Legal

Privacy Policy

Last updated: September 2026

1. Introduction

1.1 Monesize Limited ("Monesize", "we", "us", or "our") is committed to protecting the privacy of everyone who interacts with our products and services. This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with Monesize Engage ("the Service"), and describes the rights available to individuals whose personal data we process.

1.2 This Privacy Policy applies to:

1.2.1 individuals who register for an Account on the Service ("Users");

1.2.2 individuals who are invited to join an Organization on the Service ("Members");

1.2.3 individuals whose personal data is stored within the Service by an Organization as contacts, prospects, or leads ("End Users");

1.2.4 visitors to any website or interface through which the Service is accessed.

1.3 This policy should be read alongside our Terms of Service, which govern your use of the Service. Where the Service is used by an Organization to store and process End User data, the Organization acts as the Data Controller for that data and Monesize acts as the Data Processor. In that capacity, our processing obligations are governed by the Data Processing Agreement entered into with the Organization. This Privacy Policy covers Monesize's role as a Data Controller in its own right, which applies to the personal data of Users and Members.

1.4 If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us at hello@monesize.com.

2. Who We Are and Our Legal Basis for Processing

2.1 Monesize Limited is incorporated in England and Wales under company number 16964677, with its registered address at 128 City Road, London, England, EC1V 2NX.

2.2 For the purposes of the UK General Data Protection Regulation ("UK GDPR") and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), Monesize Limited is the Data Controller for the personal data of Users and Members.

2.3 We process personal data under the following legal bases:

2.3.1 Performance of a contract: processing necessary to provide the Service to you, to manage your Account, and to fulfil our obligations under our Terms of Service.

2.3.2 Legitimate interests: processing necessary for our legitimate business interests, including maintaining the security of the Service, preventing fraud and abuse, improving the Service, and communicating with you about matters relating to your Account.

2.3.3 Legal obligation: processing necessary to comply with applicable laws and regulations, including data protection law, financial record-keeping requirements, and responses to lawful requests from competent authorities.

2.3.4 Consent: where we rely on your consent for any specific processing activity, we will obtain that consent explicitly and you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

3. Personal Data We Collect

3.1 Data You Provide Directly

3.1.1 Account registration: when you create an Account, we collect your first name, last name, and email address. If you set a password, we store a cryptographic hash of that password. We never store passwords in plaintext.

3.1.2 Profile information: you may optionally provide a profile picture or avatar URL.

3.1.3 Organization information: when you create an Organization, we collect the organization name, and optionally a legal name, website URL, industry, country, address, phone number, logo URL, timezone, and currency preference.

3.1.4 Communications with us: if you contact us for support or with enquiries, we collect the content of your communications and any personal data you include in them.

3.2 Data We Collect Automatically

3.2.1 Authentication data: when you sign in, we record the time and date of login, your IP address, and your browser user agent string. This information is stored in our audit log and is used for security monitoring and fraud detection.

3.2.2 Usage data: we collect information about how you interact with the Service, including the actions you take, the features you use, and the times at which activity occurs. This is recorded in our audit log at the organizational level.

3.2.3 Technical data: we collect your IP address, browser type and version, operating system, and device information when you access the Service. This data is used to operate the Service correctly and to investigate security incidents.

3.2.4 Cookie data: the Service uses a single signed, HTTP-only authentication cookie named “engage_token” to maintain your session. This cookie does not track you across other websites. It is necessary for the operation of the Service and cannot be disabled without preventing you from signing in. We do not use tracking cookies, advertising cookies, or analytics cookies.

3.3 Data from Third Parties

3.3.1 OAuth providers: if you choose to sign in using Google or Microsoft, we receive your name, email address, and profile information from those providers as part of the OAuth authentication flow. This data is used to create or link your Account. We do not receive your password from OAuth providers.

3.3.2 Email provider webhooks: when you configure an outbound email provider for Campaign delivery, we receive delivery event data from those providers via webhooks. This data includes information about whether emails were delivered, opened, clicked, bounced, or resulted in unsubscribes. This data is associated with the recipient contact records within your Organization.

