This Privacy Policy explains how Alyx s. r. o. (“Alyx”, “we”, “us”) processes personal data when you use StackPulse (the “Service”) at stackpulse.app. We act as the data controller and process your data under the EU General Data Protection Regulation (GDPR) and Slovak law.
In short: we collect what StackPulse needs to work, we don’t sell your data or show ads, and we don’t use tracking cookies.
1. Who we are
The data controller is Alyx s. r. o., a company incorporated in Slovakia:
- Registered office: Závodská 2963/4, 010 01 Žilina, Slovakia
- Company ID: 56229763
- Tax ID: 2122249338
- VAT ID: SK2122249338
- Commercial Register: District Court Žilina, Section Sro, insert no. 84989/L
- Contact: info@stackpulse.app
2. What data we collect
- Account data — your email address and your password, which we store only as a secure hash. If you sign in with Google or GitHub, we receive your email address and username from them and keep a link to that account, so you can sign in with it again. We never see your Google or GitHub password.
- Profile data — what you add in Settings: your first and last name, your company name and a profile photo.
- Dashboards and status pages — the dashboards you create, their names and the services on them, and your status page settings: description, logo, favicon and whether the page is public. Anyone with its link can see a public status page, with its name, description, logo and the status of its services.
- Notification settings — whether you’ve turned on email alerts, whether your email address is confirmed, and which dashboards your alerts cover. For each webhook you add: its address (URL), the name you give it, which dashboards it covers, whether it’s on, and, if we switched it off because it stopped working, why and when.
- Email addresses you add to your alerts — if you add someone else’s address, we store it, which dashboards it covers, when it was confirmed, and a random code for the links in our emails to it. We email that address once, to ask whether it wants the alerts, and send nothing else until someone there confirms. Every alert to it has a link to unsubscribe.
- Technical and security data — our server records each request: your IP address, your browser (user agent), the address requested and the time. So that we can warn you when someone signs in to your account from a new device, we keep a fingerprint of the IP address and browser of each sign-in (a one-way hash). We also count requests per IP address to limit abuse; those counts stay in memory and aren’t stored.
- Activity — the day you last used StackPulse, the date only, so we can tell accounts in use from abandoned ones.
- Messages — what you write to us by email, and your email address.
- Usage data — privacy-friendly statistics about page views, described in section 4.
We don’t collect payment data: StackPulse is free. The status of the services we monitor comes from their public status pages and isn’t personal data.
3. Cookies and browser storage
We use only these cookies, all set by stackpulse.app itself:
pb_authkeeps you signed in. It lasts 14 days and is renewed while you use StackPulse. Scripts on the page can’t read it.oauth2holds a one-time code while you sign in with Google or GitHub, for at most 10 minutes.last_dashboardremembers which dashboard you opened last, so StackPulse can take you back to it. It lasts a year.pb_opskeeps our own administrators signed in to StackPulse’s administration pages, for a day at a time. Nobody else ever gets it.
These cookies are needed to provide the Service you asked for, so they don’t require your consent and we don’t show a cookie banner. We don’t use advertising or cross-site tracking cookies, and our analytics set none. While a tab is open, your browser also keeps your scroll position in its session storage, so the back button returns you to where you were.
4. Analytics
We count visits with Umami, an open-source analytics tool that we host ourselves. For each page view it records the page, the site you came from, your browser, operating system, device type, screen size, language and country. It sets no cookies, stores nothing in your browser and doesn’t store your IP address. Before a page address is sent, we remove the security tokens that the links in some of our emails contain. We use these statistics only to see how StackPulse is used, never for advertising, and we don’t share them.
5. Why we process your data, and our legal bases
- To provide the Service — your account, dashboards and status pages, and the emails that come with them: confirming your email address, resetting your password, changing your email address and warning you about a sign-in from a new device. This is necessary for our contract with you, Art. 6(1)(b) GDPR.
