Privacy Policy

Effective Date: 27 Apr 2026

Last Updated: 05 May 2026

Introduction

Welcome to Space Monkey ("we", "us", "our"), a Mailchimp dashboard and analytics platform. We are committed to protecting your privacy and being transparent about our data practices. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use Space Monkey.

This Privacy Policy should be read in conjunction with our Terms of Service, which governs your use of Space Monkey.

As a Canadian company based in British Columbia, we comply with Canada's federal PIPEDA legislation. This Privacy Policy complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other applicable privacy laws. We are committed to protecting your personal data and respecting your privacy rights regardless of where you are located.

Note on Language: This Privacy Policy is provided in English, which is the authoritative version. Any translations provided are for convenience only, and in case of any discrepancy, the English version shall prevail.

Data Controller and Privacy Officer

For the purposes of the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR), and other applicable data protection laws, the Data Controller responsible for your personal data is:

Company Name: iGods Internet Marketing Inc.

Business Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4

Phone Number: 250-382-0221

Contact Email: privacy@igods.com

Under PIPEDA's accountability principle, our organization is responsible for personal information under its control and has designated an individual who is accountable for our compliance with privacy protection principles.

As we operate globally, we may be required to appoint a representative in the EU or UK. Any such appointments will be updated in this policy.

Chief Privacy Officer

We have appointed a Chief Privacy Officer who is responsible for PIPEDA compliance and oversight, ensuring robust data protection practices across all jurisdictions we operate in, and serving as your primary point of contact for all data protection inquiries and data subject rights requests:

Name: Cameron Knowlton

Title: Chief Privacy Officer & Compliance Officer

Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4

Phone Number: 250-382-0221

Contact Email: privacy@igods.com

If you have any questions about how we process your personal data, wish to exercise your data protection rights, or have concerns about our privacy practices, please contact our Chief Privacy Officer using the contact information provided above.

Information We Collect

When you use Space Monkey, we collect several types of information. Some information is required for us to provide our services, while other information is optional. Below we explain what data we collect, whether it's mandatory or voluntary, and the consequences of not providing required data.

Account Information

  • Registration Data (Required): When you create an account, we collect your email address, display name, and require you to set a password (which we securely hash). We also require your full name, address, and phone number (collected during profile completion). This information is mandatory to create and maintain your account. Without it, you will not be able to register or access member features.
  • Profile Information (Optional): Additional profile details such as company information or other professional details if you choose to provide them. This information is voluntary and does not affect your ability to use our service.
  • Authentication Data: Session tokens and OAuth account connections (if you log in with third-party services like Floot OAuth for workspace authentication).

Integration Credentials

  • Service Access Data (Required for Sync): Mailchimp API keys and GCP Service Account JSON keys. These are required for connecting the two platforms and are strongly encrypted at rest.

Sync Metadata & Process Data

  • Configuration Data (Required): Project configurations, BigQuery dataset names, sync schedules, and sync run logs. Necessary to manage and monitor the automated sync execution.

Subscriber & Email Engagement Data

Space Monkey processes and extracts data from Mailchimp to push to BigQuery. This includes:

  • Subscriber Data: Audience lists, member ratings, engagement scores, tags, and generalized location data.
  • Email Engagement Data: Campaign opens, clicks, bounces per subscriber, send-time optimization records, and other performance metrics extracted from your Mailchimp account.

Payment and Billing Information

  • Subscription Data (Required for Paid Plans): Information about your subscription tier, billing cycle, payment status, and subscription history.
  • Billing Information (Required for Paid Plans): Billing address, payment method details (securely processed by Stripe), and transaction history.
  • Payment Processing: Credit card and payment information is processed securely by Stripe. We do not store complete payment card information on our servers.

Usage and Technical Data

  • App Telemetry: We track service health, error logs, and session information to maintain stability and diagnose issues.
  • Security Data: IP addresses, request signatures, and rate limiting data to protect our infrastructure from abuse.

Administrative Data

  • Audit Trails: Configuration changes (e.g., sync settings, integration updates) are recorded with the user ID and timestamp for security auditing.