4. How We Use Personal Data

4.1 We use the personal data of Users and Members for the following purposes:

4.1.1 to create and manage your Account;

4.1.2 to authenticate you when you sign in to the Service;

4.1.3 to provide you with access to the features and functionality of the Service appropriate to your role and organization;

4.1.4 to send transactional emails that are necessary for the operation of the Service, including email verification links, password reset links, account security alerts (such as notifications when two-factor authentication is enabled or disabled on your account), invitation notifications, and operational updates relating to your Account or Organization;

4.1.5 to enforce our Terms of Service and investigate potential violations;

4.1.6 to maintain the security, integrity, and availability of the Service;

4.1.7 to detect and prevent fraud, abuse, and unauthorized access;

4.1.8 to comply with legal obligations to which we are subject;

4.1.9 to respond to enquiries and support requests submitted to us;

4.1.10 to improve the Service, including by analysing usage patterns at an aggregated and anonymised level.

4.2 We do not use your personal data for advertising or marketing purposes. We do not sell your personal data to third parties. We do not use your personal data to train machine learning or artificial intelligence models.

4.3 We may send you communications about material changes to our Terms of Service, Privacy Policy, or the Service itself. These communications are necessary for the administration of the contractual relationship between you and Monesize and are not subject to opt-out, though you may terminate your Account if you do not wish to receive them.

5. Organization Data and End User Data

5.1 When an Organization uses the Service to store and process personal data about its contacts, prospects, customers, and leads ("End User Data"), Monesize processes that data as a Data Processor on behalf of the Organization, which acts as the Data Controller.

5.2 As a Data Processor, Monesize processes End User Data only on the documented instructions of the Organization and only to the extent necessary to provide the Service. We do not process End User Data for our own purposes.

5.3 The Organization is solely responsible for ensuring that it has a lawful basis for collecting and processing End User Data, that End Users have been provided with appropriate privacy notices, and that any outbound communications sent to End Users comply with applicable law.

5.4 If you are an End User whose personal data has been stored in Monesize Engage by an Organization, your rights in relation to that data should be directed to the Organization that holds your data. Monesize can assist Organizations in responding to data subject rights requests but does not act independently as a Data Controller for End User Data.

5.5 If you are an End User who has clicked an unsubscribe link in an email sent through the Service, your unsubscribe request is processed automatically. Your communication status is updated to Unsubscribed and you will not receive further campaign emails from that Organization through the Service. The unsubscribe mechanism does not require you to create an Account.

5.6 If you are an End User and you believe your personal data has been collected or used unlawfully by an Organization using the Service, you may contact Monesize at hello@monesize.com. While we are not the Data Controller for End User Data, we will make reasonable efforts to direct your enquiry appropriately.

6. Cookies and Tracking

6.1 The Service uses one session cookie: `engage_token`. This cookie is:

6.1.1 signed using a server-side secret and cannot be read or tampered with by client-side scripts;

6.1.2 marked as HTTP-only, which means it is not accessible to JavaScript running in your browser;

6.1.3 marked as Secure in production environments, meaning it is only transmitted over HTTPS connections;

6.1.4 set with a SameSite attribute of Strict, which provides protection against cross-site request forgery;

6.1.5 valid for a period of seven days from issuance, after which you will be required to sign in again.

6.2 We do not use analytics cookies, advertising cookies, social media tracking cookies, or any third-party cookies. We do not use Google Analytics, Meta Pixel, or similar third-party tracking technologies.

6.3 Campaign emails sent through the Service may include a tracking pixel (a one-by-one pixel image) and tracked links. These are used by the Organization sending the Campaign to measure email engagement. If you receive a Campaign email and do not wish to be tracked, you may disable automatic image loading in your email client. Clicking an unsubscribe link in any Campaign email will prevent you from receiving further campaigns from that Organization through the Service.

6.4 We note that open-tracking pixels embedded in emails are subject to limitations resulting from privacy protections in certain email clients, including Apple Mail. Open tracking data may not accurately reflect actual email opens for all recipients.

7. Data Storage and Security

7.1 Your personal data is stored on servers located within the European Economic Area and the United Kingdom. Monesize uses infrastructure provided by reputable cloud hosting providers operating within these jurisdictions.

