This Privacy Policy explains how Watchfox processes personal data when you use Watchfox websites, the Watchfox app, monitoring features, status pages, reports, alerts, billing, and support.
This document is intended for business customers and professional users. It should be read together with the Watchfox Terms of Service and, where applicable, the Watchfox Data Processing Addendum.
1. Who we are
Watchfox is operated by:
- Legal operator:
Pirbit s.r.o. - Registered address:
Chotikov 391, 330 17 Chotikov, Czech Republic - Company ID / registration number:
11787155 - Support: [email protected]
- Billing: [email protected]
- Privacy: [email protected]
- Security: [email protected]
- Abuse: [email protected]
For privacy questions, GDPR requests, export requests, deletion requests, or data retention questions, contact [email protected].
2. GDPR roles
Depending on the context, Watchfox may act as either a data controller or a data processor.
Watchfox as controller
Watchfox acts as controller for data we need to operate our own business, including:
- account registration and authentication metadata
- workspace membership administration
- billing and entitlement metadata
- security, abuse prevention, and service integrity
- support requests
- legal/compliance records
- product and service communications
Watchfox as processor
For customer-provided monitoring configuration, operational monitoring data, status page configuration, alert configuration, and report data processed on behalf of a customer workspace, Watchfox generally acts as a processor and the customer acts as controller.
Where Watchfox acts as processor, the Watchfox Data Processing Addendum applies.
3. EU-first operations
Watchfox is designed with an EU-first operational model.
- Primary application persistence is intended to be hosted in EU infrastructure.
- Watchfox minimizes unnecessary operational data where practical.
- Retention windows are explicit and documented below.
- Access to customer data is limited by authentication, workspace membership, and operational need.
Important practical note: Watchfox uses serverless and third-party infrastructure providers. Some processing may occur outside the EU/EEA, for example through global edge networks, email delivery, billing, error monitoring, support tooling, or configured notification integrations. Where applicable, Watchfox relies on processor DPAs, Standard Contractual Clauses, or equivalent transfer safeguards.
4. Data we process
4.1 Account and workspace data
When you sign in and use Watchfox, we process:
- email address
- user ID
- authentication/session metadata
- workspace / organization ID and name
- membership role, such as owner, admin, member, or billing
- selected project/workspace state
- invite and membership records
Purpose:
- account access
- workspace collaboration
- role-based permissions
- security and abuse prevention
- support and troubleshooting
4.2 Project and monitor configuration
When you create monitoring resources, we process configuration you provide, including:
- project names
- monitor labels
- monitor URLs or domains
- monitor type
- check interval
- probe coverage and historical probe-group check evidence
- expected HTTP status
- keyword rules
- TLS/domain/sitemap/heartbeat configuration
- alert settings
- maintenance window settings
Purpose:
- operate monitoring checks
- display monitor state
- detect incidents
- send configured alerts
- generate reports and status pages
Note: monitor URLs are provided by you. Avoid putting personal data or secrets in URLs, query parameters, labels, status page text, or report branding fields.
4.3 Monitoring results and incident history
Watchfox stores monitoring results and derived incident state, including:
- timestamps
- monitor ID and project ID
- monitor type
- probe group
- status code where applicable
- latency where applicable
- OK/down/warning/unknown result state
- TLS/domain/sitemap/heartbeat-specific result fields
- incident open/recovery timestamps
- minimal diagnostic details required to explain failures
Watchfox does not intentionally store full HTTP response bodies as normal monitoring history.
Purpose:
- provide recent troubleshooting data
- calculate uptime/downtime reporting
- detect and resolve incidents
- support customer debugging
4.4 Heartbeat pings
When a heartbeat endpoint is called, Watchfox stores a minimal record to determine whether the heartbeat is fresh or missing.
We store:
- timestamp
- monitor ID
- truncated IP prefix only:
- IPv4 truncated to
/24 - IPv6 truncated to
/56 - no User-Agent
Purpose:
- operate heartbeat monitoring
- detect missing scheduled jobs
- diagnose abuse or rate-limit issues at a coarse level
4.5 Notifications and delivery logs
If you configure notification channels, Watchfox processes:
- notification channel type
- target address or webhook URL
- alert rules
- delivery state
- last success/failure metadata
- delivery event logs
For webhook-style integrations, Watchfox may store destination URLs. We mask secret-bearing URLs in normal UI responses where practical.
Purpose:
- send alerts you configure
- retry or suppress failing channels
- troubleshoot delivery issues
- prevent repeated delivery failures
4.6 Status pages, status subscribers, and reports
If you use status pages or reports, Watchfox processes:
- status page title, slug, intro text, components, and visibility settings
- public incident communication updates
- maintenance window information displayed on status pages
- status page subscriber email addresses, if a visitor subscribes to updates
- subscription confirmation and unsubscribe tokens
- limited delivery state for status page subscriber emails
- report branding configuration
- report summary data
- generated PDF/CSV exports
Purpose:
- publish customer-configured status pages
- send subscribed visitors public incident, recovery, and maintenance updates
- manage double opt-in confirmation and unsubscribe requests
- generate reports
- provide client-friendly operational summaries
Status page subscriber emails are stored separately from internal notification channels. Subscriber emails are not shown on public status pages and are used only for the status page updates the visitor requested.
Do not place sensitive personal data or secrets in public status page content.
4.7 Billing data
Watchfox uses Paddle as Merchant of Record for paid subscriptions.
Watchfox does not store full card numbers or payment card details.
