This policy explains what personal information Uptime Tracker collects, why, where it is stored and the choices you have. For Customer Data you configure in workspaces (for example contact details of your colleagues or status-page subscribers), you are the controller and we process it on your instructions.
What we collect
- Account data: your email address, sign-in sessions (with last-seen time), two-factor settings and workspace memberships.
- Workspace data: monitors and their targets, check results, incidents and notes, alert destinations (for example email addresses, chat webhooks, phone numbers for SMS), status pages and their subscribers, and an audit log of changes.
- Credentials you store: secrets such as API keys or webhook signing keys are encrypted before storage and are never shown again after you enter them.
- Billing data: handled by Stripe. We store your plan, subscription status and Stripe customer identifier, not your card details.
- Technical data: IP addresses and request logs on our servers and at our CDN, kept for security and abuse prevention. We do not use advertising trackers or sell personal information.
Why we use it
- To provide the Service: running checks, sending the alerts and status updates you configure, and showing your history (contract).
- To secure the Service and prevent abuse, including rate limits and the audit log (legitimate interests).
- To bill you and meet tax and accounting obligations (contract and legal obligation).
- To send service emails: sign-in links, alerts, invitations, billing notices and important changes. We do not send marketing email without your consent.
Where your data is
- The application and its primary database run on a server operated by our hosting provider in Estonia (European Union).
- Encrypted database backups are stored in Amazon Web Services, us-east-1 (United States).
- Traffic passes through Cloudflare (content delivery and DNS), which operates worldwide.
Service providers we share data with
- Stripe (payments) — billing and payment details.
- Cloudflare (network and DNS) — request metadata such as IP addresses.
- Amazon Web Services (backup storage) — encrypted backups we hold the keys to.
- seven.io (SMS delivery, Germany) — phone numbers and message text for SMS alerts you configure.
- Our email provider — recipient addresses and message content of emails we send.
- Integrations you connect (for example Slack, PagerDuty or your webhooks) receive the alerts you route to them.
We disclose information to authorities only when legally required and will tell you where we lawfully can.
Retention
- Raw check results are kept for a period that depends on your plan (from 24 hours on Free to 14 days); aggregated availability data for up to 30–730 days by plan; incident history for 7–730 days by plan.
- Audit events are kept for 30 days (Free and Starter) or 180 days (Team).
- Backups are kept for about 28 days, so deleted data disappears from backups within roughly 35 days.
- When you delete a workspace, its data is deleted immediately from the live database.
Your rights
Depending on where you live (for example under the GDPR in the EU/EEA/UK or under US state laws such as the CCPA), you may have the right to access, correct, export or delete your personal information, to object to or restrict processing, and to complain to a supervisory authority. Much of this is self-service: export data as CSV, delete destinations or your workspace in Settings. For anything else, email us and we will respond within 30 days. We do not sell or share personal information for cross-context behavioral advertising.
Status-page subscribers
People who subscribe to a status page confirm by email first (double opt-in). Every update email includes a one-click unsubscribe link. Subscriber addresses are visible only to the workspace that owns the page, never publicly.
Security
We use TLS in transit, encryption for stored secrets and backups, row-level security that isolates each workspace in the database, two-factor authentication, and an append-only audit log. No system is perfectly secure; tell us about suspected vulnerabilities at the address below.
Children
The Service is not directed to children under 16, and we do not knowingly collect their information.
Changes and contact
We will post updates here and notify account owners of material changes. Contact: [email protected].