SFDXHub

Privacy Policy

Last Updated: February 13, 2026

1. Introduction

Swan Media Co. ("we," "us," or "our") operates sfdxhub.com (the "Site"), branded as SFDX Hub. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Site and use our services.

SFDX Hub is a community-driven web registry for Salesforce developer tools where users can browse, search, submit, rate, and review Salesforce CLI plugins, Lightning Web Component libraries, Apex utilities, Agentforce tools, and other developer resources.

Please read this Privacy Policy carefully. By using the Site, you consent to the practices described in this policy. If you do not agree with this Privacy Policy, please do not access or use our services.

2. Information We Collect

2.1 Information You Provide Directly

We collect information that you voluntarily provide to us when you:

  • Create an account (name, email address, password)
  • Log in via GitHub OAuth (GitHub profile information, email address, public profile data)
  • Submit developer tools to our registry
  • Write reviews or provide star ratings
  • Upload screenshots or images (processed and stored via Cloudinary, maximum 5MB per file)
  • Contact us for support or inquiries

2.2 Automatically Collected Information

When you visit our Site, we automatically collect certain information, including:

  • Log data (IP address, browser type, operating system, referring URLs, pages viewed)
  • Device information (device type, screen resolution, browser capabilities)
  • Usage analytics (how you interact with our Site, features used, time spent)
  • Cookies and similar tracking technologies for session management and authentication

2.3 Third-Party Data

We may collect information from third-party services:

  • GitHub API: When you authenticate via GitHub, we receive your public profile information, email address, and other data you authorize GitHub to share. We also fetch README files from GitHub repositories for tool listings.
  • Cloudinary: Image metadata and processing information for uploaded screenshots.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Account Management: To create and manage your user account, authenticate your identity, and provide access to personalized features.
  • Service Delivery: To operate and maintain SFDX Hub, display your submissions, reviews, and ratings, and enable community interaction.
  • Communication: To send you important updates, notifications about your account, responses to inquiries, and service announcements.
  • Improvement and Analytics: To analyze usage patterns, understand user preferences, improve our Site's functionality, and develop new features.
  • Security: To detect, prevent, and address technical issues, fraudulent activity, and violations of our Terms of Service.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.

4. Data Storage and Security

4.1 Data Storage

Your data is stored securely using industry-standard practices:

  • Database: User account data and content are stored in a PostgreSQL database hosted by Neon with encryption at rest.
  • Passwords: All passwords are hashed using bcryptjs before storage. We never store plain-text passwords.
  • Sessions: Authentication sessions are managed using Auth.js v5 with secure JWT (JSON Web Token) cookies.
  • Images: Uploaded images are processed and stored by Cloudinary with secure CDN delivery.
  • Hosting: Our Site is hosted on Vercel infrastructure with HTTPS encryption for all data transmission.

4.2 Security Measures

We implement reasonable administrative, technical, and physical security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

5. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following limited circumstances:

  • Service Providers: We share data with trusted third-party service providers who assist us in operating our Site (Cloudinary for image hosting, GitHub for authentication, Neon for database hosting, Vercel for site hosting). These providers are contractually obligated to protect your information.
  • Public Content: Information you choose to make public (tool submissions, reviews, ratings, profile information) will be visible to other users and may be indexed by search engines.
  • Legal Requirements: We may disclose information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for authentication, session management, and core Site functionality. These cookies cannot be disabled without affecting Site operation.
  • Analytics Cookies: Used to understand how visitors interact with our Site, which pages are most popular, and how users navigate through our content.
  • Preference Cookies: Store your settings and preferences to provide a personalized experience.

You can control cookies through your browser settings. Most browsers allow you to refuse cookies or delete them. However, disabling cookies may affect your ability to use certain features of our Site.

7. Data Retention

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:

  • Account Data: Retained while your account is active and for a reasonable period thereafter to comply with legal obligations.
  • User-Generated Content: Tool submissions, reviews, and ratings may be retained indefinitely to maintain the integrity and continuity of our registry, even after account deletion.
  • Log Data: Server logs and analytics data are typically retained for 90 days to 1 year for security and analytical purposes.

Upon account deletion, we will anonymize or delete your personal information, except where retention is required by law or legitimate business interests (such as preventing fraud or abuse).

8. Your Privacy Rights

8.1 General Rights

Depending on your location, you may have the following rights:

  • Access: Request access to the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to certain exceptions.
  • Portability: Request a copy of your data in a structured, machine-readable format.
  • Objection: Object to certain processing of your personal information.
  • Restriction: Request restriction of processing under certain circumstances.

8.2 GDPR Rights (European Economic Area)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local data protection authority
  • Right to object to processing based on legitimate interests
  • Right to not be subject to automated decision-making, including profiling

Our legal basis for processing your data includes: (1) your consent, (2) performance of a contract with you, (3) compliance with legal obligations, and (4) our legitimate interests in operating and improving our services.

8.3 CCPA Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out: Opt-out of the sale of your personal information. (Note: We do not sell personal information.)
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA rights.

8.4 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@sfdxhub.com. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

9. International Data Transfers

SFDX Hub is operated from the United States. If you are accessing our Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

These countries may have data protection laws that differ from those in your country. By using our Site, you consent to the transfer of your information to the United States and other countries. We take appropriate safeguards to ensure your personal information remains protected in accordance with this Privacy Policy.

10. Children's Privacy

SFDX Hub is not intended for use by children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@sfdxhub.com, and we will delete such information from our systems.

11. Third-Party Links

Our Site may contain links to third-party websites, services, and resources (including GitHub repositories, npm packages, and developer documentation). This Privacy Policy does not apply to those third-party sites. We are not responsible for the privacy practices of other websites. We encourage you to read the privacy policies of any third-party sites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this page.

For material changes, we will provide prominent notice on our Site or send you an email notification (if you have provided your email address). Your continued use of SFDX Hub after such modifications constitutes your acknowledgment and acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Swan Media Co.

Email: privacy@sfdxhub.com

Website: sfdxhub.com

We will respond to your inquiry as promptly as possible, typically within 2-3 business days.

14. Additional Information for Specific Jurisdictions

14.1 Nevada Residents

Nevada residents have the right to opt-out of the sale of certain personal information. We do not sell your personal information as defined under Nevada law. If you have questions, please contact us at privacy@sfdxhub.com.

14.2 Australian Residents

If you are located in Australia, you have rights under the Privacy Act 1988 (Cth), including the right to access and correct your personal information and to make a complaint about our handling of your personal information.

14.3 Canadian Residents

Canadian residents have rights under applicable provincial and federal privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA), to access and correct their personal information.

15. Consent

By using SFDX Hub, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with any part of this Privacy Policy, please do not use our Site or services.

This Privacy Policy is effective as of February 13, 2026.

© 2026 Swan Media Co. All rights reserved.