Privacy policy
Effective . Last updated .
Who we are
Mawnitor (https://app.mawnitor.io) watches websites and online stores and tells the people who look after them what changed. It is run by Monkeys at Work, a business in Canada ("we", "us").
Our privacy officer is accountable for how we handle personal information. Write to them at [email protected] with any question about this policy or about your information.
This policy is for three groups of people:
- Agencies and their team members, who sign in to Mawnitor.
- Store owners and WordPress site administrators, whose sites are connected to it.
- People whose details appear on the sites it watches, such as a reviewer named on a product page, or a user account on a WordPress site.
Whose data, and our role
An agency decides which sites to connect, who is on its team and who receives alerts. For its clients' sites we act on the agency's behalf: we handle their data only to provide Mawnitor to that agency. The agency is responsible for having its clients' permission.
The owner and staff of a connected Shopify store, when they open Mawnitor from their Shopify admin or approve it, see a read-only page about that store alone: its live theme, the theme files edited directly, a one-line status for each check and, when Google is connected, how many of its pages Google sends visitors to are dead and how many of its products Google Shopping rejected.
For an agency's own account, such as its team members' sign-ins, we decide how the data is handled, as this policy describes.
If you install Mawnitor on your Shopify store yourself, from Shopify rather than from an agency's link, your store is monitored in Monkeys at Work's own account. Monkeys at Work's team can see the results and receives the alerts.
What we collect
When you sign in
- Your name and email address.
- Your password, kept only as a scrypt hash. We never keep the password itself.
- Your role on the team, and when you last signed in.
- A cookie that keeps you signed in (see Cookies and browser storage).
- Invitations: who was invited, by whom, with which role and when.
- Your name beside things you do in Mawnitor, such as pausing a site or answering a question about a change.
Clients, contacts and alerts
- Your clients' names, a contact person's name and email address for each, and the email addresses that receive alerts and reports.
- Sale periods you enter, and the readiness emails sent for them.
- Your workspace's name, alert settings and time zone.
- A Slack webhook address, if you add one, so alerts are also posted to Slack.
From Shopify
When a store owner approves Mawnitor, Shopify grants it one permission, read_themes,
which lets it read the store's themes. With it we read and keep:
- The store's themes and their files. We keep a checksum of each file and, in reports, the parts of files that changed.
- The store's name and its domains.
- The store's contact email address. We use it to find the domain the store's emails are sent from, so we can check that domain's email records, and show it beside those results.
- An access token from Shopify, kept encrypted.
We do not read customer, order, product or payment data through Shopify, and we keep no customer data from Shopify. We do look at a store's public pages, like any visitor, so what a customer published there, such as a name on a review, can be in what we keep (see Public pages). We also ask Shopify to tell us when Mawnitor is uninstalled.
Mawnitor's Shopify app also names some optional permissions: to read products, discounts, pages, navigation, languages, markets and translations. We do not ask for any of them today. If a feature ever needs one, we will first explain what it reads and why, and ask for it separately; you can say no and keep the rest.
Some agencies connect a store with an access token made in the store's own admin instead. We read the same things with it, and keep it encrypted the same way.
From WordPress
When a site's administrator approves Mawnitor on the site, WordPress gives us an application password. We keep it, and the username it belongs to, encrypted, and use it only to read. The companion plugin, if the site installs it, reads the same things from inside the site and sends them to us. We read and keep:
- The plugins and themes installed, their versions and which are active.
- User accounts: display names and roles only, not their email addresses or passwords.
- Posts (not pages), including drafts and private ones: their titles, status, author and when each was last changed. Never their content.
- The site's settings, such as its title, address, time zone, language and administrator email address.
- With the companion plugin, the files of the live theme, including their text.
From Google
Someone who manages a site's Google Search Console property or Merchant Center account can connect it. Google then gives us two permissions:
webmasters.readonly, to read Search Console: the properties that Google account can see, the site's clicks, impressions, click rate and position over the last 28 days, its top searches and pages, and up to 250 landing pages.content, to read Merchant Center: the accounts the login can see, how many products are approved or disapproved and why, and up to 500 disapproved products with their titles and issues. Google offers no read-only version of this permission. We only read with it and never change anything.
