Privacy Policy

Last updated: July 29, 2026

1. Who we are

Uptiqr ("we", "us", "our") is operated by Lindustries. This Privacy Policy explains how we collect, use, and protect personal data when you use the uptiqr.com website and uptime monitoring platform. For privacy questions, contact us at support@uptiqr.com.

2. Data we collect

We collect the following categories of personal data:

  • Account data: name, email address, and the account handle used in your public status page URLs
  • Contact form data: name, email address, and message when you use the contact form on our website, whether or not you have an account
  • Monitor data: URLs, monitor names, check intervals, and alert settings you configure
  • Phone numbers: if you configure SMS or phone call alerts, we store your phone number and pass it to Twilio to deliver notifications
  • Status page content: names, descriptions, and incident history you publish on your status pages
  • Status page subscribers: email addresses of visitors who subscribe to your public status pages
  • Ping results: response times, status codes, and uptime history from monitoring checks
  • Billing data: payment information processed and stored by Stripe (we store only a Stripe customer ID and subscription ID; we never see or store card numbers)
  • Usage data: login timestamps, alert counts, and overage usage for service operation and billing
  • IP address: the IP address your requests come from is used to rate-limit sign-in, sign-up, the contact form, manual "Test now" checks, and our public status page API, to prevent abuse. It is held only for the length of the relevant rate-limit window and is not used to build a profile of you or combined with your account data for any other purpose
  • Team member data: if you are on the Business plan and invite a team member, their email address is stored to manage the invite; once accepted, they have full access to create, edit, and delete your monitors, status pages, maintenance windows, and escalation policies, and to acknowledge, resolve, and add updates to incidents. Billing, account deletion, managing the team roster, and API keys remain accessible only to the account owner

3. Legal basis for processing (GDPR)

For users in the EU/EEA, we process your personal data on the following legal bases:

  • Contract: processing necessary to provide the Service you signed up for
  • Legitimate interests: security monitoring, fraud prevention, and service improvement
  • Legal obligation: compliance with applicable laws and regulations
  • Consent: where we have obtained your explicit consent (e.g., marketing communications)

4. How we use your data

We use your data to: provide and operate the monitoring Service; send alert notifications (email, SMS, phone calls) when monitored URLs go down or recover; process payments; send transactional emails (receipts, downgrade notices); detect and prevent fraud and abuse (including unauthorized pinging of third-party URLs); comply with legal obligations; and communicate service updates. We do not sell your personal data to third parties. We do not use your data for advertising.

5. Third-party processors

We share data with the following service providers who process it on our behalf. Each is bound by a Data Processing Agreement and may only use your data to provide their specific service:

  • Supabase: database hosting and user authentication (Privacy Policy)
  • Google: if you sign up or log in with "Sign in with Google", Google authenticates you and shares your basic profile (name, email) with us via Supabase Auth (Privacy Policy)
  • GitHub: if you sign up or log in with "Sign in with GitHub", GitHub authenticates you and shares your basic profile (name, email) with us via Supabase Auth (Privacy Policy)
  • Stripe: payment processing (Privacy Policy)
  • Resend: transactional email delivery (Privacy Policy)
  • Twilio: SMS and phone call alert delivery; your phone number is shared with Twilio only if you enable SMS or call alerts (Privacy Policy)
  • ImprovMX: email forwarding for inbound mail to our support address (mail you send to us passes through ImprovMX before reaching our inbox) (Privacy Policy)
  • Vercel: application hosting and edge infrastructure (Privacy Policy)
  • Upstash QStash: schedules and delivers our cron-based ping checks, escalation steps, and other background jobs (Privacy Policy)
  • Upstash Redis: powers API and login rate limiting; stores a counter keyed on the requesting IP address (or account identifier), retained only for the length of the rate-limit window, typically minutes to a few hours (Privacy Policy)
  • ChatForger: AI support chatbot widget on our public marketing pages (not shown on authenticated dashboard pages); if you chat with the widget, your messages are processed by ChatForger to generate a response (Privacy Policy)
  • Slack: if you connect the Slack integration, we store an encrypted access token for your Slack workspace and send incident alerts to your chosen channel; on the Business plan, replying to those alerts (Acknowledge/Resolve buttons) is processed through Slack (Privacy Policy)
  • Anthropic: on Pro and higher plans, when an incident is resolved we send its timeline (monitor name, URL, check history, and any updates you posted) to Anthropic's Claude API to generate an AI postmortem draft (Privacy Policy)
  • check-host.net: multi-location availability checks on Starter and higher plans; when multi-location is enabled, the URL of your monitor is sent to check-host.net nodes to verify availability from multiple regions. No account or personal data is shared with check-host.net (About).
  • rdap.org: domain registration expiry checks; the registrable domain of your HTTP monitors is looked up daily via RDAP to warn you before a domain expires. No account or personal data is shared with rdap.org (About).

