Privacy Policy
Last updated · 2026-08-04
Tovrio ("we", "our", "us") respects your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights. It covers the Tovrio website and our apps on the monday.com marketplace: Mass Email for CRM (Section 3a), Apex - Cross-Board Rollup (Section 3b), Placet: Approvals (Section 3c), and Obsign: Documents (Section 3d).
Tovrio is a brand operated by repaid, a sole proprietorship registered in South Korea (business registration no. 228-58-00763).
1. Information We Collect
We collect the minimum information needed to deliver our product and support you:
- Email address, when you subscribe to updates or purchase the Product.
- GitHub username, required after purchase to grant private repository access.
- Name, when you provide it to receive your purchase or contact support.
- Payment information , processed and stored by Paddle.com Market Limited ("Paddle") as Merchant of Record. We do not see or store your full payment card details.
- Communications, emails you send to us and our responses.
2. How We Use Information
- To deliver the Product and provide customer support.
- To send product update emails (e.g., new product launches).
- To process refunds when requested.
- To comply with legal obligations (tax, accounting).
3a. Our monday.com App (Mass Email for CRM)
If you install our app Mass Email for CRM inside your monday.com account, the following applies. The app is a tool you point at your own monday data to send email to your own contacts. We do not collect or sell that data.
What the app accesses. With your authorization, monday grants the app access to your boards data (to read the recipient rows and email column on the board where you use it, and to write the result of each send back to that board), your profile, and general account information (to scope stored data to your account). After a send, the app records the outcome on the board: on first use it creates two columns ("Email status" and "Last emailed") and updates them per recipient (Sent / Failed / Unsubscribed, and the send date). If you turn on open and click tracking, engagement results (Opened / Clicked / Bounced / Complained) are written to the same board. The app only creates and updates these status columns; it does not alter your existing board content. monday grants board access at the account level; in practice the app reads and writes only the board on which you have opened it, and only when you use it.
What the app stores, and where. A small amount of data is stored inside monday.com's own infrastructure (monday Code storage and secure storage), scoped to your account: your email-sending settings (the API key for your own Resend account, held in monday's secure storage and never shown again after you save it; your "from" address; a warm-up flag), your suppression list (addresses that unsubscribed), sending-job records, and a monday installation token used to record unsubscribes and run background sends. We do not keep a separate database of our own for this content.
Email content and recipients. When you send, the message and recipient addresses are transmitted to your own connected email provider (Resend) for delivery, under Resend's terms. Each send also creates a job record in monday storage, so that the send can be driven in batches and resumed if it is interrupted. While a send is still running, that record holds the subject and body of that send, the recipient addresses, and the per-recipient result, so the send can pick up where it left off. As soon as a send finishes, whether it completed or ended in failure, the app clears the subject, body, and recipient addresses from that record and leaves only a summary: the date, the sending address, the board, and how many messages were sent, failed, or skipped. Job records created before this clearing was introduced are cleared the first time they are read after the update. Separately, unsubscribed addresses are kept in your suppression list for as long as the app is installed, so that opt-outs are honored on later sends. If you enable open and click tracking, Resend reports those events to an endpoint on monday code, which records them on your own board; we do not keep a separate copy of them or use them to build recipient profiles. You are the sender and are responsible for having a lawful basis to email your contacts.
How you heard about us. The app asks one optional question, once: where you first heard about it. You pick a category (marketplace, search, referral, social, or other) and may add a short note describing the channel. The answer is stored in monday's secure storage, scoped to your account. We use it only in aggregate, to understand which channels bring installs. It is never shared with a third party, and it is deleted when you uninstall the app.
Uninstalling the app removes its access to this stored data. You may request deletion at any time via hello@tovrio.com.
3b. Our monday.com App (Apex - Cross-Board Rollup)
If you install our app Apex - Cross-Board Rollup inside your monday.com account, the following applies. Apex aggregates numbers across your own monday boards into a single column on your summary board. We do not collect or sell that data.
What the app accesses. With your authorization, monday grants the app access to your boards data (to read the number and status columns and item counts from the source boards you select, and to write the computed total into a Number column on your summary board), your profile, and general account information (to scope stored data to your account and to verify the connecting account). The board data Apex reads is typically operational numbers (amounts, counts, durations), not personal data. The app only writes to the specific target column you configure for each rollup rule; it does not alter your other board content.
What the app stores, and where. A small amount of data is stored inside monday.com's own infrastructure (monday Code storage and secure storage), scoped to your account: your monday OAuth token (in secure storage), and your rollup rule definitions (which source boards, which column, which aggregation, and the target item and column). We do not keep a separate database of our own.
Exported reports. When you export a report, it is generated on demand from your own rollup results plus a company name, subtitle, and logo you optionally provide for branding. The report opens in a new browser tab for you to save as a PDF; we do not store or share it.
How you heard about us. The app asks one optional question, once: where you first heard about it. You pick a category (marketplace, search, referral, social, or other) and may add a short note describing the channel. The answer is stored in monday's secure storage, scoped to your account. We use it only in aggregate, to understand which channels bring installs. It is never shared with a third party.
Uninstalling the app removes its access to this stored data. You may request deletion at any time via hello@tovrio.com.
3c. Our monday.com App (Placet: Approvals)
If you install our app Placet: Approvals inside your monday.com account, the following applies. Placet lets you request and record approvals on your own monday items. We do not collect or sell that data.
What the app accesses. With your authorization, monday grants the app access to your boards data (to read the item the approval is attached to, to write the approval status back to its own column on that board, and to post each decision to the item's updates), your profile and the other users in the account (to identify approvers and show them by name instead of raw IDs), general account information (to scope stored data to your account), and permission to send notifications (to alert the next approver when it is their turn). The app only creates and updates its own status column and the item's updates; it does not alter your existing board content.
