This Privacy Policy explains what information Healthcheck IT (“we”, “us”) collects when you use the website monitoring service at this site (the “Service”), how we use it, and the choices you have.
Contact
For any privacy question, access request, correction, or deletion request, contact us at admins@healthcheckit.com.
Information we collect
- Account data. Your email address and, if you sign up with a password, a cryptographic hash of your password (we never store the password itself). If you sign in with Google, we receive the email address associated with your Google account and a persistent Google account identifier; we do not receive your Google password or, with the scopes we request, your name or profile photo.
- Monitored URLs and check results. The URLs you add for monitoring and the results of checking them: HTTP status codes, response errors, the region each check ran from, and timestamps.
- Notification settings and history. Your preferences for down/up email notifications and a record of which notifications were sent.
- Billing metadata. If you subscribe to a paid plan, we store your Stripe customer and subscription identifiers, plan tier, and subscription status. Payment card data never reaches us — it is collected and processed by Stripe (see below).
- Support and feedback. If you submit feedback through the in-app form, we receive the content you send, delivered to our feedback inbox.
- Log and abuse-prevention data. For signup, sign-in, and similar authentication actions, we log the request’s IP address, the browser user-agent, and a truncated hash of the email address (never the raw address) to detect and prevent abuse. Rate-limiting counters are kept in memory and expire.
Cookies
We use a small number of strictly necessary cookies and no advertising or cross-site tracking cookies:
- Session cookie (
session_id) — keeps you logged in; expires after 7 days. - OAuth state cookie (
google_oauth_state) — a transient, single-use value that protects the Google sign-in flow; expires after 10 minutes. - Cloudflare Turnstile — on the signup form, Cloudflare may set its own cookies to run the bot-protection challenge.
We also use Plausible Analytics, a cookieless analytics tool, to count aggregate page views in production. It does not store cookies or track you across sites, and it is disabled in local development.
Third-party services we rely on
- Google — only if you choose “Sign in with Google”. Google authenticates you and tells us your verified email address and account identifier, subject to Google’s Privacy Policy. You can revoke our access at any time from your Google account’s security settings.
- Cloudflare — Turnstile bot protection on the signup form.
- Stripe — payment processing for paid plans. Stripe handles your payment details under its own privacy policy; we only receive billing status metadata.
- Email delivery provider — sends transactional email on our behalf: address verification, password resets, and the uptime notifications you configure.
- Plausible Analytics — aggregate, cookieless usage statistics.
- Hosting provider — the cloud provider that runs our servers and database.
We do not sell your personal information, and we do not share it with anyone except the providers listed above, as needed to run the Service, or where the law requires it.
How we use information
- To provide the Service: running checks on your URLs, showing results, and sending the notifications you configure.
- To operate your account: authentication, sessions, and account security.
- To prevent abuse: rate limiting, bot protection, and abuse-pattern logging described above.
- To send transactional email (verification, password reset, billing-related notices). We do not send marketing email.
- To understand aggregate usage of the public marketing pages (cookieless analytics).
Data retention
- Account data is kept while your account is active.
- Login sessions expire after 7 days, and expired sessions are purged automatically.
- Check results are kept in a rolling window; older results are deleted automatically.
- Abuse-prevention logs are kept for a limited period for security analysis.
When you ask us to delete your account, we delete your account data, monitored URLs, and associated records.
Your choices and rights
- You can manage or stop notification emails in the in-app notification settings.
- You can request access to, correction of, or deletion of your personal data at any time by emailing admins@healthcheckit.com.
- If you signed in with Google, you can remove our access from your Google account permissions page.
- You can clear or block cookies in your browser, though the Service requires the session cookie to stay logged in.
Security
Passwords are stored only as bcrypt hashes, database access uses parameterized queries, and sessions use cryptographically random identifiers. No system is perfectly secure, but we design the Service to limit what can be exposed in the first place.
Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page with a new “last updated” date, and material changes may also be announced within the Service.