Documentation

Privacy Policy

Legal

Privacy Policy

Last updated: 1 October 2026. This Privacy Policy explains what personal data MoniterMySite ("we", "us") collects when you use monitermysite.com and the Service, why we collect it, how long we keep it and the choices you have. We are the data controller for account and billing data. For data you load into the Service about other people (for example status page subscribers), you are the controller and we act as your processor; the Data Processing section below applies.

1. Data we collect
  • Account data: name, email address, password (stored only as a bcrypt hash), workspace name, role, timezone (UTC), theme preference and sign-in timestamps.
  • Monitor configuration: the URLs, hosts, ports, DNS names, keywords, headers and credentials you configure. Credentials such as basic-auth passwords, bearer tokens, webhook signing secrets, Telegram bot tokens and PagerDuty keys are stored encrypted at rest and shown masked.
  • Check results: status, response time, HTTP status, error messages, TLS certificate metadata, the monitoring region used and timestamps. This may incidentally include data your endpoint returns in error messages.
  • Alert data: the destinations you configure (email addresses, chat webhook URLs) and a log of each delivery attempt and its outcome.
  • Status page data: components, announcements, your branding, and the email addresses and confirmation state of subscribers who sign up on your pages.
  • Billing data: plan, subscription status, invoices and the payment processor's identifiers. Card numbers are entered directly into Razorpay's checkout and never reach our servers.
  • Technical data: IP address, browser and device information, pages visited and request logs, kept for security and troubleshooting.
  • Communications: messages you send to support and emails we send you.
2. How we use data and our legal bases
  • To provide the Service you signed up for, run your checks, deliver alerts and publish your status pages (performance of a contract).
  • To bill you, prevent fraud and comply with tax and accounting law (contract and legal obligation).
  • To secure the Service, investigate abuse and keep our probes from being used against systems you do not own (legitimate interests).
  • To send service emails such as alerts, invoices, security notices and changes to these terms. We send product news only with your consent and you can unsubscribe at any time.
  • To improve the Service using aggregated, de-identified usage statistics (legitimate interests).
3. Cookies

We use a small number of strictly necessary cookies: an authentication session cookie, a CSRF token, your theme preference and, on password-protected status pages, a cookie that remembers you unlocked the page. We do not use advertising or cross-site tracking cookies. See the Cookie Policy for the full list.

4. Who we share data with

We do not sell personal data. We share it only with service providers who process it on our instructions under written agreements:

  • DigitalOcean (hosting, databases and monitoring probes in the United States, Europe, Asia and Australia).
  • Brevo (transactional email delivery).
  • Razorpay (payment processing; they are an independent controller for the payment itself).
  • Chat and incident platforms you connect (Slack, Discord, Microsoft Teams, Google Chat, Telegram, PagerDuty) receive the alert content you configure.
  • Professional advisers and authorities where required by law or to protect rights, safety and the integrity of the Service.
5. International transfers

We are based in India and our infrastructure runs in several regions worldwide so that monitoring can happen close to your users. Where personal data is transferred out of the region it was collected in, we rely on the provider's standard contractual clauses or an equivalent lawful mechanism.

6. Retention
  • Account and workspace data: for as long as your account exists, then deleted within 30 days of workspace deletion.
  • Raw check results: 30 days on Starter, 180 days on Launch, 12 months on Growth and 24 months on Summit, then deleted automatically by a daily job.
  • Daily uptime statistics: at least 400 days, so year-over-year uptime remains available on every plan.
  • Incidents and their timelines: 24 months. Alert delivery logs: 90 days.
  • Status page subscribers: until they unsubscribe or the page is deleted; unconfirmed sign-ups are removed after 7 days.
  • Billing records and invoices: 8 years, as required by Indian tax law.
  • Server request logs: up to 30 days.
7. Security

All traffic is encrypted in transit with TLS. Passwords are hashed with bcrypt; secrets are encrypted at rest; database access is restricted to the application network; probes authenticate to the API with per-deployment secrets; webhooks we send are signed with HMAC-SHA256. Access to production is limited to authorised staff and logged. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay, and within 72 hours where the law requires it.

8. Your rights

Depending on where you live (including under the GDPR, UK GDPR, CCPA/CPRA and India's Digital Personal Data Protection Act) you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to withdraw consent. You can update your name and workspace in Settings, export monitor data from the app, delete your workspace and account in Settings, and unsubscribe from status page emails using the link in each message. For anything else email [email protected]; we respond within 30 days. You may also complain to your local data protection authority.

9. Data Processing terms (for data you control)
  • We process subscriber emails, monitor targets and related data only on your documented instructions, which are the configuration you make in the Service.
  • We impose confidentiality on our staff, apply the security measures above, and engage the sub-processors listed in section 4; we will give notice of new sub-processors on this page.
  • We assist you with data subject requests and security obligations where reasonably possible, and delete or return your data when the workspace is deleted.
  • If you need a signed DPA or Standard Contractual Clauses, email [email protected].
10. Children

The Service is not directed at children under 18 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes

We may update this policy; the date at the top shows the latest version. For material changes we notify you by email or in the app before they take effect.

Contact

Privacy questions and requests: [email protected].

Didn’t find what you need?

We answer every email, usually within one business day.

Email support