This Privacy Policy is mandated by Chapter 3 of the GDPR and other applicable data protection laws. It describes how we, in our capacity as a data controller, collect, store, use, and otherwise process Personal Data (as defined below) of employees, contractors, and other representatives of our business (corporate) customers - being potential, current, and former users of our Apps (each a “Customer”), as well as Website visitors and other individuals (collectively, “you,” “your,” or “yours”). Accordingly, this Privacy Policy is addressed to you as an individual whose Personal Data we process as a controller..

Please note that the Apps are hosted by monday, run on the Customers’ monday.com instances, and we do not have access to or process any data that runs through our Apps. Thus, the only data we process in connection to the Apps is the contact details of Customer’s representatives, data contained in attachments they provide in a technical support request, and anonymized App usage analytics related to specific Apps.

If you do not agree with this Policy, do not access or use our Apps and Websites or interact with us, as applicable.

1. Definitions

App” means our App designed to interoperate with the monday.com instance. The Apps are developed by us and distributed through the Marketplace.

Customer” refers to the definition provided in the Recitals above.

License Agreement” refers to the Stiltsoft App License Agreement for monday Marketplace.

Marketplace” means the marketplace defined in the Marketplace Terms of Service

monday” means any applicable monday entity. monday owns and provides the Marketplace and acts as a reseller of Apps available through the Marketplace.

monday.com” means monday.com platform developed and distributed by monday with which the App is used.

Personal Data” means information that can be used to identify you as an individual, like your first and last name, email address, username, usage data and so on. Personal Data does not include information that does not identify you as an individual (e.g., a business phone number) or has been anonymized such that it does not allow for your identification. If you cannot be identified (e.g., when Personal Data has been aggregated and anonymized), then this Policy does not apply.

Policy” means this Stiltsoft Europe Privacy Policy for monday Marketplace.

Service Provider” means the third-party service providers listed in Section 9.1 below.

We”, “our” or “us” means Stiltsoft Europe OÜ, a company whose registered address is at Jõe tn 3-303, 10151, Harju maakond, Tallinn, Estonia, and any of our affiliates. 

Website” means the website accessible at https://stiltsoft.ee/, https://stiltsoft.com/, including its subdomains, and our other websites on which this Policy appears.

You”, “your” refer to the definitions provided in the Recitals above. In most instances you access our Apps and Websites through our Customer (or the Customer’s client) for whom or with whom you work.

2. When We Act as Processor

Our Apps and Websites are designed for use by organizations and businesses, including our Customers. Where we provide an App to a Customer, the Customer may control the information processed in connection with the use of that App. For example, this applies to Personal Data contained in attachments submitted by you as part of technical support requests. In such cases, this Privacy Policy does not apply.

3. Third Parties Processing Your Personal Data

This Privacy Policy does not apply to the collection, processing, storage, or use of your Personal Data by monday or other third parties, except where we engage third-party Service Providers as described in this Policy. We do not control, and are not responsible for, how or when such third parties collect, process, store, or use your Personal Data. Please refer to the applicable third parties’ privacy policies to understand how your information is handled.

For example, monday’s processing of your Personal Data is governed by the monday Privacy Policy.

4. When We Act as Controller

There might be instances when we, rather than our Customer or monday, or independently of the Customer or monday, determine the purposes and means of processing your Personal Data, including its collection. In such cases, this Policy applies, and these instances will be further detailed below.

5. App-Specific Privacy, Data Collection, and Security Terms

Some of our Apps may be subject to additional privacy, data collection, data retention, or security terms that are specific to the relevant App. Where applicable, such additional terms are described in the “Security and Compliance” tab on the App’s page in the Marketplace.

6. What Personal Data We Collect and How We Do That

When you visit our Website, use our App or contact us directly we collect and process your Personal Data. The ways we collect it can be broadly categorized into the following:

6.1. Information you provide to us directly

When you use our Apps and Websites, you may provide Personal Data to us directly. For example, we may ask for your contact information when you reach out with questions or request support, or you may provide your Personal Data when submitting feedback, requesting for an App feature, or leaving comments on our blog pages.

6.2. Information we or our Service Providers collect automatically

We or our Service Providers collect some information about you automatically when you visit our Websites, like your region, type of device you use, type of browser you use, language of your browser. We collect some information about you automatically when you use certain Apps, like the type of device you use, type of browser you use, language of your browser or the screen resolution of your monitor or device. For certain Apps we also collect App-specific usage data, including App-specific events or actions, like the App features you use, the links you click on, the type, size and file formats of attachments you upload to the App, and how you interact with others when using the App. This information is useful for us as it helps us get a better understanding of how you are using and configuring our Apps and Websites so that we can improve them and continue to provide the best experience possible.