7.2 We implement appropriate technical and organisational measures to protect personal data against unauthorized access, disclosure, alteration, and destruction, including but not limited to:

7.2.1 encryption of data in transit using TLS;

7.2.2 encryption of sensitive credentials at rest using AES-256-GCM authenticated encryption;

7.2.3 cryptographic hashing of passwords using bcrypt with a minimum work factor of 12;

7.2.4 signed HTTP-only session cookies;

7.2.5 rate limiting on authentication endpoints to mitigate brute force attacks;

7.2.6 an immutable audit log recording significant actions within each Organization;

7.2.7 immediate session invalidation mechanisms that prevent continued access upon removal from an Organization or upon logout;

7.2.8 input sanitization to prevent injection of malicious content.

7.3 Access to personal data within Monesize's systems is restricted to personnel who require access in order to perform their job functions. All such personnel are bound by confidentiality obligations.

7.4 Despite the measures we implement, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security and we encourage you to take appropriate steps to protect your own credentials.

7.5 In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

8. Data Retention

8.1 We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law.

8.2 Account data: we retain your Account data for as long as your Account remains active. If you delete your Account, we will retain your data for a period of 30 days to allow for Account recovery, after which it will be permanently deleted, subject to Section 8.5.

8.3 Organization data: we retain Organization Data for as long as the Organization exists on the Service. Upon deletion of an Organization, we will retain its data for a period of 30 days to allow for data export, after which it will be permanently deleted, subject to Section 8.5.

8.4 Audit logs: audit log records may be retained for a period of up to seven years to comply with our legal and regulatory obligations and to support legitimate security and fraud investigation purposes.

8.5 Legal retention obligations: certain data may be retained for longer periods where we are required to do so by applicable law, including but not limited to financial records, which may be retained for up to seven years in accordance with UK tax and accounting regulations.

8.6 Backups: personal data may persist in encrypted backup copies for a period of up to 30 days following deletion from the live system, after which it is permanently deleted from backup copies as well.

8.7 For End User Data that an Organization has chosen to erase using the Service's hard-erase function, the personally identifiable fields are immediately and permanently overwritten. The record shell (containing no personally identifiable information) is retained to preserve the integrity of historical data.

9. Sharing and Disclosure of Personal Data

9.1 Monesize does not sell, rent, or trade personal data to third parties.

9.2 We may share personal data with the following categories of recipients only to the extent necessary to provide the Service:

9.2.1 Infrastructure providers: cloud hosting providers used to operate the database, application servers, and job queue infrastructure. These providers process data on our behalf under contractual data processing agreements and do not have independent access to your data for their own purposes.

9.2.2 Email delivery providers: the system email infrastructure used to send transactional emails such as verification links, password reset emails, and account notifications. These providers process only the recipient email address and the content of the specific email being sent.

9.2.3 OAuth providers: Google and Microsoft receive identifying information from your browser as part of the OAuth authentication flow if you choose to use social login. Their handling of that data is governed by their own privacy policies.

9.2.4 Professional advisors: lawyers, accountants, and auditors who may require access to our records in connection with legal, financial, or regulatory matters, subject to confidentiality obligations.

9.2.5 Law enforcement and regulatory authorities: where we are required to disclose personal data by applicable law, court order, or lawful request from a competent authority, we will disclose the minimum information necessary to comply with the obligation. Where permitted by law, we will notify you of such a request before complying.

9.2.6 Successors: in connection with a merger, acquisition, restructuring, or sale of all or substantially all of Monesize's business or assets, personal data may be transferred to the acquiring entity, provided that the acquiring entity agrees to be bound by terms no less protective than this Privacy Policy.

9.3 We do not share your personal data with third parties for advertising, marketing, or analytics purposes.

10. International Data Transfers

10.1 Where personal data is transferred outside the United Kingdom or the European Economic Area, Monesize will ensure that appropriate safeguards are in place to protect the data in accordance with applicable data protection law.

10.2 Transfers to countries that have been deemed to provide an adequate level of protection by the UK Information Commissioner or the European Commission are permitted without additional safeguards.

10.3 Where transfers are made to countries that do not benefit from an adequacy decision, we rely on one or more of the following transfer mechanisms:

10.3.1 UK International Data Transfer Agreements or EU Standard Contractual Clauses, as applicable;

10.3.2 the UK-US Data Bridge or equivalent frameworks where applicable and available;

10.3.3 binding corporate rules or other approved transfer mechanisms where applicable.

