Privacy Policy
Effective Date: 27 Apr 2026
Last Updated: 05 May 2026
Introduction
Welcome to Space Monkey ("we", "us", "our"), a Mailchimp dashboard and analytics platform. We are committed to protecting your privacy and being transparent about our data practices. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use Space Monkey.
This Privacy Policy should be read in conjunction with our Terms of Service, which governs your use of Space Monkey.
As a Canadian company based in British Columbia, we comply with Canada's federal PIPEDA legislation. This Privacy Policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other applicable privacy laws. We are committed to protecting your personal data and respecting your privacy rights regardless of where you are located.
Note on Language: This Privacy Policy is provided in English, which is the authoritative version. Any translations provided are for convenience only, and in case of any discrepancy, the English version shall prevail.
Data Controller and Privacy Officer
For the purposes of the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR), and other applicable data protection laws, the Data Controller responsible for your personal data is:
Company Name: iGods Internet Marketing Inc.
Business Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4
Phone Number: 250-382-0221
Contact Email: privacy@igods.com
Under PIPEDA's accountability principle, our organization is responsible for personal information under its control and has designated an individual who is accountable for our compliance with privacy protection principles.
As we operate globally, we may be required to appoint a representative in the EU or UK. Any such appointments will be updated in this policy.
Chief Privacy Officer
We have appointed a Chief Privacy Officer who is responsible for PIPEDA compliance and oversight, ensuring robust data protection practices across all jurisdictions we operate in, and serving as your primary point of contact for all data protection inquiries and data subject rights requests:
Name: Cameron Knowlton
Title: Chief Privacy Officer & Compliance Officer
Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4
Phone Number: 250-382-0221
Contact Email: privacy@igods.com
If you have any questions about how we process your personal data, wish to exercise your data protection rights, or have concerns about our privacy practices, please contact our Chief Privacy Officer using the contact information provided above.
Information We Collect
When you use Space Monkey, we collect several types of information. Some information is required for us to provide our services, while other information is optional. Below we explain what data we collect, whether it's mandatory or voluntary, and the consequences of not providing required data.
Account Information
- Registration Data (Required): When you create an account, we collect your email address, display name, and require you to set a password (which we securely hash). We also require your full name, address, and phone number (collected during profile completion). This information is mandatory to create and maintain your account. Without it, you will not be able to register or access member features.
- Profile Information (Optional): Additional profile details such as company information or other professional details if you choose to provide them. This information is voluntary and does not affect your ability to use our service.
- Authentication Data: Session tokens and OAuth account connections (if you log in with third-party services like Floot OAuth for workspace authentication).
Integration Credentials
- Service Access Data (Required for Sync): Mailchimp API keys and GCP Service Account JSON keys. These are required for connecting the two platforms and are strongly encrypted at rest.
Sync Metadata & Process Data
- Configuration Data (Required): Project configurations, BigQuery dataset names, sync schedules, and sync run logs. Necessary to manage and monitor the automated sync execution.
Subscriber & Email Engagement Data
Space Monkey processes and extracts data from Mailchimp to push to BigQuery. This includes:
- Subscriber Data: Audience lists, member ratings, engagement scores, tags, and generalized location data.
- Email Engagement Data: Campaign opens, clicks, bounces per subscriber, send-time optimization records, and other performance metrics extracted from your Mailchimp account.
Payment and Billing Information
- Subscription Data (Required for Paid Plans): Information about your subscription tier, billing cycle, payment status, and subscription history.
- Billing Information (Required for Paid Plans): Billing address, payment method details (securely processed by Stripe), and transaction history.
- Payment Processing: Credit card and payment information is processed securely by Stripe. We do not store complete payment card information on our servers.
Usage and Technical Data
- App Telemetry: We track service health, error logs, and session information to maintain stability and diagnose issues.
- Security Data: IP addresses, request signatures, and rate limiting data to protect our infrastructure from abuse.
Administrative Data
- Audit Trails: Configuration changes (e.g., sync settings, integration updates) are recorded with the user ID and timestamp for security auditing.