Indirectly Collected Data

In addition to information you provide directly, we also collect data indirectly from the following sources:

  • OAuth Providers: When you authenticate using Floot OAuth or other third-party authentication services, we receive basic profile information such as your name, email address, and profile picture.
  • Payment Processors: Stripe provides us with payment confirmation data, subscription status updates, and billing event notifications necessary to manage your subscription.
  • Email Service Providers: SendGrid provides us with email delivery status information (delivered, bounced, opened) for our transactional messages to you.

Purpose Specification (PIPEDA Principle 2)

Our Commitment

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Principle 2 (Identifying Purposes) requires that we identify the purposes for which personal information is collected at or before the time of collection. We are committed to transparency and will not use your information for any purpose other than those identified below, except with your explicit consent or as required by law.

Specific Purposes for Data Collection

We collect and use your information for the following specific purposes, organized by data type:

Account Registration Data

Includes your email address, name, and password.

  • Purpose: To create and manage your user account.
  • Purpose: To authenticate you securely when you log in.
  • Purpose: To communicate important account-related information, such as security alerts or password resets.
  • Purpose: To provide you with customer support and respond to your inquiries.

Integration Credentials & Sync Data

Includes Mailchimp API keys, BigQuery configurations, and run logs.

  • Purpose: To establish secure connections and execute the automated data sync between Mailchimp and BigQuery.
  • Purpose: To manage credentials securely and isolate your pipeline from other tenants.
  • Purpose: To provide visibility into sync statuses, schedules, and troubleshooting.

Billing Information

Includes payment details, which are securely processed by our payment partner, Stripe.

  • Purpose: To process subscription payments and manage your billing cycle.
  • Purpose: To generate and manage your billing history and invoices.
  • Purpose: To comply with financial record-keeping and tax obligations.
  • Purpose: To prevent fraudulent transactions and financial abuse.

Platform Security & Technical Data

Includes app telemetry, error logs, and IP addresses.

  • Purpose: To detect and prevent fraud, security threats, and unauthorized access.
  • Purpose: To enforce rate limiting and maintain platform stability.
  • Purpose: To improve user experience, troubleshoot technical issues, and ensure compatibility.

Communications

Includes support emails, feedback submissions, and other direct communications.

  • Purpose: To respond to your inquiries, provide technical support, and resolve issues.
  • Purpose: To improve our services and products based on your valuable feedback.
  • Purpose: To maintain records of our communications for quality assurance and training purposes.

Changes to Purpose

If we wish to use your personal information for a new purpose not originally identified to you, we will notify you and seek your consent before using the information for that new purpose. You will always have the right to refuse consent for new purposes. We are committed to documenting and tracking all purposes for which we collect and use your data to ensure ongoing compliance.

Voluntary vs. Required Information

Some information is required for us to provide our core services (e.g., your email for account creation). This information is often marked with an asterisk (*) in our forms. Other information is voluntary and is used to help us improve your experience or provide additional features. You can choose not to provide voluntary information without affecting your ability to use the core functionality of our service.

How We Use Your Information

We use the collected information for the following purposes:

Service Provision

  • Data Synchronization: Establishing secure connections to Mailchimp and BigQuery to extract and transfer your audience and engagement data.
  • Analytics & Insights: Facilitating the calculation of engagement scores, identification of leader/at-risk subscribers, campaign analytics, send-time optimization insights, and subject line analysis by moving your data to BigQuery.
  • Account Management: Creating and maintaining user accounts, managing authentication sessions, and providing personalized experiences.
  • Usage Enforcement: Tracking API usage and sync frequency to enforce quota limits and maintain fair usage across the platform.

Payment and Subscription Management

  • Payment Processing: Processing subscription payments, managing billing cycles, and handling payment method updates through our secure payment processor, Stripe.
  • Subscription Administration: Managing subscription tiers, usage limits, feature access, and billing notifications.
  • Billing Support: Providing customer support for billing inquiries, subscription changes, and payment issues.

Service Improvement

  • Algorithm Enhancement: Analyzing pipeline execution patterns to optimize sync algorithms, improve reliability, and minimize data transfer latency.
  • Subscription Optimization: Analyzing feature utilization and volume metrics to improve our service offerings, scaling capacity, and pricing models.