Watchfox may store minimal billing and entitlement metadata, such as:
- Paddle customer/subscription identifiers
- plan and price identifiers
- subscription status
- renewal/cancellation timestamps
- entitlement state
- billing event IDs needed for idempotency and auditability
Payment details, taxes, invoices, chargebacks, and certain buyer-facing billing operations are handled by Paddle according to Paddle’s own terms and privacy notices.
4.8 Support, privacy, security, and abuse requests
When you contact Watchfox, we process:
- your email address
- message subject and body
- selected request category
- relevant diagnostic context, where available:
- org ID
- project ID
- monitor ID
- request ID
- trace ID
- current page URL
- timestamp
Purpose:
- respond to support requests
- investigate bugs
- handle billing questions
- process privacy requests
- investigate security reports
- respond to abuse reports
Please do not send secrets, passwords, private keys, webhook secrets, or sensitive personal data unless specifically requested through a secure channel.
4.9 Security and operational logs
Watchfox may process minimal operational logs and metadata to:
- secure the service
- detect abuse
- debug failures
- investigate incidents
- enforce rate limits
- maintain availability
These logs may include request metadata, timestamps, error traces, route names, status codes, and minimal diagnostic context. Watchfox aims to avoid storing secrets in logs.
5. Legal bases for processing
Where Watchfox acts as controller, the legal basis may include:
- performance of a contract
- legitimate interests, such as securing and operating the service
- compliance with legal obligations
- consent, where required for optional communications or optional features
Where Watchfox acts as processor, the customer is responsible for determining the applicable legal basis for personal data they submit or configure in Watchfox.
6. Data retention
Watchfox uses explicit retention windows for operational data.
Automated retention windows
- Raw monitoring logs (
monitor_checks): 30 days - 15-minute aggregated monitoring rollups: 90 days
- Daily monitoring summaries: 12 months
- Heartbeat records: 30 days
- Notification delivery events: 90 days
- Incidents: at least 12 months
Configuration data
Workspace, project, monitor, notification, status page, API key metadata, maintenance window, and report branding configuration are retained until deleted, archived, or purged by the customer or through an authorized support/privacy process.
Billing and legal records
Some billing, tax, fraud prevention, security, and legal records may be retained for longer where required by law, accounting obligations, dispute handling, chargeback handling, or legitimate compliance needs.
Backups and derived records
Deleted data may remain in backups for a limited period until backups rotate. Watchfox will not intentionally restore deleted customer data except where necessary for security, legal, or disaster recovery reasons.
7. Sub-processors
Watchfox uses third-party providers to operate the service. Current expected sub-processors include:
| Provider | Purpose | Notes |
|---|---|---|
| Cloudflare | Hosting, Pages, Workers, DNS/edge, routing, caching, rate limiting, security | Global edge processing may occur |
| Supabase | PostgreSQL database, authentication, storage of primary app data | Primary persistence intended in EU infrastructure |
| Postmark | Transactional email and alert email delivery | Used for login/support/alerts where applicable |
| Paddle | Merchant of Record, checkout, invoices, tax, subscription billing | Paddle may act as independent controller for buyer/payment data |
| Sentry | Error monitoring and diagnostics | Used to detect and debug application/runtime errors |
Customer-configured notification integrations may also receive alert data when enabled by the customer, for example Slack, Microsoft Teams, Discord, Google Chat, or generic webhook endpoints.
Watchfox may update the sub-processor list as the product evolves. Material changes should be reflected in this policy or a linked sub-processor list.
8. International transfers
Some providers may process data outside the EU/EEA. Where required, Watchfox relies on appropriate safeguards such as:
- Data Processing Agreements
- Standard Contractual Clauses
- provider security documentation
- transfer impact and risk-based assessments where appropriate
9. Security measures
Watchfox applies practical security controls, including:
- authentication and workspace membership checks
- role-based authorization
- server-side plan enforcement for paid features
- least-privilege service-role usage where practical
- CORS allowlisting
- internal API token checks for protected worker-to-app calls
- rate limiting on sensitive endpoints
- webhook verification for billing events
- masking of secret-bearing notification targets in normal UI/API responses
- privacy-minimized heartbeat metadata
- incident/security escalation process
No internet service can be guaranteed fully secure. If you believe you found a vulnerability, contact [email protected].
10. Your rights
Depending on your location and role, you may have rights to:
- access personal data
- correct inaccurate data
- request deletion
- restrict processing
- object to processing
- request portability
- lodge a complaint with a data protection authority
For GDPR/DSAR requests, contact [email protected].
We may need to verify your identity and authority before acting on a request, especially where the request affects a workspace, organization, customer account, or another person’s data.
11. How to request export or deletion
Option A: In-app request
1. Open Watchfox. 2. Use Contact support. 3. Select Privacy. 4. Describe the requested action:
- account data export
- workspace/project export
- account deletion
- workspace/project deletion
- retention clarification
Include relevant context where available:
- login email
- org ID
- project ID
- monitor ID, if relevant
Option B: Email
Email [email protected] from the email address associated with your Watchfox account.
Suggested subjects:
Watchfox data export requestWatchfox account deletion requestWatchfox retention question
12. Children
Watchfox is a B2B/professional service and is not intended for children.
13. Changes to this policy
Watchfox may update this Privacy Policy as the service evolves. The “Last updated” date indicates the latest revision.
Material changes should be communicated through the app, website, email, or another reasonable channel where appropriate.