Indirectly Collected Data
In addition to information you provide directly, we also collect data indirectly from the following sources:
- OAuth Providers: When you authenticate using Floot OAuth or other third-party authentication services, we receive basic profile information such as your name, email address, and profile picture.
- Payment Processors: Stripe provides us with payment confirmation data, subscription status updates, and billing event notifications necessary to manage your subscription.
- Email Service Providers: SendGrid provides us with email delivery status information (delivered, bounced, opened) for our transactional messages to you.
Purpose Specification (PIPEDA Principle 2)
Our Commitment
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Principle 2 (Identifying Purposes) requires that we identify the purposes for which personal information is collected at or before the time of collection. We are committed to transparency and will not use your information for any purpose other than those identified below, except with your explicit consent or as required by law.
Specific Purposes for Data Collection
We collect and use your information for the following specific purposes, organized by data type:
Account Registration Data
Includes your email address, name, and password.
- Purpose: To create and manage your user account.
- Purpose: To authenticate you securely when you log in.
- Purpose: To communicate important account-related information, such as security alerts or password resets.
- Purpose: To provide you with customer support and respond to your inquiries.
Integration Credentials & Sync Data
Includes Mailchimp API keys, BigQuery configurations, and run logs.
- Purpose: To establish secure connections and execute the automated data sync between Mailchimp and BigQuery.
- Purpose: To manage credentials securely and isolate your pipeline from other tenants.
- Purpose: To provide visibility into sync statuses, schedules, and troubleshooting.
Billing Information
Includes payment details, which are securely processed by our payment partner, Stripe.
- Purpose: To process subscription payments and manage your billing cycle.
- Purpose: To generate and manage your billing history and invoices.
- Purpose: To comply with financial record-keeping and tax obligations.
- Purpose: To prevent fraudulent transactions and financial abuse.
Platform Security & Technical Data
Includes app telemetry, error logs, and IP addresses.
- Purpose: To detect and prevent fraud, security threats, and unauthorized access.
- Purpose: To enforce rate limiting and maintain platform stability.
- Purpose: To improve user experience, troubleshoot technical issues, and ensure compatibility.
Communications
Includes support emails, feedback submissions, and other direct communications.
- Purpose: To respond to your inquiries, provide technical support, and resolve issues.
- Purpose: To improve our services and products based on your valuable feedback.
- Purpose: To maintain records of our communications for quality assurance and training purposes.
Changes to Purpose
If we wish to use your personal information for a new purpose not originally identified to you, we will notify you and seek your consent before using the information for that new purpose. You will always have the right to refuse consent for new purposes. We are committed to documenting and tracking all purposes for which we collect and use your data to ensure ongoing compliance.
Voluntary vs. Required Information
Some information is required for us to provide our core services (e.g., your email for account creation). This information is often marked with an asterisk (*) in our forms. Other information is voluntary and is used to help us improve your experience or provide additional features. You can choose not to provide voluntary information without affecting your ability to use the core functionality of our service.
How We Use Your Information
We use the collected information for the following purposes:
Service Provision
- Data Synchronization: Establishing secure connections to Mailchimp and BigQuery to extract and transfer your audience and engagement data.
- Analytics & Insights: Facilitating the calculation of engagement scores, identification of leader/at-risk subscribers, campaign analytics, send-time optimization insights, and subject line analysis by moving your data to BigQuery.
- Account Management: Creating and maintaining user accounts, managing authentication sessions, and providing personalized experiences.
- Usage Enforcement: Tracking API usage and sync frequency to enforce quota limits and maintain fair usage across the platform.
Payment and Subscription Management
- Payment Processing: Processing subscription payments, managing billing cycles, and handling payment method updates through our secure payment processor, Stripe.
- Subscription Administration: Managing subscription tiers, usage limits, feature access, and billing notifications.
- Billing Support: Providing customer support for billing inquiries, subscription changes, and payment issues.
Service Improvement
- Algorithm Enhancement: Analyzing pipeline execution patterns to optimize sync algorithms, improve reliability, and minimize data transfer latency.
- Subscription Optimization: Analyzing feature utilization and volume metrics to improve our service offerings, scaling capacity, and pricing models.