Communication

  • Transactional Emails: Sending essential account-related emails through SendGrid, including email verification, password resets, security notifications, sync failure alerts, and billing notices.
  • Service Updates: Notifying users about significant changes to our service, API deprecations, or platform maintenance (with opt-out options for non-essential communications).
  • Subscription Communications: Sending billing reminders, subscription renewal notices, and payment-related notifications.

Cookies and Tracking

Space Monkey uses minimal cookies to provide essential session management and basic functionality for our platform:

  • Authentication Cookies: Essential cookies that keep you logged in securely and maintain your session across the platform.
  • Security Cookies: Essential cookies such as CSRF (Cross-Site Request Forgery) tokens used to protect your data and forms from malicious attacks.
  • Functional Cookies: Cookies that remember your basic preferences and settings to improve your user experience on our platform.
  • Payment Processing Cookies: Stripe may set cookies during payment processing to ensure secure transactions and fraud prevention.

You can control cookie settings through your browser, though disabling essential cookies may affect the functionality of our service, preventing you from logging in or using the sync platform.

For detailed information about the cookies we use and how to manage them, please visit our Cookie Policy, where you can also manage your cookie preferences.

Third-Party Services and Data Sharing

We share limited data with the following third parties to provide and improve our services. All third-party integrations are governed by strict data processing agreements that require them to protect your information and use it only for the specified purposes.

Core Synchronization Integrations

  • Intuit Mailchimp: To facilitate the synchronization of your data, Space Monkey requires API read access to your Mailchimp subscriber data. We only fetch the data necessary to perform the sync into your BigQuery dataset. This data is handled in memory and is not persisted on our servers.
  • Google BigQuery: We require API write access to your specific, customer-owned Google BigQuery dataset. Space Monkey acts as a conduit to push your Mailchimp data directly into your BigQuery environment. Data is processed within Google Cloud infrastructure.

Payment Processing

  • Stripe: We use Stripe as our payment processor for subscription billing and payment management. Stripe processes and stores payment card information, billing addresses, and transaction data according to their privacy policy and PCI DSS standards. We share necessary billing information with Stripe to process payments and manage subscriptions.
    Data Protection: Stripe maintains adequate data protection measures and is certified under various compliance frameworks including PCI DSS Level 1, SOC 1 and SOC 2, and has implemented Standard Contractual Clauses for international data transfers. Stripe processes payment data in the United States and European Union, with appropriate safeguards in place for international transfers.

Email Services

  • SendGrid: We use SendGrid to deliver transactional emails including account verification, password resets, billing notifications, and privacy policy updates. SendGrid processes email addresses and message content according to their privacy policy.

Sub-Processors and Service Providers

Our third-party processors listed above may engage their own sub-processors to help deliver their services. We require our processors to maintain appropriate data protection safeguards with their sub-processors in accordance with GDPR Article 28 and other applicable laws.

You can review the current sub-processors for our major service providers at the following links:

Your Rights Regarding Third-Party Processing

You maintain all your data protection rights even when your data is processed by third parties on our behalf. You can request information, object to processing, or request deletion by contacting us at privacy@spacemonkey.com.

We do not sell your personal data or share it with third parties for their own marketing purposes. All third-party data sharing is strictly limited to providing and improving our services.

International Data Transfers

To provide our services, your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.

Specifically, our infrastructure and third-party service providers operate across different regions. The primary locations for data transfer and processing include:

  • United States: Intuit Mailchimp, Stripe, and SendGrid infrastructure. Note: The United States does not have an EU adequacy decision. We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards for transfers to the US.
  • User-Configured Regions (Google Cloud): Data synced to Google BigQuery is processed and stored in the Google Cloud region that you have configured for your dataset. This gives you control over the data residency of your synced destination data.

Our Safeguards

We have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Policy. These include:

  • Implementing Standard Contractual Clauses (SCCs) as the primary safeguard for transfers to the United States.
  • Utilizing robust security measures, including encryption in transit (TLS/SSL) and at rest (AES-256), to protect your data across borders.
  • Empowering you to configure your destination dataset regions (e.g., within the EU via Google BigQuery) to minimize unnecessary transfers.

For detailed information about specific third-party processors, please see the Third-Party Services and Data Sharing section.

