DRAFT — not in force yet.
This document is being prepared and does not apply yet. Highlighted notes are open decisions.
Privacy Policy
This policy explains how VitalCrawl (“we”, “us”) processes personal data when you visit our website, create an account or use the website monitoring service (the “Service”).
Controller: [to be completed], [to be completed]. Contact for privacy questions: [to be completed].
To decide: The controller is established outside the EU. An EU representative (Art. 27 GDPR) is generally required when offering services to people in the EU; services such as Prighter or EDPO provide this for a yearly fee. Name the representative here or record why it is not needed.
1. Two roles
As controller we process data about our own users: account holders, team members and visitors of our website.
As processor we process data that customers put into the Service about other people — for example email addresses of their clients, on-call contacts or status page subscribers, and whatever appears on the monitored websites. For that data the customer is the controller, and our Data Processing Agreement applies.
2. What we process and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Name, studio name, email, password (stored as a hash), time zone, language, two-factor secret | Creating and securing your account, signing in | Contract (Art. 6(1)(b)) |
| Notification settings: chat IDs, webhook URLs, Pushover and PagerDuty/Opsgenie keys | Sending alerts where you asked us to | Contract |
| Team members’ names and emails, pending invitations | Shared workspaces and roles | Contract; legitimate interest of the inviting customer (Art. 6(1)(f)) |
| Addresses of monitored websites, check results, screenshots, page snapshots and change history | Providing the monitoring service | Contract |
| Support tickets and attachments | Answering your requests | Contract; legitimate interest |
| Payment records (amount, date, plan, exchange rate). Card data is handled by Robokassa and never reaches us. | Billing, accounting, refunds | Contract; legal obligation (Art. 6(1)(c)) |
| Free website check: the domain and, if you give it, your email | Showing and sending the report | Legitimate interest; contract (if you request the email) |
| IP address, browser and device in sessions and server logs | Security, preventing abuse, troubleshooting | Legitimate interest |
| Consent to product updates (only if you ticked the box) | Occasional product news | Consent (Art. 6(1)(a)), which you can withdraw at any time |
We do not sell personal data and do not use it for advertising. We do not make decisions with legal effects based solely on automated processing.
3. Cookies and similar technologies
Our website and dashboard use only cookies that are necessary for them to work:
- Session and security cookies — keep you signed in and protect forms (CSRF);
- “Remember me” — only if you choose it at sign-in;
- Language (
locale) — remembers the language you picked on the website, for one year; - Status page access — remembers that you entered the password of a protected status page;
- the colour theme is stored in your browser’s local storage, not sent to us.
We do not use analytics, advertising or tracking cookies, so we do not show a cookie consent banner. If that changes, we will ask for consent before setting any such cookie.
4. How long we keep data
- Account data — while the account exists. When you delete the account, we delete it together with monitors, history, screenshots, status pages, team data and API tokens.
- Payment records — for as long as accounting law requires; the payment provider’s response is removed after 180 days, and immediately if you delete the account.
- Closed support tickets — 365 days after closing.
- Free website checks — 90 days.
- Server logs — 30 days.
To decide: Russian accounting law requires keeping primary documents for 5 years — state that period for payment records.
5. Who receives data
We use service providers (sub-processors) for hosting, email delivery, payments and some checks. The current list, with locations, is on the Sub-processors page.
When you connect an integration — Slack, Microsoft Teams, Discord, Google Chat, Telegram, PagerDuty, Opsgenie, Pushover, ntfy or a webhook — we send alert texts there on your instruction. Those services process the data under their own terms.
6. International transfers
Some providers are located outside the European Economic Area (see the sub-processor list). Where the destination has no adequacy decision, transfers rely on the European Commission’s Standard Contractual Clauses or another safeguard under Chapter V GDPR.
To decide: The controller and the payment provider (Robokassa) are in Russia, which has no EU adequacy decision. Before launch, state the transfer basis here — for example Standard Contractual Clauses — or explain that data is transferred because it is necessary to perform the contract with you (Art. 49(1)(b) GDPR).
7. Your rights
You can ask us to access, correct, delete or export your data, restrict or object to processing, and withdraw consent. Most of this is self-service:
- Export — Settings → Profile → “Export my data” gives you a JSON archive of your account;
- Delete — Settings → Profile → “Delete account” removes the account and its data;
- Correct — edit your profile in Settings;
- Product updates — unsubscribe with the link in any update or in Settings.
For anything else, write to the privacy contact above; we answer within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.
8. Security
Connections are encrypted (HTTPS). Passwords are stored as hashes, API and access tokens as fingerprints, and secrets of monitors (such as SMTP passwords) encrypted. Two-factor sign-in is available for every account. Access to production systems is limited to the people who run the Service.
9. Changes
We will announce material changes by email or in the dashboard before they take effect. The date at the top shows the current version.