Communication
- Transactional Emails: Sending essential account-related emails through SendGrid, including email verification, password resets, security notifications, sync failure alerts, and billing notices.
- Service Updates: Notifying users about significant changes to our service, API deprecations, or platform maintenance (with opt-out options for non-essential communications).
- Subscription Communications: Sending billing reminders, subscription renewal notices, and payment-related notifications.
Legal Basis for Processing
We process your personal data lawfully, fairly, and transparently. Under the GDPR (Article 6), we rely on the following legal bases for processing your data:
- Performance of a Contract (Article 6(1)(b) GDPR): We process your data when it is necessary to fulfill our contractual obligations to you, or to take steps at your request before entering into a contract. This includes:
- Account creation, authentication, and management.
- Processing payments for subscription services.
- Delivering our core service, which involves providing a comprehensive Mailchimp dashboard, synchronizing data to BigQuery, and managing your API credentials securely.
- Legitimate Interests (Article 6(1)(f) GDPR): We process data for our legitimate interests, provided these interests are not overridden by your rights and freedoms. This includes:
- Platform security and monitoring to prevent fraud or abuse.
- Debugging synchronization issues to ensure service reliability.
- Analyzing usage data to improve our service and develop new features.
- Consent (Article 6(1)(a) GDPR): We will ask for your explicit consent before processing your data for specific purposes, such as:
- Sending you marketing communications and newsletters.
- Using non-essential cookies for optional analytics.
- Legal Obligation (Article 6(1)(c) GDPR): We may process your data where it is necessary to comply with a legal or statutory obligation, such as:
- Maintaining financial and billing records for tax purposes.
- Responding to lawful requests from public authorities.
- Complying with regulatory requirements.
Third-Party Services and Data Sharing
We share limited data with the following third parties to provide and improve our services. All third-party integrations are governed by strict data processing agreements that require them to protect your information and use it only for the specified purposes.
Core Synchronization Integrations
- Intuit Mailchimp: To facilitate the synchronization of your data, Space Monkey requires API read access to your Mailchimp subscriber data. We only fetch the data necessary to perform the sync into your BigQuery dataset. This data is handled in memory and is not persisted on our servers.
- Google BigQuery: We require API write access to your specific, customer-owned Google BigQuery dataset. Space Monkey acts as a conduit to push your Mailchimp data directly into your BigQuery environment. Data is processed within Google Cloud infrastructure.
Payment Processing
- Stripe: We use Stripe as our payment processor for subscription billing and payment management. Stripe processes and stores payment card information, billing addresses, and transaction data according to their privacy policy and PCI DSS standards. We share necessary billing information with Stripe to process payments and manage subscriptions.Data Protection: Stripe maintains adequate data protection measures and is certified under various compliance frameworks including PCI DSS Level 1, SOC 1 and SOC 2, and has implemented Standard Contractual Clauses for international data transfers. Stripe processes payment data in the United States and European Union, with appropriate safeguards in place for international transfers.
Email Services
- SendGrid: We use SendGrid to deliver transactional emails including account verification, password resets, billing notifications, and privacy policy updates. SendGrid processes email addresses and message content according to their privacy policy.
Sub-Processors and Service Providers
Our third-party processors listed above may engage their own sub-processors to help deliver their services. We require our processors to maintain appropriate data protection safeguards with their sub-processors in accordance with GDPR Article 28 and other applicable laws.
You can review the current sub-processors for our major service providers at the following links:
- Stripe Sub-Processors
- Google Cloud Sub-Processors (for BigQuery)
- Intuit Mailchimp Privacy Statement
- Twilio SendGrid Sub-Processors
Your Rights Regarding Third-Party Processing
You maintain all your data protection rights even when your data is processed by third parties on our behalf. You can request information, object to processing, or request deletion by contacting us at privacy@spacemonkey.com.
We do not sell your personal data or share it with third parties for their own marketing purposes. All third-party data sharing is strictly limited to providing and improving our services.
International Data Transfers
To provide our services, your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.
Specifically, our infrastructure and third-party service providers operate across different regions. The primary locations for data transfer and processing include:
- United States: Intuit Mailchimp, Stripe, and SendGrid infrastructure. Note: The United States does not have an EU adequacy decision. We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards for transfers to the US.