- To send you alerts when a service on your dashboards has an outage or comes back online, by email and to the webhooks you add, only as you set them up in Settings → Notifications. Email alerts are off by default, and you can turn any of them off at any time. Art. 6(1)(b) GDPR.
- To email alerts to an address that you added, once someone there has confirmed they want them: their consent, Art. 6(1)(a) GDPR, which the unsubscribe link in every alert withdraws. The one email that asks for it relies on our legitimate interest in sending alerts only where they’re wanted, Art. 6(1)(f) GDPR.
- To keep the Service secure and reliable and to prevent abuse, with request logs, sign-in alerts, rate limits, the bot check on sign-up and password reset, and backups. Our legitimate interests, Art. 6(1)(f) GDPR.
- To understand how StackPulse is used and improve it (analytics). Our legitimate interests, Art. 6(1)(f) GDPR; you can object at any time, see section 9.
- To answer your messages. Our legitimate interests, Art. 6(1)(f) GDPR.
- To meet our legal obligations, Art. 6(1)(c) GDPR.
We don’t make decisions about you by automated means alone, and we don’t profile you.
6. Who we share data with
We don’t sell your personal data. We share it only with the service providers that help us run StackPulse, which process it on our behalf under data-processing agreements:
- Hetzner — hosts our servers, in Germany.
- Backblaze — stores our backups, in the Netherlands.
- Resend — sends our emails, from Ireland.
- Cloudflare — runs our DNS and the bot check on sign-up and password reset (Turnstile), which looks at your IP address and browser to tell people from bots. It also forwards email sent to info@stackpulse.app, and passes our analytics requests on.
In addition:
- If you sign in with Google or GitHub, they handle that sign-in under their own privacy policies.
- Our pages load their fonts from Google Fonts, so your browser connects to Google, which sees your IP address.
- Email you send to info@stackpulse.app is delivered to our mailbox at Google (Gmail).
- When you add a webhook, we send your alerts to its address: the names and statuses of the services, and the names of your dashboards. It’s the service you chose, such as Slack or Discord, that handles them then, under its own terms.
- We disclose data when the law requires it, for example to a court or public authority.
7. International transfers
Our servers are in Germany, our backups in the Netherlands, and our emails are sent from Ireland. Cloudflare, Google, GitHub, Resend and Backblaze are US companies and may process data outside the European Economic Area; where they do, it is protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework.
8. How long we keep your data
- Your account, profile, dashboards, status pages, webhooks and settings — for as long as your account exists. When you delete it in Settings → Delete account, we delete all of it right away, including your uploaded images and the fingerprints of your sign-in devices.
- Email addresses added to someone’s alerts — until that person removes it or deletes their account. An address that unsubscribed stays in their list, switched off, so they can see that it did.
- Backups — up to 14 days, so deleted data is gone from them within 14 days.
- Request logs — 5 days.
- Analytics — kept as aggregate statistics.
- Emails you send us — as long as we need them to handle your request.
9. Your rights
Under the GDPR you have the right to access, correct and delete your personal data, to restrict or object to its processing, to data portability, and to withdraw consent at any time where we rely on it. You can correct most of your data yourself in Settings, and delete your account in Settings → Delete account. For anything else, including objecting to analytics, email info@stackpulse.app and we’ll answer within one month.
You can also lodge a complaint with the Slovak supervisory authority, the Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk), or with the authority where you live or work.
10. How we protect your data
Everything is encrypted in transit (HTTPS). Passwords are stored only as hashes, and your session is kept in a cookie that scripts can’t read. Access to data is checked on our server, so each account reaches only its own data, plus the status pages others have made public. Access to our servers is restricted.
11. Children
StackPulse isn’t directed to children. You must be at least 16 years old to use it.
12. Changes to this policy
We may update this policy from time to time. We’ll change the “Last updated” date above and, for material changes, tell you by email or in the app. Our Terms of Service cover the rest of how StackPulse works.
13. Contact
Email us at info@stackpulse.app or write to Alyx s. r. o., Závodská 2963/4, 010 01 Žilina, Slovakia.