Legal

Privacy policy

Last updated: May 2026

Overview

This Privacy Policy explains how AssetMon ("we", "our", "us") collects, uses and shares personal information when you visit our website, sign up for a workspace, or use the AssetMon service. We have written this policy in plain English; the legal definitions in our Terms apply.

What we collect

We collect three categories of information:

  • Account data you provide on signup: workspace name, workspace slug, your name, email, hashed password.
  • Usage data automatically generated when you use the product: pages visited, actions taken, request metadata, IP address, browser user-agent. We use this for security, fraud prevention and product analytics.
  • Workspace data you choose to store inside AssetMon: asset records, user records you add, license keys, photos, attachments. We treat this as customer content; we are the data processor, you are the controller.

How we use it

  • To provide the service you signed up for (contract performance).
  • To send transactional emails (account changes, security alerts, billing notices).
  • To improve the product through aggregated, de-identified analytics (legitimate interest).
  • To comply with legal obligations (e.g., a valid court order or tax records).

We do not sell personal data. We do not use customer workspace data to train models, build aggregate insights for third parties, or feed advertising.

Sharing

We share data only with sub-processors that help us run the service. The current list is available in our DPA and includes: our cloud hosting provider, our database provider, our transactional email provider, and our error-tracking provider. Each sub-processor is contractually bound by GDPR Article 28 obligations.

Storage & retention

Workspace data is stored in PostgreSQL databases in our chosen region (default: EU). We keep your data for as long as your workspace is active. After cancellation, we keep an encrypted backup for 30 days and then delete permanently. Audit logs are retained 365 days unless otherwise required.

Your rights

If you are in the EU, UK, India (under DPDP Act 2023) or California, you have rights to: access your data, correct inaccuracies, request deletion, port data in machine-readable form, restrict processing and object to processing. Email support@assetmon.app and we will respond within 30 days.

Cookies

We use a minimal set of first-party cookies for authentication and CSRF protection. We do not use third-party advertising cookies. See our Cookie policy for details.

Security

See the full breakdown on our Security page. Highlights: database-per-tenant isolation, encryption at rest and in transit, helmet HTTP security headers, immutable audit log, rate limiting, HMAC-signed webhooks.

Contact

Questions, complaints or DSARs: support@assetmon.app.

Changes

If we make material changes to this policy, we will notify the workspace admin by email at least 14 days before the change takes effect.