Your Rights

You have the right to request information about the international data transfers we conduct. If you have any questions or wish to exercise your rights, please contact us through our Support page.

Data Storage and Security

We implement robust, industry-standard security measures to protect your data and credentials:

  • Encryption of Credentials: All API credentials, including Mailchimp API keys and Google Cloud Service Account JSON keys, are encrypted at rest using AES-256 encryption. They are strictly protected and never stored in plain text.
  • Data in Transit: All data transmitted between your browser, our servers, Mailchimp, and BigQuery is secured using HTTPS/TLS encryption to prevent interception or tampering.
  • In-Memory Processing: During a sync operation, the payload data extracted from Mailchimp is held entirely in memory on our servers. It is strictly used to facilitate the transfer and is never persisted or written to our own databases.
  • Direct to Destination: The synced data is written directly to your own configured Google BigQuery dataset. You maintain complete ownership and control over your destination data at all times.
  • Session Security: We use secure session tokens for authentication, which include automatic expiration mechanisms to protect inactive accounts.
  • Access Controls: Access to infrastructure and encrypted credentials is mathematically restricted and strictly governed. Only authorized automated systems and key personnel have access on a need-to-know basis.

Breach Notification

We are committed to protecting the personal information and credentials under our control. In the event of a data breach, we will adhere to the requirements set out by applicable privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

Notification Requirements

We are required to notify relevant regulatory bodies of any breach of security safeguards involving personal information that poses a "real risk of significant harm" to individuals. We must also notify affected individuals if we believe the breach creates such a risk.

Our Commitment

Space Monkey maintains comprehensive security measures to prevent data breaches and has incident response procedures in place to address them promptly if they occur. Should we determine that a breach creates a real risk of significant harm, we will notify affected individuals as soon as feasible.

Our notifications will be clear and will include:

  • A description of the breach and the personal information or credentials involved.
  • The date or estimated date of the breach.
  • The steps we have taken to reduce the risk of harm.
  • The steps individuals can take to reduce their own risk of harm (such as rotating API keys).
  • Contact information for our Privacy Officer for further inquiries.

How We Will Notify You

In the event of a notifiable breach, we will take the following steps to inform you:

  • Direct Notification: We will send a notification directly to the email address registered with your account.
  • Indirect Notification: We will post a prominent notice on our website and within your account dashboard.

Reporting a Suspected Breach

If you believe your account, credentials, or personal information has been compromised or you suspect a security vulnerability, please contact us immediately. We take all reports seriously and will investigate promptly.

Contact: Privacy Officer

Email: privacy@spacemonkey.com

Data Retention

We retain personal information and operational data only as long as necessary for the purposes for which it was collected or as required by law. Each type of data we collect serves a specific purpose, and we retain it only for as long as needed to fulfill that purpose.

Retention Periods and Purposes

We retain different types of data for varying periods based on their specific purpose and legal requirements:

  • Account Information: Retained while your account is active to provide you with our services and maintain your account settings. When you request account deletion, your account data is securely and permanently deleted within 30 days.
  • API Credentials: Your encrypted Mailchimp API keys and Google Cloud Service Account JSON keys are retained only as long as your integration is active. They are permanently and securely deleted from our systems immediately upon integration removal or account deletion.
  • Synced Payload Data: The actual Mailchimp data being synced is processed in-memory and never retained on our servers. The final destination of this data is your own Google BigQuery dataset, where it is subject entirely to your own retention policies and control.
  • Sync Run Logs: Operational metadata, error logs, and metrics about your sync runs (excluding the actual payload data) are retained for 90 days. This helps us provide you with historical sync tracking, debugging capabilities, and service support.
  • Billing and Subscription Data: Payment records, invoices, and subscription history are retained for 7 years after subscription termination to comply with tax and accounting regulations, process refunds and chargebacks, and meet audit requirements.
  • Security Data: Essential session tokens and related security identifiers automatically expire and are cleared according to standard security practices (e.g., upon logout or session timeout).

Secure Destruction

When information is no longer needed for its identified purposes and is not required to be retained for legal or business purposes, we securely destroy, erase, or anonymize it. Our secure destruction procedures include permanent deletion from active databases and removal from backup systems within standard backup retention cycles.

