OrgView-360-Privacy-Policy

OrgView 360 Privacy Policy

  1. This policy is effective August 27, 2026.
  2. OrgView 360 is an independent Salesforce-compatible security analysis extension.
  3. OrgView 360 is not affiliated with, endorsed by, or sponsored by Salesforce, Inc.
  4. The extension is intended for authorized Salesforce administrators, developers, auditors, and support professionals.
  5. Users must have permission from the applicable Salesforce organization before inspecting its configuration.
  6. The extension operates only on the supported Salesforce domains declared in its manifest.
  7. The extension connects to the active Salesforce org when the user opens its interface.
  8. The extension reads a Salesforce sid cookie to authenticate direct requests to the selected org.
  9. The extension may compare Salesforce sid cookie candidates to locate the API session for the same org on alternate Salesforce domains.
  10. It does not read unrelated cookie names or use Salesforce cookies for tracking.
  11. The session identifier is held temporarily by the Manifest V3 service worker.
  12. The session identifier is never written to Chrome storage.
  13. The session identifier is never placed in page content, extension URLs, analytics, or logs.
  14. API requests are restricted to HTTPS and approved Salesforce host patterns.
  15. API request paths are restricted to Salesforce /services/ endpoints.
  16. The extension currently permits read-only Salesforce API requests.
  17. The extension reads the current Salesforce user identifier and organization identifier.
  18. It can read active-user names, usernames, profiles, roles, and available User-field values.
  19. It can read profiles, permission sets, permission-set assignments, and system permissions.
  20. It can read object permissions, field permissions, field labels, and calculated-field indicators.
  21. It can read application, tab, Apex class, and Visualforce page access metadata.
  22. It can read organization-wide defaults and supported sharing metadata.
  23. It can request effective access information for a record ID entered by the user.
  24. Administrators can select another active user for analysis through their authorized session.
  25. Selecting another user does not impersonate or obtain that user’s Salesforce session.
  26. Salesforce remains responsible for enforcing API, setup, field, object, and record access.
  27. Missing or unavailable metadata is not automatically interpreted as denied access.
  28. API results are displayed only in the open extension interface.
  29. API results are held in memory while the extension interface is active.
  30. API results are discarded when the interface and related extension context are destroyed.
  31. The extension does not create a publisher database of Salesforce users or permission results.
  32. The extension does not transmit Salesforce org data to the publisher.
  33. The extension does not use external analytics, advertising, telemetry, or AI services.
  34. The extension does not sell, rent, or trade personal information or Salesforce data.
  35. The extension does not use collected information for advertising or credit decisions.
  36. The extension does not use Chrome storage for Salesforce credentials or permission results.
  37. Users may close the extension interface at any time.
  38. Users may uninstall the extension to prevent future access.
  39. Removing the extension ends its ability to access Salesforce sessions.
  40. Salesforce administrators may restrict installation, cookie access, or API access through organizational controls.
  41. Redirect links are limited to supported Salesforce HTTPS domains.
  42. New tabs opened by the extension remain associated with the originating Salesforce tab group when supported.
  43. Reasonable technical safeguards are used, but no software can guarantee absolute security.
  44. Users must not include session identifiers or confidential org data in support reports.
  45. Material changes to data handling require an updated policy and any disclosure or consent required by applicable rules.
  46. The publisher must provide a legal identity, jurisdiction, support email, and security contact before public release.
  47. The publisher must host this policy at a stable public HTTPS address before Chrome Web Store publication.
  48. Privacy questions should be sent to the publisher’s designated privacy contact once published.
  49. Salesforce is a trademark of Salesforce, Inc.
  50. Continued use after a published policy update remains subject to applicable disclosure, authorization, and consent requirements.