Privacy Policy
Your privacy is important to us. This policy explains what we collect and how we use it.
Last updated: March 19, 2026
This Privacy Policy explains how Redcoded Limited, trading as BAM Apps ("we", "us", "our") collects, uses, and protects your information when you use the Easy Invoice application ("App") on the monday.com marketplace.
1. Information We Collect
1.1 monday.com Session Data
The App receives your monday.com session token to verify your identity. This token contains your monday.com user ID and account ID.
1.2 Board Data
The App reads and writes data to monday.com boards that you configure as part of the Easy Invoice workspace. This includes:
- Invoice and quote items (names, numbers, dates, amounts, status)
- Customer records (names, contact details, addresses)
- Product/service items (names, descriptions, rates)
- Line items (subitems on invoice/quote items)
All board data is stored in your monday.com account — we do not copy or store board data outside of the monday.com platform.
1.3 App Settings
When you configure the App, we store your settings using monday.com's Storage API:
- Company details (name, address, email, phone, tax ID)
- Currency preference
- Invoice/quote numbering prefixes
- Board configuration (which boards are used for customers, products, quotes/invoices)
1.4 Published Invoices
When you publish an invoice as a shareable link, the invoice content is stored server-side on monday code infrastructure to serve the public page. Published content includes invoice details, line items, and company information visible on the invoice. Published invoices can be unpublished at any time.
2. How We Use Your Information
| Data | Purpose |
|---|---|
| monday.com session token | Verify your identity and authorize API requests |
| Board data | Display and edit invoices, quotes, customers, and products in the App |
| App settings | Persist your company details and configuration across sessions |
| Published invoices | Serve shareable invoice pages to your clients |
We do not use your data to:
- Serve advertisements
- Build user profiles for marketing
- Sell or rent data to third parties
- Train machine learning models
- Contact you for marketing purposes (unless you opt in)
3. How We Store Your Information
3.1 Board Data
- Stored entirely in your monday.com account via the monday.com GraphQL API
- The App reads and writes to boards using your session token
- We do not maintain a separate copy of your board data
3.2 App Settings
- Stored in monday.com Storage API (per app instance)
- Accessible only within the context of the App on your account
3.3 Published Invoices
- Stored on monday code infrastructure (server-side)
- Accessible via a unique, unguessable URL
- Can be unpublished (deleted) at any time by the user
3.4 What We Do NOT Store
- Passwords or account credentials
- Payment or banking information
- Data from boards outside the Easy Invoice workspace
- Personal data beyond what is entered into invoice/customer fields by the user
4. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
| Third Party | Data Shared | Purpose |
|---|---|---|
| monday.com platform | Session tokens, storage data | Authentication, data persistence |
All communication with third-party services is encrypted via TLS 1.2 or higher.
5. Data Retention and Deletion
- On uninstall: When you uninstall the App, app settings stored via the monday.com Storage API are removed with the app instance. Published invoices stored server-side will be deleted within 10 days.
- Board data: Invoice, quote, customer, and item data lives in your monday.com boards and is not affected by app uninstall — it remains in your account.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Delete your data (uninstall the App, delete board data from your account)
- Restrict processing (disable analytics via account settings)
- Port your data (export boards via monday.com's native export features)
- Object to data processing
To exercise these rights, contact us at support@bam-apps.com.
GDPR (European Economic Area)
If you are in the EEA, our legal basis for processing is:
- Legitimate interest — to provide and improve the App
- Consent — for optional analytics tracking
- Contract performance — to deliver the service you installed
CCPA (California)
We do not sell personal information. California residents may request disclosure of data collected and request deletion.
7. Security
- All data in transit is encrypted via TLS 1.2+
- monday.com session tokens are verified server-side using the app's signing secret (HS256)
- PDF generation is performed client-side — invoice content is not sent to external servers for rendering
- No credentials or tokens are stored in source code or environment variables accessible to the client
- The App is hosted entirely on monday code (monday.com's own infrastructure)
8. Cookies
Easy Invoice does not use cookies. Authentication is handled via monday.com session tokens (JWT in Authorization header). No tracking cookies or third-party cookies are used.
9. Children's Privacy
The App is not directed at children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App listing on the monday.com marketplace. The "Last updated" date at the top reflects the most recent revision.
11. Contact
For questions or concerns about this Privacy Policy, contact us at:
- Email: support@bam-apps.com
- Entity name: Redcoded Limited