Sensitive Data and Subscriber PII

As a data synchronization platform, Space Monkey processes subscriber Personally Identifiable Information (PII) such as email addresses, location data, and engagement behavior on behalf of our customers. We act strictly as a Data Processor in this context. Space Monkey does not use your subscribers' data for its own purposes, marketing, or profiling.

Data Flowing Through Syncs

Depending on the specific integrations you configure, the following types of data may flow through our systems:

  • Contact information (e.g., email addresses, phone numbers)
  • Location data (e.g., IP-based geolocation, addresses)
  • Engagement behavior (e.g., email opens, clicks, purchase history)
  • Custom attributes defined in your source systems

Enhanced Consent for Sensitive Data

To assist you in complying with various state and international privacy laws (such as GDPR, CCPA, and others), Space Monkey provides enhanced consent management features. While you as the Data Controller are responsible for obtaining consent, our systems can securely pass and respect consent flags:

  • Consent Status Routing: We can map and sync consent statuses (granted, withdrawn) across your integrated platforms.
  • Data Filtering: You can configure syncs to exclude certain sensitive data categories or individuals who have not provided explicit consent.
  • Auditability: We log the metadata of consent changes as they flow through our system (timestamps, source of truth) without storing the underlying sensitive data longer than necessary for the sync.

Purpose and Legal Basis

  • Purpose: To execute the data synchronization services you have configured between your chosen platforms and to ensure compliance with privacy laws regarding sensitive personal data.
  • Legal Basis: Space Monkey processes this data based on the Data Processing Agreement (DPA) and Terms of Service established with you. The legal basis for the original collection and processing relies on your relationship with your subscribers (e.g., Consent or Legitimate Interest).

Data Retention during Sync

Space Monkey is designed for secure, transient data transfer. Subscriber data flowing through our syncs is retained in our temporary processing queues only as long as necessary to complete the transfer (typically seconds or minutes) and up to a maximum of 7 days in the event of sync failures to allow for retry mechanisms. We do not maintain long-term persistent storage of your subscribers' PII.

Service Feedback and Cancellation Information

To help us improve Space Monkey and better understand our users' needs, we may ask for your feedback through satisfaction surveys or if you choose to cancel your subscription. Providing this feedback is entirely voluntary.

Information We Collect

When you respond to a survey or cancel a subscription, we may collect the following information:

  • Cancellation Reason: Your selection from a list of predefined reasons for canceling your Space Monkey service.
  • Free-Text Comments: Optional, detailed feedback you choose to provide about your experience with our integrations or platform.
  • Associated Account Data: Your email, display name, workspace details, and the subscription tier you were on at the time of feedback.
  • Timestamp: The date and time of your feedback submission.

Purpose and Legal Basis

  • Purpose: We use this information for churn analysis, to identify areas for service improvement, to prioritize new integrations, and to understand what features and pricing our users value most.
  • Legal Basis: We process this data based on our Legitimate Interest in improving the quality and usability of our synchronization platform.

Data Retention and Your Rights

  • Retention: Feedback data is retained for a period of two (2) years after collection to allow for long-term trend analysis.
  • Your Rights: Since providing feedback is optional, you are in full control. You have the right to request the deletion of your feedback at any time by contacting our privacy team.

Security Monitoring and Audit Logging

To protect your data, prevent unauthorized access, and ensure the integrity of the Space Monkey platform, we maintain a comprehensive security monitoring and audit logging system. Access to these logs is strictly limited to authorized security and administrative personnel.

General Security Logs

We log key security-related events across the application, including:

  • Login Attempt Monitoring: Successful and failed login attempts, multi-factor authentication events, and password reset requests.
  • Admin Configuration Changes: Modifications to workspace settings, billing information, and user role assignments.
  • Associated Data: The user ID, IP address, and browser user agent associated with the event.
  • Retention: General security logs are retained for 90 days.

Credential Access Logging

Given our role in connecting external systems, we heavily monitor API keys and integration credentials:

  • Event Details: Creation, rotation, deletion, and usage patterns of API keys and OAuth tokens used for your integrations.
  • Security Data: Internal service identities or IP addresses accessing these credentials, ensuring they are only used for authorized sync operations.
  • Retention: Credential access logs are retained for one (1) year.

