Watchfox

Legal & trust

Watchfox Privacy Policy

How Watchfox handles personal data, retention, support, and privacy requests.

Last updated: 2026-04-25

This Privacy Policy explains how Watchfox processes personal data when you use Watchfox websites, the Watchfox app, monitoring features, status pages, reports, alerts, billing, and support.

This document is intended for business customers and professional users. It should be read together with the Watchfox Terms of Service and, where applicable, the Watchfox Data Processing Addendum.


1. Who we are

Watchfox is operated by:

For privacy questions, GDPR requests, export requests, deletion requests, or data retention questions, contact [email protected].


2. GDPR roles

Depending on the context, Watchfox may act as either a data controller or a data processor.

Watchfox as controller

Watchfox acts as controller for data we need to operate our own business, including:

Watchfox as processor

For customer-provided monitoring configuration, operational monitoring data, status page configuration, alert configuration, and report data processed on behalf of a customer workspace, Watchfox generally acts as a processor and the customer acts as controller.

Where Watchfox acts as processor, the Watchfox Data Processing Addendum applies.


3. EU-first operations

Watchfox is designed with an EU-first operational model.

Important practical note: Watchfox uses serverless and third-party infrastructure providers. Some processing may occur outside the EU/EEA, for example through global edge networks, email delivery, billing, error monitoring, support tooling, or configured notification integrations. Where applicable, Watchfox relies on processor DPAs, Standard Contractual Clauses, or equivalent transfer safeguards.


4. Data we process

4.1 Account and workspace data

When you sign in and use Watchfox, we process:

Purpose:


4.2 Project and monitor configuration

When you create monitoring resources, we process configuration you provide, including:

Purpose:

Note: monitor URLs are provided by you. Avoid putting personal data or secrets in URLs, query parameters, labels, status page text, or report branding fields.


4.3 Monitoring results and incident history

Watchfox stores monitoring results and derived incident state, including:

Watchfox does not intentionally store full HTTP response bodies as normal monitoring history.

Purpose:


4.4 Heartbeat pings

When a heartbeat endpoint is called, Watchfox stores a minimal record to determine whether the heartbeat is fresh or missing.

We store:

Purpose:


4.5 Notifications and delivery logs

If you configure notification channels, Watchfox processes:

For webhook-style integrations, Watchfox may store destination URLs. We mask secret-bearing URLs in normal UI responses where practical.

Purpose:


4.6 Status pages, status subscribers, and reports

If you use status pages or reports, Watchfox processes:

Purpose:

Status page subscriber emails are stored separately from internal notification channels. Subscriber emails are not shown on public status pages and are used only for the status page updates the visitor requested.

Do not place sensitive personal data or secrets in public status page content.


4.7 Billing data

Watchfox uses Paddle as Merchant of Record for paid subscriptions.

Watchfox does not store full card numbers or payment card details.

Watchfox may store minimal billing and entitlement metadata, such as:

Payment details, taxes, invoices, chargebacks, and certain buyer-facing billing operations are handled by Paddle according to Paddle’s own terms and privacy notices.


4.8 Support, privacy, security, and abuse requests

When you contact Watchfox, we process:

Purpose:

Please do not send secrets, passwords, private keys, webhook secrets, or sensitive personal data unless specifically requested through a secure channel.


4.9 Security and operational logs

Watchfox may process minimal operational logs and metadata to:

These logs may include request metadata, timestamps, error traces, route names, status codes, and minimal diagnostic context. Watchfox aims to avoid storing secrets in logs.


5. Legal bases for processing

Where Watchfox acts as controller, the legal basis may include:

Where Watchfox acts as processor, the customer is responsible for determining the applicable legal basis for personal data they submit or configure in Watchfox.


6. Data retention

Watchfox uses explicit retention windows for operational data.

Automated retention windows

Configuration data

Workspace, project, monitor, notification, status page, API key metadata, maintenance window, and report branding configuration are retained until deleted, archived, or purged by the customer or through an authorized support/privacy process.

Billing and legal records

Some billing, tax, fraud prevention, security, and legal records may be retained for longer where required by law, accounting obligations, dispute handling, chargeback handling, or legitimate compliance needs.

Backups and derived records

Deleted data may remain in backups for a limited period until backups rotate. Watchfox will not intentionally restore deleted customer data except where necessary for security, legal, or disaster recovery reasons.


7. Sub-processors

Watchfox uses third-party providers to operate the service. Current expected sub-processors include:

ProviderPurposeNotes
CloudflareHosting, Pages, Workers, DNS/edge, routing, caching, rate limiting, securityGlobal edge processing may occur
SupabasePostgreSQL database, authentication, storage of primary app dataPrimary persistence intended in EU infrastructure
PostmarkTransactional email and alert email deliveryUsed for login/support/alerts where applicable
PaddleMerchant of Record, checkout, invoices, tax, subscription billingPaddle may act as independent controller for buyer/payment data
SentryError monitoring and diagnosticsUsed to detect and debug application/runtime errors

Customer-configured notification integrations may also receive alert data when enabled by the customer, for example Slack, Microsoft Teams, Discord, Google Chat, or generic webhook endpoints.

Watchfox may update the sub-processor list as the product evolves. Material changes should be reflected in this policy or a linked sub-processor list.


8. International transfers

Some providers may process data outside the EU/EEA. Where required, Watchfox relies on appropriate safeguards such as:


9. Security measures

Watchfox applies practical security controls, including:

No internet service can be guaranteed fully secure. If you believe you found a vulnerability, contact [email protected].


10. Your rights

Depending on your location and role, you may have rights to:

For GDPR/DSAR requests, contact [email protected].

We may need to verify your identity and authority before acting on a request, especially where the request affects a workspace, organization, customer account, or another person’s data.


11. How to request export or deletion

Option A: In-app request

1. Open Watchfox. 2. Use Contact support. 3. Select Privacy. 4. Describe the requested action:

Include relevant context where available:

Option B: Email

Email [email protected] from the email address associated with your Watchfox account.

Suggested subjects:


12. Children

Watchfox is a B2B/professional service and is not intended for children.


13. Changes to this policy

Watchfox may update this Privacy Policy as the service evolves. The “Last updated” date indicates the latest revision.

Material changes should be communicated through the app, website, email, or another reasonable channel where appropriate.

Use the right mailbox so we can route your request quickly.