upsonar.io

Privacy Policy - upsonar.io

Privacy Policy

Last updated: October 4, 2026

1. Who We Are

Upsonar (upsonar.io) is operated by Daria Petrova, Nicosia, Cyprus, who is the controller of your personal data. Contact: [email protected].

2. What We Collect

  • Account: your email; your password (stored only as a bcrypt hash) or your Google or GitHub account ID if you sign in with them.
  • Service data: the URLs you monitor and their settings (including custom request headers), check results and history, incidents, status pages and maintenance windows.
  • Notification settings: the channels you connect (Telegram chat ID and bot token, Slack and webhook URLs), timezone and quiet hours.
  • Billing: your plan and subscription status. Card details are handled by Stripe and never reach us.
  • Technical data: server logs with your IP address shortened to its first three parts, browser user agent and the requested page; frontend errors and performance measurements.
  • Exit survey (optional): your answers, plan, account age and the date, stored without your email or account ID.
  • Waitlists: your email.

3. Why We Use It and on What Legal Basis

PurposeLegal basis
Running monitoring, alerts and status pagesContract
Billing, refunds and tax recordsContract; legal obligation
Service emails (verification, alerts, billing, account deletion)Contract
Product emails (tips, updates, occasional offers)Our legitimate interest in telling customers about our own similar service. You are told at sign-up and can turn them off in Settings or with the link in every email
Security and abuse prevention (Cloudflare Turnstile, rate limits, logs)Our legitimate interest in keeping accounts and the service safe
Error and performance monitoringOur legitimate interest in finding and fixing errors
Website analytics (Google Analytics)Your consent, given in the cookie banner

4. Who Processes Data for Us

  • Stripe — payments — EU and US
  • Resend — sending emails — US
  • Cloudflare — content delivery, DDoS protection, Turnstile — global
  • Google — sign-in (if you use it) and Analytics (with your consent) — US
  • GitHub — sign-in (if you use it) — US
  • Grafana Labs (US company), data stored in London — server logs and frontend error monitoring
  • DigitalOcean — hosting our servers (Amsterdam) and running checks from several regions — EU, UK, US, Canada, Singapore, India and Australia

Transfers outside the EEA rely on the EU–US Data Privacy Framework, the UK adequacy decision or the European Commission's Standard Contractual Clauses. You can ask for a copy of the safeguards at [email protected].

Destinations you choose. Telegram, Slack and your webhooks receive the alert content you configure, because you asked us to send it there. They are not our processors.

5. Cookies and Similar Storage

Essential: your login session (stored in your browser's local storage), your cookie choice, your email if you tick Remember me, where to return after signing in with Google or GitHub, and your interface choices, such as a pinned sidebar or a tip you dismissed. Analytics, only if you accept: Google Analytics. Our error monitoring keeps no identifier or tracking data in your browser. Change your choice anytime with Cookie Settings in the footer.

6. How Long We Keep Data

  • Account data: while your account exists.
  • Check history: depending on your plan (the Free plan keeps less than paid plans; see Pricing).
  • When you delete your account: removed from our database immediately and removed from backups within 7 days.
  • Server logs and error-monitoring data: 14 days.
  • Invoices and payment records: as tax law requires (we keep them at Stripe).
  • A record that a deletion was carried out (account number and dates, no email): 1 year.
  • Exit survey answers: 1 year.
  • Waitlist entries: until the feature launches or you ask us to remove you.

7. Your Rights

You can object at any time to processing based on our legitimate interests.

  • Access and portability: Download my data in Settings → Account.
  • Rectification: change your details in Settings, or ask us.
  • Erasure: Delete account in Settings → Account.
  • Restriction and objection, including to product emails (Settings → Account, or the link in any product email).
  • Withdraw cookie consent: Cookie Settings in the footer.

Write to [email protected] for anything else; we answer within one month. You can complain to the Commissioner for Personal Data Protection, Cyprus (dataprotection.gov.cy) or to the data protection authority in your country.

8. Feature Waitlists

If you join a waitlist we send you one email when the feature launches and nothing else from that list. To be removed, write to [email protected].

9. Changes

We email account holders before material changes to this policy take effect.