Privacy Policy

Last updated: July 17, 2026

Pick List Generator ("the App") is a monday.com board view application developed and operated by Scritt Solutions ("Scritt", "we", "us", "our"). This Privacy Policy explains what data the App accesses, how it is used, and your rights.

1. Who we are

Scritt Solutions, a sole proprietorship operated by Ryosuke Kamei and based in Tokorozawa, Saitama, Japan, develops the App. Our detailed address is disclosed without delay on request. For any privacy question or request, contact us at support@scritt.com.

2. How the App works (data architecture)

The App runs entirely as a client-side application inside an iframe within your monday.com account. It has no backend server and no database of its own. The App's static files are served from monday.com's content delivery network. As a result, we do not receive, store, or process your data on our own servers.

3. Data the App accesses

To provide its functionality, the App accesses the following through monday.com's official SDK and API, within your account:

  • Board content you point it at: item and column values such as SKU, quantity, storage location, order identifier, and status columns. This is used to generate consolidated (total-picking) pick lists.
  • App configuration you set (column mapping, target status, wave size), which is saved using monday.com's storage API scoped to your account and board — not on any Scritt server.
  • Picking session progress, saved via monday.com's storage API so you can resume a pick list across sessions and devices. This includes a snapshot of the pick lines you generated (SKU, quantity, location) and which items have been checked off, together with the monday user ID of the person who started the session (used only to detect concurrent edits from another device).
  • Minimal monday context (such as the current board and account/user context provided by the SDK) needed to run inside monday.com.

The App requests only the boards:read and boards:write permission scopes (least privilege). It does not request access to your profile beyond what the platform provides to run the app, and it does not access documents.

4. How we use the data

  • To read the orders you select and generate pick lists in your browser.
  • To write back the status of picked orders to your board when you complete a wave (via monday.com's API, using the boards:write scope).
  • To remember your App configuration and in-progress picking session between sessions and devices (via monday.com storage).

All list generation and picking logic runs locally in your browser. We do not transmit your board data to Scritt or to any third party.

5. Data sharing and selling

We do not sell, rent, or share your data. Because the App has no server of its own, the only party that processes your data is monday.com, the platform on which the App runs, under monday.com's own terms and privacy policy. We use no third-party analytics, advertising, or tracking services within the App.

The App does call one monday.com-defined signal, valueCreatedForUser — a required piece of marketplace telemetry that monday.com's own app platform asks every app to fire when a user gets value from it (in this App, completing a pick list wave). The call carries no parameters and no board data, and it is sent directly to monday.com — the same platform named throughout this policy, not a third party.

6. Data storage and retention

  • App configuration and picking session progress are stored via monday.com's storage API and remain within your monday.com account under your control — never on a Scritt server.
  • Board data is read into your browser to generate a pick list. A snapshot of the resulting pick lines is saved as picking session progress (see above) so you can resume; beyond that snapshot, board data is not retained by the App. Nothing is stored on any Scritt infrastructure.
  • When you uninstall the App, the data stored via monday.com's storage API is removed according to monday.com's data lifecycle. We retain no copy because we hold none.

7. Security

  • The App is served over HTTPS (TLS 1.2+) via monday.com's infrastructure.
  • The App does not store or persist monday.com API tokens on the client; it relies on monday.com's in-iframe SDK authentication.
  • Least-privilege scopes (boards:read, boards:write) limit access to only what the App needs.

8. Your rights (GDPR / CCPA and similar)

Depending on your location, you may have the right to access, correct, delete, or restrict processing of your personal data, and to data portability. Because your data resides in your monday.com account, most of these rights are exercised directly within monday.com. For any request involving the App, contact support@scritt.com and we will assist and coordinate with monday.com as needed. We do not knowingly process data of children under 16.

9. International data transfers

The App processes data within monday.com's infrastructure. Any cross-border transfer is governed by monday.com's data processing terms. The App itself performs no independent cross-border transfer of your data.

10. Changes to this policy

We may update this Policy. Material changes will be reflected by updating the "Last updated" date on this page. Continued use of the App after changes take effect constitutes acceptance.

This Policy is published in English (authoritative) with a Japanese reference translation on this site; if they conflict, the English version prevails.

11. Contact

Scritt Solutions (Representative: Ryosuke Kamei), Tokorozawa, Saitama, Japan — support@scritt.com

Our Terms of Service govern your use of the App.