Sync Operation Audit Trails

To ensure reliability and transparency of your data flows, we log metadata about synchronization jobs:

  • Operational Metrics: Sync start/end times, success/failure statuses, error codes, and the volume of records processed.
  • Privacy Note: These audit trails do not contain the underlying PII or sensitive data payload being synced, only the operational metadata.
  • Retention: Sync operation logs are retained for 30 days for debugging purposes.

Security Audit Log for Privacy Actions

We maintain records of privacy-related actions taken within the system:

  • Event Details: Data Subject Requests (DSRs) submitted, changes to data processing agreements, and exports of workspace data.
  • Retention: Privacy action logs are retained for six (6) years to comply with regulatory obligations.

Breach Response Logs

In the event of a security incident, we maintain detailed records to manage our response effectively:

  • Incident Details: The nature of the incident, severity assessment, estimated number of affected workspaces, and root cause analysis.
  • Remediation Actions: Steps taken to contain and resolve the incident, and notifications sent to affected users.
  • Retention: Breach incident logs are retained for six (6) years.

Purpose and Legal Basis

We process this data for security monitoring, fraud prevention, incident response, and to maintain the stability of our sync services. Our legal bases for this processing are our Legitimate Interest in securing our platform and your integrations, and our Legal Obligation to report data breaches where required by law.

Privacy Program Administration

To effectively manage Space Monkey's privacy program and demonstrate compliance with regulations like GDPR and CCPA, we utilize a suite of internal administrative tools. These tools are essential for upholding our commitment to your privacy and are accessible only to authorized privacy and compliance personnel. All administrator actions within these tools are logged with a user ID and timestamp.

Our Internal Privacy Tools

  • Privacy Impact Assessments (PIAs): We maintain records of privacy reviews conducted for new features or significant changes. These records include assessment details, risk evaluations, and reviewer information to ensure privacy-by-design.
  • Transfer Impact Assessments (TIAs): For international data transfers, we document the legal safeguards, destination countries, and risk assessments to ensure your data remains protected across borders.
  • Data Processor Registry: We keep a detailed registry of all third-party data processors, including their contact information, processing activities, Data Processing Agreement (DPA) details, and compliance status.
  • DSR Administration Dashboard: This tool allows us to efficiently track, assign, and manage your Data Subject Requests (e.g., for access or deletion), ensuring we respond to you in a timely manner.
  • Privacy Preferences Center Backend: This system powers the user-facing preferences center, storing your specific privacy choices, consent history, and state-specific opt-outs, enabling us to honor your selections automatically.
  • Policy Update Notification Tracking: We track which users have been successfully notified of material changes to our privacy policies. This includes recording delivery confirmations and timestamps to demonstrate our compliance with transparency obligations and legal requirements for user notification.

Purpose and Legal Basis

The purpose of these tools is to manage our privacy program, demonstrate compliance, and support regulatory audits. We process this administrative data based on our Legal Obligation to be accountable for our data protection practices under GDPR and other privacy laws.

Data Retention and User Impact

  • Retention: Records from these administrative tools are typically retained for 6-7 years to meet compliance and audit requirements.
  • User Impact: These internal tools are what enable us to honor your privacy rights effectively and transparently. The data you control, such as your preferences, remains directly manageable by you through your account settings.

Your Rights and Choices

Under PIPEDA, GDPR, and other applicable privacy laws, you have several rights regarding your personal data. These rights are designed to give you control over how your information is collected, used, and shared.

No Cost for Reasonable Requests: We provide access to your personal information and process reasonable rights requests at no cost to you, in accordance with PIPEDA requirements.

