Privacy Policy
Explains what data is collected, how it is used, how payments and support data are handled, and how AI/LLM processing may be involved.
Privacy Policy
1. Scope and responsible party
This Policy explains how MonyDragon collects, uses, discloses, and retains personal information when you visit monydragon.com, create an account, request or buy services, apply for a role, communicate with us, or use project and support features. “MonyDragon” means the provider identified in your quote, invoice, order, or other relationship record. This Policy does not control third-party sites or services.
2. Information we collect
Depending on how you interact, we may collect identifiers and account data; contact details; profile and authentication records; project requirements, files, prompts, and communications; quote, invoice, transaction, credit, and subscription metadata; support and chat content; application, résumé, qualification, accommodation-request, and recruiting records; device, browser, IP, approximate location, session, log, fraud, and security data; marketing preferences and consent records; and business records required for tax, accounting, contracts, or compliance. Payment processors, rather than MonyDragon, handle full card credentials.
3. Sources
Information comes from you, your organization and authorized users, site and service activity, connected services you direct us to use, payment and communications providers, security and fraud tools, and public professional sources when relevant and lawful. Candidate reference checks or background information will only be sought through an approved process with any authorization required by law.
4. Purposes
We use information to operate and secure the site; authenticate users; provide estimates, development, consulting, support, communications, and recruiting; process transactions and subscriptions; administer contracts and records; personalize allowed preferences; prevent fraud and abuse; troubleshoot and improve reliability; comply with law; establish or defend claims; and send marketing only where permitted. We do not add applicant information to marketing lists without separate consent.
5. AI-assisted processing
Approved AI and large-language-model services may assist with project prompts, estimating, development, testing, documentation, content, support drafts, and internal workflows. Inputs and outputs may be retained for delivery, security, troubleshooting, and quality review under applicable provider settings. Do not submit sensitive information unless necessary and authorized. Candidate résumé parsing suggests editable fields; any job-related ranking feature must remain advisory, undergo review, and cannot make final decisions or send rejections automatically.
6. Cookies, storage, analytics, and location
Strictly necessary cookies, session tokens, and local or session storage support authentication, security, forms, theme, sound, and privacy preferences. Optional first-party visitor analytics records page path, session identifier, IP address, device data, and approximate location. When optional analytics is allowed, an IP-geolocation provider may receive an IP address to return approximate city, region, country, and timezone. Optional analytics is off until you choose to allow it. You can change that choice on the Privacy Choices page. Browser signals such as Global Privacy Control will be honored where legally required; this site does not use cross-context behavioral advertising in the described analytics flow.
7. Calls, email, and text messages
Transactional messages deliver account, project, purchase, security, or application updates. When you separately opt in, MonyDragon may send conversational text messages about an inquiry or active relationship. Message and data rates may apply; reply STOP to opt out or HELP for help. SMS consent is optional, is not a condition of purchase, and is not sold or shared for another party’s marketing. Communications providers process data as needed to deliver messages and maintain consent and suppression records.
8. Disclosures
We disclose information to vendors that provide hosting, databases, storage, payment processing, email, communications, analytics, security, AI processing, document generation, and professional advice; to an organization that authorized your account; at your direction; to comply with valid legal process; to protect rights, safety, and service integrity; or in a merger, financing, reorganization, or transfer subject to appropriate protections. We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising.
9. Candidate information
Candidate records are used for recruiting, qualification review, communication, accommodations, security, and required recordkeeping. Access is limited to authorized reviewers. Applicant records are generally retained for at least one year after final disposition, and longer for hires, legal holds, defense of claims, or jurisdiction-specific duties. The Candidate Privacy and AI-Assisted Review Notice provides more detail.
10. Retention
Retention depends on purpose and law. Account and project data is kept while the relationship is active and as needed for support and disputes; contracts, invoices, acceptances, tax, and transaction records may be kept for the applicable limitation and statutory periods; security logs are kept according to risk; unsuccessful candidate records are generally kept at least one year after final disposition; consent and suppression records may be kept to honor choices; and backups expire on operational cycles. Data subject to legal hold is retained until release.
11. Your choices and requests
You may update profile data, manage communications and analytics choices, withdraw an application, cancel future subscription renewal, or use available account-deletion tools. You may request access, correction, deletion, or a copy of personal information by contacting support@monydragon.com. We may verify identity, deny or limit a request where law permits, and retain records needed for security, contracts, tax, legal claims, and opt-out enforcement. Authorized-agent requests must include proof of authority. You may appeal a denied statutory privacy request by replying to the decision.
12. Security and international processing
We use reasonable administrative, technical, and organizational safeguards, including access controls and audit records for sensitive workflows. No system is guaranteed secure. Vendors may process information in the United States or other countries with different privacy laws; contractual and technical measures are used where required.
13. Children
The general site is not directed to children under 13, and we do not knowingly collect their personal information. Paid services and career applications are intended for people at least 18 unless a lawful, specifically approved program states otherwise. Contact us to request removal of information submitted by a child.
14. Changes and contact
Material changes will be posted with a new effective date and may require renewed acknowledgement. Privacy questions, rights requests, and complaints may be sent to support@monydragon.com or through the contact page. The legal entity and notice address applicable to a paid relationship appear on its quote, invoice, or signed agreement.
Effective Date: August 1, 2026 Version: 2026-08-01