Skip to content
On This Page
  • 1. Introduction

  • 2. Information We Collect

  • 3. How We Use Your Information

  • 4. Data Sharing and Disclosure

  • 5. Data Security

  • 6. Data Retention

  • 7. Your Rights

  • 8. Third-Party Services

  • 9. Children's Privacy

  • 10. International Data Transfers

  • 11. Changes to This Policy

  • 12. Contact Us

Privacy Policy

Last updated: September 26, 2026

1. Introduction

SlackBridge ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Slack-to-Microsoft Teams integration service.

By using SlackBridge, you agree to the collection and use of information in accordance with this policy.


2. Information We Collect

2.1 Information You Provide

  • Slack workspace information (workspace name, team ID)
  • Microsoft Teams tenant information (tenant ID, organization name)
  • Channel mapping configurations
  • Contact email addresses for account administration

2.2 Information Collected Automatically

  • OAuth tokens (encrypted and stored securely)
  • Message routing metadata (timestamps, message and channel identifiers) retained for 7 days; this record never contains sender names or message text
  • Transient user profile data (display names and avatar images) cached for up to 24 hours so that message senders and mentioned users appear by name on the receiving platform; these cache entries expire automatically
  • For each bridged channel with mentions turned on, a member list (each person's display name, the name they can be addressed by, and their Slack or Microsoft user ID) so that @mentions reach the right person; it is replaced after each complete refresh and kept until that channel mapping is deleted, including while the mapping is paused
  • Usage statistics (message counts, feature usage)
  • Technical logs for debugging and service improvement

2.3 Message Content

Important: SlackBridge operates on a serverless architecture. Full message content is never stored on our servers. Messages are relayed in real-time between Slack and Microsoft Teams. To support thread synchronization, we retain for 7 days only routing metadata (message and channel identifiers, timestamps, and a non-reversible one-way fingerprint, or BLAKE3 hash, of the message), after which it is automatically deleted. That record never contains the readable message body or the sender's name. Display names and avatar images are cached separately for up to 24 hours, and bridged channels with mentions turned on keep a member list of display names and user IDs, as described in section 2.2. Operational logs record identifiers, timings and error details. They never include the text of bridged messages or the names of people in bridged conversations; events about your account can include the account holder's email address. Cloudflare keeps these logs for up to 7 days. When an error occurs, an error report containing the error, the request method and path, and the most recent log lines (never the request body, headers or query string) is sent to our error-monitoring sub-processor, Sentry, which keeps it for up to 90 days.


3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the SlackBridge service
  • Route messages between Slack and Microsoft Teams
  • Authenticate your connections with Slack and Microsoft
  • Send administrative communications (service updates, security alerts)
  • Process billing and subscription management
  • Improve and optimize our service
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We use Cloudflare for hosting and Stripe for payment processing. These providers have access only to information necessary to perform their functions.
  • Platform APIs: We interact with Slack and Microsoft Graph APIs to provide our service. Your information is shared with these platforms as necessary for functionality.
  • Legal Requirements: We may disclose information only if required by law, legal process, or government request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Data Security

We implement industry-standard security measures to protect your information:

  • OAuth 2.0 authentication for all platform connections
  • TLS/SSL encryption for all data in transit
  • Encrypted storage for OAuth tokens and sensitive data
  • Serverless architecture with no long-term message storage (routing metadata retained for 7 days for thread sync)
  • Regular security audits and monitoring

For detailed information about our security controls and compliance status, see our Security & Compliance page.


6. Data Retention

  • Account Data: Retained for the duration of your account, plus 30 days after deletion
  • OAuth Tokens: Automatically refreshed and old tokens discarded
  • Message Content: Full messages are never stored. Only routing metadata (message and channel identifiers, timestamps, and a non-reversible one-way fingerprint) is retained for 7 days to support thread synchronization, then automatically deleted, never the readable message text or sender name
  • Usage Statistics: Per-organization message counts, totalled by month and by day and split by direction, containing no message content, sender names or recipient names. Used to show you your own usage in the optional weekly report and for our internal service reporting. Message volume does not affect your plan limits or your bill: plans are counted in linked channels and Teams connections only. These counts are currently retained for the life of the account
  • Technical Logs: Platform request logs used for debugging, containing identifiers and error details but never the text of bridged messages or the names of people in bridged conversations (events about your account can include the account holder's email address), retained by our infrastructure provider (Cloudflare) for up to 7 days. Error reports, which include the most recent log lines but never request bodies, headers or query strings, are retained by our error-monitoring provider (Sentry) for up to 90 days
  • Billing Records: Retained as required by law (typically 7 years)

7. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a portable format
  • Objection: Object to certain processing of your data

To exercise these rights, contact us at privacy@slackbridge.com.


8. Third-Party Services

SlackBridge uses third-party service providers (sub-processors) to deliver our service. For a complete list, see our Sub-Processors page. Key integrations include:


9. Children's Privacy

SlackBridge is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.


10. International Data Transfers

SlackBridge operates globally using Cloudflare's edge network. Your data may be processed in various locations worldwide. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where applicable.


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of SlackBridge after changes constitutes acceptance of the updated policy.


12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@slackbridge.com
Website: https://slackbridge.com