Privacy Policy
Last updated September 28, 2026
This Privacy Policy explains how CompleteStatus ("we", "us") collects, uses, and protects information when you use our uptime and security-monitoring service. It applies to our website, applications, and related services. CompleteStatus is a small business based in Florida, United States.
1. Data we collect
- Account data — your name, email address, and password (stored only as a hash). If you choose "Sign in with Google", we receive your name, email address, and Google account identifier from Google.
- Monitoring configuration — the targets (URLs, hosts, domains) and settings you add, and the results of checks we run for you.
- Billing data — plan and subscription details. Payment card details are collected and processed by our payment processor, not stored by us.
- Communications — messages you send us and your notification and status-page subscription preferences.
- Referral data — if an existing user invites you by email, we store your email address, who invited you, and whether you signed up. If you arrive through someone's referral link, we record the visit against that link.
- Technical data — IP address, browser and device information, and log data generated when you use the service.
2. How we use data
- to provide and operate the service — running checks, sending alerts, and rendering status pages and reports;
- to process payments and manage subscriptions;
- to secure the service, prevent abuse, and enforce our Terms of Service;
- to communicate with you about your account, incidents, and service changes;
- to credit the person who referred you, if you signed up through a referral; and
- to comply with legal obligations.
We do not use your data for advertising, and we do not build profiles of you across other websites.
3. Legal bases (EEA and UK users)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:
- Contract — to create and run your account, perform the monitoring you set up, send the alerts and reports you configure, and bill paid plans.
- Legitimate interests — to keep the service secure and prevent abuse, to keep logs needed to operate it, to improve it, and to attribute referrals. We balance these interests against your rights, and you can object (see section 11).
- Consent — where we ask for it, for example when you subscribe to a public status page (we confirm by email first). You can withdraw consent at any time, for example with the unsubscribe link in each email.
- Legal obligation — to keep billing and tax records and to respond to lawful requests.
4. Cookies
We keep cookies to a minimum. We do not use analytics cookies, advertising cookies, or tracking pixels, and we do not load third-party analytics on our website. These are the only cookies our website sets:
| Cookie | Purpose | Duration |
|---|---|---|
completestatus-session |
Strictly necessary. Keeps your session working (for example, keeps you signed in and remembers form state between pages). | 120 minutes of inactivity |
XSRF-TOKEN |
Strictly necessary. Protects forms against cross-site request forgery. | Same as the session |
remember_web_… |
Strictly necessary, and only set if you tick "Remember me" when signing in. Keeps you signed in on that device. | Up to 400 days, or until you sign out |
cs_ref |
Referral attribution. Set only when you open someone's referral link (/r/…), so that if you sign up, the person who referred you gets credit. It holds the referral code only. It is not used for advertising or to track you on other sites. It is not set if your browser sends a Global Privacy Control signal (see section 5). |
30 days |
cs_status_lang |
Language preference on public status pages. Set only when you pick a language in a status page's language menu, and only for that page, so it keeps showing in the language you chose. It holds the language code only. | 365 days |
Because the session, security, and remember-me cookies are strictly necessary for the site to work, we do not show a cookie consent banner. The referral cookie is optional: you can avoid it by not using referral links, by turning on Global Privacy Control, or by blocking or deleting cookies in your browser.
When signed in, the app also stores your light/dark theme choice in your browser's local storage. It never leaves your device.
Some forms (sign-up, password reset, and the waitlist) may use Cloudflare Turnstile to tell people from bots. When it is switched on, Cloudflare processes technical information such as your IP address and browser signals for that check under its own privacy policy. "Sign in with Google" takes you to Google, where Google's own cookies and privacy policy apply.
5. Do Not Track and Global Privacy Control
Do Not Track: we do not track you across other websites or over time for advertising, and we do not allow third parties to do so on our site. Because of that, a browser "Do Not Track" signal does not change what we do — there is no cross-site tracking to turn off.
Global Privacy Control (GPC): if your browser sends a GPC signal,
we do not set the cs_ref referral cookie. We do not sell
or share personal information in the first place (see section 12), so no other
change is needed.
6. Payment processing
Payments are handled by Stripe, our third-party payment processor. When you subscribe to a paid plan, your payment details are provided directly to Stripe and processed under Stripe's own terms and privacy policy. We receive limited billing information (such as subscription status and the last few digits of a card) but not full card numbers.
7. Emails we send
If you subscribe to a status page, we store your email address to send incident and recovery notifications for that page. We send a confirmation link before activating a subscription, and every notification includes an unsubscribe link. Account-related emails (such as alerts you configure, security, and billing notices) are part of the service.
Status-page subscribers. Each status page is run by the organization that owns it, usually one of our customers rather than us. That organization controls the page's subscriber list: it can see how many people have subscribed, and its owners can export subscribers' email addresses and the date each subscription was confirmed. It also writes the incident updates sent to subscribers. We process your address on that organization's behalf, only to send that page's notifications. You can unsubscribe at any time with the link in any notification. To access or delete your data, contact the organization that runs the page, or email us at support@completestatus.com and we will pass your request on.
If a user invites you by email, we send you one invitation on their behalf. It includes a one-click unsubscribe link; if you use it, we will not send you invitations again. We do not add you to any mailing list and we do not follow up unless you sign up.
