Cronomonitor

Privacy Policy

Last updated: 9 October 2026

1. What we collect

We collect only what's needed to run the Service:

  • Account data: your email address and a hashed (never plaintext) password.
  • Project/check data: project names, slugs, check names, schedules, chat and webhook URLs, and the timestamps of pings and incidents you configure the Service to track.
  • Billing data: handled by Lemon Squeezy, our merchant of record — we store only your subscription status and their internal customer/subscription IDs, never your card details.
  • Operational data: IP addresses are used transiently for rate-limiting abuse protection and aren't retained beyond that.

2. How we use it

To operate your account and dashboard, detect missed check-ins and send the email/ webhook alerts you configure, process subscription payments, and keep the Service secure and reliable. We don't sell your data or use it for advertising.

3. Third parties we use

Resend delivers transactional emails (verification, password reset, down/recovery alerts). Lemon Squeezy processes payments and acts as merchant of record. Sentry receives error reports (the error message, stack trace and affected page route) so we can fix bugs; we don't send it passwords, check payloads or request bodies. Our infrastructure runs on a hosted server; none of these providers use your data for anything beyond delivering the Service to you. If you add a Slack, Discord, Microsoft Teams or generic webhook URL to a check, we send the alert (the check name, its state and a link to your status page) to that address; those services handle it under their own terms.

4. Cookies

We use strictly functional cookies only: a session cookie to keep you signed in, a CSRF cookie to protect form submissions, and a theme-preference cookie. No analytics or advertising cookies.

5. Data retention

We keep your data for as long as your account is active. Deleting a project or check removes its data immediately; deleting your account removes your account and all associated projects, checks, and incident history.

6. Your rights

You can access, export, or delete your data at any time from the dashboard, or by emailing us. If you're in the UK/EEA, you have rights under GDPR/UK GDPR to access, correct, or erase your personal data, and to object to or restrict certain processing.

7. Security

Passwords are hashed with bcrypt, sessions are signed and httpOnly, and all production traffic is served over HTTPS.

8. Changes

We'll update this policy as the Service evolves and bump the date above.

9. Contact

Questions about this policy or your data? Email privacy@cronomonitor.com.