10.4 You may request information about the specific transfer mechanisms we use for international data transfers by contacting us at hello@monesize.com.

11. Your Rights

11.1 Subject to applicable law, you have the following rights in relation to your personal data held by Monesize in its capacity as Data Controller:

11.1.1 Right of access: you have the right to request a copy of the personal data we hold about you and information about how we process it.

11.1.2 Right to rectification: you have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

11.1.3 Right to erasure: you have the right to request that we delete your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other lawful basis for processing.

11.1.4 Right to restriction of processing: you have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds.

11.1.5 Right to data portability: you have the right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible, where processing is based on consent or contract and is carried out by automated means.

11.1.6 Right to object: you have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis, and we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

11.1.7 Rights related to automated decision-making: you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you. Monesize does not make automated decisions of this nature about Users or Members.

11.2 To exercise any of these rights, please contact us at hello@monesize.com. We will respond to your request within one calendar month of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you within the first month.

11.3 We may ask you to verify your identity before processing a rights request to ensure that personal data is not disclosed to unauthorized persons.

11.4 We will not charge a fee for handling rights requests unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to process the request.

11.5 If you are dissatisfied with our response to a rights request, you have the right to lodge a complaint with the relevant supervisory authority.

12. Rights for California Residents

12.1 If you are a resident of California, you have additional rights under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), including:

12.1.1 the right to know what personal information we collect, use, disclose, and sell about you;

12.1.2 the right to delete personal information we have collected about you, subject to certain exceptions;

12.1.3 the right to correct inaccurate personal information we hold about you;

12.1.4 the right to opt out of the sale or sharing of your personal information. Monesize does not sell or share personal information as defined under the CCPA/CPRA;

12.1.5 the right to limit the use and disclosure of sensitive personal information. Monesize does not use sensitive personal information beyond the purposes permitted under the CCPA/CPRA without your consent;

12.1.6 the right to non-discrimination for exercising your privacy rights.

12.2 To exercise your rights under the CCPA/CPRA, please contact us at hello@monesize.com. We will respond within 45 days of receiving a verifiable consumer request. We may extend this period by a further 45 days where reasonably necessary, in which case we will notify you within the initial 45-day period.

12.3 You may designate an authorized agent to submit a request on your behalf. We may require the authorized agent to provide written proof of authorization and may require you to verify your identity directly with us.

12.4 The categories of personal information we collect, as defined under the CCPA/CPRA, are as follows: identifiers (name, email address, IP address); commercial information (organization details, subscription status); internet or other electronic network activity information (usage logs, session data); and professional or employment-related information (job title, organization role).

13. Children's Privacy

13.1 The Service is not directed at or intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16.

13.2 If we become aware that we have collected personal data from a child under 16 without appropriate parental or guardian consent, we will take steps to delete that information promptly.

13.3 If you believe that we may have inadvertently collected personal data from a child under 16, please contact us at hello@monesize.com.

14. Changes to This Privacy Policy

14.1 Monesize reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by email to the address associated with your Account at least 14 days before the changes take effect and will update the "Last updated" date at the top of this policy.

14.2 Where changes are required to comply with a legal obligation or to address a security issue, we may implement them immediately, in which case we will notify you as soon as reasonably practicable.

14.3 Your continued use of the Service after the revised Privacy Policy takes effect constitutes your acknowledgement of the changes. If you do not agree with the revised policy, you should stop using the Service and may delete your Account in accordance with our Terms of Service.

15. Supervisory Authorities

15.1 If you are located in the United Kingdom and you believe that we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's OfficeWycliffe HouseWater LaneWilmslowCheshireSK9 5AFUnited KingdomWebsite: ico.org.ukTelephone: 0303 123 1113

15.2 If you are located in the European Union, you have the right to lodge a complaint with the data protection supervisory authority in the EU member state in which you are habitually resident, in which you work, or in which an alleged infringement of data protection law has taken place.

15.3 If you are located in the United States, you may have rights to contact your state attorney general or relevant consumer protection authority, depending on the state in which you reside.

16. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us at:

Monesize Limited128 City RoadLondon, EnglandEC1V 2NXUnited Kingdom

Email: hello@monesize.com

For matters specifically related to data protection, please mark your correspondence for the attention of Data Protection.

We aim to respond to all privacy enquiries within five business days.