- User-Configured Regions (Google Cloud): Data synced to Google BigQuery is processed and stored in the Google Cloud region that you have configured for your dataset. This gives you control over the data residency of your synced destination data.
Our Safeguards
We have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Policy. These include:
- Implementing Standard Contractual Clauses (SCCs) as the primary safeguard for transfers to the United States.
- Utilizing robust security measures, including encryption in transit (TLS/SSL) and at rest (AES-256), to protect your data across borders.
- Empowering you to configure your destination dataset regions (e.g., within the EU via Google BigQuery) to minimize unnecessary transfers.
For detailed information about specific third-party processors, please see the Third-Party Services and Data Sharing section.
Your Rights
You have the right to request information about the international data transfers we conduct. If you have any questions or wish to exercise your rights, please contact us through our Support page.
Data Storage and Security
We implement robust, industry-standard security measures to protect your data and credentials:
- Encryption of Credentials: All API credentials, including Mailchimp API keys and Google Cloud Service Account JSON keys, are encrypted at rest using AES-256 encryption. They are strictly protected and never stored in plain text.
- Data in Transit: All data transmitted between your browser, our servers, Mailchimp, and BigQuery is secured using HTTPS/TLS encryption to prevent interception or tampering.
- In-Memory Processing: During a sync operation, the payload data extracted from Mailchimp is held entirely in memory on our servers. It is strictly used to facilitate the transfer and is never persisted or written to our own databases.
- Direct to Destination: The synced data is written directly to your own configured Google BigQuery dataset. You maintain complete ownership and control over your destination data at all times.
- Session Security: We use secure session tokens for authentication, which include automatic expiration mechanisms to protect inactive accounts.
- Access Controls: Access to infrastructure and encrypted credentials is mathematically restricted and strictly governed. Only authorized automated systems and key personnel have access on a need-to-know basis.
Breach Notification
We are committed to protecting the personal information and credentials under our control. In the event of a data breach, we will adhere to the requirements set out by applicable privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
Notification Requirements
We are required to notify relevant regulatory bodies of any breach of security safeguards involving personal information that poses a "real risk of significant harm" to individuals. We must also notify affected individuals if we believe the breach creates such a risk.
Our Commitment
Space Monkey maintains comprehensive security measures to prevent data breaches and has incident response procedures in place to address them promptly if they occur. Should we determine that a breach creates a real risk of significant harm, we will notify affected individuals as soon as feasible.
Our notifications will be clear and will include:
- A description of the breach and the personal information or credentials involved.
- The date or estimated date of the breach.
- The steps we have taken to reduce the risk of harm.
- The steps individuals can take to reduce their own risk of harm (such as rotating API keys).
- Contact information for our Privacy Officer for further inquiries.
How We Will Notify You
In the event of a notifiable breach, we will take the following steps to inform you:
- Direct Notification: We will send a notification directly to the email address registered with your account.
- Indirect Notification: We will post a prominent notice on our website and within your account dashboard.
Reporting a Suspected Breach
If you believe your account, credentials, or personal information has been compromised or you suspect a security vulnerability, please contact us immediately. We take all reports seriously and will investigate promptly.
Contact: Privacy Officer
Email: privacy@spacemonkey.com
Data Retention
We retain personal information and operational data only as long as necessary for the purposes for which it was collected or as required by law. Each type of data we collect serves a specific purpose, and we retain it only for as long as needed to fulfill that purpose.
Retention Periods and Purposes
We retain different types of data for varying periods based on their specific purpose and legal requirements:
- Account Information: Retained while your account is active to provide you with our services and maintain your account settings. When you request account deletion, your account data is securely and permanently deleted within 30 days.
- API Credentials: Your encrypted Mailchimp API keys and Google Cloud Service Account JSON keys are retained only as long as your integration is active. They are permanently and securely deleted from our systems immediately upon integration removal or account deletion.
- Synced Payload Data: The actual Mailchimp data being synced is processed in-memory and never retained on our servers. The final destination of this data is your own Google BigQuery dataset, where it is subject entirely to your own retention policies and control.
