Privacy Policy
Last updated: 2026-10-01
This policy explains how Tulip Approvals ("the app"), a monday.com app made by Tulip Apps ("we", "us"), handles information. Tulip Apps is run by Alain Navarro in the Netherlands. Contact: support@tulipapps.app.
The short version
- The app runs entirely inside monday.com. We operate no servers or databases of our own for it.
- Approval records are stored in monday.com's app storage, inside your monday.com account.
- We set no cookies, use no analytics or tracking, and share nothing with third parties.
- Optional AI features run on monday.com's own AI service, only when a user clicks an AI button, and use your account's monday AI credits.
- We do not sell personal data.
What the app processes
| Data | Why | Where it is kept |
|---|---|---|
| Names, user IDs and profile pictures of users in your monday.com account | To let you choose approvers and show who decided | Read from monday.com when needed; names and IDs of requesters and approvers are saved with each approval record |
| Approval records: message, approvers, decisions, comments, timestamps, and names and links of attached item files | To run the approval workflow and keep its history | monday.com app storage for your account |
| Item name, field values, the last 5 updates and attached file names; an approver's draft comment | Only when a user clicks an AI button: to generate the AI review brief or improve the wording of a comment | Sent to monday.com's AI service (monday's AI gateway) for that one request; the result is shown to that user and not stored by the app |
| Item and board IDs, item files list | To attach approvals to the right item and let you attach files | Read from monday.com when needed |
To work, the app writes to your monday.com account on behalf of the signed-in user: notifications to approvers and requesters, notes in the item's Updates, and, if your board has a status column named "Approval", that column's value.
Permissions the app asks for
me:read, users:read (choose approvers), boards:read, boards:write (read the item and set the optional Approval status column), assets:read (list item files), notifications:write (notify approvers and requesters), updates:write (record decisions in Updates), AI:Consume (use monday's AI for the optional AI features).
Legal basis and roles
Under the GDPR, your organisation decides how approval data is used and is the controller. The data is stored by monday.com under your agreement with monday.com. We process it only to provide the app's features, on your instructions.
Retention and deletion
Approval records are kept in monday.com's app storage, which monday.com operates and retains under its own data retention policies, separated per account. They are not stored anywhere else. If the app is uninstalled, the records are kept by monday.com so your history is still there if you reinstall. For questions about removing this data, email support@tulipapps.app and we will help, together with monday.com where needed. The app also keeps a monthly count of approval requests per account, used only to apply plan limits.
Security
The app is served by monday.com over HTTPS and uses monday.com's own authentication. It does not store passwords or API tokens.
Your rights
You can ask for access to, correction of, or deletion of personal data related to the app by emailing us. You can also complain to your data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
Changes
If we change this policy, we will update the date above. Significant changes will be announced in the app's marketplace listing.