Privacy Policy

Last updated: 14 September 2026

1. Who We Are

UptimeWarrior is a website uptime monitoring service. In the context of this policy, "we", "us", and "our" refer to M-Kloosterman, based in the Netherlands. We are the data controller for personal data collected through this service.

2. What Data We Collect

We collect the following personal data.

You and your team

  • Account: the name or company name and the email address you register with. The account's email address is where we send billing, account and deletion notices.
  • Logins: the email address of everyone who can sign in, when each login was created, and, for everyone who registered, when they agreed to our terms and this policy.
  • Last visit: when each login last used the service, recorded at most once an hour. We use it to find free accounts that nobody uses any more (see section 4).
  • Team invitations: the email address of each person invited to an account, the role they were given, and when they accepted or declined.
  • Sign-in codes: the address a code was sent to, a keyed hash of the code, when it expires and how many attempts were made.
  • How you found us: if you answer it, the answer to "How did you hear about us?" on the sign-up form and anything you type beside it; and, if you arrived through another website or a tagged link, what our arrived_from cookie remembered of that first visit: the name of the website, the page you landed on, the link's campaign tags, the date, and, if the link was on a customer's public status page, that page's address and which of our customers it belonged to when you signed up. It is saved once, when the account is created, and our administrators use it only to count which ways of finding us lead to accounts. That customer is not told.
  • Sessions: while you use the site, a session stored in our database holds your sign-in state. It is deleted when you sign out. Otherwise it expires after 14 days without a visit and is removed by periodic clean-up (see our Cookie Policy).

What you monitor

  • Sites and branding: the addresses you monitor, their names and settings, and any logo or brand colour you set for your account, a status page or a client, and the timezone you choose for the account.
  • Check results: for each check, whether the site was up, its status code and response time, certificate and domain expiry dates, the domain's registrar, the broken links found on the page with their addresses, and which page tags were missing.
  • Alerts: the email addresses and webhook URLs alerts are sent to, which sites or clients each one covers, whether its last delivery worked and why it failed, and a history of the alerts we sent.
  • Clients: the names of the clients you group sites under, and the email address a client's report is sent to.
  • Maintenance windows: their start and end times and the reason you give.

Billing

  • Your plan and subscription status, and the references that link your account to Stripe. For a paid plan we give Stripe the account's name and email address. Card details are entered on Stripe's own checkout page and never reach our servers. Paid plans are sold through Link, Stripe's merchant of record service, so Stripe also holds the name and billing address you enter at checkout, and uses them to calculate VAT and issue your invoices.

Contacting us

  • Contact form: the topic, email address and message you send. Our database holds it only until it has been emailed to our inbox, where we keep it as long as we need to answer you. If you are signed in when you send it, the message also says which login and account it came from.

Preventing abuse

  • One account per mailbox: with each email address we store a normalised form of it (without any "+tag", and on Gmail without dots) so the same mailbox cannot register twice. Signing in still uses the address exactly as you typed it.
  • Free sign-up review: our administrators can see a report of where one mailbox, one company email domain, or one monitored domain appears across more than one free account. It is built from the data above and collects nothing new; it blocks nothing and emails nobody.
  • Rate limits: when you request or enter a sign-in code, register, run a free scan, or send a message through the contact form, your IP address (and, depending on the action, the email address or the domain being scanned) is used as the key of a counter that limits how often it can happen. The counters are kept in our database and removed by a nightly clean-up once they have expired. We do not otherwise store IP addresses, and none is kept with your account.

Logs

  • Application logs: the application writes operational logs, which our hosting provider stores. They can include monitored addresses, addresses submitted to the free scan, the destination of an alert that failed to deliver, an account’s old and new name when it is renamed, and error details.

3. Why We Process Your Data

We process your data on the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR): to provide the monitoring service you signed up for, including sending uptime alerts, weekly reports, and the account and billing emails the service depends on.
  • Legitimate interests (Art. 6(1)(f) GDPR): to keep the service secure, prevent fraud and abuse (the rate limits, one account per mailbox, the free sign-up review, and ending free accounts nobody uses), to learn which of the ways people find us lead to accounts, and to improve functionality.
  • Legal obligation (Art. 6(1)(c) GDPR): to comply with applicable laws, including financial record-keeping.

