Privacy Policy
Last updated: July 2026
1. Introduction
Crosstown Tech ("we," "our," or "us") operates Team Workload for Microsoft Planner ("the Service"), a web application available at planner.crosstowntech.com. This Privacy Policy explains how we collect, use, store, and protect information related to your use of the Service.
By using Team Workload, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect only the data necessary to provide the Service.
2.1 Account data. When you sign in with Microsoft, we store your Microsoft user ID, tenant (organization) ID, and sign-in name, together with an OAuth refresh token that lets the Service read your Planner data on your behalf. Tokens are encrypted at rest using AES-256-GCM.
2.2 Workload snapshots. To render your workload view quickly, the Service stores a cached snapshot of the Planner data you can already access: plan, bucket, and label names; task titles, due dates, and completion status; and the names and IDs of people tasks are assigned to. Snapshots are stored compressed and expire automatically within 30 days of your last refresh.
2.3 Premium plan connections. If your organization uses Planner Premium plans and connects them, we additionally store your organization's Microsoft Dataverse environment address so the Service can read Premium plan tasks.
2.4 Application logs. We maintain logs for debugging and performance monitoring. Logs may temporarily contain user display names or identifiers when they appear in error or debug messages. Logs are rotated automatically and routinely deleted.
2.5 What we do not collect. The Service requests read-only Microsoft permissions (it never creates, edits, or deletes your Planner tasks). We do not collect passwords, file contents, chat messages, or email.
2.6 Background refresh & historical reporting. So your workload view stays current and to power trend and historical reporting, the Service refreshes your Planner data on a recurring schedule — including at times when you are not signed in — using the encrypted refresh token you granted when you connected your account. From these refreshes the Service keeps a historical series of the aggregated task counts and metadata described in 2.2 (for example, counts by assignee, bucket, status, and due date over time). This historical reporting data is retained for approximately 13 months and is separate from the 30-day live snapshot in 2.2. You can stop background refresh at any time by revoking the Service's access (see Section 5).
3. How We Use Your Information
We use collected data to:
- Provide and maintain the workload view across your Planner plans
- Provide trend and historical workload reporting over time
- Improve user experience and troubleshoot issues
- Enhance application performance and security
- Comply with legal and regulatory requirements
We do not use your data for marketing or advertising purposes, nor do we sell or share personal data with third parties.
4. Data Storage Locations
Our infrastructure is hosted on Microsoft Azure:
| Component | Location | What it stores |
|---|---|---|
| Application server | Canada Central | Application logs (short-term) |
| Database (Azure Cosmos DB) | Central US | Account data, encrypted tokens, workload snapshots |
| Job queue (Azure Redis) | Canada Central | Temporary refresh-job data (non-persistent) |
Data also passes through the Microsoft Graph API and, for Premium plans, Microsoft Dataverse — routed by Microsoft to its nearest datacenters.
5. Data Retention & Deletion
- Live workload snapshots: expire automatically within 30 days of your last refresh.
- Historical reporting data: the aggregated series described in Section 2.6 is retained for approximately 13 months.
- Account data and tokens: stored while you use the Service; deleted within 30 days of a deletion request.
- Logs: rotated automatically and routinely deleted.
Automatic purge. Your organization's stored data is permanently deleted when any of the following happens:
- your organization's paid entitlement ends and 90 days pass without renewal;
- every user in your organization has had their Microsoft access to the Service lapse — expired or revoked — for 90 days; or
- the Service is disconnected (deletion is immediate).
Because our data is partitioned per organization, each purge removes your organization's stored data set at once. The only exception is a minimal billing record — your organization ID, subscription dates, plan, and payment identifiers, with personal details such as names removed — which we retain only as required for tax and accounting and to prevent a previously-closed organization from starting a repeat free trial.
Revoking access. You can withdraw the Service's permission to access your Microsoft account at any time from your Microsoft account portal at https://myapps.microsoft.com — open Team Workload and choose to remove or revoke it. Revoking consent stops all background refresh immediately; your organization's stored data is then purged under the automatic-purge rules above.
To request deletion, contact us at support@crosstowntech.com.
6. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, logging | All stored data (see Section 2) |
| Microsoft Graph API | Reading your Planner data | Planner task data (read-only) |
| Microsoft Dataverse | Reading Premium plan data (only if connected) | Premium task data (read-only) |
These services have their own privacy policies, which apply to their handling of data.
7. International Data Transfers
Crosstown Tech is based in Toronto, Canada. Data is processed in Canada and the United States. Canada has an EU adequacy decision (Commission Decision 2002/2/EC), permitting data transfers from the EEA without additional safeguards. Transfers to Microsoft Azure in the United States are governed by Microsoft's Data Protection Addendum incorporating the European Commission's Standard Contractual Clauses (SCCs).
8. GDPR
Under the General Data Protection Regulation (GDPR):
- As a Data Controller, we are responsible for the account data we collect and determine the purpose of.
- As a Data Processor, we process Planner task metadata (titles, due dates, assignments) on behalf of and at the instruction of our customers.
Your rights under GDPR include the right to access, rectify, erase, and port your data. To exercise these rights, contact us at the address below.
9. Your Rights & Choices
- Request access to your stored data
- Request data deletion
- Disable or stop using the application at any time
- Contact us for any privacy-related concerns
10. Changes to This Privacy Policy
We may update this Privacy Policy as needed. Changes will be posted on this page with an updated "Last updated" date. We encourage users to review this policy periodically.
11. Contact Information
For any privacy-related questions or concerns, please contact us at:
- Support: support@crosstowntech.com
- Security: security@crosstowntech.com