What the app stores, and where. A small amount of data is stored inside monday.com's own infrastructure (monday Code storage and secure storage), scoped to your account: your monday OAuth token (in secure storage), and the approval state for each item, the approver chain, the decisions and any comments, and the timestamped audit trail. We do not keep a separate database of our own.
Uninstalling the app removes its access to this stored data. You may request deletion at any time via hello@tovrio.com.
3d. Our monday.com App (Obsign: Documents)
If you install our app Obsign: Documents inside your monday.com account, the following applies. The app turns a monday item into a PDF using a Word template you upload, and, where you enable it, routes that PDF for approval and keeps a record of what was approved.
What the app accesses. With your authorization, monday grants the app access to your boards data (to read the item you opened it on, that item's subitems, and the board's column list, so those values can be merged into your template, and to write back only where you explicitly ask for it), your profile and general account information (to scope stored data to your account), and your account's user and team lists (to check that the person asking is allowed to see that board, and to let you choose approvers by name). We read no email addresses. We do not collect or sell your board data.
Writing back is explicit. The app can attach a PDF to a file column you pick, post it to the item's updates, or deliver it on approval. Each of these is off until you turn it on. The app never changes your existing column values and never creates columns.
What the app stores, and where. All of it lives inside monday.com's own infrastructure, scoped to your account. In monday Object storage: the .docx templates you upload, draft PDFs, approved PDFs, the board values captured alongside them, version records, and the approval event chain. In monday Storage: the approval ledger head and a monthly render count. In monday secure storage: the monday OAuth token. We operate no database of our own.
How long we keep it. A draft PDF, and the board values captured with it, expire 24 hours after rendering. An approved PDF, and the values it was built from, are kept for as long as you keep that version, and go when it goes. Version records and the approval event chain are kept as an audit trail, so that someone can prove later which version was approved and by whom. In that trail the board values appear only as salted hashes, never as field values: the layer we keep longest holds the least.
A PDF you choose to attach to a file column becomes an ordinary file on your own board, created at your request and under your control like any other file there.
External service (document conversion). Converting .docx to PDF runs on a LibreOffice-based converter we host outside monday code and reach over TLS. It is called once per render: the app posts the assembled document, the converter writes it into a temporary directory for that job, converts it, returns the PDF, and deletes that directory. It has no database and keeps no customer content. The only thing it writes to disk is an anonymous monthly counter of the form {"month":"YYYY-MM","count":N}, which holds no account identifier, no user identifier and no document content.
What we do not do. We do not share your data with any other third party, and we do not use it for profiling, model training or resale.
3. Third-Party Services
We use the following third-party services to operate Tovrio:
- Paddle.com Market Limited , payment processing, tax compliance, invoicing. See Paddle's Privacy Policy.
- Vercel Inc., website hosting and traffic measurement for the tovrio.com website (Vercel Analytics). Not used in our monday apps. See Vercel's Privacy Policy.
- GitHub, Inc., product delivery (private repository access).
- Google LLC (Gmail) , email communications from hello@tovrio.com.
- Google LLC (Google Analytics) , traffic measurement for the tovrio.com website. Not used in our monday apps.
- monday.com Ltd., hosting and storage for our monday apps, Mass Email for CRM, Apex - Cross-Board Rollup, Placet: Approvals, and Obsign: Documents (they run on monday Code).
- Resend, the email delivery provider for Mass Email for CRM. You connect your own Resend account, either by authorising it over OAuth or by entering your own API key. Email you send passes through Resend for delivery.
The apps themselves contact only the following external hosts, each of them required for the app to function. There are no advertising, analytics, monitoring, or CDN third parties, and no tracking scripts in the app's frontend:
- auth.monday.com, OAuth install and token exchange.
- api.monday.com, the monday GraphQL API, used to read the board data you point the app at and to write results back to your board.
- api.resend.com, your own Resend account, which you connect over OAuth or with your own API key. Used by Mass Email for CRM to send your email, register the delivery and tracking webhook, and verify your sending domain. Apex - Cross-Board Rollup, Placet: Approvals and Obsign: Documents do not contact it.
- conv.tovrio.com, our own LibreOffice-based document converter, described in Section 3d. Used by Obsign: Documents to turn the assembled .docx into a PDF, once per render. Mass Email for CRM, Apex - Cross-Board Rollup and Placet: Approvals do not contact it.
Mass Email for CRM also links out to resend.com when you click a setup button, which opens Resend's own site in a new browser tab. The app sends no data there.
4. Data Retention
We retain your information for as long as necessary to provide the Product, comply with legal obligations, resolve disputes, and enforce our agreements. Purchase records are retained for at least 5 years to meet Korean accounting and tax requirements.
5. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information (subject to legal retention obligations).
- Withdraw consent for marketing communications at any time.
- Export your information in a portable format.
To exercise these rights, email hello@tovrio.com.
6. Security
We use reasonable administrative, technical, and physical safeguards to protect your information. Payment data is handled by Paddle under PCI-DSS compliance. However, no method of electronic transmission or storage is 100% secure.
7. Children's Privacy
Tovrio is not intended for individuals under 16 years of age. We do not knowingly collect information from children under 16. If you believe we have collected such information, contact us to have it removed.
8. International Transfers
Our service providers (Paddle, Vercel, GitHub, Google, monday.com, Resend) may process your information outside of your country of residence. By using Tovrio, you consent to such transfers.
9. Changes
We may update this Privacy Policy from time to time. We will notify customers of material changes by email. Continued use of the Product after changes constitutes acceptance.
10. Contact
Questions about this Privacy Policy? Email hello@tovrio.com.