- Sync Run Logs: Operational metadata, error logs, and metrics about your sync runs (excluding the actual payload data) are retained for 90 days. This helps us provide you with historical sync tracking, debugging capabilities, and service support.
- Billing and Subscription Data: Payment records, invoices, and subscription history are retained for 7 years after subscription termination to comply with tax and accounting regulations, process refunds and chargebacks, and meet audit requirements.
- Security Data: Essential session tokens and related security identifiers automatically expire and are cleared according to standard security practices (e.g., upon logout or session timeout).
Secure Destruction
When information is no longer needed for its identified purposes and is not required to be retained for legal or business purposes, we securely destroy, erase, or anonymize it. Our secure destruction procedures include permanent deletion from active databases and removal from backup systems within standard backup retention cycles.
Sensitive Data and Subscriber PII
As a data synchronization platform, Space Monkey processes subscriber Personally Identifiable Information (PII) such as email addresses, location data, and engagement behavior on behalf of our customers. We act strictly as a Data Processor in this context. Space Monkey does not use your subscribers' data for its own purposes, marketing, or profiling.
Data Flowing Through Syncs
Depending on the specific integrations you configure, the following types of data may flow through our systems:
- Contact information (e.g., email addresses, phone numbers)
- Location data (e.g., IP-based geolocation, addresses)
- Engagement behavior (e.g., email opens, clicks, purchase history)
- Custom attributes defined in your source systems
Enhanced Consent for Sensitive Data
To assist you in complying with various state and international privacy laws (such as GDPR, CCPA, and others), Space Monkey provides enhanced consent management features. While you as the Data Controller are responsible for obtaining consent, our systems can securely pass and respect consent flags:
- Consent Status Routing: We can map and sync consent statuses (granted, withdrawn) across your integrated platforms.
- Data Filtering: You can configure syncs to exclude certain sensitive data categories or individuals who have not provided explicit consent.
- Auditability: We log the metadata of consent changes as they flow through our system (timestamps, source of truth) without storing the underlying sensitive data longer than necessary for the sync.
Purpose and Legal Basis
- Purpose: To execute the data synchronization services you have configured between your chosen platforms and to ensure compliance with privacy laws regarding sensitive personal data.
- Legal Basis: Space Monkey processes this data based on the Data Processing Agreement (DPA) and Terms of Service established with you. The legal basis for the original collection and processing relies on your relationship with your subscribers (e.g., Consent or Legitimate Interest).
Data Retention during Sync
Space Monkey is designed for secure, transient data transfer. Subscriber data flowing through our syncs is retained in our temporary processing queues only as long as necessary to complete the transfer (typically seconds or minutes) and up to a maximum of 7 days in the event of sync failures to allow for retry mechanisms. We do not maintain long-term persistent storage of your subscribers' PII.
Service Feedback and Cancellation Information
To help us improve Space Monkey and better understand our users' needs, we may ask for your feedback through satisfaction surveys or if you choose to cancel your subscription. Providing this feedback is entirely voluntary.
Information We Collect
When you respond to a survey or cancel a subscription, we may collect the following information:
- Cancellation Reason: Your selection from a list of predefined reasons for canceling your Space Monkey service.
- Free-Text Comments: Optional, detailed feedback you choose to provide about your experience with our integrations or platform.
- Associated Account Data: Your email, display name, workspace details, and the subscription tier you were on at the time of feedback.
- Timestamp: The date and time of your feedback submission.
Purpose and Legal Basis
- Purpose: We use this information for churn analysis, to identify areas for service improvement, to prioritize new integrations, and to understand what features and pricing our users value most.
- Legal Basis: We process this data based on our Legitimate Interest in improving the quality and usability of our synchronization platform.
Data Retention and Your Rights
- Retention: Feedback data is retained for a period of two (2) years after collection to allow for long-term trend analysis.
- Your Rights: Since providing feedback is optional, you are in full control. You have the right to request the deletion of your feedback at any time by contacting our privacy team.
Security Monitoring and Audit Logging
To protect your data, prevent unauthorized access, and ensure the integrity of the Space Monkey platform, we maintain a comprehensive security monitoring and audit logging system. Access to these logs is strictly limited to authorized security and administrative personnel.
