1. Who operates SheetPins
SheetPins and the Sablemark Labs brand are operated by Sean Fujiwara, a sole proprietor based in California, United States (“Sablemark Labs,” “we,” “us,” or “our”). This is the same operator identified in the SheetPins marketplace submission and Terms of Service.
Questions or privacy requests can be sent to support@sheetpins.app.
2. Scope
This policy covers the public website at sheetpins.app, support correspondence, and the SheetPins application installed in a monday.com account. monday.com separately controls information it collects through its platform, accounts, marketplace, billing, and native assets under its own privacy terms.
If your organization provides your monday.com account, that organization may control the board content and decide how its users may use SheetPins. Contact your organization for questions about its own data practices.
3. Information SheetPins processes
Account and authorization information
- monday account, user, board, and Board View identifiers supplied in a signed monday session;
- monday app subscription state and plan identifiers needed to apply Free or Pro limits; and
- user-specific monday OAuth access and refresh credentials needed to verify current board access and support connected operations.
Shared SheetPins workspace information
- PDF asset references and metadata, including the monday asset, source item and Files column identifiers, filename, size, page count, timestamps, and revision history;
- pin identifiers, PDF page and normalized coordinates, linked monday item identifiers, creation timestamps, and optional pin notes; and
- mappings to the board columns selected for status, owner, priority, due date, and site photos.
Content processed temporarily
To display a plan, synchronize tasks, upload or show photos, and generate a punch-list report, SheetPins temporarily processes the current PDF bytes, image bytes, filenames, item titles and field values, user display names, and other content requested from the relevant monday board. Current PDF plans, site photos, and live item fields are not copied into the SheetPins workspace database. Generated reports are returned to the requesting browser and are not retained by SheetPins.
Technical and support information
- privacy-limited application log events such as an opaque request ID, route template, result status, duration, timestamp, and diagnostic stage; and
- information you choose to include in support email, such as an error description, platform, and opaque support ID.
SheetPins logs are designed not to include access tokens, customer names, item fields, filenames, PDF or photo contents, or raw monday account, board, view, and user identifiers.
Browser storage, cookies, and analytics
SheetPins may store only the current user's last-opened saved PDF identifier in browser local storage as a navigation convenience. The public website does not intentionally set cookies, use advertising pixels, or run analytics. monday.com and Cloudflare may process standard platform or network information under their own policies when they deliver the application or website.
4. How and why we use information
We process the information above to:
- authenticate users and verify access to the requested board;
- load, save, synchronize, and protect a Board View workspace;
- resolve monday PDFs and site photos requested by an authorized user;
- create or link board items and update selected live fields;
- generate a requested Pro punch-list PDF;
- apply subscription entitlements and product limits;
- prevent abuse, investigate errors, and maintain service security;
- answer support and privacy requests; and
- comply with legal obligations and enforce our Terms.
Depending on where you are located, the legal basis may be performance of the service agreement, our legitimate interest in operating and securing SheetPins, your consent where requested, or compliance with law.
5. Storage and security
Authoritative SheetPins workspace metadata is stored in monday code Document DB. Encrypted, user-specific OAuth credentials and limited legacy migration records use monday code storage. Multi-region deployments route application storage and processing to the monday code region associated with the customer account: United States, European Union, Australia, or Israel.
OAuth credentials are encrypted using AES-256-GCM before storage. The application uses signed short-lived monday sessions, user-specific OAuth authorization, live board-access checks, tenant-separated opaque storage keys, authorization checks on every protected API request, HTTPS, bounded inputs, and concurrency controls. No transmission or storage system can be guaranteed completely secure.
The public website is delivered over HTTPS through Cloudflare and uses restrictive browser security headers. It contains no account login, customer-document upload, analytics, or advertising code.
6. Service providers and disclosures
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We disclose information only as needed to operate SheetPins, comply with law, protect rights and security, or complete a business transfer.
| Provider | Purpose | Relevant domains/products |
|---|---|---|
| monday.com | App installation, authentication, API access, Board View delivery, regional monday code hosting/storage/logging, native file assets, subscriptions, and billing. | monday.com, api.monday.com, auth.monday.com, regional *.monday.app services, and temporary monday-controlled asset or CDN hosts returned by the monday API. |
| Cloudflare | Public website hosting, DNS, TLS, network security, and routing email sent to the SheetPins support address. | sheetpins.app, Cloudflare Workers static-asset hosting, DNS, and Email Routing. |
These providers may use their own infrastructure providers and process limited technical information according to their terms and privacy policies. We may also disclose information when reasonably necessary to comply with legal process, prevent fraud or harm, enforce agreements, or protect users and the public.
7. Retention and deletion
- Workspace metadata: retained while SheetPins is installed and the workspace is needed to provide the service.
- OAuth credentials: retained while the connection remains active and deleted after disconnection, uninstall, or account termination, subject to retry-safe cleanup.
- Application logs: available only through monday code for the platform-provided retention window; SheetPins does not export them to a separate analytics or log warehouse.
- Support correspondence: retained only as long as reasonably needed to resolve the request, maintain security and business records, or meet legal obligations.
- Local preference: the last-opened PDF identifier remains in the user's browser storage until it is cleared by the browser, host, or user.
When monday.com or an authorized customer deauthorizes, uninstalls, or terminates SheetPins, app-controlled end-user data is scheduled for authenticated deletion and will be deleted no later than 10 days unless retention is required by law. Native monday board items, PDFs, and site photos remain under the customer's control in monday and are not deleted merely because SheetPins is uninstalled.
8. Your privacy choices and rights
Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or receive a portable copy of personal information controlled by SheetPins. You may also disconnect SheetPins' monday authorization or ask your monday administrator to uninstall the app.
Send a request to support@sheetpins.app. We may need to verify your identity and authority through your monday account before acting. We will not discriminate against you for exercising an applicable privacy right. Authorized agents may submit requests where permitted by law, subject to verification.
9. International processing
monday app data is processed through the regional monday code deployment associated with the customer account. Website requests and support correspondence may be processed in the United States and other locations where Cloudflare or the operator's service providers operate. Where required, providers use legal mechanisms intended to support cross-border transfers.
10. Children
SheetPins is a business productivity application and is not directed to children under 13. We do not knowingly collect personal information directly from children. If you believe a child supplied information to us, contact support so we can review and delete it as appropriate.
11. Changes to this policy
We may update this policy as SheetPins, our providers, or legal requirements change. We will post the revised policy here with a new effective date. If a change materially affects how we handle information, we will provide additional notice through a reasonable channel when required.
12. Contact
Privacy questions and requests:
Sablemark Labs / SheetPins
Operated by Sean Fujiwara
California, United States
support@sheetpins.app