DRAFT waiting for feedback from Privacy
Purpose
This page provides Incubator-specific guidance on how podlings should understand and apply the ASF’s Privacy Policy in practice. It does not define or restate ASF policy, the authoritative source is the ASF Privacy website and Committers’ FAQ.
Many podlings and mentors are new to ASF processes. This guide helps orient them to common privacy considerations during incubation, such as project websites, analytics, mailing lists, and community tools, and directs them to the appropriate ASF contacts and resources.
ASF Privacy Policy Overview
The ASF maintains a central Privacy Policy that covers all Foundation systems and websites. Projects must not publish their own privacy statements or attempt to restate policy in their documentation. Podling websites should include a link to the Apache Software Foundation Privacy Policy. This ensures users always see the current, authoritative version maintained by the ASF Privacy team.
Applying ASF Privacy in Practice
1. Setting up project websites
- Do not include independent privacy or cookie policies.
- Include a footer link to the official ASF Privacy Policy.
- Avoid embedding third-party scripts unless reviewed with Infra or the Privacy team.
- If using JavaScript frameworks or external content (for example, a YouTube embed or a CDN-hosted library), ensure that no personal data is collected or transmitted without user consent.
- When in doubt, check the Privacy Committers’ FAQ or contact privacy@apache.org.
2. Analytics and tracking
- ASF provides a Foundation-managed analytics platform (currently Matomo) for apache.org sites.
- Projects wishing to enable analytics should email privacy@apache.org for setup or to confirm suitability.
- Do not use Google Analytics or similar third-party tools without written approval from the Privacy team.
- Never embed tracking pixels, advertising tags, or external monitoring tools without prior review.
3. Mailing lists and public archives
- Mailing lists are public by default; messages become part of the public record.
- Avoid sending personal information to mailing lists (e.g., private emails, phone numbers, or internal company data).
- If you receive a request to remove content for privacy reasons, direct it to privacy@apache.org.
4. Data collection and consent
- Avoid collecting personal data (such as names, emails, and survey responses) unless it is clearly necessary and complies with ASF privacy guidelines.
- Use ASF-approved services (e.g., Apache-hosted forms, mailing lists) rather than third-party tools whenever possible.
- When you need data collection, please clearly describe how the data will be used and for how long it will be retained.
- Always check with privacy@apache.org if uncertain whether consent is required.
5. Contributor license agreements (ICLAs)
- Podlings must not collect or handle ICLAs themselves.
- All ICLAs are submitted directly by contributors to the ASF Secretary, following the process at https://www.apache.org/licenses/icla.pdf.
- ICLAs contain personal information (e.g., name, email, signature) and are treated as confidential legal records under ASF policy.
- Never forward or store ICLA forms within project repositories, mailing lists, or private archives.
6. Third-party services
- Review the Committers’ FAQ before connecting any third-party platform.
- Common examples:
- GitHub: Allowed; ASF has a legal data-sharing agreement in place.
- Slack, Discord, etc.: May be linked to, but not used as an official ASF communication channel.
- Survey tools: Use ASF-hosted or approved services only, with explicit notice of data collection.
Working With ASF Privacy and Infra
Summary
ASF privacy policies are centrally maintained and apply to all Apache projects. Podlings are responsible for following those policies in how they operate, communicate, and build their communities. This page is designed to help podlings apply ASF policy, not define it, and to ensure every incubating project meets the Foundation’s privacy and data-handling standards while learning how to operate as an Apache project.