Make monday.com work with Microsoft 365 & SharePoint →
Master Data logo

Master Data

Mint Consulting Australia

101 installs, since July 25, 2024.   8 installs/month.   Updated July 22, 2024.

14 days trial No touch
Gallery image Gallery image Gallery image

Merge & Sync data from multiple boards into a Master Board!

Merge and sync data from multiple boards into one Master Board!


Master Data by Mint allows you to consolidate items from across different boards into one master board to provide complete visibility and control.


With Master Data, you can:

  • Combine data from multiple boards into one powerful overview
  • Say goodbye to tedious copy-pasting between boards
  • Get rid of the clutter from connected and mirrored columns
  • Simplify your dashboard by linking to a single master board, setting your filters just once
  • Bypass complicated board permissions and ensure visibility of multi-board data in a single board
  • Retain information from archived data
  • Eliminate fragmentation and disparate information silos
  • Enable reporting on long term data and trends
  • Share different views (Charts/Gantts/Kanban) of your Master Board with anyone

Take advantage of the full potential of your CRM and Work Management data


You can :

Security & Compliance

Security

Does the developer periodically perform penetration testing?

No

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
Naveed Choudhury, Director, [email protected]

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The app only redirects monday.com OAuth flow when getting a user's access token.

Does the app protect against mass parameter assignment attacks?

Yes
All requests are verified using a session token. The app retrieves only the necessary parameters from the request before performing an action. The app sanitizes these parameters before putting their values into the database.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
React has a built-in mechanism to prevent this on the frontend. The app has no place to input any malicious scripts in the UI. To ensure security, the backend uses parameter filtering, sanitization, and session tokens.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
In all cases, whenever the app state is changed by a user, the app authorizes all requests with a monday.com session token. Changes can only be made through integration and cannot be forged.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
We will restrict access to AWS systems and any unusual activity will be reported to Naveed Choudhury. These will then be forward to monday.com. 1. Initial Notification. We will notify monday.com within 24 hours of detecting a security breach. The initial notification will be sent via email. Alongside this email, this will also be escalated with the Partner Manager. The initial notification will include: (1) A brief description of the breach; (2) The potential impact on monday.com; (3) Immediate actions taken to mitigate the breach 2. Ongoing Updates. We will provide ongoing updates as we gather more information and as the situation evolves. Each update will include: (1) Latest findings and status of the breach; (2) Actions taken since the last update; (3) Next steps in our response plan 3. Post-Incident Report. Once the breach is contained and resolved, we will provide a detailed post-incident report. The report will include: (1) A detailed account of the breach: (2) Root cause analysis; (3) Steps taken to resolve the breach; and (4) Measures implemented to prevent future breaches

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
We are using AWS as infrastructure: it takes care for DB updates. There are enabled, and any security patch will be applied by the AWS itself. For the app itself, we are using Dependabot tool in Github, to notify us about any security updates in dependent packages. So the security patches will be applies as soon as we get a notification.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No
We are not collecting any HIPAA-sensitive data.

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

No
N/A

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
We are compliant with the General Data Protection Regulation (GDPR). By using our app, users acknowledge and agree to our collection, use, and sharing of their information as described in the Data Privacy Clause of our T&C, ensuring full compliance with GDPR. Our Terms and Conditions for app usage outline the data privacy policies of Mint, which align with the seven protection and accountability principles outlined in Article 5.1-2 of the GDPR.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
The app logs errors, synchronization results, and monday.com app events. The only user information logged is accountId and userId.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
We store three types of data: Data required for proper synchronization: This includes only IDs and timestamps. Account details (account slug and user’s email): We obtain these from app events to resolve payment issues. These details are deleted if users uninstall the integration. Access tokens: These are used to perform the actual synchronization. Access tokens are encoded before being saved in the database and removed when users uninstall the integration. The DB is encrypted by default using the built-in AWS tools. The encryption token is saved separately from DB.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
AWS MFA

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Apps data is stored inside AWS. We use MFA to provide access to this data.

Reviews

March 26, 2025

BK: This app did exactly what it advertised and saved a tonne of manual handling that was otherwise complicated to automate natively.

October 14, 2024

TH: Great app

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000552App ID: 10149422Listing updated: March 3, 2025