Privacy Policy
Last updated: August 2026
MonthMark is currently in a pre-launch, waitlist and validation stage. Today we collect only the information needed to operate the website, waitlist, and concierge validation pilot. This policy also explains how we intend to handle account, analytics, client, AI, and report data if the founding beta opens. We will update this policy before paid beta access begins and whenever our processing practices materially change.
Who we are
MonthMark is currently operated by Skar Consulting (Christer Skar), a sole proprietorship registered in Norway and based in Langhus, Norway. If the legal entity operating MonthMark changes before the paid beta, this policy will be updated before payments or production data processing begin.
For questions about this policy or your personal data, contact christer@monthmark.app .
Our role under data protection law
MonthMark may have different roles depending on whose personal data we are processing and why it is being processed.
- For MonthMark account holders, waitlist members, validation pilot applicants, website visitors, and billing contacts, MonthMark generally acts as the data controller and determines why and how that information is processed.
- For personal data that an agency provides about its own clients or client contacts, the agency generally acts as the data controller and MonthMark acts as a data processor, processing that information on the agency's instructions to provide the requested MonthMark service or validation pilot.
Where a concierge validation pilot or later paid MonthMark service requires MonthMark to process personal data on behalf of an agency, an appropriate Data Processing Addendum ("DPA") will be made available before that processing begins where required.
What we collect today
Waitlist information
If you join the waitlist, we collect the email address you submit through our form provider, Tally. We use it to send information about the MonthMark beta and occasional build updates that you requested.
Concierge pilot requests
If you apply for the concierge validation pilot, we collect your work email address, agency name, preferred method for sharing GA4 data, and any optional information you provide about your current reporting setup.
We use this information to assess your pilot request, contact you about the request, and, if accepted, arrange the next steps.
Submitting a pilot request does not add you to the MonthMark waitlist or marketing list.
Please do not submit client names, GA4 exports, login credentials, or other client data through the pilot application form. If your request is accepted, we will arrange any client-data sharing separately.
Accepted concierge pilot data
If your agency is accepted for the concierge validation pilot, you may choose to provide a GA4 export or arrange read-only access to reporting data for one client account.
We use that data only as reasonably necessary to prepare the requested MonthMark pilot report, create the accompanying talking-point brief, discuss the result with you, and evaluate whether the MonthMark concept is useful to agencies.
We ask participating agencies to provide only the data reasonably necessary for the pilot. You are responsible for ensuring that you are authorised to share or provide access to the relevant client data.
If an accepted pilot would require MonthMark to process personal data on behalf of your agency, we will address the applicable data-processing arrangements before that processing begins.
We do not sell waitlist information or pilot-request information or provide it to third parties for their independent advertising or marketing purposes.
Website analytics
We use Vercel Web Analytics to understand aggregate website usage, such as page views, referrers, general geographic region, browser, operating system, and device type.
Vercel Web Analytics is designed to provide anonymized website analytics without using cookies to identify visitors across websites.
What we plan to collect if the beta opens
Account and agency information
Depending on the features you use, this may include:
- Your name and email address
- Your agency or business name
- Logo, colors, and other report branding
- Your subscription plan
- Connected client accounts and properties
- Service preferences and report configuration
Your clients' data
When you use MonthMark to prepare or deliver reports for your clients, we may process information that you provide about those clients, including:
- Client or company names
- Client contact names and email addresses used for report delivery
- Report delivery status
- Report page visits and report interactions
- Clicks on tracked links where enabled
- Email engagement events, such as opens, where technically available and where that functionality has been introduced
Email-open information is inherently imperfect because email clients can block, proxy, cache, or automatically load tracking content. MonthMark therefore treats email opens only as a low-confidence supporting signal and does not use a missed email open by itself to determine that a client is at risk.
Google Analytics 4 data
During the concierge validation pilot, participating agencies may choose to provide a GA4 export or arrange read-only viewer access separately.
For the planned MonthMark beta, MonthMark intends to connect to Google Analytics using Google's authorization process and request only the permissions reasonably needed to provide the reporting features you choose to use.
MonthMark's planned GA4 integration uses read-only access. Depending on your report configuration, MonthMark may access analytics information such as:
- Sessions and user counts
- Engagement metrics
- Conversion or key-event data
- Traffic sources and campaign information
- Revenue and ecommerce information where available
- Historical reporting periods needed for comparisons and trends
MonthMark uses this information to create client reports, period-over-period comparisons, narrative summaries, trend analysis, and business-impact explanations based on the connected data.