Some of this information is collected using cookies, other similar tracking technologies and third-party tools like Google Analytics.

We use persistent cookies to recognize you when you use our Apps. A persistent cookie remains after you close your browser. Most browsers allow some control of most cookies through the browser settings. You may be able to reset your browser to refuse all cookies or to indicate when a cookie is being sent. If you do not want us to use cookies, please be sure to block or disable them in your browser.

We also use session cookies that allow us to link your actions during a browser session. A browser session starts when you open the browser window and finishes when you close it. Session cookies are created temporarily and are deleted once the browser window is closed.

We use our own cookies (first party cookies):

  • to remember your choice about cookies on the Websites and for the Apps;
  • to recognize you when you visit the Website and Apps;
  • to remember your preferences.

Additionally, we work with reputable Service Providers who may use their cookies when you use the Website and Apps (third party cookies). For example, we use Google Analytics to collect App-specific usage data. Google Analytics collects only the anonymous information rather than your name or other identifying information. We do not combine the information collected through the use of Google Analytics with your Personal Data. Although Google Analytics plants a permanent cookie on the web browser you use to identify you as a unique user, the cookie cannot be used by anyone but Google. Google’s ability to use and share information collected by Google Analytics is restricted by the Google Analytics Terms of Service and the Google Privacy Policy.

We use tools like Google remarketing to advertise on third-party websites (including Google) to individuals who may have shown interest in our Apps (e.g., previous visitors to our Website). This could mean that we advertise to previous visitors who have not completed a task on our Website, for example by using the contact form to make an inquiry. This remarketing could be in the form of an advertisement on the Google search results page, or a site in the Google Display Network. Google uses cookies to serve advertisements based on someone’s past visits to the Website (more information on advertising cookies used by Google can be found by visiting ‘How Google uses cookies in advertising’ page). You can set preferences for how Google advertises to you, including by opting out of interest-based advertising over Google through the use of cookies, by visiting the Google Ad Preferences page. We may use remarketing tools offered by other platforms (for example, X), which function similarly to those  described above.

We also place tracking and/or retargeting pixels on our Website pages, such as, for example: 

  • X Pixel. It helps us collect information about actions you take after viewing or engaging with our ads on X, particularly regarding visits to our Website. The cookies collect information in an anonymous form, including the number of visitors to the Website and how they arrived at the Website, whether through interaction with X posts or our advertisements. Visit this page to learn more about X’s cookies policy. 
  • Meta Pixel. It allows us to track and monitor the success of advertisements we post on Facebook and to improve the effectiveness of those advertisements by recording information such as the device you used to access our Website and the actions you took on our Website using cookies. We may also use Meta Pixel to create retargeting advertisements and custom audiences for our advertisements on Facebook and on our Website. Visit this page to learn more about Meta cookies policy.

For clarity, this Policy does not cover the use of cookies and other similar technologies by third parties, which services we may utilize.

Web browsers will enable you to see what cookies you have got, allow you to delete them all or on an individual basis, and enable you to block or allow cookies for all websites or individually selected websites. You can also normally turn off third party cookies separately (e.g., to opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout).

6.3. Information we receive from monday, our Customer, and other sources

We might receive and collect Personal Data about you from third parties, such as monday or our Customer, including from other users of the App within the Customer. For example, the Customer may designate you as a billing and technical contact on the Customer’s monday account or designate you as an administrator. Certain data is accessed from your monday account via the monday API in order to provide the core functionality of the App and, where applicable, to support communication related to the App experience. This may include:

  • User information (such as your name and email stored in the monday.com storage), which is used to display the identity of users within the App interface and to include the user’s name in email notifications and in-App activity updates triggered by actions taken through the App. For example, if you leave a comment in the App, we may use the corresponding user name and email address to personalize notifications about that comment.
  • Account details (such as plan type and maximum number of users), which are used to tailor the in-App experience and notifications. This may include displaying relevant information about your account plan, providing service-related messages within the App, or tailoring in-App notifications based on your subscription type.

Access to this information is limited to what is necessary to perform these functions. We do not use this data for unsolicited marketing communications outside of the contexts described above, and do not share it with third parties except as required to provide the App’s functionality or as otherwise disclosed in this Privacy Policy.

