Legal
Privacy
What we read from your Salesforce org, what we keep, and what we throw away. Written to describe this product specifically rather than adapted from a template.
Last updated 2 August 2026
Who we are
CPQ Compass is operated by Xosmic Inc., 50 Harpreet Circle, Etobicoke, Ontario, Canada. For any privacy question, or to exercise the rights below, contact support@cpqcompass.com.
What we read from Salesforce
With your authorisation we read configuration metadata only: price rules, product rules and discount schedules with their conditions, actions and tiers, and your own Apex classes, triggers and Flows, searched for references to the CPQ (SBQQ) namespace.
We do not read quotes, orders, contracts, subscriptions, accounts, contacts, opportunities, or any customer record. We never write to your org.
What we store
Only the generated report. Raw API responses exist in memory for the duration of a scan and are discarded once the report is produced.
The report contains rule names, counts, field and object API names, line numbers, and our findings. It does not contain condition values, formula bodies, or source code. If you consider your rule names sensitive, that is the thing to weigh before connecting.
We also store your email address, the Salesforce organisation ID and instance URL, the username that authorised the connection, and your OAuth tokens.
How tokens are protected
Salesforce access and refresh tokens are encrypted with AES-256-GCM before they reach our database, using keys held only in the server environment. Session cookies contain a random token; we store only its SHA-256 hash.
Who else sees it
We do not sell or share your data. It is processed by our infrastructure providers acting on our instructions, each named on the subprocessors page with what it receives and where it is. Stripe receives your payment details directly — they never pass through our servers, and we never see your card number. Your reports and tokens are stored in Canada.
How long we keep it
Reports are retained while your account exists. Disconnecting an org deletes its stored tokens immediately. You can download everything we hold about you, or delete your account outright, from your account page — deletion also revokes our access at Salesforce. You can still ask us to do it for you.
Revoking access
You can revoke our access at any time from inside your own org: Setup → Connected Apps OAuth Usage → Revoke. That works whether or not we cooperate, and the same screen shows every API call we have made. More detail on what we read.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to processing. Contact us and we will respond within the period required by applicable law.
We are based in the Province of Ontario, Canada and handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). If you are in the UK or the European Economic Area, the UK GDPR or GDPR may also apply to our processing of your data, and the rights above apply to you regardless.
We send only transactional email — sign-in links and reports you have asked for. We do not send marketing email without your consent, as required by Canada's anti-spam legislation.