These providers may process data outside the EU/EEA. Where they do, we rely on Standard Contractual Clauses or other approved transfer mechanisms.

6. Data retention

  • Ping results: check history is retained for 90 days on the Free plan and 12 months on paid plans, then automatically deleted (or sooner, if the associated monitor is deleted)
  • Monitor and status page data: retained until you delete it or close your account
  • Account data: deleted immediately when you delete your account, unless a longer retention period is required by law
  • Billing records: retained for 7 years for tax and legal compliance
  • Status page subscribers: retained until the subscriber unsubscribes or you delete the status page

7. Your rights (GDPR: EU/EEA users)

If you are in the EU or EEA, you have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data (subject to legal retention requirements)
  • Data portability: receive your data in a structured, machine-readable format
  • Restriction: request that we limit how we process your data in certain circumstances
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: where processing is based on consent, withdraw it at any time

To exercise any of these rights, email support@uptiqr.com or delete your account directly from the Settings page. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (e.g., the ICO in the UK, CNIL in France, or the DPC in Ireland).

8. Your rights (CCPA: California residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the following rights:

  • Right to know: request disclosure of what personal information we collect, use, and disclose
  • Right to delete: request deletion of your personal information
  • Right to opt out of sale: we do not sell your personal information, so this right does not apply
  • Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights

To submit a request, email support@uptiqr.com with "CCPA Request" in the subject line.

9. Cookies

We use session cookies strictly necessary for authentication. We do not use advertising or tracking cookies. We do not use any third-party analytics cookies on our marketing pages.

10. Data breach notification

In the event of a personal data breach, we will notify affected users and relevant supervisory authorities as required by applicable law. For GDPR purposes, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms, and will notify affected individuals without undue delay where the breach is likely to result in high risk.

11. Security

We use industry-standard security measures including: encrypted connections (TLS/HTTPS) for all data in transit; encrypted storage at rest via Supabase; row-level security policies on all database tables; and server-side authentication with short-lived session tokens. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

12. Children

The Service is intended for users 18 and older. We do not knowingly collect personal data from anyone under 13. If you believe we have inadvertently collected data from a child under 13, please contact us at support@uptiqr.com and we will delete it promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice in the Service at least 14 days before changes take effect. The "Last updated" date at the top of this page indicates when it was last revised.

14. SMS communications

If you opt in to SMS alerts by entering your phone number in the Uptiqr dashboard, the following applies:

  • Message types: transactional alerts only: downtime notifications and recovery confirmations for monitors you configure. SSL certificate and domain registration expiry warnings are sent by email only. No marketing messages.
  • Message frequency: message frequency varies based on how many monitors you have and how often they go down. You may receive multiple messages per day if monitored URLs experience repeated outages.
  • Rates: message and data rates may apply depending on your mobile carrier and plan.
  • Opt out: reply STOP to any message to opt out, or remove your phone number from monitor settings at any time.
  • Help: reply HELP to any message for assistance, or contact us at support@uptiqr.com.
  • Non-sharing: your mobile phone number is never sold, rented, or shared with third parties for marketing purposes. It is shared only with Twilio solely to deliver your alert messages.

15. Contact

Uptiqr is operated by Lindustries. Privacy questions: support@uptiqr.com. We aim to respond to all inquiries within 5 business days.