Legal

Privacy policy

What Montvo collects from creators and from visitors who pass through a montvo.link page, why, how long it is kept, and what you can do about it.

Last updated 19 September 2026

01Who is responsible

The operator of montvo.com and montvo.link is the controller of the personal data described here.

The operator is established in the Czech Republic. Full identification — legal name, registration number and an address for service — is being added to this page and is available on request from [email protected] in the meantime.

For anything about your data, write to [email protected]. A person reads it.

03If you looked round the site

Montvo buys advertising. When somebody arrives on montvo.com from one of those adverts and goes on to create an account, we would like to know which advert it was — the alternative is to keep paying for all of them and guess.

That is what Google's advertising tag is for here, and the whole of what it is for. It runs on the open pages of montvo.com — the pages about the product, the documentation, the sign-up form — and nowhere else. It does not run on montvo.link, which is the subject of the section above: nobody who opened somebody else's link came here to be advertised to later. It does not run on the dashboard or on any other page you reach by signing in either: by then you have an account, and there is nothing left for it to work out.

Google's measurement tag is the other one, and it is a plainer thing: it counts visits — how many, to which page, roughly from where. That one runs on the open pages of montvo.com and on montvo.link alike, for everybody, and it is not asked about on either. We would rather know how many people read this site than know only about the ones who agreed to be counted, and that is the whole of the reason. It is not on the dashboard or anywhere else you reach by signing in. Blocking Google Analytics in your browser stops it, and nothing on the site changes when you do.

Nothing of Google's advertising loads until you say yes. Not the cookie, not the tag, not a request that would tell them an advert of ours brought you here: decline, or simply leave the question alone, and nothing of it is ever configured. Nothing on the site needs it to work, and nothing about the site changes if you say no.

We ask once and remember the answer in your browser. The "Cookies" link at the bottom of any page reopens the question, and choosing differently there takes effect immediately.

Once you have agreed, what the advertising tag reports is that a visit happened and whether it turned into a sign-up. Google receives your IP address and what a script running in your browser can ordinarily see, and it decides for itself what else it does with that — it is their code and their cookie, and we can no more promise what they do with it than we can for any other network. What comes back to us is counts of adverts and sign-ups, and nothing that names you.

04If you have an account

Creating an account means we hold rather more, because an account is a relationship and a payout needs somewhere to go.

  • Your email address, your display name and the handle your referral link is built from.
  • Your password, stored only as a hash we cannot reverse — or, if you signed in with Google, the name, email address and profile picture Google returns and a token to confirm it is still you.
  • The Bitcoin address you gave us, and your payout history.
  • Your links, their destinations, and the day-by-day counts behind them.
  • The IP address and browser of each sign-in, kept with the session. This one is stored as itself: it is what lets you see where your account is signed in and what lets us notice somebody else signing in as you.
  • If somebody referred you, who.
  • Anything you write to us, and what we wrote back.

If you use the API, the calls you make are logged — method, path, result and how long it took — for 7 days. Bodies are not stored; what you send us is not kept.

05Why we are allowed to

Under the GDPR every use of personal data needs a basis. Ours are:

  • To perform our contract with you (Art. 6(1)(b)): running your account, serving your links, counting what they earned and paying it out.
  • Our legitimate interests (Art. 6(1)(f)): keeping automated and fraudulent traffic off the service, keeping the service secure, and not paying twice for the same visitor. We take the view that somebody opening a link expects the service to be defended against abuse, and the data used for it is the least that answers the question.
  • Legal obligation (Art. 6(1)(c)): keeping accounting records, and responding when the law requires it.
  • Your consent (Art. 6(1)(a)): Google's advertising tag on montvo.com, which measures what our advertising brought in. Consent is the basis because a cookie that is not needed to deliver what you came for is not something a service may assume — so it is asked for before anything of it loads rather than after, and you can take it back at any time from the footer without losing anything you came for.
  • Our legitimate interests (Art. 6(1)(f)) again, for counting visits with Google Analytics on montvo.com and montvo.link: how many people arrive, and where from, is how the service is sized and what tells us which half of it is worth running. That one is not asked about first, which is the plain difference between it and the line above. Blocking Google Analytics in your browser stops it, and nothing about either site changes when you do.

We do not sell personal data, and we hand nothing we hold to anybody for their advertising. An advertising partner on the ad page collects from a visitor directly, through their own code in their own ad — it does not receive our records, and it never sees who holds an account.

No decision that produces a legal effect for you is made purely automatically. The traffic checks decide whether a single visit counts, which is not a decision about a person; a decision to suspend an account or withhold a balance is taken by a person, and you can reply to it.

06Cookies

Montvo sets three cookies of its own, all of them for the site to work rather than to watch you:

  • A session cookie, once you sign in. Without it you would be signed out on every page.
  • A referral cookie, if you arrived through somebody's referral link — it lasts 30 days and holds only their handle, so that they are credited if you sign up. It is set only by following a referral link.
  • A preference cookie remembering whether you left the dashboard sidebar open.

