Privacy Policy

Last updated: 7 September 2026

Multi Step Approval Process is a monday.com application provided by Francesco Pelloni, a private individual based in Italy, who is the data controller for the personal data described below. You can reach the controller at [email protected].

The short version: the app stores who was asked to approve what, and their decisions. It stores nothing else, shares nothing with anyone, and everything it stores lives inside monday.com's own infrastructure. There is no tracking, no analytics and no advertising.

1. What the app stores

DataWhy
monday.com account IDTo keep each customer's approval requests separate from every other customer's.
monday.com user IDs of the requester and the approversTo know who asked, who has to decide, and whose turn it is.
Board ID and item IDTo attach the approval request to the item it belongs to.
The id of the board column you chose to mirror the result into, if you chose oneSo the app knows where to write Approved, Rejected or Pending approval. It stores which column, never what else is in it.
The item's nameSo notifications and updates say "Invoice #204" instead of "item 3185821474".
Each approval decision, with its timestampThis is the record the app exists to produce.
An OAuth access token for the accountSo the app can post updates and send notifications inside monday.com on the account's behalf.

Data the app reads but does not keep

When you open the approver picker, the app asks monday.com for the list of people in your account (name, email and profile picture) so you can search for them by name. That list is held in the server's memory for at most ten minutes and is then discarded. It is never written to storage.

Data the app never collects

2. Where it is stored

All stored data is written to monday.com's own encrypted storage (monday code SecureStorage), on monday.com's infrastructure. The app runs on monday code, monday.com's application hosting platform. No data is copied to any other server, and none of it is stored by us anywhere else.

The servers are currently in the United States. If you are in the European Union or the United Kingdom, that means the data described above leaves your region. monday.com Ltd. is the processor and operates that infrastructure; we do not choose the machines and we do not hold a copy. If this is a problem for your organisation, write to [email protected] before you install: we would rather tell you now than have you find out later.

3. Who it is shared with

Nobody. The data is not sold, rented, shared with advertisers, or passed to any third party. The only processor involved is monday.com Ltd., which hosts both the application and its storage.

4. Cookies

The app sets no cookies and uses no browser storage for tracking. Inside monday.com it authenticates each request with a short-lived session token issued by monday.com itself.

5. How long it is kept

Approval requests are kept for as long as you use the app, because they are the record of decisions already taken.

Uninstalling the app erases them. When an account removes the app, monday.com tells us, and we delete everything belonging to that account: the requests and their history, the board column you had chosen, and the access token. Nothing of yours is kept as a souvenir.

Usually this happens within minutes of the removal. It can take longer: the notice may arrive while our server is starting up, in which case we ask monday.com to send it again rather than pretend we deleted anything. The commitment we make is 30 days, because we would rather promise the slower number and keep it.

If that notice never reaches us, you can still ask. Write to [email protected] from an address on that account: we do it and confirm within 30 days — normally within a few working days — and you do not have to give a reason.

6. Your rights

If you are in the European Union, the GDPR gives you the right to access your personal data, to have it corrected or erased, to receive a copy of it, to restrict or object to its processing, and to lodge a complaint with your national supervisory authority. To exercise any of these, write to [email protected]. Requests are answered within 30 days.

7. Security

Every request from inside monday.com is authenticated by verifying the cryptographic signature of the session token monday.com issues; unsigned or badly signed requests are rejected. The OAuth token for your account is stored in monday.com's encrypted storage and is never exposed to the browser. Application secrets are held as environment variables and are not present in the source code.

8. Children

The app is a workplace tool and is not directed at children. It is used through a monday.com account, which has its own age requirements.

9. Changes to this policy

If this policy changes, the date at the top of this page changes with it. Material changes will also be announced on the app's marketplace listing.