General Security Logs
We log key security-related events across the application, including:
- Login Attempt Monitoring: Successful and failed login attempts, multi-factor authentication events, and password reset requests.
- Admin Configuration Changes: Modifications to workspace settings, billing information, and user role assignments.
- Associated Data: The user ID, IP address, and browser user agent associated with the event.
- Retention: General security logs are retained for 90 days.
Credential Access Logging
Given our role in connecting external systems, we heavily monitor API keys and integration credentials:
- Event Details: Creation, rotation, deletion, and usage patterns of API keys and OAuth tokens used for your integrations.
- Security Data: Internal service identities or IP addresses accessing these credentials, ensuring they are only used for authorized sync operations.
- Retention: Credential access logs are retained for one (1) year.
Sync Operation Audit Trails
To ensure reliability and transparency of your data flows, we log metadata about synchronization jobs:
- Operational Metrics: Sync start/end times, success/failure statuses, error codes, and the volume of records processed.
- Privacy Note: These audit trails do not contain the underlying PII or sensitive data payload being synced, only the operational metadata.
- Retention: Sync operation logs are retained for 30 days for debugging purposes.
Security Audit Log for Privacy Actions
We maintain records of privacy-related actions taken within the system:
- Event Details: Data Subject Requests (DSRs) submitted, changes to data processing agreements, and exports of workspace data.
- Retention: Privacy action logs are retained for six (6) years to comply with regulatory obligations.
Breach Response Logs
In the event of a security incident, we maintain detailed records to manage our response effectively:
- Incident Details: The nature of the incident, severity assessment, estimated number of affected workspaces, and root cause analysis.
- Remediation Actions: Steps taken to contain and resolve the incident, and notifications sent to affected users.
- Retention: Breach incident logs are retained for six (6) years.
Purpose and Legal Basis
We process this data for security monitoring, fraud prevention, incident response, and to maintain the stability of our sync services. Our legal bases for this processing are our Legitimate Interest in securing our platform and your integrations, and our Legal Obligation to report data breaches where required by law.
Privacy Program Administration
To effectively manage Space Monkey's privacy program and demonstrate compliance with regulations like GDPR and CCPA, we utilize a suite of internal administrative tools. These tools are essential for upholding our commitment to your privacy and are accessible only to authorized privacy and compliance personnel. All administrator actions within these tools are logged with a user ID and timestamp.
Our Internal Privacy Tools
- Privacy Impact Assessments (PIAs): We maintain records of privacy reviews conducted for new features or significant changes. These records include assessment details, risk evaluations, and reviewer information to ensure privacy-by-design.
- Transfer Impact Assessments (TIAs): For international data transfers, we document the legal safeguards, destination countries, and risk assessments to ensure your data remains protected across borders.
- Data Processor Registry: We keep a detailed registry of all third-party data processors, including their contact information, processing activities, Data Processing Agreement (DPA) details, and compliance status.
- DSR Administration Dashboard: This tool allows us to efficiently track, assign, and manage your Data Subject Requests (e.g., for access or deletion), ensuring we respond to you in a timely manner.
- Privacy Preferences Center Backend: This system powers the user-facing preferences center, storing your specific privacy choices, consent history, and state-specific opt-outs, enabling us to honor your selections automatically.
- Policy Update Notification Tracking: We track which users have been successfully notified of material changes to our privacy policies. This includes recording delivery confirmations and timestamps to demonstrate our compliance with transparency obligations and legal requirements for user notification.
Purpose and Legal Basis
The purpose of these tools is to manage our privacy program, demonstrate compliance, and support regulatory audits. We process this administrative data based on our Legal Obligation to be accountable for our data protection practices under GDPR and other privacy laws.
Data Retention and User Impact
- Retention: Records from these administrative tools are typically retained for 6-7 years to meet compliance and audit requirements.
- User Impact: These internal tools are what enable us to honor your privacy rights effectively and transparently. The data you control, such as your preferences, remains directly manageable by you through your account settings.
Your Rights and Choices
Under PIPEDA, GDPR, and other applicable privacy laws, you have several rights regarding your personal data. These rights are designed to give you control over how your information is collected, used, and shared.