4. How Long We Keep Your Data

  • Check results and alert history: for your plan's history window (Free: 7 days; Pro: 90 days; Agency: 365 days), then deleted by a nightly clean-up. Paused sites are cleaned up the same way. A plan no longer offered keeps the window it was sold with.
  • Sign-in codes: deleted by the nightly clean-up once they are a day past their expiry.
  • Rate-limit counters: removed by the nightly clean-up once they have expired.
  • Everything else in an account: until you delete it, or the account is deleted. That covers sites, alert channels, clients, maintenance windows, team, and how you found us.
  • Deleted accounts: requesting deletion stops monitoring at once and ends the subscription with its current billing period. For 30 days the owner can undo it, and everything returns as it was. The delay is there so a deletion nobody meant can be undone. After that the account and all of its data are erased from our database (up to 2 days later when its billing period is about to end, so that period is billed first), and the customer record at Stripe is deleted. Invoices already issued stay with Stripe, as financial records we are required by law to keep (for example, 7 years in the Netherlands).
  • Free accounts nobody uses: if nobody on a free account signs in or uses the dashboard for 60 days, we email the account to say monitoring will pause. It pauses at 74 days without a visit, and never sooner than 14 days after that email. At 180 days we request deletion of the account, which opens the 30-day window above. Signing in before the account is erased undoes each step. Paid accounts are never affected.
  • Invited teammates: someone invited to another person's account who owns no account themselves can delete their own login from account settings. A login that owns no account and belongs to no team is removed after 30 days without a visit.
  • Application logs: kept under our hosting provider's log retention. They are not part of the account export.

5. Who We Share Data With

We do not sell your personal data. We share data only with the sub-processors needed to operate the service:

  • Stripe sells paid plans through Link as merchant of record: payment processing, subscription billing, VAT, invoices and receipts, and payment support. For these transactions Stripe acts on its own account, not only on ours.
  • Resend, for sending sign-in codes, alerts, reports, account emails and messages from the contact form (USA, Standard Contractual Clauses apply)
  • Railway, for application hosting, database and application logs

What checking a site involves

No third-party monitoring service sits between your site and your result: the checks are made by the service itself. Checking a site still means that others see part of it:

  • The sites you monitor receive our requests: the page at the address you gave, a connection to read its TLS certificate, and a request to each link found on the page (up to 50 per scan), which reaches whichever sites those links point to. Every request identifies itself as UptimeWarrior in its User-Agent.
  • Domain registries. On plans that check domain expiry, and in the free scan, we look the domain up with the registry that holds it: over RDAP, at the server listed for that domain ending in the public list IANA publishes at data.iana.org, and over WHOIS where RDAP gives no answer. These servers receive the domain name, not the full address.
  • The alert destinations you choose receive your alerts: the email addresses you enter, and the chat services behind the webhook URLs you add (Slack, Teams, Discord or Google Chat). An alert names the site, its address and what went wrong.
  • Status pages and client reports go where you send them: a status page you enable is public to anyone with its address, and a client's weekly report is emailed to the address set on that client.

6. International Transfers

Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

7. Your Rights Under GDPR

As a data subject in the EU/EEA you have the following rights:

  • Right of access: request a copy of the data we hold about you.
  • Right to rectification: ask us to correct inaccurate data.
  • Right to erasure: request deletion of your data ("right to be forgotten").
  • Right to restriction: ask us to restrict processing in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.

Two of these you can exercise yourself, without asking us:

  • Portability: account settings → export emails everything the account holds to the account's email address, as JSON and CSV: its sites and settings, check results including link details, alert channels and their routing, alert history, clients, maintenance windows, team members and logins. Check results are newest first, up to the most recent 50,000; the export says so when older ones were left out.
  • Erasure: account settings → delete this account (see section 4). An invited teammate who owns no account can delete their own login there.

For anything else, use our contact form. We will respond within 30 days.

8. Cookies

We set one essential cookie, for your session; one cookie that remembers which website or tagged link first brought you here, for 30 days and without any identifier; and keep two preferences in your browser's local storage. Stripe may set cookies on the page where you enter card details. For details, see our Cookie Policy.

9. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure, including encrypted connections (TLS) and access controls.

There are no passwords to store: signing in uses a single-use code emailed to the address on the account, which expires shortly after it is sent and works once. Codes are stored only as a keyed hash, and every failed attempt is counted against the code.

10. Changes to This Policy

We may update this policy from time to time. We will email material changes to the email address of each account. The date at the top of this page reflects the most recent revision.

11. Contact & Complaints

For privacy-related questions or to exercise your rights, use our contact form.

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.