In short
We collect only the data we need to run your account, run your monitors, send your alerts and comply with Dutch tax law. We do not sell data and we do not use advertising cookies. Google Analytics runs only if you accept it in the cookie banner. You can access, correct, export or delete your data at any time. This policy explains exactly what we process, why, for how long and with whom.
1. Controller
The controller of the personal data described in this policy, within the meaning of Article 4(7) GDPR, is Stanbyte B.V., a Besloten Vennootschap (Dutch private limited company) with its corporate seat in Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KVK) under number 42153933 and with RSIN 869952079, incorporated on 1 September 2026. The company is represented by its director Dmitri Stanitšenko. Its registered and visiting address is:
Korte Lijnbaanssteeg 1, Kantoornummer 4598 1012 SL Amsterdam, the Netherlands
You can reach us about privacy matters at legal@stanbyte.app. We have not appointed a formal data protection officer because the scale and nature of our processing does not require one, but the legal contact above handles all data protection requests.
This policy applies to Stanbyte Monitor at https://stanbyte.app, including the dashboard, public status pages, our e-mails and support correspondence. It should be read together with our Terms of Service and Cookie Policy.
2. The data we process and why
The table below lists each category of personal data we process, where it comes from, why we process it and the legal basis under the General Data Protection Regulation (GDPR).
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, e-mail address, hashed password, IP address and timestamp of each login, account creation date | Creating and securing your account, signing you in, detecting unauthorised access, sending transactional e-mails about your account | Contract (Art. 6(1)(b)); legitimate interest in security (Art. 6(1)(f)) |
| Billing data | Transaction reference, amount, currency, VAT details, billing e-mail, country, invoice | Processing your licence purchase, issuing invoices, handling refunds, keeping tax records | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Monitor configuration | URLs and hostnames, ports, keywords, expected status codes, check interval, monitor names, status page slugs and text | Running the checks you configure and displaying the results | Contract (Art. 6(1)(b)) |
| Check results | Timestamp, status, response time, status code, error message, SSL certificate details, incident start and end | Showing uptime history, detecting incidents, generating alerts and status pages | Contract (Art. 6(1)(b)) |
| Alert channel data | Alert e-mail addresses, Telegram chat ID, webhook URLs and optional headers | Delivering incident and SSL expiry alerts to the channels you choose | Contract (Art. 6(1)(b)); consent for Telegram (Art. 6(1)(a)) |
| Support correspondence | Your e-mails to us, our replies, any attachments you send | Answering your questions and resolving problems | Contract (Art. 6(1)(b)); legitimate interest in handling requests (Art. 6(1)(f)) |
| Newsletter | E-mail address, opt-in timestamp | Sending product news if you have subscribed | Consent (Art. 6(1)(a)), withdrawable at any time |
| Technical logs | IP address, user agent, requested URL, timestamp, error details | Keeping the Service secure and stable, diagnosing faults, preventing abuse | Legitimate interest (Art. 6(1)(f)) |
| Analytics data | Anonymised (truncated) IP address, pages visited, referring site, approximate location derived from the truncated IP, device and browser type, random client identifier stored in the _ga cookie | Understanding how the website is used so that we can improve it; only if you accept analytics cookies | Consent (Art. 6(1)(a)), withdrawable at any time via the cookie banner |
We do not deliberately collect special categories of personal data (such as health or political data). Please do not put such data in monitor names, keywords, status page text or support messages.
3. Data you put into the Service about other people
Monitor configuration may contain personal data, for example a URL that includes a username, a webhook endpoint belonging to a colleague, or a status page that names a member of your team. For that data you are the controller and we act as your processor, processing it only to provide the Service. You are responsible for having a lawful basis to use it. We do not read your monitor configuration for any purpose other than running your checks, except where needed to investigate abuse, security incidents or a support request from you.
4. Legal bases in more detail
4.1 Contract
Most of our processing is necessary to perform the contract you enter into when you create an account or buy a licence, as set out in the Terms of Service. Without this data we cannot run your monitors or alert you.
