Mawnitor

Privacy policy

Effective . Last updated .

Who we are

Mawnitor (https://app.mawnitor.io) watches websites and online stores and tells the people who look after them what changed. It is run by Monkeys at Work, a business in Canada ("we", "us").

Our privacy officer is accountable for how we handle personal information. Write to them at [email protected] with any question about this policy or about your information.

This policy is for three groups of people:

Whose data, and our role

An agency decides which sites to connect, who is on its team and who receives alerts. For its clients' sites we act on the agency's behalf: we handle their data only to provide Mawnitor to that agency. The agency is responsible for having its clients' permission.

The owner and staff of a connected Shopify store, when they open Mawnitor from their Shopify admin or approve it, see a read-only page about that store alone: its live theme, the theme files edited directly, a one-line status for each check and, when Google is connected, how many of its pages Google sends visitors to are dead and how many of its products Google Shopping rejected.

For an agency's own account, such as its team members' sign-ins, we decide how the data is handled, as this policy describes.

If you install Mawnitor on your Shopify store yourself, from Shopify rather than from an agency's link, your store is monitored in Monkeys at Work's own account. Monkeys at Work's team can see the results and receives the alerts.

What we collect

When you sign in

Clients, contacts and alerts

From Shopify

When a store owner approves Mawnitor, Shopify grants it one permission, read_themes, which lets it read the store's themes. With it we read and keep:

We do not read customer, order, product or payment data through Shopify, and we keep no customer data from Shopify. We do look at a store's public pages, like any visitor, so what a customer published there, such as a name on a review, can be in what we keep (see Public pages). We also ask Shopify to tell us when Mawnitor is uninstalled.

Mawnitor's Shopify app also names some optional permissions: to read products, discounts, pages, navigation, languages, markets and translations. We do not ask for any of them today. If a feature ever needs one, we will first explain what it reads and why, and ask for it separately; you can say no and keep the rest.

Some agencies connect a store with an access token made in the store's own admin instead. We read the same things with it, and keep it encrypted the same way.

From WordPress

When a site's administrator approves Mawnitor on the site, WordPress gives us an application password. We keep it, and the username it belongs to, encrypted, and use it only to read. The companion plugin, if the site installs it, reads the same things from inside the site and sends them to us. We read and keep:

From Google

Someone who manages a site's Google Search Console property or Merchant Center account can connect it. Google then gives us two permissions:

We keep a refresh token from Google, encrypted, so we can read again each day. The short-lived access tokens made from it are not stored. We also visit the landing pages Google lists, the same way we visit other public pages.

Public pages

Mawnitor visits the public pages of the sites it watches, without signing in and without cookies. From them it keeps things such as page titles and descriptions, tags and tracking IDs, structured data, robots.txt, sitemaps, links and an outline of each page's visible text. For stores, it reads up to 30 products from the public product list, with their addresses and prices. For WordPress sites, it reads the public list of published posts, with each one's address and when it last changed.

It also takes screenshots of key pages and runs Lighthouse performance checks, on our own server. If a page shows someone's name or other details, in a review for example, those can be part of what we keep.

Email records

For each site's domains we read public DNS records (such as MX, SPF, DKIM and DMARC) and check public email blocklists. A DMARC record can include an address for reports; we keep it as part of the record.

Server logs

Our server writes logs so we can run and secure the service: for example the IP address of a failed sign-in, the domains of connected stores, and errors. To slow down password guessing and repeated requests, we also hold in memory the IP addresses and email addresses of failed sign-ins and of password-reset requests, and the IP addresses of unknown invitation links, for about 15 minutes after the last attempt.

How we use it

We use what we collect only to:

We never:

Google user data

Mawnitor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The policy is at developers.google.com/terms/api-services-user-data-policy. In plain words:

To stop, press Disconnect on the site's Google tab in Mawnitor. We then delete the Google token and the Google figures shown on that tab. Changes already recorded from Google, such as a page Google sends visitors to that stopped answering, with its address and its clicks and impressions, stay in the site's history unless we are asked to delete them, and so do alerts and reports already sent. To also withdraw the approval at Google, remove Mawnitor from your Google Account's third-party connections.

Who we share it with

Our service providers are bound to protect the data.

Alerts and reports go to the people the agency chooses. The owner and staff of a connected Shopify store see that store's own page (see Whose data, and our role). An agency can also share a link to a screenshot with whoever fixes a site; the link opens that one picture, without signing in, for about 30 days. We also disclose information when the law requires it.

Data may be stored and processed in Canada or the United States. Where it is, that country's laws apply to it, and its courts and authorities may be able to reach it.

How we protect it

No system is perfectly secure. If a breach puts you at real risk of significant harm, we will tell you, and the authorities, as the law requires.

How long we keep it

Deleted data can remain in our hosting provider's backups for a limited time, until they are replaced.

Cookies and browser storage

Your rights

You can ask us to:

You can withdraw your consent at any time: disconnect Google, uninstall the Shopify app, or remove the companion plugin or the WordPress application password. We then stop reading through what you withdrew. To have a site's public pages left alone too, ask the agency that watches it, or us.

To ask, email [email protected]. We answer within 30 days, and may first need to confirm who you are. If your information reached us through an agency, as one of its clients or contacts, you can also ask the agency; we will help it answer.

If you are in the European Union or the United Kingdom, the GDPR also gives you the rights of access, rectification, erasure, restriction, objection and data portability, and the right to complain to a data protection supervisory authority.

In Canada, if you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca, 1-800-282-1376.

Children

Mawnitor is a service for businesses. It is not directed at children, and we do not knowingly collect information from them.

Changes to this policy

When we change this policy, we update the date at the top. When a change is significant, we also tell account owners.

Contact

Monkeys at Work, Canada. Privacy officer: [email protected].