Overview
Monday.com is a cloud-based work operating system used by over 225,000 organizations for project management, team collaboration, and workflow automation. On third-party websites, Monday.com's presence is limited to embedded intake forms and widgets — functional tools that route structured submissions into Monday.com boards and workspaces, not advertising or tracking infrastructure.
What This Script Does
Monday.com widgets embed on host websites as iframes or via a JavaScript embed snippet, loading a form interface from Monday.com's servers.
Script Files and Domains
- Monday.com form embeds load from
forms.monday.comas iframes, or via a JavaScript snippet fromdapulse.com(Monday.com's legacy domain retained for compatibility). - The embed JavaScript initializes the iframe with form configuration parameters and handles cross-frame communication for dynamic height adjustment.
- Form submission API:
api.monday.com/v2— GraphQL API receiving form submissions. - Widget assets (CSS, images):
assets.monday.com
Cookies Set
- Within the
monday.comiframe context:monday_session_id— Session-scoped cookie identifying the current form session. Expires on browser close.csrf_token— CSRF protection token for form submission validation. Session-scoped._ss_pp_id— Session replay / page performance cookie used by Monday.com's own analytics. Set within the iframe context and scoped tomonday.com, not the host domain.
- On the host website domain: No persistent tracking cookies are set by Monday.com's embed scripts.
Data Collected Per Form Submission
- All user-entered form field values (these are the fields defined by the site operator — may include name, email, phone, project description, budget range, etc.)
- File attachments (if file upload columns are configured in the board)
- IP address (captured server-side on submission)
- Submission timestamp
- Referrer URL (captured client-side and passed as metadata)
Workflow Automations On submission, Monday.com can trigger automations: sending email notifications to board owners, creating sub-items, assigning owners, setting due dates, and triggering integrations with Slack, Jira, Salesforce, or Zapier. Each downstream integration is an additional data processor.
Monday.com CRM (if enabled) If the host organization uses Monday CRM, embedded lead forms may create contact records and trigger sales workflow automations. In this context, the functional intake form also feeds a CRM system with marketing implications.
Consent & Compliance
Consent category: Functional
- GDPR/ePrivacy: Monday.com embedded forms serve a functional purpose — they collect structured user input at the user's explicit initiative (clicking a form and filling it out). Session cookies for CSRF protection and form state management are strictly necessary for the form to function correctly. Under ePrivacy, strictly necessary cookies serving a user-requested function are exempt from consent requirements. However, loading a third-party iframe from
monday.comdomain technically sets cookies on that domain, which some DPAs (particularly strict interpretations in Germany and France) may require disclosure for. - GDPR as data controller/processor: Monday.com acts as a data processor, processing form submission data on behalf of the site operator (the data controller). A Data Processing Agreement is provided by Monday.com and required under GDPR Article 28.
- CCPA/CPRA: Form submission data is personal information provided directly by the user. It does not constitute a sale. Downstream integrations (Salesforce, Marketo) should be disclosed in the privacy policy.
- EU-US Data Privacy Framework: Monday.com is an Israeli company with US operations. Its US entity participates in the DPF. EU data is primarily processed in the EU (Monday.com operates EU data centers). SCCs are available.
Should You Block This Without Consent?
No. Monday.com's embedded intake forms are functional tools that process user-initiated form submissions. They do not perform behavioral profiling, cross-site tracking, or advertising attribution. The session cookies serve CSRF protection and form continuity — purposes that are strictly necessary for the form to function. Disclosure in the site's cookie policy and privacy policy is recommended, but prior consent for loading is not required.
Is Monday.com GDPR compliant?
Monday.com typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Monday.com can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Monday.com, not on Monday.com itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
assets.monday.comFunctionalassets.monday.com is a functional domain operated by Monday.com, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Monday.com
ConsentStack automatically detects and manages Monday.com trackers so your site stays compliant with global privacy regulations.