4.2 Legitimate interest
We rely on our legitimate interest to keep the Service secure, to prevent fraud and abuse, to keep technical logs, to measure aggregate usage of features without identifying individuals, and to defend legal claims. We have balanced these interests against your rights and concluded that they do not override them, given the limited and expected nature of the processing. You may object to processing based on legitimate interest as described in section 9.
4.3 Consent
We ask for your consent before we enable Telegram alerts, because this involves sending data to Telegram, before we send you a newsletter, and before we load Google Analytics on the website. You can withdraw consent at any time by disabling the Telegram channel in the dashboard, by using the unsubscribe link in any newsletter, or by changing your choice through the Cookie settings link in the footer. Withdrawal does not affect processing that happened before it.
4.4 Legal obligation
Dutch tax law requires us to keep administrative records, including invoices and payment records, for seven years. We cannot delete billing records before that period ends, even if you ask us to delete your account.
5. Who receives your data
5.1 Sub-processors
We use a small number of service providers who process data on our behalf under written data processing agreements:
| Provider | Purpose | Location | Data involved |
|---|---|---|---|
| Hosting providers | Running our application servers, databases and checker nodes | European Union | All data stored in the Service |
| Cloudflare | DNS, CDN, protection against attacks, and delivery of transactional e-mail | Global network, EU-based processing where available | IP addresses, request metadata, e-mail addresses and e-mail content |
| Telegram | Delivering alerts to the chat you connect, only if you enable the Telegram channel | Global | Telegram chat ID, alert text including monitor name and URL |
| Payment processor | Taking card payments and issuing refunds | Depends on processor, with EU entity for EU customers | Card details (never seen by us), billing e-mail, amount, transaction reference |
| Google Ireland Limited (Google Analytics 4) | Website usage statistics, only if you accept analytics cookies in the consent banner | Ireland, with transfers to the United States | Anonymised IP address, pages visited, referrer, device and browser type, random client identifier |
5.1a Google Analytics in more detail
We use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure how visitors use the website. The analytics script is loaded only after you accept analytics cookies in the consent banner, and the legal basis is your consent. We have configured Google Analytics so that IP addresses are anonymised before storage, advertising features and Google Signals are switched off, and no account content such as monitor URLs or e-mail addresses is sent to Google. Google acts as our processor under its data processing terms. Google may transfer analytics data to the United States; such transfers are covered by Google LLC's certification under the EU-US Data Privacy Framework and, in addition, by the Standard Contractual Clauses included in Google's data processing terms. You can opt out at any time through the Cookie settings link in the footer, or by installing Google's opt-out browser add-on at https://tools.google.com/dlpage/gaoptout. Full details of the cookies involved are in the Cookie Policy.
We will update this list when we add or replace a sub-processor. If you hold an active licence we will tell you about a new sub-processor by e-mail at least 14 days before it starts processing your data, so that you can object or terminate.
5.2 Other recipients
We may disclose personal data to professional advisers such as accountants and lawyers under confidentiality obligations, to a buyer or successor if our business is sold or merged (with notice to you), and to courts, regulators or law enforcement where the law requires it or where it is necessary to protect our rights or the safety of others.
5.3 Public status pages
Information you publish on a public status page is visible to anyone who knows the URL. Think carefully before including monitor names, hostnames or text that you would not want to be public.
5.4 What we never do
We do not sell personal data. We do not share it with advertisers. We do not use advertising cookies. Analytics cookies are used only with your consent, as described above. We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
6. International transfers
Our primary infrastructure is in the European Union. Some providers, in particular Cloudflare, Telegram, the payment processor and Google (for analytics, with your consent), may process data outside the EU and EEA, including in the United States. Where this happens we rely on an adequacy decision of the European Commission where one exists, including the EU-US Data Privacy Framework for certified US organisations such as Google LLC, or on the Standard Contractual Clauses approved by the European Commission together with any additional safeguards that are needed. You can ask us for a copy of the relevant safeguards at legal@stanbyte.app.
