TimeBoard Privacy Policy

Effective: 2026-09-05 ยท Controller: [COMPANY LEGAL NAME]. Draft for legal review before Marketplace submission.

What we store

DataSourceWhyProtection
monday account id, slug, seat countmonday install webhook / OAuthIdentify your accountEncrypted database volume
OAuth access token (and refresh token)monday OAuthRead item names, post updates, maintain the Hours columnAES-256-GCM encrypted at rest; key held outside the database; nulled immediately on uninstall
User id, name, email, timezone, role flagsmonday users APIShow who logged time; CSV exportName and email AES-256-GCM encrypted at rest
Board and item ids and names, group titlesmonday boards/items APIDisplay and CSVEncrypted database volume; refreshed, not archived
Time entries (start, end, duration, note, billable) and an audit log of editsYour usersThe productEncrypted database volume

We do not read item column values other than names and groups, and we never capture screenshots, keystrokes, URLs, or activity outside monday.com.

Logs

Server logs contain request method, path, status code, timing and monday account id. They contain no tokens, names, emails or notes, and are retained for 30 days.

Third parties

No analytics, advertising, or tracking cookies. We set no cookies at all; authentication uses monday's signed session token on each request.

Retention and deletion

Uninstalling TimeBoard removes our access token immediately. All remaining data for the account is permanently deleted within 10 days, automatically. Email [SUPPORT EMAIL] to request earlier deletion or an export.

Your rights

Depending on where you live you may have rights to access, correct, export, or delete personal data. Contact us at the address above; we respond within 30 days.

Changes

We will post changes here and, for material changes, notify account admins in the app.