Legal
Privacy Policy
Last updated: August 22, 2026
Montly ("Montly", "we", "us") is operated by Dumitru Lunic. This policy explains what data Montly collects, why, how long it's kept, who it's shared with, and the rights you have over it. It applies to everyone who visits montly's website or uses the Montly application (an "agency" or "you").
Montly reads Google Analytics 4 (GA4) data on behalf of agencies, to generate and deliver reports to those agencies' own clients. Because of that, this policy covers two different relationships at once — read the "Two roles Montly plays" section below before anything else; it changes who counts as "controller" of which data.
1. Two roles Montly plays
Under GDPR, a data controller decides why and how personal data is processed; a data processorprocesses data only on a controller's instructions, for the controller's purposes.
- For your own account data (sign-up details, agency profile, billing, how you use the site) — Montly is the controller. This policy describes that processing directly.
- For the GA4 report data Montly reads and delivers on your behalf (your clients' website traffic, sessions, users, and similar analytics) — you (the agency) are the controller, and Montly is only a processor, acting on your instructions to generate and send reports. You're responsible for having a lawful basis to connect that GA4 property and to have Montly process it — typically, your own agreement with your client already covers analytics reporting; if it doesn't, that's worth confirming before connecting their property.
A separate Data Processing Agreement, on the terms GDPR Article 28 requires for that second relationship, is available on request at dumitrulunic@gmail.com.
2. Information we collect
Account & agency information
When you sign up, we collect your email address and, if you sign in with Google, the basic profile Google shares (name, email, profile photo). During onboarding we collect your agency name, brand color, and logo (if you upload one). If billing is active on your account, our payment processor collects and stores your payment details directly — Montly never sees or stores your card number.
Google Analytics connection
Connecting Google Analytics is a separate, optional step from signing in — it requests read-only access (analytics.readonly) to the GA4 properties you choose to link. We store the resulting access and refresh tokens, encrypted at rest (AES-256-GCM), tied to your agency account. You can revoke this access at any time from your dashboard, which deletes the stored tokens immediately — or directly from your Google Account's connected apps settings.
Using that access, we read report data from your linked GA4 properties: sessions, users, page views, engagement rate, session duration, conversion events, top pages, traffic channels, and country-level geography. This is aggregate analytics about your clients' website visitors, not data we collect from those visitors directly — Google Analytics collected it on your client's site, under your client's own GA4 configuration, before Montly ever reads it.
Client & report data you provide
To send reports, you give us your clients' names, recipient email addresses, which GA4 property belongs to which client, and (optionally) freeform notes you write into a report. We also keep a record of each report generated — its period, delivery status, and send timestamp.
Live report links
A "Copy link" or emailed report link is a signed, self-contained token — not a database record. It encodes the client, period, and a 30-day expiry, and is verified cryptographically when opened; nothing is stored server-side beyond what the token itself carries. Anyone holding a valid, unexpired link can view that report — treat it the same as you would an email attachment.
Cookies & usage data
We use two categories of cookies:
- Strictly necessary— your login session (httpOnly, can't be read by scripts) and a short-lived (10-minute) cookie during the Google Analytics connect flow, used only to prevent cross-site request forgery. These aren't optional; the app can't function without them, and they aren't used for tracking.
- Analytics— on our marketing pages (not inside the logged-in app), Google Analytics, used to understand traffic to montly's own site. This only runs after you accept it in the cookie banner; declining or ignoring the banner keeps it off.
We also keep one browser-local (not sent to our servers) preference — which client is currently selected in the dashboard — in your browser's local storage, to survive page refreshes.
Communications
If you email us for support, we keep that correspondence to respond and to improve the product.
3. Why we process this data (legal basis)
- Performance of a contract — account creation, generating and delivering reports, billing, and support are all necessary to provide the service you signed up for.
- Legitimate interests — securing accounts, preventing abuse, and diagnosing failures (e.g. a broken GA4 connection) — always weighed against your right to privacy, which is why access tokens are encrypted and server logs are scrubbed of anything sensitive before being written.
- Consent— non-essential cookies (the marketing site's analytics) only run once you accept them.
- Your instructions— for the GA4 report data itself, we process it because you've instructed us to, as your processor (see Section 1).
4. Who we share data with
We don't sell data. We share it only with the infrastructure providers ("sub-processors") that make Montly work, each bound by its own data processing terms:
- Supabase (database, authentication, file storage) — our EU hosting region is
eu-north-1(Stockholm). - Vercel (application hosting) — primary compute region
eu-north-1(Stockholm); Vercel's global edge network may route requests through other regions purely for network delivery, without storing data there. - Google(Sign-in, and the Google Analytics Data/Admin APIs) — under Google's own data processing terms.
- Resend (delivering report emails) — may process data outside the EEA, under Standard Contractual Clauses.
- A payment processor, once billing is active on your account.
We disclose data beyond this list only if legally required to (a valid court order or similar), or with your explicit consent.
5. International data transfers
Our core infrastructure (database, file storage, hosting) runs in the EU (Stockholm). Where a sub-processor is based outside the EEA — Google and Resend both have US operations — transfers rely on that provider's own EU-approved safeguards, typically the European Commission's Standard Contractual Clauses.
6. How long we keep data
- Account and agency data — for as long as your account is active.
- Google Analytics tokens — until you disconnect Google Analytics or delete your account, whichever comes first.
- Client and report records — until you delete that client, or your account.
- Live report link tokens — never stored; they self-expire after 30 days by design (Section 2).
- Server logs — kept only as long as our hosting provider's operational log retention window, and never contain access tokens, refresh tokens, or passwords (redacted automatically before anything is written).
"Delete account" in your account settings deletes everything immediately - your agency profile, every client, every linked GA4 property, and every report - no waiting period. If you'd rather we handle it, emailing dumitrulunic@gmail.com works the same way.
7. Security
Google Analytics access and refresh tokens are encrypted at rest (AES-256-GCM) — even someone with direct database access can't read them without the server's separate encryption key. All traffic to and from Montly is encrypted in transit (HTTPS). Database access is scoped per-agency at the row level, not just in application code. No system is perfectly secure, and we can't guarantee absolute security — but this is the standard we hold ourselves to.
8. Your rights
If you're in the EEA, UK, or another jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request erasure ("right to be forgotten").
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent (e.g. analytics cookies).
- Lodge a complaint with your local data protection authority — for example, Austria's Datenschutzbehörde.
To exercise any of these, email dumitrulunic@gmail.com. If you're an end-client of one of our agency customers and want data corrected or removed from a report, the fastest path is contacting that agency directly — they control that data; we process it on their instructions (Section 1).
9. Children's privacy
Montly is a business tool, not directed at children, and we don't knowingly collect data from anyone under 16.
10. Changes to this policy
If we make a material change, we'll update the date at the top of this page and, for significant changes, notify active accounts by email before the change takes effect.
11. Contact
Questions, requests, or complaints about this policy: dumitrulunic@gmail.com. See also our Terms of Service.