Last updated: 22 September 2026
This Privacy Policy explains how Monochrome (also referred to as “Mono”, “we”, “us” or “our”) collects, uses, stores and discloses personal information when you use our website at www.monochrome.exchange, our applications and the related services that link to this policy. It also explains how we handle information obtained through Google Sign-In and how you can exercise choices concerning your information.
The company responsible for this policy is MONOCHROME TECHNOLOGIES PTY LTD. Its details appear in Section 8. For privacy enquiries or requests, contact support@monochrome.exchange.
1. Information We Collect
The information involved depends on the services you use. We collect information you provide directly, information generated through your use of our services, and information supplied by an authentication provider when you choose that sign-in method.
- Account and contact information: your name, email address, contact details, country or region, and profile or social account information you choose to provide or connect.
- Transaction and financial information: records relating to your use of our transaction services and, where necessary for a particular service, bank account and related payment information.
- Identity-verification information: identification documents and information, such as government-issued identification numbers, passport details and document copies, where required for identity verification, fraud prevention or applicable compliance obligations.
- Device and service-use information: IP address, browser or user-agent information, device information and identifiers, and records of interactions with our services. The information available depends on the device, platform, permissions and feature concerned.
- Communications: information you provide when contacting customer support, submitting a privacy request, reporting a problem or participating in an activity.
- Google sign-in information: the Google account and authentication information described in Section 9, when you choose to sign in with Google.
Identity documents, bank details and transaction information are not obtained from Google merely because you use Google Sign-In. They relate to separate Monochrome services and any information requested for those services.
Where information is necessary to provide a service or fulfil an applicable obligation, not providing it may prevent us from providing that service. We do not treat simply visiting our website as consent to every possible use of personal information.
2. How We Use Information
We use relevant personal information to:
- create, authenticate, maintain and support your account;
- provide the services you request and process related transactions;
- verify identity where required, prevent fraud and misuse, and protect accounts and services;
- communicate about your account, security, transactions, service changes and policy updates;
- answer enquiries, investigate complaints and resolve disputes;
- meet applicable legal and regulatory requirements and respond to lawful requests;
- understand service performance and usage, troubleshoot problems and improve our services; and
- administer activities you choose to join and provide promotional communications where permitted and subject to applicable consent and opt-out requirements.
The specific purposes and restrictions for information obtained through Google Sign-In are set out in Section 9. The general purposes above do not authorise unrelated use of Google user data.
3. Storage, Sharing and Security
3.1 Storage and access
Personal information is held in electronic records used to operate our services, including account, transaction, security and support records as relevant. Authentication records for Google Sign-In are processed using Firebase Authentication, as explained in Section 9.
Access to personal information is restricted to personnel and service providers who need it for the purposes described in this policy. They are required to handle that information subject to applicable confidentiality, security and data-protection obligations.
3.2 When information is shared
We disclose relevant information only to the extent necessary for the purposes below and the measurement activities described in Section 3.3, subject to the restrictions in Section 9:
- Service delivery: to providers supporting authentication, hosting, technical operations, customer support, security and other functions necessary to provide our services. Information is limited to what is relevant to the function they perform.
- Affiliates and professional support: to affiliates, authorised personnel and professional advisers where needed to operate our services, obtain advice or protect legitimate legal interests.
- Legal and safety requirements: where disclosure is required or authorised by applicable law, in response to lawful requests from courts or authorities, or where necessary and legally permitted to address fraud, abuse or threats to safety or security.
- Corporate transactions: in connection with a merger, reorganisation, acquisition or transfer of business assets, subject to applicable safeguards and notification requirements.
- Your instructions: where you request or authorise a particular disclosure and it is otherwise permitted.
We do not sell personal information. Information obtained through Google Sign-In is also subject to the specific recipient and use restrictions in Section 9; this section does not override those restrictions.
3.3 AppsFlyer and measurement
We may use the AppsFlyer SDK, as part of our services, to understand how users find and interact with the platform, measure advertising effectiveness and detect fraud. Where used, the SDK may process device and interaction information, such as device identifiers, IP address, app activity and attribution information, depending on the platform, permissions and configuration.
Information about AppsFlyer’s processing is available in its Services Privacy Policy. Our use of measurement tools remains subject to this policy and applicable consent requirements. It does not authorise using or transferring Google user data for advertising or other purposes prohibited under Section 9 or applicable Google policies.
3.4 Security
We take reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, loss or disclosure. These include HTTPS/TLS protection for information transmitted through our website and authentication services, limiting access according to operational need, and confidentiality requirements for authorised recipients.
Firebase Authentication uses Google’s documented security safeguards, including encryption in transit and at rest. More information is available in Firebase’s privacy and security information. No internet transmission or storage system can be guaranteed completely secure. Please protect your account credentials and report suspected unauthorised access promptly.
3.5 International processing
Our company is based in Australia, and information may be processed outside your country by service providers supporting our services. Firebase Authentication operates from data centres in the United States, as described in Google’s documentation. Other processing locations depend on the service provider and function involved.
Cross-border handling is subject to applicable data-protection requirements and the safeguards described in this policy. You may contact us for information about overseas handling relevant to your personal information.
4. Retention, Access, Correction and Deletion
4.1 How long information is retained
We retain personal information only for as long as needed for the purposes described in this policy, taking into account the information’s nature, the services provided, applicable record-keeping obligations, security needs and the resolution of disputes.
- Account and Google sign-in records: retained as needed to operate your account, maintain its authentication link and provide related support and security. They are assessed for deletion when you request account closure or deletion of the relevant information.