7. Legal Grounds to Process Personal Data

Where we collect Personal Data under applicable data protection laws, we will only process it when we have the legal basis for doing so. Such legal bases are:

  • The performance of a contract. We may process your Personal Data where we need to take steps prior to entering into a contract or where it is necessary for the performance of a contract.
  • The legitimate interests. Your Personal Data may be processed when we, other companies in our group of companies or third parties (e.g., our Service Providers) have a business or commercial reason to process your Personal Data.
  • A legal obligation. Various laws and regulations may impose certain obligations on us. To comply with them we have to process your Personal Data.
  • Your consent. In certain limited cases, we process your Personal Data based on your consent. For example, this may occur when consent is required for direct marketing purposes and the applicable law mandates obtaining your consent.

8. How We Use Personal Data

Our processing of your Personal Data is necessary for us to provide you with the Websites and Apps. If we do not process your Personal Data, we may be unable to provide you with all or some features of the Apps.

We use your Personal Data for a number of purposes, which may include the following:

Use of your Personal Data

Legal basis

To operate our products, ensure they work as intended and deliver the requested services.

Performance of a contract

Legitimate interest

To set up and operate user accounts, including to authenticate you when you log in.

Performance of a contract

Legitimate interest

To support our Customer and you, including assisting with the resolution of technical or other issues relating to the Apps and Websites.

Performance of a contract

To enhance our products, to conduct research, test and develop new features and carry out analysis of our products so that we can optimize your user experience and provide you and other users with more efficient tools and features.

Legitimate interest

To analyze and aggregate data, to prepare statistics, in particular, to produce aggregated and anonymized analytics and reports, which we may use internally or share publicly or with third parties.

Legitimate interest

To manage our relationship and communicate with you. This may include:

  • operational and transactional communications sent to you in course of ordering and using the App, including suggestions as you onboard to the App, updates on changes to our Apps, new features, and security updates, when assisting with using our Apps, or requests for feedback;
  • survey requests, feedback collection and follow-up communication after the App’s license has expired or has been terminated;
  • providing you with the information you have requested from us or information we are required to send to you.

These communications are part of the services we provide you through the Apps and in most cases you will not be able to opt out of them. If an opt out is available, you will find that option within the communication itself or in your account settings.

Performance of a contract

Legitimate interest

To promote and drive engagement with our products.

Legitimate interest

To send marketing communications that may be of specific interest to you.

These communications are aimed at driving engagement and maximizing what you get out of our products, including information about new products, newsletters, product offers, and promotions we think may be of interest to you.

You may opt out of receiving marketing communications from us by using the unsubscribe link within each email, updating your email preferences in your account settings, or contacting us at smart-spreadsheet@stiltsoft.atlassian.net to have your contact information removed from our promotional email list.

Legitimate interest

Your consent

To prevent, detect and report crime, protect you, other users and us, for example, by ensuring network and information security, mitigating security risks, detecting and preventing any fraudulent or malicious activity, and make sure that everyone is using our products fairly and in accordance with the License Agreement.

Legal obligation

Legitimate interest

Performance of a contract

To perform legal duties, responsibilities, and obligations; and to comply with any laws and regulations that apply to us.

Legal obligation

To exercise our rights set out in the License Agreement or other agreements with you.

Performance of a contract

To disclose information following a restructure, sale of business, merger, or acquisition.

Legitimate interest

9. To Whom We Disclose Personal Data

When you post on our forums or blogs you make your username and/or email address publicly visible. Thus, you acknowledge that your Personal Data (your name) will be publicly exposed if you post your comments or feedback in the public sections of our Websites (e.g. forums, blogs, feedback portals, etc.).

There will be times when we may need to share your Personal Data with third parties. We may disclose your Personal Data to:

  • Other users of the App;
  • monday;
  • Our Customer for whom or with whom you work;
  • Third-party Service Providers;
  • Regulators, law enforcement agencies, government bodies, courts, fraud prevention agencies, or other third parties, where in our opinion it is necessary to comply with applicable laws or regulations, or to exercise, establish or defend our legal rights (where possible and appropriate, we will notify you of this type of disclosure); and/or
  • An actual or potential buyer (and its agents and advisers) in connection with an actual or proposed purchase, merger, financing, or acquisition of any part of our business.

9.1. List of third-party Service Providers

We may disclose your Personal Data to the following Service Providers who assist us in connection with our Apps, Websites, and other products:

Service Provider

Purpose

Links to the Service Provider's documentation

Country

Applicable Apps

Google, Inc.

Font loading for VibeUI

https://developers.google.com/fonts/docs/getting_started

USA

Interactive Gantt Timeline

ActiveCampaign, LLC (Postmark)

Transactional emails

https://postmarkapp.com/privacy-policy

https://postmarkapp.com/eu-privacy

USA

Interactive Gantt Timeline, Smart Spreadsheet, Board Email Reports

Supabase Inc.

