SeatSpend privacy policy
1. What SeatSpend stores
For each account that installs the app, SeatSpend stores:
- Your settings: the per seat monthly price you enter, your renewal date, your alert lead days, and your digest cadence.
- Aggregate counters: timestamps and counts describing the app's own activity, such as when the last digest was sent, how many digests have been sent, and which renewal milestone was last notified.
- A permission token, only if you turn on scheduled digests. This is the grant monday issues so the digest service can read your seat activity and send you notifications on a schedule.
Your settings are saved in monday's own app storage for your account, and are mirrored into the app's storage on monday code so the scheduled digest can read them. Both locations are monday infrastructure.
2. What SeatSpend does not store
SeatSpend does not store, log, export, or share:
- user names, user ids, email addresses, avatars, or job titles,
- last activity dates, idle day counts, or any per user row,
- board names, item names, updates, files, messages, or any board content,
- billing details or payment information, which monday handles entirely.
The report you see on screen and the text of a digest are built in memory and are not retained after they are delivered. Nothing about an individual user is written to storage or to a log line.
3. How your data moves
- You open SeatSpend inside monday. The app asks monday, through monday's own SDK, for your account's user list with each user's last activity date, and for your plan tier and seat count.
- The report is calculated in your browser and displayed. Nothing is sent anywhere else.
- If you enable scheduled digests, the digest service repeats the same read on your cadence, builds the digest text, sends it to you as a monday notification, and keeps only the aggregate counters from section 1.
Every read is a fresh read. There is no copy of your roster, and no history of it, anywhere in SeatSpend.
4. Third party domains and products
SeatSpend is built to have an unusually short list here. Every domain it touches belongs to monday.com, and each one is listed with the reason it is contacted.
Front end (in your browser, inside monday)
| Domain or product | Why it is used |
|---|---|
monday.com and its subdomains | The platform SeatSpend runs inside. The app renders in a monday iframe, and every read of your seat data goes through monday's own SDK to monday's API. Your monday session authenticates it, so the app never handles a password or an API token in your browser. |
The SeatSpend client bundle on monday code (a monday owned address, currently in the form https://<id>.cdn2.monday.app) | This is where the app's own HTML and JavaScript are served from. monday assigns the address and reassigns it on each app version. |
The SeatSpend service on monday code (a monday owned address, currently in the form https://<id>-service-<id>.us.monday.app) | The app calls its own service to save a copy of your settings for the scheduled digest, to show the digest status line, and to start the monday permission flow when you enable scheduled digests. |
Back end (the SeatSpend service, running on monday code)
| Domain or product | Why it is used |
|---|---|
api.monday.com | monday's API. Read the account's users with their last activity dates and the account plan, and send the digest and renewal notices as monday notifications. |
auth.monday.com | monday's OAuth service. Used once, when you turn on scheduled digests, to obtain the permission grant that lets the scheduled service act for your account. |
| monday code storage (monday's own app hosting infrastructure) | Holds your settings mirror, the aggregate counters, and the permission token. Values are stored per account. |
Everything that is not in the path
There is no analytics or product telemetry service, no error or crash reporting service, no advertising or marketing pixel, no tag manager, no session recorder, no external font, image, or script CDN, no external database, no file storage, no email or SMS provider, no customer messaging widget, no payment processor (monday bills the subscription), and no AI, machine learning, or large language model provider. No part of your data is used to train any model, and none of it is sold or shared with anyone.
5. Permissions and why each one is needed
| Permission | Why SeatSpend asks for it |
|---|---|
users:read | Lists the account's users with their last activity date. This is the report. |
account:read | Reads the account plan tier and seat count, so the report can show plan context and pre-fill a starting per seat price. |
me:read | Identifies the admin who connects scheduled digests, so the digest service knows which account a connection belongs to. |
boards:read | Reads one board id. monday's notification API requires a target id of type Project, so the digest service resolves a single board to address the notification to. No board content is read or stored. |
notifications:write | Sends the scheduled digest and the renewal countdown to your monday notifications. This is the only write the app performs. |
6. Notifications
Digests and renewal notices are delivered as notifications inside monday, to the admin who connected scheduled digests. SeatSpend does not send email, does not send SMS, and does not post to any outside service. Setting your digest cadence to Off stops the digest; clearing your renewal date stops the countdown.
7. Retention and deletion
- Settings and counters are kept while the app is installed, so your figures stay stable between visits.
- On uninstall, monday notifies the app and SeatSpend deletes that account's stored settings, counters, and permission token.
- You can also ask us to delete your account's stored settings at any time by emailing HHonlineventures@proton.me from an address associated with the account. We will confirm when it is done.
- Because no personal data about your users is ever stored, there is no user level record to request or erase.
8. Cookies and browser storage
SeatSpend sets no cookies of its own and runs no tracker. Any cookies present while you use monday are monday's own and are governed by monday's privacy policy.
9. Security
- The app runs inside monday and authenticates through your existing monday session, so no password or API token is handled in your browser.
- Requests between the app and its own service are authenticated with a token monday signs for your session, and the scheduled service verifies every request it receives.
- Stored values live in monday code's storage for the app, separated by account.
- Secrets are supplied to the service as environment configuration and are never written into the app's code or logs.
10. Children
SeatSpend is a workplace administration tool sold to businesses. It is not directed at children and is not intended for use by anyone under 16.
11. Changes to this policy
If this policy changes, the effective date at the top changes with it, and the current version always lives at this address. Material changes to what is stored or which domains are contacted will be described here before they take effect.
Contact
HH Online Ventures
HHonlineventures@proton.me