Privacy
Privacy Policy
Subitem Bulk Date Shift ("the app", "we", "us") is a monday.com marketplace application that shifts the dates on subitems in bulk. This policy explains what the app does with your data, why, and the choices you have. It is written to be read, not just filed away, so plain language comes first and the legal shape follows.
The app is built and maintained by MD. Mohibur Rahman, an individual developer. Questions about anything below can go to monday-support@rnui.dev.
The short version
The app runs entirely on monday code, monday.com's own hosting infrastructure. Everything it stores stays there, scoped to your account. Nothing is sent to any outside company. There is no advertising, no analytics sold on, and no AI or large language model in the loop. When you uninstall the app, its data goes with it.
What we collect and why
The app only touches data it needs to do its one job. Concretely, per monday.com account, it stores:
| What | Why we keep it |
|---|---|
| OAuth access token | To call monday.com's API on your behalf when you shift dates. Held in monday's SecureStorage, keyed by account ID. |
| Audit log | So you can see who shifted which subitems and when. This records the acting user's ID and name, the board ID, and timestamps. |
| Presets | Your saved date-offset configurations, personal or shared with your team, so you don't re-enter them each time. |
| Pre-apply snapshots | The date values that existed before a shift, kept so you can undo or restore them. |
That is the whole list. To be explicit about what the app does not collect:
- No email addresses.
- No payment or billing data.
- No board content beyond the date-column values the app has to read and write.
- Nothing sent to external services of any kind.
The app performs no profiling, runs no advertising, and does not feed your data into any AI or machine-learning system.
Permissions the app requests
The app authenticates through OAuth only — it never asks for your password. During installation you grant a fixed set of monday.com scopes, each of which maps to something the app actually does:
me:read,account:read,users:read— to identify the acting user and account for the audit log and to scope data correctly.boards:read,boards:write— to read the current date values and write the shifted ones.notifications:write— to notify you about the results of an operation.
Legal basis for processing
For users in jurisdictions where a legal basis is required (for example, under the EU/UK GDPR), we rely on:
- Performance of a contract — processing needed to provide the app's functionality you asked for.
- Legitimate interests — keeping an audit log and pre-apply snapshots so that changes are traceable and reversible, which protects both you and your team's data.
Where you or your organization act as the data controller for the monday.com content involved, the app operates as a processor carrying out the actions you initiate.
Storage and security
All data lives on monday code, isolated per account. Access tokens are held in monday's SecureStorage rather than in plain application storage. Every query the app runs is scoped by a JWT tied to a single account, so one account's data is never reachable from another's. Because hosting sits inside monday.com's infrastructure, the app inherits the security controls monday.com maintains for that platform.
Sub-processors
The app uses exactly one sub-processor: monday.com (monday.com Ltd.), which provides the hosting, storage, and API the app runs on. No other third party receives your data. Your use of monday.com is also governed by monday.com's own privacy policy.
Retention and deletion
Data is kept only as long as the app is installed and only for the purposes above:
- Access tokens are held while the app is installed and are used solely to act on your behalf.
- Audit logs and snapshots are retained so history and undo remain available to you.
- Presets persist until you delete them.
When you uninstall the app, its stored data is deleted. If you want specific data removed sooner — an old preset, for instance — you can delete it in the app, or contact us at the address below.
Your rights
Depending on where you live, you may have rights under laws such as the GDPR or the CCPA, including the right to access the data the app holds about you, to correct or delete it, and to object to or restrict certain processing. We do not sell personal information and never have.
Much of this you can exercise directly: presets and snapshots are visible and removable inside the app, and uninstalling removes the rest. For anything you can't do yourself, email monday-support@rnui.dev and we'll help.
International transfers
The app stores and processes data wherever monday.com hosts the relevant monday code region for your account. If your data crosses borders, it does so within monday.com's infrastructure and under the safeguards monday.com applies to such transfers.
Children
The app is a workplace tool aimed at monday.com account holders. It is not directed at children and does not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy as the app evolves or as the law requires. When we do, we'll revise the effective date at the top. Material changes will be communicated through the app's marketplace listing or documentation.
Contact
Questions, requests, or concerns about this policy or your data:
MD. Mohibur Rahman
Email: monday-support@rnui.dev