it to determine credit, insurance, employment, or other unrelated eligibility. We do not transfer Google user data to third parties except as needed for the authentication flow and the service providers that operate the application on our instructions.
4. Cookies and local storage
Project Tracker uses essential authentication cookies so Supabase can maintain a signed-in session. It also uses a preference stored in the browser for the selected color theme and may use a functional cookie to remember the selected planning quarter. These are not advertising cookies, and the service does not use cross-site behavioral advertising.
5. Sharing and service providers
We share information only as needed to operate the internal service, protect it, or comply with law. Depending on the deployment configuration, this includes Google for authentication, Supabase for authentication and database hosting, Vercel or another hosting provider for application delivery, Sentry for scrubbed operational error monitoring, Jira for the configured read integration, and Google Chat for the configured internal notification destination. Each integration is limited to the information needed for its configured purpose.
6. Retention
Authentication sessions are retained only for the session and provider-controlled token lifetime. Operational tracker data, including archived projects and worklog ledgers, is kept as an internal business record unless an authorized administrator removes it or a longer or shorter period is required by applicable law or Bank Sinarmas policy. Disabling an integration does not automatically erase the tracker records already imported from it.
7. Security and access
Access to tracker data is restricted to verified company identities and application roles. Database authorization is enforced server-side and by row-level policies. Integration secrets are kept server-side. No method of transmission or storage is completely secure, but we use reasonable technical and organizational safeguards appropriate to this internal service.
8. Your choices and requests
You can stop using the service by signing out. Because Project Tracker is an internal business system, requests to correct, export, or delete tracker records should be made to the Project Tracker administrator through the normal Bank Sinarmas support channel. We may need to retain records required for operational, audit, security, or legal purposes.
9. Changes to this policy
We may update this policy when the service, integrations, or applicable requirements change. The “Last updated” date above identifies the current version. Material changes will be made available through the public policy page and, where appropriate, communicated to authorized users through internal channels.
10. Contact
For privacy questions or requests, contact the Project Tracker administrator or the user support email shown on the Google Cloud OAuth consent screen for this application.