We keep a refresh token from Google, encrypted, so we can read again each day. The short-lived access tokens made from it are not stored. We also visit the landing pages Google lists, the same way we visit other public pages.
Public pages
Mawnitor visits the public pages of the sites it watches, without signing in and without cookies. From them it keeps things such as page titles and descriptions, tags and tracking IDs, structured data, robots.txt, sitemaps, links and an outline of each page's visible text. For stores, it reads up to 30 products from the public product list, with their addresses and prices. For WordPress sites, it reads the public list of published posts, with each one's address and when it last changed.
It also takes screenshots of key pages and runs Lighthouse performance checks, on our own server. If a page shows someone's name or other details, in a review for example, those can be part of what we keep.
Email records
For each site's domains we read public DNS records (such as MX, SPF, DKIM and DMARC) and check public email blocklists. A DMARC record can include an address for reports; we keep it as part of the record.
Server logs
Our server writes logs so we can run and secure the service: for example the IP address of a failed sign-in, the domains of connected stores, and errors. To slow down password guessing and repeated requests, we also hold in memory the IP addresses and email addresses of failed sign-ins and of password-reset requests, and the IP addresses of unknown invitation links, for about 15 minutes after the last attempt.
How we use it
We use what we collect only to:
- Run the monitoring: read each site, compare it with what we saw before, and find what changed.
- Send alerts and reports to the people the agency chose, by email and, if it is set up, Slack.
- Show the owner and staff of a connected Shopify store that store's own page.
- Send sign-in links and approval links.
- Keep accounts secure: signing in, roles, and limits on password guessing.
- Answer questions, and help when something goes wrong.
We never:
- Sell data.
- Use it for advertising.
- Use it to train AI or machine-learning models.
- Use a Shopify merchant's data for anything this policy does not describe.
Google user data
Mawnitor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The policy is at developers.google.com/terms/api-services-user-data-policy. In plain words:
- We use data from Google only to provide Mawnitor's Google features: a site's Search Console and Merchant Center results and the checks of its landing pages, shown in Mawnitor, in the alerts and reports the agency sends, and on a connected Shopify store's own page.
- We do not transfer it to anyone else, except as needed to provide those features, to keep the service secure, or when the law requires it.
- It is read by the agency's team, in Mawnitor; by the people the agency chooses to receive its alerts and reports, by email and, if it is set up, Slack; and by the owner and staff of a connected Shopify store, on that store's own page, which includes how many of its pages Google sends visitors to are dead and how many of its products Google Shopping rejected. Nobody else reads it, except with your permission, for security, or when the law requires it.
- We never use it for advertising, never sell it, and never use it to train AI or machine-learning models.
To stop, press Disconnect on the site's Google tab in Mawnitor. We then delete the Google token and the Google figures shown on that tab. Changes already recorded from Google, such as a page Google sends visitors to that stopped answering, with its address and its clicks and impressions, stay in the site's history unless we are asked to delete them, and so do alerts and reports already sent. To also withdraw the approval at Google, remove Mawnitor from your Google Account's third-party connections.
Who we share it with
- DigitalOcean hosts Mawnitor and its database.
- Our email delivery provider sends alerts, reports, sign-in links and approval links.
- Slack, only if an agency connects it: alerts are posted to the channel the agency chose.
- Shopify, WordPress sites and Google receive our requests as part of being read, with the access they gave us.
- Public DNS services (Cloudflare and Google Public DNS) and email blocklists receive the domain names and mail server addresses we check.
- Google Fonts and Fontshare serve the Mawnitor app's fonts to your browser, so they receive your browser's IP address and the usual details of a web request.
Our service providers are bound to protect the data.
