Privacy Policy

Effective date: 2026-08-11

1. Controller and contact

The data controller for personal data processed in connection with YouMonit.com ("Service") is Webmint s.r.o., Jana Ε½elivskΓ©ho 2, 130 00 Praha 3, Czech Republic, European Union. Responsible person: TomΓ‘Ε‘ Rohlena. Privacy contact: support@youmonit.com.

For purposes of the EU General Data Protection Regulation (GDPR) we act as controller for account, billing and marketing data, and as processor of any personal data you store inside YouMonit (e.g. monitor metadata, status-page subscribers). For purposes of the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) we act as a "business".

2. What we collect

2.1 Information you provide

  • Account: name, email, password hash, optional company name, language preference.
  • Billing: billing address, VAT/Tax ID, last 4 of card & payment token (held by Stripe; we never see full card numbers).
  • Service data: monitor configurations, alert recipients, status-page content.
  • Communications: messages you send to support@youmonit.com or the contact form.

2.2 Information collected automatically

  • Telemetry: request logs (IP address, user-agent, URL, timestamp) for security and abuse prevention; retained max. 30 days.
  • Cookies and similar: a strictly-necessary session cookie, a language cookie, reCAPTCHA cookies on form pages. We do not use cross-site tracking cookies. Analytics, if enabled, is privacy-preserving and IP-anonymised.
  • Check results: response codes, latency, error strings produced by monitoring your endpoints (these may incidentally contain technical strings from your services).

2.3 Information collected by our mobile apps (iOS / Android)

  • Push notification token: the Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS) token issued to your device, so we can deliver status alerts. Rotated by the OS; deleted from our servers when you sign out of the app or uninstall it.
  • Device metadata: device model, OS name and version, app version and language. Used only for troubleshooting and to route push notifications to the correct platform.
  • Locally-stored API key: after login the app stores a scoped API key in the operating system's secure storage (iOS Keychain / Android EncryptedSharedPreferences). It never leaves the device except in authenticated API requests to our servers.
  • Diagnostic logs: anonymous crash reports and non-personal performance counters when you opt in on first launch. Contain no monitor content or account identifiers.

2.4 We do not collect

Special-category data (Article 9 GDPR) intentionally. Children's data under age 16 (EU/EEA) or 13 (USA, COPPA) β€” accounts are not for use by children.

3. Why we use it (legal bases)

PurposeLegal basis (GDPR Art. 6)
Providing the Service (running checks, sending alerts)Performance of a contract β€” Art. 6(1)(b)
Billing, invoicing, tax complianceLegal obligation β€” Art. 6(1)(c)
Security, fraud and abuse preventionLegitimate interests β€” Art. 6(1)(f)
Improving the Service (aggregate, non-identifying)Legitimate interests β€” Art. 6(1)(f)
Marketing emails (existing customers, similar products)Legitimate interests β€” Art. 6(1)(f), opt-out at any time
Newsletter sign-ups, optional cookiesConsent β€” Art. 6(1)(a)

4. Sharing and processors

We share personal data only with these categories of recipients:

  • Payments: Stripe Payments Europe, Ltd. (Ireland) β€” billing data, card token.
  • Transactional email: Mailgun (EU region) β€” recipient email, subject, body.
  • SMS: Twilio Ireland Limited β€” phone number, alert text (only when SMS alerts are enabled).
  • Bot defence: Google reCAPTCHA (Google Ireland Ltd.) β€” IP, headers, behavioural signals on form pages.
  • Infrastructure / CDN / DDoS: Cloudflare, Inc. β€” request metadata.
  • Hosting: WEDOS Internet, a.s. (Czech Republic) β€” encrypted application data.
  • Push notifications (Android): Google Firebase Cloud Messaging (Google Ireland Ltd.) β€” device push token, notification payload (monitor name and short status text).
  • Push notifications (iOS): Apple Push Notification service (Apple Distribution International Ltd., Ireland) β€” device push token, notification payload.
  • Mobile app distribution: Google Play Store (Google Ireland Ltd.) and Apple App Store (Apple Distribution International Ltd.) β€” install / update telemetry visible only to us in aggregate form.
  • Legal/authorities where we are required to disclose by law.

We do not sell or share personal data for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.

5. Mobile applications (iOS and Android)

The YouMonit mobile app for iOS (App Store) and Android (Google Play) is a thin client for the YouMonit API. It authenticates with a scoped API key and pulls the same monitor / incident / uptime data you see in the web app. It sends push notifications for status transitions (online β†’ offline, offline β†’ online, incident opened / resolved) and for account events.

