OrgView 360 Privacy Policy
- This policy is effective August 27, 2026.
- OrgView 360 is an independent Salesforce-compatible security analysis extension.
- OrgView 360 is not affiliated with, endorsed by, or sponsored by Salesforce, Inc.
- The extension is intended for authorized Salesforce administrators, developers, auditors, and support professionals.
- Users must have permission from the applicable Salesforce organization before inspecting its configuration.
- The extension operates only on the supported Salesforce domains declared in its manifest.
- The extension connects to the active Salesforce org when the user opens its interface.
- The extension reads a Salesforce
sid cookie to authenticate direct requests to the selected org.
- The extension may compare Salesforce
sid cookie candidates to locate the API session for the same org on alternate Salesforce domains.
- It does not read unrelated cookie names or use Salesforce cookies for tracking.
- The session identifier is held temporarily by the Manifest V3 service worker.
- The session identifier is never written to Chrome storage.
- The session identifier is never placed in page content, extension URLs, analytics, or logs.
- API requests are restricted to HTTPS and approved Salesforce host patterns.
- API request paths are restricted to Salesforce
/services/ endpoints.
- The extension currently permits read-only Salesforce API requests.
- The extension reads the current Salesforce user identifier and organization identifier.
- It can read active-user names, usernames, profiles, roles, and available User-field values.
- It can read profiles, permission sets, permission-set assignments, and system permissions.
- It can read object permissions, field permissions, field labels, and calculated-field indicators.
- It can read application, tab, Apex class, and Visualforce page access metadata.
- It can read organization-wide defaults and supported sharing metadata.
- It can request effective access information for a record ID entered by the user.
- Administrators can select another active user for analysis through their authorized session.
- Selecting another user does not impersonate or obtain that user’s Salesforce session.
- Salesforce remains responsible for enforcing API, setup, field, object, and record access.
- Missing or unavailable metadata is not automatically interpreted as denied access.
- API results are displayed only in the open extension interface.
- API results are held in memory while the extension interface is active.
- API results are discarded when the interface and related extension context are destroyed.
- The extension does not create a publisher database of Salesforce users or permission results.
- The extension does not transmit Salesforce org data to the publisher.
- The extension does not use external analytics, advertising, telemetry, or AI services.
- The extension does not sell, rent, or trade personal information or Salesforce data.
- The extension does not use collected information for advertising or credit decisions.
- The extension does not use Chrome storage for Salesforce credentials or permission results.
- Users may close the extension interface at any time.
- Users may uninstall the extension to prevent future access.
- Removing the extension ends its ability to access Salesforce sessions.
- Salesforce administrators may restrict installation, cookie access, or API access through organizational controls.
- Redirect links are limited to supported Salesforce HTTPS domains.
- New tabs opened by the extension remain associated with the originating Salesforce tab group when supported.
- Reasonable technical safeguards are used, but no software can guarantee absolute security.
- Users must not include session identifiers or confidential org data in support reports.
- Material changes to data handling require an updated policy and any disclosure or consent required by applicable rules.
- The publisher must provide a legal identity, jurisdiction, support email, and security contact before public release.
- The publisher must host this policy at a stable public HTTPS address before Chrome Web Store publication.
- Privacy questions should be sent to the publisher’s designated privacy contact once published.
- Salesforce is a trademark of Salesforce, Inc.
- Continued use after a published policy update remains subject to applicable disclosure, authorization, and consent requirements.