Privacy Policy

Last updated 5 July 2026

In short: your Salesforce record data streams straight to your own Google Drive and is never stored on our servers. We keep only the minimum needed to run the service (your email, connection settings, and run logs), we do not sell your data, and we use only essential cookies.

1. Who we are

Vault Maagic ("Vault Maagic", "we", "us", "our") provides a service that backs up selected Salesforce records to a customer's own Google Drive. This policy explains what we do with personal data when you visit our site or use the service. Vault Maagic is a service provided by Maagic Apps, owned and operated by Sobek Stelmaczonek. For any privacy question, contact us at vault@maagic.co.uk.

For most personal data we handle on behalf of business customers (the Salesforce records inside your backups), you are the data controller and we act as your processor. Our Data Processing Addendum governs that relationship.

2. Information we collect

Account information

When you sign up we collect your email address and authentication details managed by our auth provider. If you set a password, it is stored only as a salted hash by that provider; we never see it.

Connection information

When you connect Salesforce or Google, we store metadata about the connection: your Salesforce organisation id and instance URL, your Google account email, the scopes granted, and an encrypted OAuth refresh token. Refresh tokens are held in an encrypted secrets vault and are never exposed to your browser.

Backup settings and run logs

We store the configurations you create (name, selected objects, schedule, timezone, Drive folder id) and a log of each run. Run logs contain object names, row counts, timestamps, actions taken (created/updated/skipped/failed), and any error messages.

Basic technical data

Like any website, our hosting provider processes standard request data such as IP address and browser type for security and reliability. We do not use advertising or analytics trackers.

3. What we do not collect

We do not store the contents of your Salesforce records. During a backup, records pass through our server's memory on their way from Salesforce to your Google Drive, and are not written to any database or file storage on our side. The resulting CSV files live in your Drive, under your control. Record contents never appear in our logs.

4. How we use information and our legal bases

Where the UK GDPR and EU GDPR apply, we rely on these legal bases:

  • To provide the service (run backups, manage your connections and configs, send run summaries): performance of our contract with you.
  • To secure and improve the service (prevent abuse, debug errors, keep logs): our legitimate interests in running a reliable, safe product.
  • To send service emails (confirmation, re-auth alerts, run summaries): performance of our contract. We do not send marketing email without your consent.
  • To meet legal obligations where required.

5. Cookies

We use only strictly necessary cookies to keep you signed in and to protect the sign-in process. We do not use advertising, marketing, or third-party analytics cookies, so there is no tracking to opt out of. Your theme preference is stored locally in your browser, not in a cookie sent to us.

6. Service providers

We share data with a small set of processors who help us run the service: our hosting and application platform, our database and authentication provider, and our transactional email provider. We also connect, at your instruction, to Salesforce and Google. A current list is in our Data Processing Addendum. We do not sell your personal data or share it for advertising.

7. Google user data (Limited Use)

When you connect Google Drive, Vault Maagic requests only the drive.file scope. This scope lets the app see and manage only the files it creates itself (your backup CSV files) and gives it no access to any other file in your Drive. We use this access solely to create and update those backup files on your instruction; we do not read, organise, or otherwise touch the rest of your Drive.

Vault Maagic's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, and we do not transfer it to others except as needed to provide the service, to comply with applicable law, or as part of a merger or acquisition under the same protections. We do not use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models. Humans do not read your Google data except with your explicit consent to resolve a specific support issue, where required for security, or to comply with the law.

8. International transfers

Our core infrastructure is hosted in the United Kingdom (London region), and our transactional email provider processes data within the European Union (Ireland). Transfers from the UK to the EEA are covered by the UK's adequacy regulations. If we ever transfer data further afield, we rely on appropriate safeguards such as the UK International Data Transfer Agreement and the EU Standard Contractual Clauses.

9. Data retention

We keep account, connection, and configuration data for as long as your account is active. Run logs are kept to give you a usable history and are periodically pruned. If you delete a config or your account, we delete the associated records from our systems. Your CSV backups remain in your Google Drive and are only ever removed by you.

10. Security

We encrypt data in transit, store refresh tokens in an encrypted vault, keep access tokens in memory only, and isolate each customer's data with row-level security. See our Security page for detail.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email vault@maagic.co.uk and we will respond within the time required by law.

UK and EU (GDPR). You may lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk).

California (CCPA/CPRA). You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share your personal information, and we do not discriminate against you for exercising your rights.

12. Children

Vault Maagic is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

13. Changes to this policy

We may update this policy from time to time. We will change the "last updated" date above and, for material changes, give notice through the service or by email.

14. Contact

Questions or requests: vault@maagic.co.uk. If you are in the UK or EU and need our data protection point of contact, use the same address and we will route your request appropriately.

Privacy Policy | Vault Maagic