Privacy Policy

Last updated: June 4, 2026

GitPipeline is a monday.com marketplace app, operated by IdeaPlaces, that keeps the status of your monday.com tasks in sync with activity in your connected GitHub repositories. This policy explains what data we collect, why we collect it, how we store it, and the choices you have. It applies to the GitPipeline board view and all GitPipeline services at gitpipeline.ideaplaces.com.

1. Who we are

GitPipeline is operated by IdeaPlaces. For any privacy question or request, contact us at support@ideaplaces.com.

2. Data we collect from monday.com

  • Account identifiers. Your monday.com account ID, account name, and account slug, received when the app is installed. These identify your organization in our system.
  • User identifiers. The monday.com user ID, name, and email of the person configuring or using the GitPipeline view. We use these only to attribute configuration changes in an audit trail (for example, who connected a repository or changed a pipeline stage).
  • Board data you connect. Board IDs, item IDs, and the status column you explicitly select in the GitPipeline view. We need these to update the correct status on the correct task and to post task updates.

3. Data we collect from GitHub

  • The GitHub App installation ID for the account you connect.
  • Repository names and IDs for the repositories you grant access to.
  • The contents of incoming webhook payloads: commit messages, pull request titles and numbers, branch names, and author logins. We use these to determine which monday.com task to update and what comment to post.

4. How we use data

We use the data above solely to provide the GitPipeline service: updating task statuses, posting task comments, rendering the board view, and maintaining an activity log of the webhooks we processed. We do not use your data for advertising. We do not sell, rent, or share your data with third parties for their own purposes.

5. Where data is stored and how it is protected

Data is stored in a managed PostgreSQL database hosted on Microsoft Azure in the Canada Central region. Data is encrypted in transit over TLS and encrypted at rest. monday.com and GitHub access tokens are encrypted with AES-256-GCM before they are written to the database. Access to production systems is restricted to authorized IdeaPlaces personnel.

For users in the European Union: data is processed in Canada, which benefits from a European Commission adequacy decision. We do not move personal data outside Canada except as needed to deliver the integration with monday.com and GitHub.

6. Sub-processors

We rely on the following service providers to operate GitPipeline:

  • Microsoft Azure (application hosting and database)
  • Cloudflare (DNS and network)
  • PostHog (product analytics)
  • monday.com and GitHub (the platforms GitPipeline integrates with)

7. Data retention and deletion

When you uninstall GitPipeline from your monday.com account, we mark your organization data for deletion and remove it within 30 days. You can request deletion of your data at any time by emailing support@ideaplaces.com. Backups containing data may persist for a limited additional period before they are rotated out.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact support@ideaplaces.com and we will respond within a reasonable time.

9. Changes to this policy

We may update this policy as the product evolves. When we make a material change, we will update the date at the top of this page. Your continued use of GitPipeline after a change means you accept the updated policy.

10. Contact

Questions about this policy or your data can be sent to support@ideaplaces.com.