This policy explains how Vensali Studio (“we”, “us”) handles information
when you use our monday.com applications: Team Availability and
Worklog Timesheet.
1. Summary
In short:
We build apps that run inside monday.com — we do not sell personal data.
Application data is stored per monday.com account in monday Document DB (monday code).
We read monday.com data only within OAuth scopes you approve at installation.
User names are resolved live from monday.com and are not stored at rest.
When you uninstall an app, we delete that app’s data for your account within 24 hours.
Billing is handled by monday.com — we do not process payment cards directly.
2. Scope & who this applies to
This policy applies to:
Users of Team Availability and Worklog Timesheet on monday.com
Account administrators who install, configure, or manage these applications
Visitors to vensali.com (this site does not use tracking cookies or analytics pixels)
Each application is a separate monday.com marketplace listing with its own subscription.
Data for each app is stored and deleted independently per account.
3. Publisher information
Vensali Studio is an independent software studio publishing applications
for the monday.com platform.
Tenant isolation — Each monday.com account’s data is logically separated. We do not commingle customer data.
Hosting — Application backends run on monday code; databases use monday Document DB.
Authentication — Users access apps inside monday.com iframes using monday session tokens. Server-side API calls use verified session tokens and, where configured, stored OAuth tokens.
Exports — CSV, XLSX, and PDF exports are generated on demand for licensed accounts and are not stored separately after download.
Website — vensali.com is a static publisher site. We do not collect personal data through the website beyond what your browser sends to any web server (e.g. access logs held by our host).
6. How we use information
We use collected information solely to:
Operate application features (leave management, timesheets, calendars, reports)
Resolve user names and organizational context from monday.com
All application and account data flows through monday.com infrastructure per their terms
Payoneer
Payout processing for marketplace revenue via monday native monetization
Publisher payout details only — we do not receive or store your payment card data
Cloudflare
Static website hosting for vensali.com
Standard web server logs; no application data
8. Retention & deletion
Active use — Data is retained while the application remains installed on your monday.com account and is needed to provide the service.
Uninstall — When you uninstall an application, we delete that application’s stored data for your account from our database within 24 hours.
Subscription cache — License status cached from webhooks is deleted along with other tenant data on uninstall.
Support emails — Correspondence with help@vensali.com is retained as long as needed to resolve your request and for reasonable business records.
9. Security measures
HTTPS for all application and website traffic
monday session-token verification on API requests from application iframes
JWT verification on application event webhooks
OAuth state validation and account binding on token exchange
Per-account data isolation in monday Document DB
No secrets embedded in client-side application bundles
10. Your rights & choices
Depending on your jurisdiction, you may have rights to access, correct, or delete personal data we hold. Because most data lives in your monday.com account context:
Access & correction — Much data is visible and editable inside the applications (e.g. leave requests, worklogs, settings).
Deletion — Uninstalling the application triggers deletion of stored tenant data as described in Section 8.
OAuth permissions — Account administrators control app installation and OAuth scopes through monday.com.
Questions — Contact help@vensali.com for privacy requests. We respond within two business days.
11. Changes to this policy
We may update this policy when we add features, change OAuth scopes, or modify data handling.
The “Last updated” date at the top will change when we do. Material changes may also be
communicated via the application or to account administrators by email.