OAuth-CDNC Privacy Policy
Application name: OAuth-CDNC
This Privacy Policy describes how OAuth-CDNC (“we”, “our”, or “the service”) collects, uses, stores, and shares personal information when you use the OAuth-CDNC identity and access management application.
1. Information we collect
- Account information: display name, internal user ID, and email address used for OIDC integrations.
- Authentication credentials: Passkey public keys; account identifiers and emails returned by Google or Microsoft when you choose to link those accounts.
- Session information: session identifiers, expiry, login IP address, and User-Agent.
- Audit logs: administrator actions, sign-in events, and OAuth link/unlink events.
2. How we use information
We use collected information only to:
- provide, maintain, and improve authentication and SSO;
- verify identity and protect account security;
- respond to support requests;
- detect, prevent, and respond to fraud, abuse, or security incidents;
- comply with applicable law.
We do not use personal information for advertising or marketing, and we do not sell it to third parties.
3. Google user data
When you sign in with Google or link a Google account, OAuth-CDNC receives your Google user
identifier (sub) and verified email address. This Google user data is used
only to authenticate you and associate your Google identity
with your OAuth-CDNC account. OAuth-CDNC does not sell Google user data, does not use it for
advertising, and does not share it with unrelated third parties.
Google’s own processing is governed by the Google Privacy Policy.
4. Third-party services
- Google OAuth — only when enabled and when you choose Google sign-in/link.
- Microsoft OAuth — only when enabled and when you choose Microsoft sign-in/link.
- Infrastructure providers used to host OAuth-CDNC (for example Cloudflare and/or our organization servers).
5. Storage and security
We use industry-standard safeguards, including encrypted transport (HTTPS) and signed session cookies. No system is 100% secure; we work to protect your information but cannot guarantee absolute security.
6. Your rights
- View and update your display name and email (where supported)
- Remove your own Passkeys
- Unlink Google or Microsoft accounts
- Request account deletion via your organization administrator
7. Cookies
OAuth-CDNC uses session cookies required for authentication. We do not use advertising or third-party tracking cookies.
8. Contact
Questions about this Privacy Policy or OAuth-CDNC can be sent to kenny.soul@gmail.com or your organization administrator.