Legal

Privacy Policy

Last updated: August 22, 2026

Montly ("Montly", "we", "us") is operated by Dumitru Lunic. This policy explains what data Montly collects, why, how long it's kept, who it's shared with, and the rights you have over it. It applies to everyone who visits montly's website or uses the Montly application (an "agency" or "you").

Montly reads Google Analytics 4 (GA4) data on behalf of agencies, to generate and deliver reports to those agencies' own clients. Because of that, this policy covers two different relationships at once — read the "Two roles Montly plays" section below before anything else; it changes who counts as "controller" of which data.

1. Two roles Montly plays

Under GDPR, a data controller decides why and how personal data is processed; a data processorprocesses data only on a controller's instructions, for the controller's purposes.

A separate Data Processing Agreement, on the terms GDPR Article 28 requires for that second relationship, is available on request at dumitrulunic@gmail.com.

2. Information we collect

Account & agency information

When you sign up, we collect your email address and, if you sign in with Google, the basic profile Google shares (name, email, profile photo). During onboarding we collect your agency name, brand color, and logo (if you upload one). If billing is active on your account, our payment processor collects and stores your payment details directly — Montly never sees or stores your card number.

Google Analytics connection

Connecting Google Analytics is a separate, optional step from signing in — it requests read-only access (analytics.readonly) to the GA4 properties you choose to link. We store the resulting access and refresh tokens, encrypted at rest (AES-256-GCM), tied to your agency account. You can revoke this access at any time from your dashboard, which deletes the stored tokens immediately — or directly from your Google Account's connected apps settings.

Using that access, we read report data from your linked GA4 properties: sessions, users, page views, engagement rate, session duration, conversion events, top pages, traffic channels, and country-level geography. This is aggregate analytics about your clients' website visitors, not data we collect from those visitors directly — Google Analytics collected it on your client's site, under your client's own GA4 configuration, before Montly ever reads it.

Client & report data you provide

To send reports, you give us your clients' names, recipient email addresses, which GA4 property belongs to which client, and (optionally) freeform notes you write into a report. We also keep a record of each report generated — its period, delivery status, and send timestamp.

Live report links

A "Copy link" or emailed report link is a signed, self-contained token — not a database record. It encodes the client, period, and a 30-day expiry, and is verified cryptographically when opened; nothing is stored server-side beyond what the token itself carries. Anyone holding a valid, unexpired link can view that report — treat it the same as you would an email attachment.

Cookies & usage data

We use two categories of cookies:

We also keep one browser-local (not sent to our servers) preference — which client is currently selected in the dashboard — in your browser's local storage, to survive page refreshes.

Communications

If you email us for support, we keep that correspondence to respond and to improve the product.

3. Why we process this data (legal basis)

4. Who we share data with

We don't sell data. We share it only with the infrastructure providers ("sub-processors") that make Montly work, each bound by its own data processing terms:

We disclose data beyond this list only if legally required to (a valid court order or similar), or with your explicit consent.

5. International data transfers

Our core infrastructure (database, file storage, hosting) runs in the EU (Stockholm). Where a sub-processor is based outside the EEA — Google and Resend both have US operations — transfers rely on that provider's own EU-approved safeguards, typically the European Commission's Standard Contractual Clauses.

6. How long we keep data

"Delete account" in your account settings deletes everything immediately - your agency profile, every client, every linked GA4 property, and every report - no waiting period. If you'd rather we handle it, emailing dumitrulunic@gmail.com works the same way.

7. Security

Google Analytics access and refresh tokens are encrypted at rest (AES-256-GCM) — even someone with direct database access can't read them without the server's separate encryption key. All traffic to and from Montly is encrypted in transit (HTTPS). Database access is scoped per-agency at the row level, not just in application code. No system is perfectly secure, and we can't guarantee absolute security — but this is the standard we hold ourselves to.

8. Your rights

If you're in the EEA, UK, or another jurisdiction with similar protections, you have the right to:

To exercise any of these, email dumitrulunic@gmail.com. If you're an end-client of one of our agency customers and want data corrected or removed from a report, the fastest path is contacting that agency directly — they control that data; we process it on their instructions (Section 1).

9. Children's privacy

Montly is a business tool, not directed at children, and we don't knowingly collect data from anyone under 16.

10. Changes to this policy

If we make a material change, we'll update the date at the top of this page and, for significant changes, notify active accounts by email before the change takes effect.

11. Contact

Questions, requests, or complaints about this policy: dumitrulunic@gmail.com. See also our Terms of Service.

Montly

Automated GA4 reports for agencies. Built with care, delivered on time.

Product

Company

Legal

© 2026 Montly