Gravitate Software Incorporated operates Monopaly. This policy explains how we handle information on monopaly.com, in the Monopaly application and when you communicate with us.
1. Who handles your information
We are a corporation incorporated in Delaware, United States. For information we collect to manage our own business, such as account administration, inquiries and service analytics, we determine the purposes of processing.
When a business uses Monopaly to manage its leads, contacts, calls and messages, that business generally determines why its contact data is processed. We process that data to provide the service under the customer’s instructions and applicable agreement. If a Monopaly customer contacted you, direct requests about that customer’s use of your information to that business. We can help route a request where appropriate.
2. Information we collect
- Account and business information: names, email addresses, authentication information, workspace details, roles, invitations and information you provide about your business.
- Customer content: lead and contact details, phone numbers, email addresses, addresses, notes, messages and attachments, uploaded files, campaign materials, follow-up instructions and outcomes.
- Calling information: participants and phone numbers, call times, duration, status, disposition and related activity. Depending on enabled features, we process call audio, recordings, transcripts and derived conversation statistics.
- Connected-service information: data you authorize integrations to provide, such as Facebook lead submissions, connected account identifiers and authentication tokens, and data received through webhooks.
- Technical and usage information: IP addresses, browser/device information, identifiers, page visits, interactions, errors, diagnostic logs and service activity. App analytics may associate activity with your account and workspace.
- Communications and transaction information: inquiries, support correspondence and records needed to administer your service arrangement and payments.
Information may come from you, your workspace administrator or colleagues, connected services, customer imports and automatic service operation. Business-profile and property features may also use website content, address searches and other publicly available information.
3. How we use information
We use information to provide and operate Monopaly: authenticate users, maintain workspaces, route calls and messages, organize contacts and follow-up, deliver integrations, generate requested outputs, and provide reports. We also use information to support customers, communicate about the service, administer agreements, investigate errors, improve usability, detect abuse and protect the service.
Where a legal basis is required, we rely on performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required. For customer-controlled data, the customer is responsible for its legal basis and instructions. Where processing relies on consent, you may withdraw it without affecting prior lawful processing.
4. Analytics, recordings and AI features
We use PostHog for application analytics and error diagnostics. It can collect page activity and interactions and associate them with an account name, email address and workspace. Session replay and console diagnostics may be enabled to help understand and resolve problems. Input masking is configured for replay, but information displayed elsewhere on a page may still be included.
Application analytics can begin when you visit an app page, including before login. The marketing landing page does not itself run this analytics script. See the Cookie Policy for the storage involved and available browser controls.
When transcription or AI features are enabled, the relevant service providers may receive call audio, business context, prompts, website content or property-location information needed for that feature. For example, transcription requires processing the original audio; redacting a resulting transcript does not mean the original audio was never processed. See our provider list for these services.
5. When information is shared
- Service providers: infrastructure, authentication, analytics, database, communications, transcription and other feature providers process information needed for their services. Our Subprocessors page describes them, including AWS and DigitalOcean hosting.
- Your organization: workspace administrators and authorized colleagues can access information according to their roles and the way your organization uses Monopaly.
- Connected destinations: information may be sent to a carrier, Meta account, webhook endpoint or other service selected or authorized by your organization.
- Legal and security purposes: we may disclose information when required by law or valid legal process, or where reasonably necessary to investigate abuse, protect rights and safety, or enforce an agreement.
- Business changes: information may be transferred as part of a merger, acquisition, financing, reorganization or sale of assets, subject to applicable confidentiality and data-protection obligations.
Sharing described here is for operating the service, carrying out customer instructions and the other purposes identified in this policy. Third-party services you connect separately are subject to their own privacy practices.
6. Retention and security
We retain information for the purposes described in this policy, including providing the service, maintaining account and business records, resolving disputes, preventing abuse and meeting legal obligations. Retention depends on the type of information, account status, customer instructions and the applicable agreement. Browser-storage lifetimes are described separately in the Cookie Policy.
Deletion and return of customer content are governed by the applicable customer agreement and DPA, if any. Backup copies and records subject to legal retention requirements may be retained as permitted by those agreements and law. Contact us or your workspace administrator to request deletion rather than assuming that closing a browser or removing a cookie deletes server-side data.
We use technical and organizational measures intended to protect information, including access controls and encrypted connections. No transmission or storage system can be guaranteed completely secure. Keep your credentials private and contact us promptly about suspected unauthorized access.
7. International processing
We operate from the United States and use service providers that may process information in the United States and other countries. Those countries may have different privacy laws from your own. Where applicable law requires safeguards for an international transfer, the applicable agreement or DPA must address those safeguards. A vendor’s headquarters or an API hostname does not by itself specify every processing location.
8. Your rights and choices
Depending on your location and applicable law, you may have rights to access, correct, delete or obtain a copy of personal information; restrict or object to processing; withdraw consent; or appeal a decision on a request. You may also have the right to complain to your local data-protection authority. These rights can be subject to exceptions, and we may need to verify your identity and authority before acting.
Email thomas@gravitateinc.com to make a request or appeal. We will respond in accordance with applicable law. Where a customer controls the information, we may refer the request to that customer or assist them under our agreement. We will not discriminate against you for exercising applicable privacy rights.
You can manage browser cookies and storage through your browser settings. Removing necessary storage may sign you out or disrupt calls, drafts and preferences. If we send promotional email, use its unsubscribe instructions or contact us; necessary account and service messages may continue.
9. Children
Monopaly is a business service and is not directed to children under 18. We do not knowingly collect personal information directly from children under 18 for their own use of the service. If you believe a child has provided information in that context, contact us so we can investigate and take appropriate action.
10. Changes and contact
We may update this policy as the service or our practices change. The date at the top identifies the current version. We will provide additional notice of material changes where required by applicable law.
For privacy questions and requests, contact Gravitate Software Incorporated at thomas@gravitateinc.com.