  • Right to Know Purposes: Under PIPEDA, you have the right to know the purposes for which your personal information is being collected BEFORE or at the time of collection. We clearly state our purposes in this Privacy Policy and in our data collection forms.
  • Right to Access: You can view your account information, subscription details, usage statistics, and sync history through your profile and settings pages. You may also request a complete copy of all personal data we hold about you.
  • Right to Challenge Accuracy (PIPEDA Principle 10): You have the right to challenge the accuracy and completeness of your personal information and have it corrected as appropriate. You can update your profile information, billing details, and preferences at any time through your account settings. If you believe any information we hold is inaccurate or incomplete, you have the right to have it corrected, and we will amend the information as required.
  • Right to Rectification (Correction): You can update your profile information, billing details, and preferences at any time through your account settings. If you believe any information we hold is inaccurate or incomplete, you have the right to have it corrected.
  • Right to Erasure (Deletion): You can request account deletion, which will remove your personal information from our systems. Note that some billing and transaction data may be retained for legal and accounting requirements (typically 7 years for tax purposes).
  • Right to Data Portability (Data Export): You can request a complete export of your personal data in machine-readable formats. Data exports are available in multiple formats including CSV (for structured data like usage history), JSON (for technical integrations), or PDF (for human-readable reports). Data exports include account information, project configurations, sync history, usage statistics, and preferences. This right allows you to receive your data and transmit it to another service provider where technically feasible.
  • Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in specific circumstances, such as when you contest the accuracy of the data, when the processing is unlawful but you prefer restriction over deletion, when we no longer need the data but you need it for legal claims, or while we verify your objection to processing based on legitimate interests.
  • Right to Object: You have the right to object to processing of your personal data based on our legitimate interests or for direct marketing purposes. This includes:
    • Objecting to data processing for direct marketing (including profiling related to marketing)
    • Objecting to processing based on legitimate interests (we will cease processing unless we can demonstrate compelling legitimate grounds that override your rights)
    • Objecting to automated decision-making and profiling that produces legal effects or similarly significantly affects you
  • Data Management: You can manage your sync history storage preferences, delete individual project records, and control data retention settings through your account preferences.
  • Subscription Control: You can modify, cancel, or upgrade your subscription at any time through your account settings.
  • Opt-out of Analytics: You can opt out of non-essential analytics tracking through your cookie consent preferences or browser settings.
  • Withdrawal of Consent: Where we process your data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to Lodge a Complaint: If you believe we have not handled your personal data properly, you have the right to:
    • Lodge a complaint with the Privacy Commissioner of Canada (for PIPEDA-related concerns)
    • Lodge a complaint with your local data protection supervisory authority (for GDPR-related concerns)
    • Contact the appropriate regulatory body in your jurisdiction

How to Exercise Your Rights

You can exercise any of these rights by submitting a Data Subject Request through our secure online form, or by contacting us at privacy@igods.com.

Response Timeframe: We will respond to your request within one (1) month of receipt, in accordance with both PIPEDA (30-day standard) and GDPR requirements. In complex cases or if we receive multiple requests from you, we may extend this period by up to two (2) additional months (for a total of three months). If we need to extend the timeframe, we will inform you within the first month and explain the reason for the delay.

We will not charge a fee for processing reasonable requests. However, if your request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or refuse to act on the request.

US State Privacy Rights

Effective Date: August 1, 2024

Residents of certain U.S. states, including California, Colorado, and Connecticut, have additional rights regarding their personal information. This section describes those rights and explains how you can exercise them. To manage your preferences or submit a data request, please visit our Privacy Preferences Center or our Data Subject Rights page.

California Privacy Rights (CCPA/CPRA)

Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information.

We collect the following categories of personal information for Space Monkey:

  • Account Information: Profile details and contact information.
  • Integration Credentials: Access tokens and keys for third-party platforms.
  • Sync Metadata: Data regarding your synchronization processes.
  • Subscriber Data: Processed strictly on behalf of the customer. Note that your subscriber data resides in your own BigQuery dataset.
  • Usage Data: Analytics and system interactions.

Colorado Privacy Rights (CPA)

Under the Colorado Privacy Act (CPA), Colorado residents have the right to access, correct, delete, and opt-out of certain processing of their personal data. Space Monkey facilitates these rights through our privacy settings.

Connecticut Privacy Rights (CTDPA)

Under the Connecticut Data Privacy Act (CTDPA), Connecticut residents are afforded rights concerning their personal data, including the right to access, correct, and delete data, which you can manage within Space Monkey.

Right to Data Portability

Under Article 20 of the GDPR, you have the right to data portability. This allows you to obtain and reuse your personal data for your own purposes across different services.