7. How long we keep data
| Data | Retention period |
|---|---|
| Check results and incident history | 30 days on Starter, 90 days on Pro, counted from the time of each check; older results are deleted automatically |
| Monitor configuration, alert channels, status pages | Until you delete them, or 90 days after your last licence expired, whichever comes first |
| Account data | Until you delete your account, plus 30 days to allow recovery from accidental deletion and to complete backups rotation |
| Login IP addresses and timestamps | 90 days |
| Technical logs | 30 days, except where retained longer to investigate a security incident |
| Invoices and payment records | 7 years, as required by Dutch tax law |
| Support correspondence | 2 years after the ticket is closed |
| Newsletter subscription | Until you unsubscribe; we keep a record of the unsubscribe to honour it |
| Google Analytics data | Set to the shortest retention period Google Analytics offers, after which Google deletes event-level data automatically; the _ga cookie in your browser lasts 2 years unless you delete it or withdraw consent |
| Cookie consent choice (sb_consent) | 12 months |
Backups may contain copies of data for up to 30 days after it is deleted from the live system. Backups are encrypted and are not used to restore individual deleted accounts.
8. How we protect your data
We apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for all traffic between your browser and the Service, and between our own components;
- passwords stored only as salted hashes using a modern algorithm; we never store or see your plain-text password;
- encryption at rest for secrets such as webhook headers and Telegram tokens;
- access controls so that only staff who need access to production systems have it, with multi-factor authentication;
- separation of the checker infrastructure from the data store;
- regular patching, dependency updates and backups;
- logging of administrative access.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as required by the GDPR, and will inform you without undue delay where the breach is likely to result in a high risk to you.
9. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access. You can ask for a copy of the personal data we hold about you and information about how we use it.
- Rectification. You can correct inaccurate or incomplete data. Most account data can be edited directly in the dashboard.
- Erasure. You can ask us to delete your data. You can delete your account yourself from the account settings. We will keep data we are legally required to retain, such as invoices.
- Restriction. You can ask us to limit how we use your data while a dispute about accuracy or lawfulness is resolved.
- Portability. You can receive the data you provided to us in a structured, machine-readable format. Monitor configuration and check history can be exported from the dashboard.
- Objection. You can object to processing based on legitimate interest, and we will stop unless we have compelling legitimate grounds. You can object to direct marketing at any time and we will stop immediately.
- Withdraw consent. Where processing is based on consent, you can withdraw it at any time.
- Complaint. You can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl), or with the supervisory authority in the EU or EEA country where you live or work. We would appreciate the chance to resolve your concern first.
To exercise a right, e-mail legal@stanbyte.app from the address registered on your account, or contact support at support@stanbyte.app. We may ask you to confirm your identity. We respond within one month, which may be extended by two further months for complex requests, in which case we will tell you. Requests are free of charge unless they are manifestly unfounded or excessive.
10. Children
The Service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
11. Cookies and local storage
We set strictly necessary cookies for sessions, security, remembering your login and remembering your cookie choice, and we use a small amount of browser local storage for interface preferences. Google Analytics cookies are set only if you accept them in the consent banner, and you can change your choice at any time through the Cookie settings link in the footer. No advertising cookies are set. Full details are in our Cookie Policy.
12. Changes to this policy
We may update this policy to reflect changes in the Service, in our providers or in the law. If a change materially affects how we use your personal data we will notify account holders by e-mail at least 14 days before it takes effect. The date at the top of the page shows the latest revision. Earlier versions are available on request.
13. Contact
Privacy requests and questions: legal@stanbyte.app
General support: support@stanbyte.app
Postal address: Stanbyte B.V. (Besloten Vennootschap (Dutch private limited company)), corporate seat Amsterdam, the Netherlands, KVK 42153933, RSIN 869952079, represented by its director Dmitri Stanitšenko
Korte Lijnbaanssteeg 1, Kantoornummer 4598 1012 SL Amsterdam, the Netherlands