Privacy Policy

Last updated: August 19, 2026

1. Introduction

Welcome to Monstera Cloud ("we," "our," or "us"), operated at https://monsteracloud.com. We are committed to protecting your personal information, your advertising data, and your right to privacy. If you have any questions or concerns about our policy or data practices, please contact us at privacy@monsteracloud.com.

This Privacy Policy explains how Monstera Cloud collects, uses, protects, stores, and transfers information when you use our web application, our Google Sheets™ Add-on, our Looker Studio™ connectors, and our reporting APIs (collectively, the "Services").

2. Information We Collect

We only collect information necessary to provide marketing performance reporting, attribution, and analytics:

  • Account & Contact Information: Name, email address, company/agency name, and authentication credentials when creating an account.
  • Payment & Billing Data: Handled securely by our Merchant of Record, Paddle (Paddle.com Market Ltd). We never store payment card details on our servers.
  • Connected Advertising Accounts: OAuth access tokens and refresh tokens necessary to fetch campaign performance data from connected platforms (Google Ads, Meta Ads, TikTok Ads, Shopee).
  • Advertising Performance Metrics: Read-only aggregate metrics (campaign names, ad group names, impressions, clicks, spend, conversions, ROAS) extracted from authorized accounts.

3. Data Protection & Security Mechanisms for Sensitive Data

Monstera Cloud employs rigorous technical and organizational security measures to safeguard all sensitive user data, OAuth tokens, and advertising performance data against unauthorized access, loss, destruction, or alteration:

🔐 Cryptographic Encryption at Rest

All sensitive credentials, OAuth refresh tokens, API keys, and connection secrets are encrypted at rest using industry-standard AES-256-GCM authenticated encryption with unique initialization vectors. Plaintext credentials are never written to disk or logs.

🌐 Encryption in Transit

All communications between our users, web browsers, Google Workspace™ applications, and third-party APIs (including Google APIs) are strictly enforced over TLS 1.3 / HTTPS encryption with HTTP Strict Transport Security (HSTS).

🏢 Multi-Tenant Database Isolation & RBAC

Our application enforces strict multi-tenant logical isolation and Role-Based Access Control (RBAC). Data belonging to one workspace or agency is cryptographically bounded and cannot be accessed or viewed by any other tenant or user.

🛡️ Principle of Least Privilege & Access Controls

Production databases and cloud infrastructure are protected behind multi-factor authentication (MFA), private VPC networks, and strict least-privilege IAM permissions. Automated security vulnerability scanners continuously monitor our codebase and dependencies.

4. Google User Data & Scopes (Google Ads & Google Workspace™)

Monstera Cloud integrates with Google APIs to enable automated advertising reporting and Google Sheets™ export. We only request the minimum necessary scopes to deliver this functionality:

4.1 Google Scopes Requested & How They Are Used

  • Google Ads API (https://www.googleapis.com/auth/adwords):
    Used solely to read campaign performance metrics (campaign names, impressions, clicks, spend, cost, conversions, ROAS) from authorized Google Ads accounts. We do not create, modify, pause, or delete ads, campaigns, budgets, or account settings.
  • Current Spreadsheet Access (https://www.googleapis.com/auth/spreadsheets.currentonly):
    Used by the Monstera Cloud Google Sheets™ Add-on to write requested report tables and refresh metric cells only within the currently open, active spreadsheet selected by the user. The Add-on cannot and does not access, read, scan, or view any other files in your Google Drive™.
  • External Requests (https://www.googleapis.com/auth/script.external_request):
    Used by the Add-on to securely connect to Monstera Cloud's backend API (https://monsteracloud.com/api/addon/*) to authenticate and retrieve normalized reporting data over HTTPS.
  • User Email & Profile (userinfo.email, userinfo.profile, openid):
    Used for account authentication, workspace identity, and subscription tier verification.

4.2 Google API Services User Data Policy & Limited Use Disclosure

Google Limited Use Compliance Notice:

Monstera Cloud's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.3 Specific Prohibitions on Google Data

  • We do NOT sell, rent, or trade Google user data to any third party or broker.
  • We do NOT use Google user data for advertising, retargeting, profiling, or lead generation.
  • We do NOT use Google user data to train generalized AI or machine learning models.
  • We do NOT allow human access to your raw Google data, except when explicitly required to resolve a technical support request initiated by you.

5. Data Retention & Deletion Policy

We retain personal and advertising data only for as long as necessary to provide the reporting services requested by your workspace:

  • OAuth Tokens: Stored in encrypted format only while the connection is active. When you disconnect a source or delete a connection, the corresponding OAuth credentials and tokens are permanently purged immediately.
  • Warehouse Metrics: Retained during the active subscription period to provide historical trend analysis and scheduled reporting.
  • Account Deletion: You can request full deletion of your account, all associated workspaces, and all stored data at any time by emailing privacy@monsteracloud.com or support@monsteracloud.com. Upon request, all data is permanently and irreversibly deleted from our active databases within 30 days.
  • Revoking Access: You can revoke Monstera Cloud's access to your Google account at any time via your Google Account Permissions Manager.

6. Your Rights & Privacy Choices

Depending on your location (including under GDPR, CCPA, and global privacy frameworks), you have the right to:

  • Request access to the personal data we hold about you.
  • Request rectification or correction of any inaccurate data.
  • Request erasure and complete deletion of your data.
  • Request restriction of data processing or object to processing.
  • Export your data in a portable, machine-readable format (CSV/JSON).

7. Contact & Inquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact our Data Protection Team:

Monstera Cloud
Email: privacy@monsteracloud.com / support@monsteracloud.com
Website: https://monsteracloud.com

Google Ads™, Google Sheets™, Google Drive™, and Google Workspace™ are trademarks of Google LLC.