If roadmap features such as Client Retention Scores, churn-risk signals, advanced Value Translation, or client talking points are later introduced, relevant connected data may also be used to provide those features.
MonthMark cannot use read-only GA4 access to change your Google Analytics configuration or analytics data.
When the production Google integration is available, you will be able to revoke MonthMark's Google access using the controls made available by MonthMark or directly through your Google account.
Google API Limited Use
MonthMark's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
Google API data is used only to provide or improve the user-facing MonthMark features that you authorize. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI or machine-learning models.
Where Google data needs to be processed by a service provider in order to deliver an authorized MonthMark feature, the processing is limited to providing that feature and is subject to appropriate contractual and security safeguards.
Google Ads or other Google integrations may be added in later product phases. This policy will be updated before MonthMark requests access to additional categories of Google user data.
Generated reports and AI content
MonthMark may process analytics data and report context to generate content on behalf of your agency, including:
- Plain-language performance summaries
- "So what?" explanations of important metrics
- Period-over-period comparisons
- Business-impact explanations based on observed connected data
If roadmap functionality is later introduced, generated content may also include Client Retention Scores, churn-risk signals, client talking points, advanced attribution, or other account-health analysis.
When reliable revenue data is available from connected sources, MonthMark may show that revenue as observed data.
Where a monetary value is attributed, modelled, or otherwise estimated, it will be identified as an estimate. If the available data cannot support a reasonable monetary value, MonthMark is designed to leave it out rather than invent one.
Generated reports may be stored so that you can review, edit, deliver, and reference them later, subject to the applicable retention practices.
Billing information
Payment processing is currently planned to be handled by Paddle. MonthMark would receive information needed to manage your subscription, such as payment status, subscription status, plan, billing identifiers, and transaction information, but would not store your full payment-card details.
How we use AI
MonthMark may use external large language model APIs to help transform analytics and report data into narrative summaries, business context, recommendations, and other user-facing report content.
MonthMark does not use customer or client data to train its own general-purpose AI models.
Before client data from an accepted concierge pilot is sent to an external AI provider, MonthMark will disclose the relevant provider and processing arrangement to the participating agency as appropriate.
Before the paid beta opens, we will identify the AI provider or providers used for production processing and use business/API arrangements designed so that customer content is processed to provide the MonthMark service rather than to train general-purpose models.
Relevant production AI providers will also be identified in MonthMark's subprocessor information before production customer data is processed.
AI-generated content is intended to assist the agency and may contain errors, incomplete information, or conclusions that require additional business context.
The founding beta is designed to allow customers to review and edit generated content before client delivery. Automatic delivery may be introduced later as an optional feature.
Roadmap: Client Retention Scores and automated analysis
Client Retention Scores, churn-risk signals, deeper report-engagement intelligence, and similar account-health functionality are currently roadmap concepts rather than guaranteed founding-beta features.
If this roadmap functionality is introduced, MonthMark may use automated analysis to identify patterns in report engagement and marketing performance and to produce Client Retention Scores, account-health indicators, or churn-risk signals.
These signals would be designed as business-assistance tools for agencies. They are not intended to make decisions that produce legal or similarly significant effects for an individual.
Relevant signals could include report interactions, clicks, performance trends, conversion changes, account context, and other data made available to MonthMark.
Email opens, where available, would be treated only as a supporting signal because they may not reliably represent actual human engagement.
Why we process personal data
Depending on the circumstances, MonthMark processes personal data on one or more of the following bases:
- Consent — for example, when you voluntarily join the waitlist and request product updates.
- Performance of a contract — where processing is necessary to create and manage a paid account or provide MonthMark services under an applicable agreement.
- Legitimate interests — where reasonably necessary to operate, secure, maintain, improve, and understand MonthMark, including evaluating and responding to concierge validation pilot requests and conducting product validation, provided those interests are not overridden by your rights.
- Legal obligations — where we must retain or disclose certain information to comply with applicable law, accounting, tax, fraud-prevention, or regulatory requirements.
Where MonthMark processes personal data solely on behalf of an agency customer or pilot participant, the agency remains responsible for determining the appropriate legal basis for its own processing and for its instructions to MonthMark.
Cookies & website analytics
MonthMark currently uses Vercel Web Analytics for aggregate website analytics. Vercel Web Analytics is designed to store anonymized analytics data without using cookies to identify visitors.
If MonthMark later introduces analytics, advertising, or other technologies that require additional cookies or consent, this policy and the website's consent controls will be updated before those technologies are enabled where required.
Service providers and subprocessors
We use third-party providers where needed to operate MonthMark. They may process information to the extent required to provide their services to us and subject to the applicable contractual, privacy, and security arrangements.