8. Sharing and service providers
We do not sell your personal data, and we do not use it for advertising. We share data only with the service providers who help us run the service, under appropriate confidentiality and data-processing terms; with the organization that runs a status page you subscribe to (see section 7); or where required by law. The main service providers are:
- DigitalOcean — hosting and infrastructure.
- Postmark (ActiveCampaign, LLC) — delivery of alert, report, and account email.
- Stripe — payment processing for paid plans.
- Google — optional "Sign in with Google", and the Google Web Risk threat lists we check website addresses against for reputation checks and the free Security Score. The check runs on our servers against a copy of Google's lists; Google never receives the address itself, only, when an address partly matches a listed entry, a short hash prefix of it to confirm the match.
- Cloudflare — Turnstile bot protection on some forms, when switched on.
- Microsoft 365 — our company email, including the support inbox that receives messages you send us.
The full list, with what each provider receives and where, is on our subprocessors page.
Where you configure outbound alert integrations yourself (for example Slack, Microsoft Teams, Discord, PagerDuty, or your own webhook endpoint), we send the alert content you have asked us to send to that destination; those services handle it under their own terms and your agreement with them.
9. Where data is processed and international transfers
The service is operated from the United States and your data is stored and processed there. If you access the service from outside the United States, your data is transferred to the United States for the purposes described in this policy. US data protection law may differ from the law where you live.
Our main service providers publish their own data processing terms, which include safeguards for international transfers. For business customers in the EEA or UK who need them, we can put the European Commission's Standard Contractual Clauses (and the UK addendum) in place on request. If your organization needs a data processing agreement, contact us at support@completestatus.com.
10. Retention
We keep personal data for as long as your account is active and as needed to provide the service, then for a reasonable period to meet legal, accounting, or security obligations.
Monitoring and activity data are retained on these schedules:
- Individual check results — 48 hours. These are the raw, per-check records; after that window they are permanently deleted.
- Hourly summaries — 90 days.
- Daily summaries and incident records — retained for the life of the account. How far back you can view this history in the service (uptime history, charts, SLA reports and the API) depends on your plan: 14 days on Free, 365 days (1 year) on Pro, 730 days (2 years) on Business, 730 days (2 years) on Agency and 1,095 days (3 years) on Enterprise. History older than your plan's window is kept, not deleted, and is shown again if you move to a plan that covers it.
- Alert and webhook delivery records — 180 days.
- Account audit log — retained for the length of your plan's audit-log window, then permanently deleted. That window is 7 days on Free, 30 days on Pro, 365 days (1 year) on Business and Agency, and 1,095 days (3 years) on Enterprise. Entries older than your plan's window are permanently deleted rather than merely hidden, so your audit history matches the window your plan provides. System-level security events that belong to no single account are kept for up to 365 days.
When you delete a monitor, its associated check data is removed on these schedules or sooner. You can close your account and delete its personal data yourself at any time from your account settings (see section 11). Backups are retained for a limited period and are overwritten in the ordinary course.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing.
Two of these you can exercise directly, without waiting on us, from Account & security → Privacy & data in your account settings:
- Access & portability. Use Export my data to download a single machine-readable JSON file containing your profile, your memberships, and the data of every organization you own (projects, monitors, incidents, alert channels, status pages and subscribers, and the audit log). Secrets — authentication tokens, API keys, webhook URLs, your two-factor secret and your password — are redacted from the file.
- Erasure. Use the Danger zone to permanently delete an entire organization you own, or to delete your account. Both actions are irreversible, require re-entering your password and a typed confirmation, and cancel any active subscription. Deleting your account also deletes the organizations you solely own.
For correction, restriction, objection, or any request you cannot complete yourself, email us at support@completestatus.com. We will verify your request and action it within a reasonable time, and within any deadline the law sets. If you are in the EEA or UK, you also have the right to complain to your local data protection authority.
12. California privacy rights
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). We honor these rights for all users, whether or not the law applies to a business of our size:
- Right to know what personal information we collect, use, and disclose, and to get a copy of it. The categories we collect are listed in section 1: identifiers (such as name, email address, and IP address), account and billing records, internet or network activity (such as log data), and the monitoring configuration you give us. We collect it from you, from your use of the service, and — if you use them — from Google sign-in and from people who invite you. We use it for the purposes in section 2 and disclose it only to the service providers in section 8.
- Right to delete personal information we hold about you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information. The only sensitive personal information we hold is your account login (your password is stored only as a hash). We use it only to sign you in and secure your account, so there is nothing further to limit. Card details are held by Stripe, not by us.
- No discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service for exercising these rights.
We do not sell or share personal information, as "sell" and "share" are defined by the CCPA/CPRA, and we have not done so in the past 12 months. We do not knowingly collect personal information from anyone under 16.
How to exercise your rights: use Export my data and the Danger zone in your account settings (see section 11), or email support@completestatus.com. We will confirm your request within 10 business days and aim to respond within 45 days. We verify requests by confirming control of the email address on the account. You may use an authorized agent; we may ask the agent for proof of authorization and ask you to confirm the request directly.
13. Children
The service is for businesses and professionals and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.
14. Security
We use technical and organizational measures to protect personal data, including encryption in transit, hashed passwords, and encrypted storage of sensitive credentials. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be signposted, and the "last updated" date above will reflect the latest revision.
16. Contact
For privacy questions or to exercise your rights, email support@completestatus.com.