No Cost for Reasonable Requests: We provide access to your personal information and process reasonable rights requests at no cost to you, in accordance with PIPEDA requirements.
- Right to Know Purposes: Under PIPEDA, you have the right to know the purposes for which your personal information is being collected BEFORE or at the time of collection. We clearly state our purposes in this Privacy Policy and in our data collection forms.
- Right to Access: You can view your account information, subscription details, usage statistics, and sync history through your profile and settings pages. You may also request a complete copy of all personal data we hold about you.
- Right to Challenge Accuracy (PIPEDA Principle 10): You have the right to challenge the accuracy and completeness of your personal information and have it corrected as appropriate. You can update your profile information, billing details, and preferences at any time through your account settings. If you believe any information we hold is inaccurate or incomplete, you have the right to have it corrected, and we will amend the information as required.
- Right to Rectification (Correction): You can update your profile information, billing details, and preferences at any time through your account settings. If you believe any information we hold is inaccurate or incomplete, you have the right to have it corrected.
- Right to Erasure (Deletion): You can request account deletion, which will remove your personal information from our systems. Note that some billing and transaction data may be retained for legal and accounting requirements (typically 7 years for tax purposes).
- Right to Data Portability (Data Export): You can request a complete export of your personal data in machine-readable formats. Data exports are available in multiple formats including CSV (for structured data like usage history), JSON (for technical integrations), or PDF (for human-readable reports). Data exports include account information, project configurations, sync history, usage statistics, and preferences. This right allows you to receive your data and transmit it to another service provider where technically feasible.
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in specific circumstances, such as when you contest the accuracy of the data, when the processing is unlawful but you prefer restriction over deletion, when we no longer need the data but you need it for legal claims, or while we verify your objection to processing based on legitimate interests.
- Right to Object: You have the right to object to processing of your personal data based on our legitimate interests or for direct marketing purposes. This includes:
- Objecting to data processing for direct marketing (including profiling related to marketing)
- Objecting to processing based on legitimate interests (we will cease processing unless we can demonstrate compelling legitimate grounds that override your rights)
- Objecting to automated decision-making and profiling that produces legal effects or similarly significantly affects you
- Data Management: You can manage your sync history storage preferences, delete individual project records, and control data retention settings through your account preferences.
- Subscription Control: You can modify, cancel, or upgrade your subscription at any time through your account settings.
- Opt-out of Analytics: You can opt out of non-essential analytics tracking through your cookie consent preferences or browser settings.
- Withdrawal of Consent: Where we process your data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: If you believe we have not handled your personal data properly, you have the right to:
- Lodge a complaint with the Privacy Commissioner of Canada (for PIPEDA-related concerns)
- Lodge a complaint with your local data protection supervisory authority (for GDPR-related concerns)
- Contact the appropriate regulatory body in your jurisdiction
How to Exercise Your Rights
You can exercise any of these rights by submitting a Data Subject Request through our secure online form, or by contacting us at privacy@igods.com.
Response Timeframe: We will respond to your request within one (1) month of receipt, in accordance with both PIPEDA (30-day standard) and GDPR requirements. In complex cases or if we receive multiple requests from you, we may extend this period by up to two (2) additional months (for a total of three months). If we need to extend the timeframe, we will inform you within the first month and explain the reason for the delay.
We will not charge a fee for processing reasonable requests. However, if your request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or refuse to act on the request.
US State Privacy Rights
Effective Date: August 1, 2024
Residents of certain U.S. states, including California, Colorado, and Connecticut, have additional rights regarding their personal information. This section describes those rights and explains how you can exercise them. To manage your preferences or submit a data request, please visit our Privacy Preferences Center or our Data Subject Rights page.
California Privacy Rights (CCPA/CPRA)
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information.
We collect the following categories of personal information for Space Monkey:
- Account Information: Profile details and contact information.
- Integration Credentials: Access tokens and keys for third-party platforms.
- Sync Metadata: Data regarding your synchronization processes.
- Subscriber Data: Processed strictly on behalf of the customer. Note that your subscriber data resides in your own BigQuery dataset.