Alerts and reports go to the people the agency chooses. The owner and staff of a connected Shopify store see that store's own page (see Whose data, and our role). An agency can also share a link to a screenshot with whoever fixes a site; the link opens that one picture, without signing in, for about 30 days. We also disclose information when the law requires it.
Data may be stored and processed in Canada or the United States. Where it is, that country's laws apply to it, and its courts and authorities may be able to reach it.
How we protect it
- Mawnitor is served over HTTPS.
- Access credentials for Shopify, WordPress and Google are encrypted with AES-256-GCM.
- Passwords are hashed with scrypt. Invitation and password-reset links are kept only as hashes, work once and run out after 7 days.
- What each person can do is limited by their role, and each agency's data is kept apart from every other's.
- Sign-in attempts are rate-limited.
No system is perfectly secure. If a breach puts you at real risk of significant harm, we will tell you, and the authorities, as the law requires.
How long we keep it
- Accounts and monitoring history are kept while the agency's account is active. We delete them when the agency asks us to.
- A team member the agency removes loses access at once. Ask us if their sign-in details should be deleted too.
- A client the agency removes has its name, contacts and alert addresses deleted.
- A site the agency removes is no longer checked, and its Shopify or WordPress access credentials are deleted. The history already recorded stays in the agency's account unless the agency asks us to delete it, and so does a Google approval for that site: disconnect Google first, or ask us.
- Shopify: uninstalling Mawnitor ends our access at once and deletes the store's access token. About 48 hours later Shopify asks us to erase the store's data, and we delete the store's records, reports, snapshots, screenshots and credentials, unless the store has installed Mawnitor again by then. We keep only a record that the request arrived and what we did; the store's name can also remain in alerts and emails already written.
- Shopify customers: we keep no customer data from Shopify. When Shopify passes on a customer's request to see or erase their data, we record that the request arrived, but not who it is about; there is nothing from Shopify to send or erase. A customer's name or words on a store's public pages, in a review for example, can be in the page records and screenshots we keep. Write to us at [email protected] and we will remove them.
- Google: disconnecting deletes the Google token and the Google figures shown on the site's Google tab. Changes already recorded from Google, with the addresses and the clicks and impressions they carry, stay in the site's history unless we are asked to delete them.
- WordPress: deactivating or deleting the companion plugin stops its reports. To end our access completely, also revoke Mawnitor's application password, under Users, Profile, Application Passwords on the site.
Deleted data can remain in our hosting provider's backups for a limited time, until they are replaced.
Cookies and browser storage
- Signing in sets one cookie,
wm_session. It keeps you signed in for up to 14 days, scripts cannot read it (it is HttpOnly), and signing out removes it. - Opening Mawnitor from a Shopify admin, or approving it on a store, sets one cookie,
mw_store, which opens that store's own page. It names the store, lasts an hour, and scripts cannot read it. - The Mawnitor app keeps two choices in your browser's storage: its appearance (light, dark or system) and how the sites list is grouped. They stay in your browser.
- There are no analytics or advertising cookies, and no tracking scripts.
Your rights
You can ask us to:
- Show you the personal information we hold about you.
- Correct it.
- Delete it.
You can withdraw your consent at any time: disconnect Google, uninstall the Shopify app, or remove the companion plugin or the WordPress application password. We then stop reading through what you withdrew. To have a site's public pages left alone too, ask the agency that watches it, or us.
To ask, email [email protected]. We answer within 30 days, and may first need to confirm who you are. If your information reached us through an agency, as one of its clients or contacts, you can also ask the agency; we will help it answer.
If you are in the European Union or the United Kingdom, the GDPR also gives you the rights of access, rectification, erasure, restriction, objection and data portability, and the right to complain to a data protection supervisory authority.
In Canada, if you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca, 1-800-282-1376.
Children
Mawnitor is a service for businesses. It is not directed at children, and we do not knowingly collect information from them.
Changes to this policy
When we change this policy, we update the date at the top. When a change is significant, we also tell account owners.
Contact
Monkeys at Work, Canada. Privacy officer: [email protected].