Privacy Policy
Learn how Moneiva protects your data with SOC2 and CASA2 compliant security measures.
We never use your information for targeted marketing or sell it to third parties.
Effective Date
This Privacy Policy is effective as of November 3, 2025. Moneiva LLC ("Moneiva," "we," "us," or "our") is committed to protecting your privacy and handling your personal information with the highest standards of security and transparency.
Scope and Applicability
This Privacy Policy applies to all information collected through our website (www.moneiva.com), mobile applications, and services (collectively, the "Services"). By using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein.
Information We Collect
We collect only the minimum information necessary to provide our Services. This includes: (1) Information you voluntarily provide when requesting services, such as your name, email address, phone number, company name, and message content when using our contact forms or requesting support; (2) Technical information automatically collected for internal analytics purposes only, including IP address, browser type, operating system, pages visited, time spent on pages, and referring URLs. We do not use cookies or any tracking technologies for targeted marketing, advertising, or third-party communication purposes. All data collection serves solely to deliver the services you request and to analyze internal usage patterns for business improvement.
How We Use Your Information
Your information is used exclusively to provide the Services you request from Moneiva. Specifically, we use your information to: (1) Respond to your inquiries and service requests; (2) Provide customer support and technical assistance; (3) Improve our Services through internal analytics and usage pattern analysis; (4) Send administrative communications related to your requests; (5) Comply with legal obligations and enforce our Terms of Service. We do not and will never use your information for targeted marketing, advertising, behavioral tracking, or profiling. We do not sell, rent, lease, or share your personal information with any third parties for their marketing purposes.
Data Sharing and Third-Party Disclosure
Moneiva does not sell, rent, or trade your personal information to any third parties under any circumstances. We may share your information only in the following limited situations: (1) Service Providers: We may engage trusted third-party service providers who assist us in operating our Services, conducting our business, or servicing you, provided they agree to keep this information confidential and use it only for the specific services they provide to us; (2) Legal Compliance: We may disclose your information when required by law, legal process, litigation, or requests from governmental authorities; (3) Business Protection: We may disclose information to protect and defend our rights, property, or safety, or that of our users or the public, as required or permitted by law; (4) Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred, subject to the same privacy protections outlined in this policy.
Google User Data
Moneiva's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, Moneiva accesses your Google data solely to provide the workflow features you configure: reading and labeling email messages you direct our workflows to process (Gmail); appending rows to and reading spreadsheets you select (Google Sheets); listing your spreadsheets and documents by name so you can pick them (Google Drive metadata); reading, appending to and creating documents you select (Google Docs); and posting notification messages, reading replies, adding reactions and creating spaces in Google Chat spaces you choose.
AI processing disclosure: to execute the workflows you configure, the content of individual email messages, documents and chat messages may be transmitted to large-language-model providers - Anthropic, OpenAI, and Google - strictly for per-request inference under your direction. This data is never used to train or improve generalized AI or machine-learning models, by us or by our sub-processors.
Retention and deletion: Google-derived data processed by a workflow is stored in our databases and file storage only as needed to provide the service, and is deleted upon account termination or on request.
You can revoke Moneiva's access at any time from your Google Account security settings or by disconnecting the credential in the app; revocation invalidates our stored tokens immediately.
Data Security - SOC2 and CASA2 Compliance
Moneiva implements comprehensive security controls in accordance with SOC2 (Service Organization Control 2) Type II and CASA2 (Cloud Application Security Assessment) frameworks. Our security measures include: (1) Encryption: All data is encrypted in transit using TLS 1.2 or higher protocols, and encrypted at rest using AES-256 encryption standards; (2) Access Controls: Strict role-based access controls (RBAC) limit data access to authorized personnel only, with multi-factor authentication (MFA) required for all administrative access; (3) Network Security: Firewall protection, intrusion detection and prevention systems (IDS/IPS), and regular vulnerability scanning; (4) Monitoring and Logging: Continuous monitoring, audit logging, and security event management to detect and respond to potential security incidents; (5) Incident Response: Documented incident response procedures with defined escalation paths and breach notification protocols; (6) Regular Audits: Annual third-party security audits and penetration testing to validate our security posture; (7) Employee Training: Mandatory security awareness training for all personnel with access to customer data.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Specifically: (1) Contact and service request information is retained for the duration of the business relationship and for up to seven (7) years thereafter for legal and compliance purposes; (2) Analytics data is aggregated and anonymized for long-term trend analysis, with no personally identifiable information retained beyond thirty (30) days; (3) When your information is no longer required, we securely delete or anonymize it using industry-standard data sanitization methods that comply with NIST 800-88 guidelines.
Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information: (1) Access: The right to request a copy of the personal information we hold about you; (2) Correction: The right to request correction of inaccurate or incomplete information; (3) Deletion: The right to request deletion of your personal information, subject to legal retention requirements; (4) Restriction: The right to request that we restrict processing of your information in certain circumstances; (5) Portability: The right to receive your information in a structured, commonly used, machine-readable format; (6) Objection: The right to object to our processing of your information; (7) Withdraw Consent: The right to withdraw consent at any time where we rely on consent as the legal basis for processing. To exercise any of these rights, please contact us at hello@moneiva.com. We will respond to your request within thirty (30) days in accordance with applicable law.
International Data Transfers
Moneiva operates in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located. By using our Services, you consent to the transfer of your information to the United States. We implement appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy and applicable data protection laws.
Children's Privacy
Our Services are not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information as soon as possible. If you believe we have collected information from a child, please contact us immediately at hello@moneiva.com.
California Privacy Rights (CCPA)
California residents have specific privacy rights under the California Consumer Privacy Act (CCPA). In the preceding twelve (12) months, we have collected the categories of personal information described in the "Information We Collect" section. We do not sell personal information. California residents have the right to: (1) Know what personal information we collect, use, disclose, and sell; (2) Request deletion of personal information; (3) Opt-out of the sale of personal information (though we do not sell personal information); (4) Non-discrimination for exercising CCPA rights. To exercise these rights, contact us at hello@moneiva.com or call our toll-free number.
European Privacy Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). Our legal basis for processing your personal information includes: (1) Consent: Where you have provided explicit consent; (2) Contract: Where processing is necessary to perform a contract with you; (3) Legal Obligation: Where processing is necessary to comply with legal obligations; (4) Legitimate Interests: Where processing is necessary for our legitimate business interests, provided those interests do not override your fundamental rights. You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe our processing violates GDPR requirements.
Cookies and Tracking Technologies
Moneiva uses minimal cookies and tracking technologies, strictly for essential website functionality and internal analytics. We do not use cookies for: (1) Targeted advertising; (2) Marketing communications; (3) Behavioral tracking across websites; (4) Third-party advertising networks; (5) Social media tracking. The cookies we use include: (1) Essential Cookies: Required for basic website functionality, such as session management and security; (2) Analytics Cookies: Used solely for internal business purposes to understand usage patterns, page views, and user interactions. This data is aggregated and anonymized. You can control cookies through your browser settings, though disabling essential cookies may affect website functionality.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the effective date at the top of this policy and, where appropriate, provide additional notice such as a prominent announcement on our website or via email. Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Data Breach Notification
In the unlikely event of a data breach that affects your personal information, Moneiva will notify affected individuals and relevant authorities in accordance with applicable laws. Notification will be provided without undue delay and, where feasible, within seventy-two (72) hours of discovering the breach. Our notification will include: (1) A description of the nature of the breach; (2) The categories and approximate number of individuals affected; (3) The categories and approximate number of personal data records affected; (4) The likely consequences of the breach; (5) Measures taken or proposed to address the breach and mitigate potential adverse effects.
Third-Party Links
Our Services may contain links to third-party websites, applications, or services that are not operated by Moneiva. This Privacy Policy does not apply to third-party websites or services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party sites you visit to understand how they collect, use, and protect your information.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at: Email: hello@moneiva.com | Mailing Address: Moneiva LLC, Privacy Department, 10008 S 163rd Ave, Suite 001 | Phone: 402.740.2069. We are committed to resolving privacy concerns promptly and will respond to your inquiry within five (5) business days.
Questions?
Contact our privacy team for more details about your data.