- Usage Data: Analytics and system interactions.
Colorado Privacy Rights (CPA)
Under the Colorado Privacy Act (CPA), Colorado residents have the right to access, correct, delete, and opt-out of certain processing of their personal data. Space Monkey facilitates these rights through our privacy settings.
Connecticut Privacy Rights (CTDPA)
Under the Connecticut Data Privacy Act (CTDPA), Connecticut residents are afforded rights concerning their personal data, including the right to access, correct, and delete data, which you can manage within Space Monkey.
Right to Data Portability
Under Article 20 of the GDPR, you have the right to data portability. This allows you to obtain and reuse your personal data for your own purposes across different services.
This right applies to personal data you have provided to us, where the processing is based on your consent or on a contract, and the processing is carried out by automated means.
Upon request, we will provide you with your data in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another data controller without hindrance from us. The data included in an export is:
- Account Information: Your profile details, such as name and email address.
- Project Configurations & Sync History: Records of the syncs and projects you have set up in Space Monkey.
- Usage Statistics: Information about your service usage and credits.
- Preferences: Your saved user settings.
Note: Your subscriber data is already maintained securely in your own BigQuery dataset, so it does not need to be exported from Space Monkey directly.
You can exercise this right by submitting a request through your account settings or by contacting us directly at privacy@igods.com. We offer data exports in the following formats:
- JSON: For technical integrations and complete data representation.
- CSV: For structured data like usage history, suitable for spreadsheets.
- PDF: For human-readable reports of your account information and sync history.
Where technically feasible, you also have the right to request that your personal data be transmitted directly from us to another data controller (GDPR Article 20(2)). However, as there are currently no comparable services that support standardized data imports, direct transfer is not available at this time. The portable export formats we provide (JSON, CSV) enable you to manually transfer your data to other services of your choice.
Withdrawing Consent
Where we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of any processing we conducted prior to your withdrawal.
We have made it as easy to withdraw consent as it is to give it. You can withdraw your consent in the following ways:
- Cookie Consent: You can change your cookie preferences at any time through Space Monkey's cookie consent management tool, accessible via the "Cookie Policy" page or a persistent link in the website footer.
- Marketing Communications: You can opt-out of receiving marketing emails by clicking the "unsubscribe" link provided in every email we send.
- Account-Based Consent: For any consent given through your account settings, you can withdraw it by adjusting your preferences in your account dashboard or by deleting your account.
If you have difficulty withdrawing your consent through these methods, please contact us at privacy@igods.com for assistance. We will process your request within a reasonable timeframe.
Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
Space Monkey uses algorithms to perform engagement scoring, leader and at-risk subscriber classification, and Otsu threshold computation for test/production campaign classification. This automated processing is integral to the functionality of Space Monkey and is used to generate insights. However, this does not constitute automated decision-making as defined under Article 22 of the GDPR, as it does not result in legal or other significant consequences for you. The output is for informational and analytical purposes to assist your own decision-making.
Children's Privacy
Space Monkey is a service designed for professionals and businesses. It is not directed to, nor do we knowingly collect personal information from, children. You must be at least 16 years of age (or the age of digital consent in your country) to use our services. In the United States, this corresponds to the Children's Online Privacy Protection Act (COPPA), which applies to children under 13.
If we become aware that we have inadvertently collected personal data from a child without verification of parental consent, we will take steps to delete that information from our servers as quickly as possible.
If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at privacy@igods.com so that we can take necessary action.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in Space Monkey's practices or legal requirements. We will notify you of significant changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to registered users for material changes
- Providing notice through our website or service interface
Your continued use of Space Monkey after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy, want to exercise your data rights, or have privacy concerns, please contact us:
Chief Privacy Officer
Name: Cameron Knowlton
Title: Chief Privacy Officer & Compliance Officer
Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4
Phone: 250-382-0221
Email: privacy@igods.com
General Contact Methods
- Through the official Space Monkey website
- By email at privacy@igods.com
- Via our support channels listed on our website
Response Timeframe: In accordance with PIPEDA requirements, we will respond to your inquiries within 30 days and work to address any concerns you may have. In complex cases, we may extend this period with notice and explanation.