There is one more on montvo.com, and it is not ours. Google Ads sets _gcl_au, which lasts 90 days and lets Google recognize a browser that reached us through one of our adverts. It is Google's to read, not ours. It is the reason you are asked before it is set rather than after, it is never created if you decline, and it is not set on montvo.link at all.

Google Analytics sets its own on top of that — _ga and one per property — to tell a returning visitor from a new one. They last up to two years and they are Google's to read. These are set on montvo.com and on montvo.link alike and are not covered by any question, which is the difference between them and the advertising cookie above; the section on measurement says why, and your browser can block them.

Your answer to the advertising question is not itself a cookie. It is one word kept in your browser's own storage, it is never sent to us, and it is the only reason we can ask once instead of on every page. Clearing your site data forgets it, and you will be asked again.

There is advertising storage on the ad page too, which there did not use to be. Monetag's script runs in your browser there and may set cookies of its own and keep its own identifiers — how many, what they hold and how long they last are its decisions rather than ours. None of it is set on the marketing site or on any page you reach by signing in, and none of it reaches us.

The ad page does keep one thing in your browser's own storage, which is not a cookie and is never sent to us: a single identifier from Linkvertise GmbH (Germany) that exists so you are not shown an ad you have already opened. Clearing your site data removes it, and nothing breaks if you do.

07Who else sees it

The companies that run parts of the service on our behalf, and only for that:

  • netcup GmbH (Germany) — the servers the application, the database and the cache run on.
  • Cloudflare, Inc. (United States) — DNS and the proxy every request passes through. Traffic is inspected there to place visitors by country and to keep bots off the gate.
  • Seznam.cz, a.s. (Czech Republic) — outgoing email, such as a password reset.
  • Google LLC (United States) — for creators who choose to sign in with Google, and only the name, email address and profile picture that Google returns. Google also counts visits to montvo.com and montvo.link, for every visitor and without being asked, and is not acting only for us when it does; the section on cookies says what it sets and the sections above say why. Google Ads is a third arrangement again, on montvo.com alone and only for visitors who agree to it.

Google is on that list for more than one reason, and only the first is a processor. Signing in with Google is something you asked for and Google acts for us in doing it. Their tags are not: Google decides for itself what else it does with what it sees, whatever we asked it for. The advertising tag is the one thing here that waits for your agreement and the one thing you can switch off from the footer without losing anything. The measurement tag is not asked about and runs on both sites; the sections above say so rather than leaving you to find it.

The application, the database and the cache all run on servers in Germany. Cloudflare and Google are in the United States, and data reaching them is transferred on the basis of the European Commission's standard contractual clauses and the EU–US Data Privacy Framework.

Linkvertise GmbH (Germany) and Monetag are the advertising partners on the ad page, and they are deliberately not in the list above. A network is not a processor acting only for us: it decides for itself what it does with what it learns. Linkvertise GmbH (Germany) receives what the section on visits sets out, which is the least a targeted advert can be chosen with. Monetag receives whatever a script running in your browser can see, which is more, and is the price of the adverts that pay for that page.

Beyond that, we disclose personal data only where the law requires it, and we will tell you when we are permitted to.

08How long we keep it

  • Visitor hashes: 24 hours, then deleted automatically.
  • Individual unlock records: a recent window, after which only the daily totals per link remain. Those totals identify nobody.
  • Checked unlocks, where the link carried a creator's reference: 24 hours, then deleted automatically.
  • API call logs and webhook delivery logs: 7 days.
  • Support conversations: for as long as the account they belong to. They are kept so you can read back what was agreed, and closing your account deletes them with it.
  • Your account and its links: until you delete them. Closing your account deletes your links and their history.
  • Payout records: kept as long as accounting law requires, which is longer than your account, and is the one thing deleting an account does not remove.

09Your rights

You can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable form, restrict what we do with it, or object to us relying on legitimate interests. Most of it you can do yourself from your settings, and the rest by writing to us.

Write to [email protected]. We answer within 30 days. We may need to confirm who you are first, which for an account holder normally means writing from the address on it.

For a visitor with no account there is usually nothing we can look up: what is stored about a visit is a hash we cannot search back to a person, and it is gone within a day. The exception is a link that carried a creator's reference — tell us what the reference was and there is a row to show you, for the 24 hours it exists. Either way it is a consequence of collecting little, not a refusal.

If you think we have got it wrong you can complain to your data protection authority. In the Czech Republic that is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).

10Children

Montvo is not for children. You must be 18 to hold an account, and we do not knowingly collect data from anyone younger.

If you believe a child has an account, tell us at [email protected] and we will remove it.

11Security and changes

Passwords are stored hashed, API keys are stored hashed, and a secret key is shown to you once and never again — we keep only a fingerprint of it. Traffic to the site is encrypted. None of that makes a service impossible to breach, and we will tell you and the authority if one happens to us, as the law requires.

If this policy changes, the date at the top changes with it. For a change that materially affects what we collect or why, we will email account holders before it takes effect.

Questions about this document?Contact us →