Privacy policy
What we collect, why we collect it, who else sees it and how long we keep it. Written to be read rather than skimmed past.
Last updated 24 August 2026
Who we are
Moonitor is operated by The Cool Software Company(“we”, “us”), the data controller for the personal data described here. For anything in this policy, write to hello@moonitor.dev.
What we collect
Data you give us
- Account details. Your name and email address, and a hash of your password — never the password itself.
- Organization and team. Your organization name, the members you invite, and their roles.
- Monitor configuration. The URLs, hostnames, ports and request headers you ask us to check. If you put a credential in a request header so a check can authenticate, we store it in order to send it.
- Alert destinations. The email addresses, phone numbers, Telegram chats and webhook URLs you want alerts delivered to.
- Status page content. Anything you publish on a status page, and the email addresses of people who subscribe to it.
Data we generate by running your checks
- Check results. A timestamped record of every check: up, down or degraded, its response time, and which vantage point ran it.
- Failure evidence. When a check fails we keep a small amount of the response so you can see why — response headers drawn from a fixed allow-list, and at most 8 KB of the response body. The allow-list exists so a credential in an unexpected header is never persisted.
- Incidents. When something broke, when it recovered, and which vantages agreed.
Data we collect automatically
- Session and security data. IP addresses and user-agent strings, used to keep you signed in and to rate-limit sign-in and API abuse.
- Error reports. When the application throws, we send the stack trace and request context to Sentry so we can fix it.
- Marketing-site analytics. Aggregate page-view statistics via Google Analytics, on the public marketing pages only. The signed-in dashboard is not tracked.
Note
We don’t sell personal data, we don’t share it with advertisers, and we don’t use your monitor data to train machine-learning models.
Why we're allowed to hold it
Under the UK and EU GDPR we rely on three lawful bases, depending on the data:
- Contract. Account, organization, monitor and alert data — we cannot provide the service without it.
- Legitimate interests. Security logging, rate limiting, error reporting and aggregate analytics, so the service stays available and we can fix what breaks.
- Legal obligation. Billing and tax records.
Who else processes it
These are the third parties that process data on our behalf. We keep this list current — if a provider is added, it appears here.
| Provider | What it's used for | Where |
|---|---|---|
| Hetzner Online GmbH | Primary application, database and check infrastructure | Finland (Helsinki) |
| RackNerd LLC | Verification vantage point (Los Angeles) | United States |
| Xneelo (Pty) Ltd | Verification vantage point (Johannesburg) | South Africa |
| Stripe, Inc. | Payment processing and subscription billing | United States / Ireland |
| Resend | Transactional and alert email | United States |
| Twilio Inc. | SMS alerts, where you enable them | United States |
| Telegram FZ-LLC | Telegram alerts, where you enable them | United Arab Emirates |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States |
| Google LLC (Analytics) | Aggregate analytics on the marketing site only | United States |
| AppSumo (Sumo Group Inc.) | Licensing for lifetime-deal accounts only | United States |
The verification vantage points in Los Angeles and Johannesburg receive only the check specification — the target address and any headers you configured for it — so that they can repeat the request. They are not sent your account details, your team, or your alerting destinations.
Some of these providers are outside the UK and EEA. Those transfers rely on the standard contractual clauses in each provider’s data processing agreement.
How long we keep it
| Data | Kept for |
|---|---|
| Captured failure evidence Response headers (from a fixed allow-list) and up to 8 KB of the response body, captured when a check fails so you can see why. | 30 days |
| Check results and incident history The timestamped up/down/degraded record behind your uptime figures and status pages. | For as long as the monitor exists |
| Account and organization data Your name, email, organization, team members and monitor configuration. | Until you delete the account |
| Billing records Invoices and payment metadata held by Stripe. Moonitor never sees or stores full card numbers. | As required by tax and accounting law |
| Backups Nightly database snapshots taken on the application host. | Rolling, deleted on the backup cycle |
Delete your account and we remove your monitors, check history, incidents, status pages and alert destinations. Billing records survive that deletion because tax law requires it.
How it's protected
- All traffic is served over TLS, with HSTS enabled.
- Passwords are hashed. Webhook signing secrets are encrypted at rest.
- API keys are scoped to a single organization and can be read-only. Every request is checked against the organization that owns the record, so one customer’s key cannot reach another’s data.
- Database access is restricted to the application host; backups run nightly.
If you believe you have found a vulnerability, mail hello@moonitor.dev. We’ll acknowledge within one business day.
Cookies
We use a session cookie to keep you signed in, and cookies set by Google Analytics on the marketing pages. There are no advertising or cross-site tracking cookies. Blocking analytics cookies has no effect on the product.
Your rights
If the UK or EU GDPR applies to you, you have the right to access, correct, delete, export, or restrict our processing of your personal data, and to object to processing we base on legitimate interests.
Most of this you can do yourself: account settings cover correction and deletion, and the public API will export everything we hold about your monitors in JSON. For anything else, mail hello@moonitor.dev and we’ll respond within 30 days. If you think we’ve got it wrong, you can complain to your local data protection authority.
Children
Moonitor is a tool for people running infrastructure. It isn’t directed at children and we don’t knowingly collect data from anyone under 16.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your data, we’ll email account holders before it takes effect rather than relying on you to re-read the page.
Note
This policy describes what the service actually does. It isn’t legal advice, and it doesn’t replace a data processing agreement — if your organization needs a signed DPA, mail hello@moonitor.dev.