Data base instance

https://supabase.com/docs

USA

Interactive Gantt Timeline

Rocket Science Group LLC (Mailchimp)

Transactional emails

https://mailchimp.com/about/security/

https://mailchimp.com/legal/privacy/

USA

Interactive Gantt Timeline, Smart Spreadsheet, Board Email Reports

Google, Inc.

Google Analytics - to collect anonymous App usage data

https://developers.google.com/analytics/devguides/collection/ga4

USA

Interactive Gantt Timeline, Smart Spreadsheet, Board Email Reports

Sentry

Monitor errors

https://docs.sentry.io/

USA

Smart Spreadsheet

10. International Data Transfers

When we process and share data, it may be transferred to, and processed in, countries other than your country. Where Personal Data is processed in another country, we put safeguards in place to ensure your Personal Data remains protected.

For individuals in the European Economic Area (EEA), this means that your data may be transferred outside of the EEA. Where your Personal Data is transferred outside the EEA, it will be transferred to countries where we have compliant transfer mechanisms in place to protect your Personal Data, in particular, by implementing the European Commission’s Standard Contractual Clauses to the contracts with the entities the data is transferred to or by using other appropriate legal mechanisms to safeguard the transfer.

11. Security

We take appropriate technical and organizational measures to help ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing of Personal Data. These measures are designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed. Access to Personal Data is limited to our employees, contractors, and agents who require such access for legitimate business purposes. We maintain procedures intended to monitor our systems and identify potential security incidents. 

Further information about our security practices is available in our Trust Center and in the “Security and Compliance” tab on the relevant App’s page in the Marketplace. 

Where our Apps are hosted by monday and used by a specific Customer, responsibility for the security of data storage and access rests with those entities, and not with us.

12. Personal Data Retention

Some Personal Data is controlled by our Customers; some Personal Data may be deleted by you at any time; some Personal Data is deleted automatically; and some Personal Data may be retained for longer periods where necessary. Where Personal Data is deleted, we take reasonable steps to ensure that it is securely removed from our systems or retained only in anonymized form.

Customer Data is automatically removed from the database after uninstalling an app.

Customer Data will not be automatically removed if:

  • you have terminated the subscription to an app, but did not remove the app from the monday.com account.
  • your monday.com account was terminated or removed by monday.com upon expiry of a trial period or the expiration of its subscription.

In some cases, the app’s functionality allows customers to control the removal of their data.

12.1. Personal Data retained until Customer removes it

When the App is made available to you through our Customer, we retain your Personal Data as long as required by the controller (the Customer), unless we use such information as a controller ourselves, in which case the provisions of subsections 12.2 and 12.3 below apply.

12.2. Personal Data used for marketing communications

If you have not opted-out or have consented (as the case may be) to receive marketing communications from us, we retain Personal Data about your marketing preferences for a reasonable period of time from the date you last used or expressed interest in our Apps.

12.3. Personal Data retained for extended time periods for limited purposes

Sometimes business and legal requirements oblige us to retain certain Personal Data, for specific purposes, for an extended period of time. Reasons we might retain some data for longer periods of time include:

  • To ensure that the Apps and Websites are available to you and other users.
  • To protect you, other persons, and us from fraud, abuse, illegal activity and unauthorized access.
  • To  facilitate dispute resolution.
  • To comply with applicable law, regulation, legal process or enforceable governmental request, or when we are required to enforce the License Agreement, including investigation of potential violations.
  • If you have directly communicated with us, for example, through a customer support channel or provided feedback or a bug report.

13. Your Rights

Depending on the applicable local data protection laws and subject to the exclusions and limitations set forth in them, you  may have the following rights with respect to your Personal Data that we process as a controller:

  • Right to know / to access. You have the right to access (and obtain a copy of, if required) your Personal Data.
  • Right to rectification. You have the right to update your Personal Data or to correct any inaccuracies.
  • Right to erasure. You may have the right to request that we delete your Personal Data in certain circumstances, such as when it is no longer necessary for the purpose for which it was originally collected.
  • Right to restrict processing. You may have the right to request to restrict the use of your Personal Data in certain circumstances, such as when you have objected to our use of your Personal Data but we need to verify whether we have overriding legitimate grounds to use it.
  • Right to data portability. You have the right to transfer your Personal Data to a third party in a structured, commonly used and machine-readable format, in circumstances where the Personal Data is processed with your consent or by automated means.
  • Right to object. You may have the right to object to the use of your Personal Data in certain circumstances, such as the use of your Personal Data for direct marketing.