Current pre-launch providers
- Tally — waitlist and validation pilot application forms
- Vercel — website hosting and web analytics
Additional providers may be used for an accepted concierge pilot where needed to create the requested report. Where a provider will process client data, relevant information will be provided to the participating agency before such processing where appropriate.
Planned beta providers
- Google — authorization and connected analytics services
- Paddle — planned payments and subscription billing
- AI API provider(s) — narrative and report generation; exact production provider(s) will be identified before beta processing begins
- Email delivery provider — transactional and report email delivery; the selected provider will be identified before beta
- Cloud, database, and storage providers — used to host the application and customer data; final production providers will be identified before beta
Before the paid beta opens, MonthMark will update this section or provide a dedicated subprocessor list reflecting the production services actually in use.
International data transfers
Some service providers may process information outside Norway or the European Economic Area.
Where personal data is transferred to a country that is not covered by an applicable adequacy decision, MonthMark will use an appropriate transfer mechanism where required, such as approved Standard Contractual Clauses, together with additional safeguards where appropriate.
Data Processing Addendum
Where MonthMark processes personal data on behalf of an agency, the agency generally acts as controller and MonthMark as processor for that processing.
If an accepted concierge validation pilot requires such processing, an appropriate Data Processing Addendum will be made available before that processing begins where required.
A production DPA will also be available before paid beta processing of customer client-data begins.
The DPA will address matters such as the nature and purpose of processing, categories of personal data, confidentiality, security, subprocessors, retention, deletion, data-subject assistance, and other applicable processor obligations.
Security
MonthMark is designed to apply appropriate technical and organisational safeguards to customer information.
Planned production safeguards include encrypted network connections, encrypted storage for sensitive credentials, access controls, least-privilege permissions, and secure handling of authorization tokens.
During the manual concierge validation phase, access to pilot data will be limited to what is reasonably necessary to prepare and evaluate the requested report.
No online service can guarantee absolute security. We will update this policy and our security documentation as the production architecture is finalized.
Data retention & deletion
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to contractual, security, or legal retention requirements.
Pre-launch waitlist
Waitlist information is retained while we prepare and operate the founding beta unless you unsubscribe or request deletion earlier.
Concierge pilot requests
Pilot-request information is retained while we evaluate and run the validation pilot and for as long as reasonably necessary for pilot-related follow-up and product validation.
It is then deleted or anonymized unless you separately join the MonthMark waitlist, become a MonthMark customer, or limited retention is reasonably necessary for legal or security purposes.
Accepted concierge pilot data
GA4 exports, analytics information, generated reports, and other data provided for an accepted concierge pilot are retained only for as long as reasonably necessary to prepare the requested report, conduct the agreed follow-up, and evaluate the pilot.
Pilot data will then be deleted or anonymized unless a longer period is separately agreed with the participating agency or retention is required for legal, security, or other legitimate purposes.
Beta customer data
- Account information is retained while your account is active and as required afterwards for legitimate billing, tax, security, or legal purposes.
- Generated reports are currently intended to be retained for up to 12 months by default unless deleted earlier or a different retention setting is offered.
- Authorization tokens are deleted or invalidated when the applicable connection is removed or the account is deleted, subject to technical backup and security requirements.
- Client lists and related service data are deleted following account deletion, subject to limited backup, security, billing, and legal retention requirements.
Production deletion and backup-retention periods will be finalized and published before the paid beta begins.
You may contact christer@monthmark.app to request account or personal-data deletion.
Your rights
Where GDPR or similar data-protection law applies, you may have rights including the right to:
- Request access to personal data we hold about you
- Request correction of inaccurate personal data
- Request deletion of personal data
- Request restriction of processing
- Object to certain processing
- Receive eligible personal data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with the relevant data protection supervisory authority
Contact christer@monthmark.app to exercise a right relating to information for which MonthMark is the controller.
If your request concerns personal data that MonthMark processes only on behalf of an agency customer or pilot participant, we may refer the request to that agency or assist the agency in responding.
Sale and advertising use of personal data
MonthMark does not sell customer, pilot, or client personal data.
We do not use Google user data or customer report data for third-party advertising, behavioural advertising, or data-broker purposes.
Changes to this policy
We may update this policy as MonthMark develops. The current version will always be published here with its latest update date.
If a material change affects existing account holders, pilot participants, or materially changes how their data is used, we will provide appropriate notice before the new processing begins where required.
Contact
Questions, privacy requests, or deletion requests can be sent to:
← Back to MonthMark