- Transaction and identity-verification records: retained for the relevant service and for any applicable legal, regulatory, accounting or dispute-resolution requirements. Closing an account does not necessarily require or permit immediate deletion of these records.
- Security and support records: retained for the period reasonably needed to investigate problems, prevent misuse, handle requests and establish relevant actions taken.
- Backups and provider-held copies: addressed through the applicable deletion and backup-management processes. They may not disappear at the same time as active records, but are not retained indefinitely without a continuing permitted reason.
When personal information is no longer needed and is not subject to a legal retention requirement, we take reasonable steps to delete it or de-identify it so that it can no longer reasonably be associated with you. This includes addressing relevant copies held by service providers and in backups.
4.2 Your requests
You may use available account settings to review or update your information. You may also request access, correction, account closure or deletion by emailing support@monochrome.exchange. You do not need to locate an in-app deletion button to submit a request by email.
Please describe your request and identify the relevant Monochrome account. We may ask for information reasonably necessary to verify your identity and protect the account. Do not send passwords, one-time codes, private keys or authentication tokens.
We will assess the request, take the action required by applicable law and explain the outcome. Where particular information must be retained or a request cannot be fully fulfilled, we will explain the relevant reason unless legally prohibited. Retained information remains subject to this policy and is limited to the purpose justifying its retention.
4.3 Removing a Google connection
You can manage or revoke Monochrome’s connection to your Google Account through Google Account connections.
Revoking the connection is not the same as deleting your Monochrome account or information already held by Monochrome. To request that deletion, contact support@monochrome.exchange. Revoking the connection may affect your ability to use Google Sign-In; contact us if you need help accessing your Monochrome account.
5. Changes to This Policy
We may update this policy to reflect changes in our services, data practices or applicable requirements. The “Last updated” date identifies this version.
For material changes, we will provide an appropriate notice through our website, application or account communication channels. Where a change requires consent, including an applicable change to the Google user data accessed or the purposes for which it is used, we will obtain that consent before implementing the change. This policy does not constitute advance consent to all future changes.
6. Privacy Enquiries and Complaints
For privacy questions, access or correction requests, account or data-deletion requests, or privacy complaints, contact:
Email: support@monochrome.exchange
You may also use the Monochrome Help Centre request form.
We use the information supplied with a request to verify it, investigate the matter, respond and keep an appropriate record of its handling. We will consider privacy complaints and communicate our response within a reasonable period, subject to any applicable legal deadline. If you are dissatisfied with our response, you may contact the privacy regulator responsible for your jurisdiction. Where Australian privacy law applies, information about complaints is available from the Office of the Australian Information Commissioner.
7. Languages
This policy is prepared in English and may be provided in other languages for convenience. If there is an inconsistency between language versions, the English version prevails to the extent permitted by applicable law. This provision does not limit rights that cannot lawfully be excluded.
8. Company Information
Company: MONOCHROME TECHNOLOGIES PTY LTD
ACN: 680 819 612
Registered address: Suite 303, 3 Hosking Place, SYDNEY NSW 2000, Australia
Privacy contact: support@monochrome.exchange
9. Google Sign-In and Firebase Authentication
9.1 Information involved
Monochrome offers Google Sign-In using Firebase Authentication. When you choose this method, the sign-in process accesses your Google account identifier, email address and email-verification information, and your name and profile picture information where supplied by Google. Firebase Authentication maintains an associated user identifier and authentication record to support your Monochrome sign-in.
Authentication credentials or tokens are processed to establish and manage your signed-in session. Firebase Authentication also processes technical information, including IP address and user-agent information, for authentication security and abuse prevention.
Your Google password is entered in Google’s sign-in interface and is not provided to Monochrome through Google Sign-In. The basic profile and email permissions used for sign-in do not themselves give access to Gmail message content, Google Drive files, contacts or calendars. Any feature requiring additional Google access must identify the data and purpose and request the necessary permission before access.
9.2 Purposes
We use Google sign-in information to authenticate you, create or access your Monochrome account, associate your Google identity with that account, maintain relevant account profile information, protect account access and resolve sign-in or account-support problems. Where your Google email address is your Monochrome account contact address, it may also be used for essential account, security and service communications.
Access is limited to the permissions needed for the relevant user-facing feature. Google sign-in information is not permission to collect unrelated Google account content.
9.3 Storage, access and recipients
Google and Firebase Authentication process the information needed to provide sign-in and manage authentication records. Relevant account information is also handled within Monochrome’s account and operational records for the purposes above.
Where necessary, relevant Google-derived account information may be accessed by authorised personnel and service providers supporting account hosting, customer support, security and authentication troubleshooting. Access and disclosure are limited to the information required for those functions. Any legal or corporate-transaction disclosure must also comply with applicable law and Google’s requirements.
The security, international processing, retention and deletion provisions in Sections 3 and 4 apply to this information. You can request deletion by contacting support@monochrome.exchange; removing the Google connection alone does not delete data already held by Monochrome.
9.4 Restrictions on Google user data
Our use of information received from Google APIs, and any transfer of that information to another app, must comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
Google user data must not be sold, transferred to data brokers, used for personalised or targeted advertising, or used to train general-purpose artificial-intelligence or machine-learning models. These restrictions also apply where the information is processed through an analytics or attribution provider or is represented by a derived identifier that remains linked to a person.
The general business, promotional and measurement provisions elsewhere in this policy do not override these Google-specific restrictions.
Comments
0 comments
Article is closed for comments.