Privacy Policy
This Privacy Policy explains how CompleteStatus ("we", "us") collects, uses, and protects information when you use our uptime and security-monitoring service. It applies to our website, applications, and related services.
1. Data we collect
- Account data — your name, email address, and password (stored only as a hash).
- Monitoring configuration — the targets (URLs, hosts, domains) and settings you add, and the results of checks we run for you.
- Billing data — plan and subscription details. Payment card details are collected and processed by our payment processor, not stored by us.
- Communications — messages you send us and your notification and status-page subscription preferences.
- Technical data — IP address, browser and device information, and log data generated when you use the service.
2. How we use data
- to provide and operate the service — running checks, sending alerts, and rendering status pages and reports;
- to process payments and manage subscriptions;
- to secure the service, prevent abuse, and enforce our Terms of Service;
- to communicate with you about your account, incidents, and service changes; and
- to comply with legal obligations.
3. Cookies
We use strictly necessary cookies to keep you signed in and to secure the service (for example, session and CSRF-protection cookies). We aim to keep cookie use minimal. Where required, any non-essential cookies would be used only with your consent.
4. Payment processing
Payments are handled by Stripe, our third-party payment processor. When you subscribe to a paid plan, your payment details are provided directly to Stripe and processed under Stripe's own terms and privacy policy. We receive limited billing information (such as subscription status and the last few digits of a card) but not full card numbers.
5. Subscriber and notification emails
If you subscribe to a status page, we store your email address to send incident and recovery notifications for that page. We send a confirmation link before activating a subscription, and every notification includes an unsubscribe link. Account-related emails (such as security and billing notices) are part of the service.
6. Sharing and service providers
We do not sell your personal data, and we do not use it for advertising. We share data only with the service providers who help us operate, under appropriate confidentiality and data-processing obligations, or where required by law:
- DigitalOcean — hosting and infrastructure.
- Stripe — payment processing for paid plans.
- Our transactional email provider — delivery of alert, report, and account email.
Where you configure outbound alert integrations yourself (for example Slack, Microsoft Teams, Discord, PagerDuty, or your own webhook endpoint), we send the alert content you have asked us to send to that destination; those services handle it under their own terms.
6a. Where data is processed
The service is operated from the United States and your data is stored and processed there. If you access the service from outside the United States, you are transferring data to the United States for the purposes described in this policy.
7. Retention
We keep personal data for as long as your account is active and as needed to provide the service, then for a reasonable period to meet legal, accounting, or security obligations.
Monitoring and activity data are retained on these schedules:
- Individual check results — 48 hours. These are the raw, per-check records; after that window they are permanently deleted.
- Hourly summaries — 90 days.
- Daily summaries — retained for the life of the account, so long-term uptime history and SLA reporting remain available.
- Alert and webhook delivery records — 180 days.
- Account audit log — retained for the life of the account. How far back you can view the log depends on your plan (from the last 7 days on Free up to the last 365 days on Business and Agency); older entries are hidden, not deleted, and reappear if you upgrade.
When you delete a monitor, its associated check data is removed on these schedules or sooner. You can close your account and delete its personal data yourself at any time from your account settings (see section 8); Backups are retained for a limited period and are overwritten in the ordinary course.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing.
Two of these you can exercise directly, without waiting on us, from Account & security → Privacy & data in your account settings:
- Access & portability. Use Export my data to download a single machine-readable JSON file containing your profile, your memberships, and the data of every organization you own (projects, monitors, incidents, alert channels, status pages and subscribers, and the audit log). Secrets — authentication tokens, API keys, webhook URLs, your two-factor secret and your password — are redacted from the file.
- Erasure. Use the Danger zone to permanently delete an entire organization you own, or to delete your account. Both actions are irreversible, require re-entering your password and a typed confirmation, and cancel any active subscription. Deleting your account also deletes the organizations you solely own.
For correction, restriction, objection, or any request you cannot complete yourself, email us using the details in section 11 and we will verify your request and action it within a reasonable time.
9. Security
We use technical and organizational measures to protect personal data, including encryption in transit, hashed passwords, and encrypted storage of sensitive credentials. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be signposted, and the "last updated" date above will reflect the latest revision.
11. Contact
For privacy questions or to exercise your rights, email alerts@completestatus.com.