5.1 Data collected by the mobile app

The complete list β€” grouped the way the Google Play Data safety form and the Apple App Store App Privacy label expect it:

Data type Purpose Linked to identity Optional?
Email address Login Yes (your account) Required for sign-in
Device push token (FCM / APNs) Deliver monitor alerts Yes (linked to account) Required if you want push alerts; can be disabled in system settings
Device model, OS version, app version, language Troubleshooting and correct push routing (iOS vs Android) Yes Required (sent with API requests)
Crash logs and non-personal performance counters App stability Not linked Opt-in on first launch
Content of notifications (monitor name, status, first error line) Show alerts on lock screen and in the app inbox Yes Required for the alert feature

What we do NOT collect from the app: we do not collect precise or approximate location, contacts, calendar, camera, microphone, photos, browsing history from your device, advertising ID / IDFA, or any biometric data. We do not use SDKs for cross-app tracking or behavioural advertising.

5.2 Third-party services used by the mobile app

5.3 Notifications and quiet hours

Push notifications are opt-in per iOS/Android system prompt on first launch. You can withdraw them at any time in Settings β†’ Notifications on your device. In-app you can also mute individual monitors and set quiet hours from Settings β†’ Alerts. Muting stops us from sending pushes for the affected monitors; the underlying checks continue to run.

5.4 Data retention and deletion (mobile)

  • Sign out or uninstall β€” the app deletes the locally-stored API key from device secure storage. On our side we deactivate the push token within a few minutes and delete it during the next daily housekeeping run (max 24 hours).
  • Account deletion β€” removes all device tokens, notification history and app-specific preferences alongside your account data (see section 7. Retention).
  • Right to delete on-demand β€” request via support@youmonit.com or the "Delete my account" button in Settings β†’ Account in either app.

5.5 Children

Both apps are rated 4+ (App Store) / Everyone (Google Play). They are not directed at children and do not knowingly collect data from users under 16 (EEA) / 13 (USA). No advertising or in-app purchases targeted at children are present.

5.6 Permissions requested

  • Notifications β€” to deliver monitor alerts (iOS + Android).
  • Internet β€” to talk to api.youmonit.com (Android only; iOS is granted implicitly).
  • Wake lock / background fetch β€” to react to incoming pushes even when the app is closed.

We do not request location, storage, camera, microphone or contacts permissions.

6. International transfers

YouMonit primary infrastructure is in the European Union. Some sub-processors (Stripe, Cloudflare, Google, Twilio) operate globally. Transfers outside the EEA rely on Standard Contractual Clauses (Decision 2021/914), the EU-U.S. Data Privacy Framework where applicable, and supplementary measures (encryption in transit and at rest).

7. Retention

  • Active account data: retained while your account is active.
  • Closed accounts: 30 days in active systems, then deleted; encrypted backups roll off within 90 days.
  • Check results / uptime history: per your plan (max. 24 months).
  • Invoices: 10 years (Czech tax-archiving requirement).
  • Contact-form messages: 12 months from last activity unless required longer for support or legal reasons.
  • Security logs: 30 days.

8. Your rights

Under GDPR (EU/EEA/UK), CCPA/CPRA (California), and similar laws in other jurisdictions, you have the right to:

  • Access β€” get a copy of personal data we hold about you.
  • Rectification β€” correct inaccurate data.
  • Erasure / deletion β€” request deletion ("right to be forgotten"; "right to delete" under CCPA).
  • Restriction / limit-use of processing.
  • Portability β€” receive your data in a portable format.
  • Object to processing based on legitimate interests, including direct marketing.
  • Opt out of "selling/sharing" (CCPA) β€” note: we do not sell or share.
  • Withdraw consent where processing is consent-based.
  • Non-discrimination β€” we will not penalise you for exercising your rights.

To exercise rights, write to support@youmonit.com. We respond within 30 days (GDPR) or 45 days (CCPA), extendable once where allowed. You may also lodge a complaint with the Czech Data Protection Authority (uoou.cz) or, in California, with the California Privacy Protection Agency.

9. Cookies

We set only the cookies strictly necessary for the site to function (session, language, CSRF) plus reCAPTCHA cookies on form pages. We do not use cross-site advertising cookies. You can clear cookies at any time in your browser settings β€” doing so will sign you out.

10. Security

Personal data is encrypted in transit (TLS 1.2+) and at rest. Passwords are stored using bcrypt. Access is least-privilege and logged. We test backup restores regularly. No system is 100% secure; if a breach affecting your personal data occurs we will notify the relevant authorities within 72 hours and affected individuals without undue delay where required.

11. Children

YouMonit is not directed to children under 16 (EU/EEA) or under 13 (USA). We do not knowingly collect data from such children. If you believe we have done so, contact us and we will delete it.

12. California-specific disclosures

In the previous 12 months we have collected the categories of personal information listed in section 2, for the purposes listed in section 3, and disclosed them to the categories of recipients in section 4. We have not sold or shared personal information. California residents may request information about specific pieces of personal information we hold and may designate an authorised agent to exercise rights on their behalf.

13. Changes to this Policy

We may update this Privacy Policy. Material changes will be announced by email and here at least 14 days before they take effect.

14. Contact

Privacy questions or requests: support@youmonit.com
Postal: Webmint s.r.o., Jana Ε½elivskΓ©ho 2, 130 00 Praha 3, Czech Republic, EU.