Skip to content

Atlassian Marketplace privacy policy checklist (practical)

September 23, 2026

careers-remote

Atlassian Marketplace listing review will look at your privacy policy—especially for apps that process user-generated content, call external APIs, or store tenant data. A thin “we care about privacy” page is not enough. Treat the policy as a product artefact.

What to disclose clearly

  • Data categories: account info, Jira issue fields, user emails, analytics, support tickets.
  • Purposes: provide the app, secure the service, improve features, legal obligations.
  • Processing location: Forge/Atlassian hosting regions + any remotes you operate (e.g. EU VPS).
  • Subprocessors: Atlassian, your host, email, error tracking—name them and link policies.
  • Retention: how long install data and logs live after uninstall.
  • Rights: access, deletion, export—how customers exercise them.
  • Contact: a real email monitored by humans.

Forge-specific notes

If the app runs primarily on Forge, say so. Explain that compute/storage may be provided by Atlassian as a subprocessor, and describe any egress to your infrastructure. Do not claim “we never see your data” if your remote logs request payloads.

Marketplace practicalities

  • Host the policy on an HTTPS URL you control (not a Google Doc).
  • Keep Marketplace privacy URL and in-app link identical.
  • Version the policy with an “last updated” date; announce material changes.
  • Match scopes to narrative—if you request read access to issues, explain why.

GDPR baseline for EU sellers

  • Identify roles: you are typically a processor for customer Jira content; controller for your own billing/account data.
  • Offer a DPA when you sell to EU organisations.
  • Document lawful bases for any marketing you do around the app.

Checklist before you submit

  1. Walk a fresh install and list every field touched.
  2. Trace logs for accidental PII.
  3. Confirm uninstall deletes or schedules deletion of tenant data.
  4. Have a non-engineer read the policy—confusion means rewrite.
  5. Align support macros with what the policy promises.

HostHob publishes privacy pages for our own products (including Marketplace-oriented apps) and can help engineering teams turn a real data map into listing-ready copy.

Need this built? HostHob ships production integrations and Marketplace-ready apps from Rotterdam. See our services or Get a Marketplace privacy review.

Need help shipping your platform?

HostHob engineers WordPress, Laravel, and enterprise stacks with measurable outcomes.

Start a Project