Privacy Policy
Last updated: 29 September 2026
This Privacy Policy explains how HubConnector collects, uses, stores, and discloses personal information. It applies to visitors of hubconnector.io, HubConnector account holders, and people whose records pass through the HubSpot or ConnectWise PSA accounts that our customers connect to HubConnector.
Contents
- Who we are
- Scope of this policy
- Information we collect
- Information from connected platforms
- How we use your information
- Cookies and analytics
- Sharing your information and sub-processors
- Overseas disclosure
- Security
- Data retention
- Your rights: access, correction and deletion
- Data breach notification
- Children's privacy
- Changes to this policy
- Contact us and complaints
1. Who we are
HubConnector is an Australian business ("HubConnector", "we", "us" or "our"). You can contact us about privacy matters at hello@hubconnector.io.
2. Scope of this policy
This policy covers two groups of people. Account holders are the people who sign up for HubConnector, log in, and manage a subscription; we collect their information directly. The second group are the people whose company, contact, deal, ticket, or product records exist in a customer's connected HubSpot or ConnectWise PSA account; we process that information on the customer's behalf, as described in section 4.
3. Information we collect
When you create a HubConnector account, we collect your email address, your password (stored as a salted BCrypt hash, never in plain text), and your company or tenant name. When you connect a platform, we store an encrypted copy of the OAuth token or API key you provide, as described in section 9. We also generate operational records as you use the service: an audit trail of sync activity, and a record of any sync message that failed to send.
4. Information from connected platforms
HubConnector reads and writes company, contact, deal, ticket, and product records in the HubSpot or ConnectWise PSA accounts our customers connect, in order to sync them. We do not keep a full copy of those records. The exceptions are: a stable identifier and a fingerprint (a one-way hash of the record's contents, used to detect changes) for each matched record pair; auto-match proposals, which store the names of candidate records and the values compared to suggest a match, such as a name, email address or domain, and phone number; audit trail entries, which can include field names and values relevant to a conflict or an error message; change notifications your connected platforms send us, which can include record values and are held in message queues for a limited period (see section 10); and, for a sync message that could not be delivered, the message payload, kept so support can diagnose and retry it.
If you are a HubConnector customer, you are responsible for having a lawful basis and, where required, appropriate notice to the individuals whose records exist in your connected platforms, for having those records processed by HubConnector on your behalf.
5. How we use your information
We use account information to operate your account, provide the sync service, bill your subscription through Stripe, send transactional email such as welcome messages and password resets, and respond to support requests. We use audit trail and dead-letter data to show you sync history, help you resolve conflicts and errors, and provide support. We use auto-match proposal data to suggest likely matches between records in your connected platforms for you to review. We do not use your information for advertising, and we do not sell personal information.
6. Cookies and analytics
The HubConnector application sets three cookies, all strictly necessary for the service to work: access_token (httpOnly, secure, 15 minutes) authenticates your API requests; refresh_token (httpOnly, secure, 7 days) lets you stay signed in without re-entering your password; and XSRF-TOKEN protects against cross-site request forgery. None of these are used for tracking or advertising.
The hubconnector.io marketing site uses Cloudflare Web Analytics, a cookieless, privacy-focused analytics service that does not track individual visitors or use persistent identifiers.
7. Sharing your information and sub-processors
We share information with the service providers below (our sub-processors) to the extent necessary for them to perform their function. We do not sell or rent personal information to third parties.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, database, message queues, encryption key management, transactional email (Amazon SES) | Sydney, Australia (ap-southeast-2) |
| Stripe | Payment processing and subscription billing | United States (and other Stripe processing locations) |
| Cloudflare | Cookieless web analytics for hubconnector.io | Global network (United States-based provider) |
| Microsoft (Microsoft 365) | Business email for support and privacy requests sent to hello@hubconnector.io | Australia |
HubSpot and ConnectWise are not our sub-processors. They are your own platforms, which you authorise HubConnector to access under section 4 of our Terms of Service. Your use of those platforms is governed by your own agreements with those providers.
We may also disclose information where required by law, or to protect our rights, users, or the public.
8. Overseas disclosure
Our application infrastructure runs in AWS's Sydney (ap-southeast-2) region. Some of our sub-processors, including Stripe and Cloudflare, are based in the United States and may process information outside Australia. Where we disclose personal information overseas, we take reasonable steps consistent with Australian Privacy Principle 8 to ensure it is handled consistently with the Australian Privacy Principles, including relying on our sub-processors' own privacy and security commitments.
If you are located in the European Union or United Kingdom, you may have additional rights under the GDPR or UK GDPR, such as the right to access, correct, or erase your personal data, or to object to certain processing. Contact us at hello@hubconnector.io to exercise these rights, and we will respond as required by applicable law.
9. Security
Connected-platform credentials (OAuth tokens and API keys) are encrypted at rest using AES-256-GCM with a per-tenant data key generated and protected by AWS Key Management Service. Account passwords are hashed with BCrypt and are never stored or logged in plain text. Data in transit to the application is protected with TLS.
10. Data retention
Application logs are retained in AWS CloudWatch for 30 days. Automated database backups are retained for 14 days. Change notifications received from your connected platforms are held in AWS message queues for up to 4 days while they are processed, and notifications that repeatedly fail to process are held for up to 14 days so we can diagnose them. Audit trail entries are retained for 13 months and then deleted automatically. Dead-letter records are deleted automatically 90 days after they are redriven or dismissed; unresolved dead-letter records are kept until you resolve them. Account data and auto-match proposals are retained for the life of your account. On account closure, we delete or de-identify this data on request.
11. Your rights: access, correction and deletion
To access or correct your account information, request a copy of your personal information, or ask us to delete your account and associated data, email hello@hubconnector.io. We will respond within a reasonable time and may need to verify your identity first.
12. Data breach notification
If we become aware of a security incident that affects your account or the data we hold for you, we will notify you without undue delay and give you the information you reasonably need to understand the incident and meet your own obligations. Where the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) applies to us, we will also notify affected individuals and the Office of the Australian Information Commissioner as that scheme requires.
13. Children's privacy
HubConnector is a business tool and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect personal information from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will notify you by email or by a notice within the product at least 30 days before the change takes effect. Where a change is required by law or is needed to address a security risk, it may take effect sooner, and we will give you as much notice as is reasonably practicable.
15. Contact us and complaints
For privacy questions or to make a complaint, email hello@hubconnector.io. We will investigate and respond. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.