1. Introduction
MonitorWorkspace ("we", "our", or "us") provides Google Workspace monitoring and management tools for IT administrators. This Privacy Policy explains how we collect, use, store, and protect information when you use our services.
2. Information We Collect
2.1 Google Workspace Data
When you authorize MonitorWorkspace via domain-wide delegation, we access the following Google Workspace data on behalf of your organization's super administrator:
- User directory information: Email addresses, names, profile photos, organizational units, account status, 2FA enrollment, last login times
- Storage usage data: Gmail and Google Drive storage consumption per user
- Email content: Message headers, body content, labels, and metadata (accessed only when explicitly requested by an authorized administrator)
- Google Chat data: Chat spaces, messages, and metadata (accessed only when explicitly requested by an authorized administrator)
2.2 Account and Authentication Data
We collect email addresses of authorized administrators who sign in via Google OAuth, along with session tokens for authentication.
2.3 Audit Logs
We automatically log all administrative actions performed within MonitorWorkspace, including: user list views, email access, chat space views, email transfers, and chat exports. Logs include admin email, action type, timestamp, and target user.
3. How We Use Your Information
We use collected information solely to:
- Display user directory, email, and chat data to authorized administrators via the MonitorWorkspace dashboard
- Execute email transfer and chat export operations initiated by administrators
- Maintain audit logs for compliance and accountability
- Authenticate administrators and enforce access controls
- Provide technical support and troubleshoot issues
4. Limited Use Requirements
MonitorWorkspace's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
We do not:
- Sell Google user data to third parties
- Use data for advertising, retargeting, or personalized ads
- Use data for credit assessment or lending decisions
- Transfer data to third parties except as required for providing user-facing features, security purposes, or legal compliance
5. Data Storage and Security
5.1 Storage
Data is stored in encrypted databases hosted on secure cloud infrastructure. Service account credentials are encrypted at rest. Email content is fetched on-demand and not persistently stored. Chat exports and audit logs are retained per your subscription tier (30 days to 1 year).
5.2 Security Measures
- All data transmitted via TLS/HTTPS encryption
- Encryption at rest for sensitive data (service account keys, user data)
- Email allowlist access control — only pre-authorized super administrators can sign in
- Regular security audits and vulnerability assessments
- Compliance with OWASP Application Security Verification Standard (ASVS)
6. Data Sharing and Disclosure
We do not sell, rent, or share your data with third parties except:
- With your consent: When you explicitly authorize data sharing
- Service providers: Hosting infrastructure providers (under strict data processing agreements)
- Legal requirements: When required by law, subpoena, or court order
- Security incidents: To investigate fraud, security threats, or violations of our Terms of Service
7. Data Retention and Deletion
We retain data as follows:
- User directory data: Until you delete your MonitorWorkspace account or remove the service account delegation
- Audit logs: 30 days (Starter/Professional), 90 days (Business), 1 year (Enterprise)
- Chat exports: 30 days after export completion, then automatically deleted
- Email transfer metadata: 90 days after transfer completion
You may request deletion of your organization's data at any time by contacting support@monitorworkspace.com. We will delete all data within 30 days of your request.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the data we hold about your organization
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability (receive a copy of your data)
To exercise these rights, contact privacy@monitorworkspace.com.
9. Cookies and Tracking
We use essential cookies for authentication (NextAuth session cookies). We do not use tracking cookies, analytics, or third-party advertising cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the MonitorWorkspace dashboard. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: privacy@monitorworkspace.com