Privacy Policy

Last updated: May 14, 2026

ChipMonkeys Inc. ("we," "our," or "the Company") operates the Monkey Business Manager platform ("MBM" or "the Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, phone number, and organization details. If you are an operator, we also collect business information such as your company name, EIN, and billing address.

Financial Data

We use Plaid Inc. to connect your bank accounts for transaction monitoring and financial reporting within the platform. When you link your bank account through Plaid, we receive access to your account balances and transaction history. We do not store your bank login credentials. Our use of Plaid is governed by the Plaid End User Privacy Policy.

Payment Information

Payment processing is handled by Stripe Inc. We do not directly store credit card numbers or bank account numbers for payment purposes. Stripe's handling of your data is governed by their privacy policy.

Vehicle & Inspection Data

We collect vehicle information (VIN, make, model, year, color), inspection photos, damage assessments, repair records, and paint match data as part of normal platform operations.

Location Data

With your permission, we collect GPS location data for mileage tracking, technician routing, and NFC tag scan geolocation. Location is captured at the time of specific actions (clock-in, scan, mileage log) and we do not perform continuous background location tracking.

Usage Data and Telemetry

We automatically collect information about how you interact with the platform, including pages visited, features used, timestamps, device type, browser information, action breadcrumbs (job logged, photo captured, invoice marked paid, etc.), canvas dispatch logs (event-driven workflow walks on your blueprint), and standard service logs (request metadata, errors, performance metrics).

Facebook Page Integration

If you choose to connect a Facebook Page so MBM can publish before/after photos on your behalf, we receive and store: your Facebook Page ID and name, a list of Pages you administer, a long-lived Page access token, and a long-lived User access token used to refresh the Page token before it expires. Both tokens are encrypted at rest with AES-256-GCM before being written to our database. We never receive your Facebook password, your personal newsfeed content, your Messenger conversations, or any data about your Facebook friends. We use these tokens solely to publish posts you have explicitly initiated from inside MBM (clicking the "Post to {Page Name}" button on a before/after slider). We do not post on your behalf automatically or without your direct action in MBM. You can disconnect at any time; see "Facebook / Meta Data Deletion" below.

AI Feature Inputs and Outputs

When you use AI-assisted features (transaction categorization, dashboard summaries, draft customer communications, paint-match suggestions, and similar tools), we transmit the relevant inputs (transaction details, business records, prompts) to third-party AI providers including Anthropic and OpenAI to generate the output. Some AI features may also use Google Cloud services. Each provider operates under its own terms and privacy policy. We configure providers to process your data without using it to train public foundation models where commercially reasonable, but we do not guarantee any provider's data-handling practice.

2. How We Use Your Information

  • Provide, operate, and maintain the platform
  • Process invoices, payments, Licensing Fees, and marketplace settlements
  • Display financial dashboards and transaction history
  • Generate payroll, mileage, and expense reports
  • Improve paint-matching accuracy through our Monkey Match system
  • Power AI-assisted features such as transaction categorization, dashboard summaries, paint-match suggestions, and customer communication drafts
  • Send transactional emails (invoices, notifications, reports)
  • Enforce quality standards and accountability (e.g., yellow flag system)
  • Audit reporting per the Technology & Systems License Agreement
  • Provide creator-side analytics to blueprint creators (aggregate install / fork / session counts on their lineage)
  • Comply with legal obligations, including tax reporting and retention requirements

3. How We Share Your Information

We do not sell your personal information. We may share data with:

  • Infrastructure providers: Supabase (database), Vercel (hosting and serverless functions)
  • Payments: Stripe (payment processing, Stripe Connect for marketplace settlements, payouts to your bank)
  • Banking: Plaid (bank-account linking, transaction data when you authorize it)
  • AI providers: Anthropic, OpenAI, and Google (large language models and AI services that power transaction categorization, dashboard summaries, paint-match suggestions, and similar tools when you use AI-assisted features)
  • Meta Platforms (Facebook): If you connect a Facebook Page, we exchange OAuth tokens with Meta to publish posts you initiate. We send only the photo and caption you choose to publish. No other MBM data is transmitted to Meta.
  • Communications: Resend, SendGrid, and similar transactional-email providers; Telnyx for voice and SMS routing
  • Marketplace creators: If you install a third-party blueprint, the blueprint's creator may receive aggregate install, fork, and session counts for the blueprint(s) they published, and creator-side analytics about how their blueprint is being used
  • Your organization: Admins and operators within your organization can view data relevant to their role
  • Dealership/customer partners: Where applicable, dealers and customers can view inspection and repair data for vehicles at their location
  • Legal compliance: When required by law, subpoena, or to protect our rights

We do not sell your personal information.

4. Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, and row-level security policies at the database level. All API keys and secrets are stored securely as environment variables and are never exposed in client-side code. We offer TOTP-based multi-factor authentication (MFA) and may require it for accounts with elevated privileges, financial access, or admin functions.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods by data category, our disposal procedures, and our anonymization policy are set forth in our Data Retention and Disposal Policy. Notable retention periods: financial transaction records are retained for 7 years for IRS compliance, Monkey Match paint-match data is retained indefinitely in anonymized form, location/GPS data is retained for 2 years for mileage reporting, and usage/analytics data is retained for 1 year. You may request deletion of your account and associated data by emailing the contact below; data required for legal or tax compliance is retained but access-restricted for the remainder of the applicable retention window.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correct: Ask us to fix inaccurate or incomplete personal information
  • Delete: Request deletion of your personal information, subject to legal retention requirements
  • Port: Receive a copy of your data in a structured, commonly used, machine-readable format
  • Opt out of sale: We do not sell personal information, but you may confirm this in writing
  • Withdraw consent: Where we process data based on your consent, you may withdraw that consent at any time
  • Lodge a complaint: With a supervisory authority in your jurisdiction

To exercise any of these rights, contact us at the email below. We respond to verified requests within 30 days. We may request additional information to verify your identity before fulfilling a request.

7. Cookies and Tracking

We use first-party cookies and similar technologies to maintain your authenticated session, remember your preferences, and operate the platform. We do not use third-party advertising cookies. Essential cookies cannot be disabled without breaking core platform functionality.

8. International Transfers

We are based in the United States. If you access the platform from outside the United States, your information will be transferred to and processed in the United States. By using the platform, you consent to this transfer.

9. Children's Privacy

The platform is intended for use by adults operating businesses. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it.

10. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities consistent with applicable law and within the timeframes required by your jurisdiction (generally within 72 hours of discovery for breaches affecting EU/UK residents under GDPR, and per the timeline required by the relevant state law for US residents).

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date and, for material changes, by email or in-app notice with at least 30 days' advance notice.

12. Facebook / Meta Data Deletion

If you have connected a Facebook Page to MBM and want us to delete the data we received from Meta (your encrypted Page access token, the encrypted User access token, your Page ID and name, and the list of Pages you administer), you have two options:

  • Inside MBM: Go to Settings → Integrations, find the Facebook Page row, and click the trash icon. This immediately deletes your Meta credential row from our database.
  • From Facebook: Open Facebook Settings → Business Integrations and remove ChipMonkeys Business Manager. Facebook will notify our app that you revoked access; we will then delete the stored token within 30 days as part of normal credential-cleanup processing.

To request explicit deletion of all data MBM holds that originated from Meta (including backups, log entries, and audit history), email brandon@chipmonkeysinc.com with the subject "Facebook Data Deletion Request." We will confirm receipt within 5 business days and complete the deletion within 30 days, subject to any active legal holds.

13. Contact Us

If you have questions about this Privacy Policy, contact us at:

ChipMonkeys Inc.
Email: brandon@chipmonkeysinc.com