SeatSpend privacy policy

Effective date: July 24, 2026 · Applies to: the SeatSpend app for monday.com · Published by: HH Online Ventures · Contact: HHonlineventures@proton.me

Summary. SeatSpend stores your account settings and a small number of counters. It does not store any personal data about your users. Seat names and last active dates are read live from monday every time a report or a digest is built, used for that one output, and then discarded. The app and its scheduled digest service both run on monday code, monday's own app hosting, so nothing about your account travels to a server we operate outside monday. There is no analytics, no tracking, no advertising, no AI processing, and no email provider anywhere in the path.

1. What SeatSpend stores

For each account that installs the app, SeatSpend stores:

Your settings are saved in monday's own app storage for your account, and are mirrored into the app's storage on monday code so the scheduled digest can read them. Both locations are monday infrastructure.

2. What SeatSpend does not store

SeatSpend does not store, log, export, or share:

The report you see on screen and the text of a digest are built in memory and are not retained after they are delivered. Nothing about an individual user is written to storage or to a log line.

3. How your data moves

  1. You open SeatSpend inside monday. The app asks monday, through monday's own SDK, for your account's user list with each user's last activity date, and for your plan tier and seat count.
  2. The report is calculated in your browser and displayed. Nothing is sent anywhere else.
  3. If you enable scheduled digests, the digest service repeats the same read on your cadence, builds the digest text, sends it to you as a monday notification, and keeps only the aggregate counters from section 1.

Every read is a fresh read. There is no copy of your roster, and no history of it, anywhere in SeatSpend.

4. Third party domains and products

SeatSpend is built to have an unusually short list here. Every domain it touches belongs to monday.com, and each one is listed with the reason it is contacted.

Front end (in your browser, inside monday)

Domain or productWhy it is used
monday.com and its subdomainsThe platform SeatSpend runs inside. The app renders in a monday iframe, and every read of your seat data goes through monday's own SDK to monday's API. Your monday session authenticates it, so the app never handles a password or an API token in your browser.
The SeatSpend client bundle on monday code (a monday owned address, currently in the form https://<id>.cdn2.monday.app)This is where the app's own HTML and JavaScript are served from. monday assigns the address and reassigns it on each app version.
The SeatSpend service on monday code (a monday owned address, currently in the form https://<id>-service-<id>.us.monday.app)The app calls its own service to save a copy of your settings for the scheduled digest, to show the digest status line, and to start the monday permission flow when you enable scheduled digests.

Back end (the SeatSpend service, running on monday code)

Domain or productWhy it is used
api.monday.commonday's API. Read the account's users with their last activity dates and the account plan, and send the digest and renewal notices as monday notifications.
auth.monday.commonday's OAuth service. Used once, when you turn on scheduled digests, to obtain the permission grant that lets the scheduled service act for your account.
monday code storage (monday's own app hosting infrastructure)Holds your settings mirror, the aggregate counters, and the permission token. Values are stored per account.

Everything that is not in the path

There is no analytics or product telemetry service, no error or crash reporting service, no advertising or marketing pixel, no tag manager, no session recorder, no external font, image, or script CDN, no external database, no file storage, no email or SMS provider, no customer messaging widget, no payment processor (monday bills the subscription), and no AI, machine learning, or large language model provider. No part of your data is used to train any model, and none of it is sold or shared with anyone.

5. Permissions and why each one is needed

PermissionWhy SeatSpend asks for it
users:readLists the account's users with their last activity date. This is the report.
account:readReads the account plan tier and seat count, so the report can show plan context and pre-fill a starting per seat price.
me:readIdentifies the admin who connects scheduled digests, so the digest service knows which account a connection belongs to.
boards:readReads one board id. monday's notification API requires a target id of type Project, so the digest service resolves a single board to address the notification to. No board content is read or stored.
notifications:writeSends the scheduled digest and the renewal countdown to your monday notifications. This is the only write the app performs.

6. Notifications

Digests and renewal notices are delivered as notifications inside monday, to the admin who connected scheduled digests. SeatSpend does not send email, does not send SMS, and does not post to any outside service. Setting your digest cadence to Off stops the digest; clearing your renewal date stops the countdown.

7. Retention and deletion

8. Cookies and browser storage

SeatSpend sets no cookies of its own and runs no tracker. Any cookies present while you use monday are monday's own and are governed by monday's privacy policy.

9. Security

10. Children

SeatSpend is a workplace administration tool sold to businesses. It is not directed at children and is not intended for use by anyone under 16.

11. Changes to this policy

If this policy changes, the effective date at the top changes with it, and the current version always lives at this address. Material changes to what is stored or which domains are contacted will be described here before they take effect.

Contact

HH Online Ventures
HHonlineventures@proton.me