Legal
Privacy Policy
This policy explains what Concepcion.Work ("we", "us") collects when you use Site Monitor (the "Service"), why we collect it, who we share it with, and the choices you have. We have tried to keep it short and plain. If anything is unclear, email support@concepcion.work.
In short: we collect what we need to run your account, check the websites you ask us to check, and send the alerts you ask for. We do not sell your data and we do not run advertising or analytics trackers.
1. Who this covers
This policy applies to people who create or use a Site Monitor account, and to visitors of our public pages. If you are an agency using Site Monitor to monitor your clients' websites, you are the controller of any personal data you enter (such as your clients' alert recipients) and we process it on your behalf under our Data Processing Addendum.
2. What we collect
Account data
- Name, email address, username, and company or team name.
- A salted hash of your password. We never store the password itself.
- If you enable two-factor authentication: a TOTP secret and hashed backup codes.
- Team members you invite, with the same fields.
- Billing status and plan, and identifiers that link your account to Stripe. Card numbers are entered directly with Stripe and never reach our servers.
Monitoring data
- The URLs you ask us to monitor, their display names, and the check settings you choose.
- Check results: timestamps, HTTP status codes, response times, error messages, outage start and end times, and SSL certificate expiry dates.
- Alert and report configuration: recipient email addresses, Slack and webhook URLs, phone numbers for SMS, report schedules, your logo and brand name.
- SMTP settings you connect so alerts can be sent from your own domain, including the credentials needed to send.
Technical data
- IP addresses, browser and device information, and timestamps of requests, kept in server logs.
- Login attempts, including failed ones, used for rate limiting and abuse prevention.
- A session cookie that keeps you signed in (see Cookies below).
We do not collect content from the websites you monitor beyond what is needed to decide whether they are up: we fetch public pages the way a browser would and keep the status, timing and any error. We never log in to your sites, never submit forms, and never handle patient or customer records.
3. How we use it
- To run the Service: check your sites, send alerts and reports, show your dashboard, and bill your subscription.
- To keep accounts secure: verify logins, enforce rate limits, screen passwords against known breaches, and investigate abuse.
- To support you: answer questions and troubleshoot delivery problems.
- To send service messages: trial and billing notices, security notices, and changes to these terms. We do not send marketing email without your consent.
- To meet legal obligations, such as tax and accounting rules.
4. Legal bases (GDPR)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve it, balanced against your rights.
- Legal obligation — to keep billing records.
- Consent — for anything optional, which you can withdraw at any time.
5. Who we share it with
We share data only with the providers we need to run the Service (our sub-processors), listed below, and:
- with services you connect yourself, such as your SMTP server, Slack workspace or webhook endpoint, which receive the alert content you configure;
- with your team members, who can see your account's sites, results and settings;
- with the public, for any status page you choose to make public;
- with authorities where the law requires it, or to protect our rights, users or the public;
- with a successor if we are acquired or merge, under this same policy.
We do not sell personal data and never have.
Sub-processors
| Provider | Location | Purpose |
|---|---|---|
| Vercel Inc. | USA | Hosting and serverless compute for the application and check scheduler |
| Upstash Inc. | USA | Database (Redis) for account data, site configuration and check history |
| Resend Inc. | USA | Transactional email for alerts and reports when you have not connected your own SMTP |
| Stripe Inc. | USA | Subscription billing and payment processing |
| Twilio Inc. | USA | SMS alerts, only when SMS is enabled on your account |
Each of these providers processes data under its own agreement with us. We give 30 days' notice of new sub-processors to customers with a Data Processing Addendum in place.
6. How long we keep it
- Check history is kept for the retention period of your plan (30 or 90 days) or a shorter period you choose in Settings, then deleted automatically.
- Account and configuration data is kept while your account is active and deleted within 30 days after you delete your account.
- Server logs are kept for up to 30 days.
- Billing records are kept for as long as tax and accounting law requires, typically seven years.
- Backups made by our database provider expire on their own schedule after deletion.
7. Your rights
Everyone
You can view and update your account details in Profile and Settings, and delete your sites and account from Settings. For anything else, including a copy of your data, email us and we will respond within 30 days.
European Economic Area, United Kingdom and Switzerland (GDPR)
You have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to our processing, to withdraw consent, and to complain to your local supervisory authority. We are based in the United States; where we transfer data from these regions we rely on the European Commission's Standard Contractual Clauses and the UK Addendum.
California (CCPA/CPRA and CalOPPA)
- You have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to not be discriminated against for exercising these rights.
- We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- We do not respond differently to browser "Do Not Track" signals because we do not track visitors across sites in the first place.
- Requests can be made by email; we will verify them using the email address on your account.
8. Cookies
We use essential cookies only. A single session cookie (sm_session) keeps you signed in and is removed when you sign out. There are no analytics, advertising or third-party tracking cookies on the Service or on these public pages.
9. Security
Passwords are hashed with bcrypt, all traffic is encrypted in transit, data is encrypted at rest by our database provider, and optional two-factor authentication is available for every user. The Security page describes our controls in more detail and how to report a vulnerability. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
10. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes
We will post updates here and change the date at the top. For material changes we will email account holders at least 14 days before they take effect.
12. Contact
Concepcion.Work · support@concepcion.work