Right to opt-out of “sale” or “sharing.” You can opt out of any data "sales" or “sharing” related to cross-context behavioral advertising or targeted advertising. One of the ways to exercise this right is by managing your cookie settings

  • Right to complain. If you are not happy with how we are processing your Personal Data, please let us know by sending an email to smart-spreadsheet@stiltsoft.atlassian.net. We will review and investigate your complaint, and try to get back to you within a reasonable time frame. You have the right to complain to your local data protection authority. 

Please note that we will be able to assist you in exercising your rights only when we are a controller of your Personal Data (e.g., when we use your information for marketing communications or when you have contacted us not as an employee, contractor, or representative of an organization). You can exercise your rights at any time by sending an email to smart-spreadsheet@stiltsoft.atlassian.net. In all other cases, please direct your data privacy questions and requests to your organization.

We may require evidence of and be satisfied as to your identity before we take any requested action.

14. Modifications

We reserve the right, at our sole discretion to put into effect, modify or revise this Policy at any time by posting the Policy or revised Policy on this page. The Policy or any changes will become effective upon posting of the revised Policy. Depending on the significance of the changes to this Policy we will use reasonable efforts to inform you by posting a notice on the Website or by using other ways to notify you about the changes.

15. Privacy Related Inquiries

If, for any reason, you are concerned with the way that we may be using your Personal Data, you have questions about the privacy aspects of the Apps or Websites, please, contact us at smart-spreadsheet@stiltsoft.atlassian.net.

16. U.S. Privacy Rights Notice

This Privacy Notice (Section 16) is intended for residents of specific U.S. states where data protection laws have been enacted, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. It supplements the information contained in this Privacy Policy.

As a data controller, we collect Personal Data from a limited number of individuals. Although we do not meet the revenue and/or consumer thresholds set by these state data protection statutes, meaning they do not legally apply to us, we still adhere to the core principles of these laws.

Personal Data that we may collect and disclose, or may have collected from you and disclosed in the preceding twelve months, fall into the following categories:

  • identifiers, such as your name, alias, email address or IP address;
  • Internet or other electronic network activity information, including, but not limited to, browsing history, search history, pseudonymous identifiers, clickstream data, device and connection information, crash data, referring/exit URLs,, and information regarding your interaction with the Apps and Websites;
  • commercial information, such as purchase details, transaction records, billing information, billing address, payment card details;
  • non-precise geolocation data, such as an approximate location of your device or computer;
  • audio, visual, electronic or other similar information, including when you communicate with us;
  • professional or employment information, such as your job title, company name, company domain; and
  • inference data, such as information about your preferences.

For more information about Personal Data we may disclose to third parties for a business purpose and the categories of recipients of disclosures, please see Section 9 ‘To Whom We Disclose Personal Data’.

We do not process sensitive personal data as this term is defined in current state privacy laws, with the exception of the California Consumer Privacy Act (CCPA). Under the CCPA, we may process your credentials, including passwords, which are classified as sensitive Personal Information. We use and disclose sensitive Personal Information solely for the limited purposes permitted under the CCPA and not for inferring characteristics about a consumer. For instance, we may process your sensitive Personal Information to fulfill a service request. The CCPA does not grant you the right to limit the use or disclosure of your sensitive Personal Information for these purposes.

Please visit Section 12 ‘Personal Data Retention’ for more information about our data retention criteria for different categories of Personal Data.

We use Personal Data we collect for business and commercial purposes listed in Section 8 ‘How We Use Personal Data.’

In the past twelve months we have collected Personal Data from the sources outlined in Section 6 ‘What Personal Data We Collect and How We Do That.’

Information about you, your devices, and your behavior collected through third-party cookies, pixels, tags, or other tracking technologies for purposes of cross-context behavioral advertising or targeted advertising may be considered a “sale” or “share” under certain US state data protection laws. However, we do not sell personal information for monetary consideration. In the past twelve months the following categories of Personal Data may have been "sold" or “shared” with third party advertising partners and analytics providers:

  • identifiers, such as device identifiers;
  • online activity information, such as information about devices and browsers, IP addresses associated with those devices and browsers, and usage data);
  • non-precise geolocation data, such as IP addresses.

The purpose for such “sale” or “sharing” is for us to use these third-party services to analyze your interactions with the Apps and Websites and to advertise them.

We do not process Personal Data for the purpose of profiling in furtherance of decisions that produce legal or similarly significant effects concerning consumers.

You may have the rights under the applicable state data protection law, which are described in Section 13 ‘Your Rights’.

We will not discriminate against any consumer for exercising their rights.

Last updated: January 29, 2026