This right applies to personal data you have provided to us, where the processing is based on your consent or on a contract, and the processing is carried out by automated means.

Upon request, we will provide you with your data in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another data controller without hindrance from us. The data included in an export is:

  • Account Information: Your profile details, such as name and email address.
  • Project Configurations & Sync History: Records of the syncs and projects you have set up in Space Monkey.
  • Usage Statistics: Information about your service usage and credits.
  • Preferences: Your saved user settings.

Note: Your subscriber data is already maintained securely in your own BigQuery dataset, so it does not need to be exported from Space Monkey directly.

You can exercise this right by submitting a request through your account settings or by contacting us directly at privacy@igods.com. We offer data exports in the following formats:

  • JSON: For technical integrations and complete data representation.
  • CSV: For structured data like usage history, suitable for spreadsheets.
  • PDF: For human-readable reports of your account information and sync history.

Where technically feasible, you also have the right to request that your personal data be transmitted directly from us to another data controller (GDPR Article 20(2)). However, as there are currently no comparable services that support standardized data imports, direct transfer is not available at this time. The portable export formats we provide (JSON, CSV) enable you to manually transfer your data to other services of your choice.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes data protection regulations. This right is without prejudice to any other administrative or judicial remedy.

We encourage you to contact us first to resolve any issues, but you can contact the relevant authority directly:

Primary Authority (British Columbia)

Office of the Information and Privacy Commissioner for BC (OIPC BC)

BC residents should contact OIPC BC first for privacy complaints and inquiries related to the Personal Information Protection Act (PIPA) and Freedom of Information and Protection of Privacy Act (FIPPA).

Secondary/Federal Authority (Canada)

Office of the Privacy Commissioner of Canada (OPC)

For federal privacy matters under the Personal Information Protection and Electronic Documents Act (PIPEDA), you may contact the Office of the Privacy Commissioner of Canada.

For Users in Other Jurisdictions

  • For users in the European Union (EU): You can file a complaint with the data protection authority in your member state. A list of EU Data Protection Authorities can be found on the European Data Protection Board website.
  • For users in the United Kingdom (UK): The relevant authority is the Information Commissioner's Office (ICO). You can contact them via their website at www.ico.org.uk.
  • For users in the United States (US): While there is no single federal data protection authority, you may have rights under state laws, such as the California Consumer Privacy Act (CCPA). You can typically lodge complaints with your state's Attorney General.

To submit a data subject request (access, deletion, correction, etc.), please visit our Data Subject Request page.

Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

Space Monkey uses algorithms to perform engagement scoring, leader and at-risk subscriber classification, and Otsu threshold computation for test/production campaign classification. This automated processing is integral to the functionality of Space Monkey and is used to generate insights. However, this does not constitute automated decision-making as defined under Article 22 of the GDPR, as it does not result in legal or other significant consequences for you. The output is for informational and analytical purposes to assist your own decision-making.

Children's Privacy

Space Monkey is a service designed for professionals and businesses. It is not directed to, nor do we knowingly collect personal information from, children. You must be at least 16 years of age (or the age of digital consent in your country) to use our services. In the United States, this corresponds to the Children's Online Privacy Protection Act (COPPA), which applies to children under 13.

If we become aware that we have inadvertently collected personal data from a child without verification of parental consent, we will take steps to delete that information from our servers as quickly as possible.

If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at privacy@igods.com so that we can take necessary action.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in Space Monkey's practices or legal requirements. We will notify you of significant changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending an email notification to registered users for material changes
  • Providing notice through our website or service interface

Your continued use of Space Monkey after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy, want to exercise your data rights, or have privacy concerns, please contact us:

Chief Privacy Officer

Name: Cameron Knowlton

Title: Chief Privacy Officer & Compliance Officer

Address: #319-50 Songhees Rd., Victoria, BC, Canada V9A 7J4

Phone: 250-382-0221

Email: privacy@igods.com

General Contact Methods

  • Through the official Space Monkey website
  • By email at privacy@igods.com
  • Via our support channels listed on our website

Response Timeframe: In accordance with PIPEDA requirements, we will respond to your inquiries within 30 days and work to address any concerns you may have. In complex cases, we may extend this period with notice and explanation.