What the service does
Automation Ledger reads automations available to an authorising monday.com user, builds a current inventory, and records compact changes over time. It does not write to customer boards.
Information we collect
To provide the service, we collect and hold:
- the monday account ID and ID of the user who authorises the connection;
- OAuth access and refresh credentials issued by monday.com;
- board IDs, names, types and workspace IDs visible to that user;
- automation IDs, titles, source type, active state, relevant timestamps, dependency identifiers and one-way configuration hashes;
- scan coverage, revision, change and operational status records; and
- information provided when requesting support, such as contact details, account or board identifiers, screenshots and problem descriptions.
Board and automation titles are customer-authored and may contain personal information even though Automation Ledger does not ask customers to put personal information in those fields.
We do not intentionally retain raw automation recipes or workflow configuration, item values, updates, files, message bodies, documents, user names, user email addresses, advertising identifiers or payment-card details. Payment and subscription processing is handled by monday.com.
How we collect and use information
We collect service information from monday.com after an authorised user connects the app. We use it only to authenticate the connection, scan eligible boards, show the automation inventory, detect and display changes, operate subscriptions, secure and support the service, investigate faults, and meet legal obligations.
We do not sell personal information or use customer information for third-party advertising. The initial release uses no third-party product analytics.
Storage and disclosures
Application data, credentials and operational logs are stored in monday.com’s Secure Storage, Document DB and monday Code services in the United States. monday.com also handles app installation, identity, subscription and billing information under its own privacy terms.
Google Firebase hosts the public Automation Ledger website and may process ordinary web-request information, such as IP address and browser details, to deliver and secure those pages. The website does not use Firebase Analytics.
GitHub hosts source code and deployment evidence. Customer content and OAuth credentials are not intentionally placed in GitHub. A support-mail provider may process correspondence in Australia, the United States or other locations where that provider operates. We may also disclose information when required by law, to protect users or the service, or with the relevant person’s direction.
The service is not represented as providing Australian or customer-selected data residency.
Security
OAuth credentials are kept out of the browser and stored in monday Secure Storage. Customer records are separated by verified monday account ID. The app uses encrypted transport, bounded logging, least-privilege access, automated tests and tenant-specific deletion controls. No internet service can guarantee absolute security, but we use reasonable safeguards appropriate to the information handled.
Retention and deletion
- Pending OAuth state is valid for 10 minutes and targeted for deletion within 24 hours if abandoned.
- Change history is retained for up to 730 days. A customer’s plan may expose a shorter rolling window.
- Hourly worker-run records are retained for up to 90 days.
- Operational logs are targeted for 30 days or a shorter provider-supported period.
- Closed support correspondence is retained for up to 24 months, unless needed longer for a dispute or legal obligation.
- Current account, connection and snapshot records remain while needed to provide a reconnectable ledger.
An account administrator can permanently delete the account’s Automation Ledger data in Settings. A verified uninstall event also deletes the account’s OAuth record, account registry, current snapshot, history and worker records. Deletion is designed to be tenant-specific and retry-safe.
Access, correction and complaints
To request access to, correction or deletion of information, or make a privacy complaint, email support@innestech.com.au with enough information to verify the affected monday account. Do not send passwords, OAuth tokens, session tokens or API keys.
We aim to respond to privacy complaints within 30 days. If an Australian privacy complaint is not resolved, a person may be entitled to contact the Office of the Australian Information Commissioner.
Automated decisions and children
Automation Ledger compares automation records and reports detected changes. It does not use personal information to make decisions that significantly affect a person’s legal rights or access to essential services. The service is intended for business users of monday.com and is not directed to children.
Changes and contact
We will keep this policy accurate and update the “Last updated” date when our information practices materially change. Material changes will be communicated through the website, the app or monday.com’s available customer channels.
Tasmania, Australia
support@innestech.com.au