Privacy Policy
Last updated: 2026-08-30
How Nancy Sahu collects, uses, shares and protects personal data in the course of running IsItStillUp — and what you can ask us to do with it.
1. Who is responsible for your data
The controller of the personal data described in this policy is Nancy Sahu, registered at Bengaluru, Karnataka, India. You can contact us about anything in this policy, including a request to exercise your rights, at support@isitstillup.com.
This policy covers https://www.isitstillup.com, the IsItStillUp dashboard, the public status pages we serve, and the emails and messages the Service sends. It does not cover the websites or services our customers link to from their own status pages.
2. Two roles: controller and processor
IsItStillUp sits in the middle of two relationships, and the law treats them differently. Being clear about which one applies is the fastest way to know who to ask about your data.
- Our customers’ account data. When someone signs up, invites teammates and pays for a plan, we decide what to collect and why. For that data we are the controller, and this policy is the notice for it.
- Status-page subscriber data. When a visitor subscribes to a customer’s status page, the customer decides to run that page and to notify its subscribers. That customer is the controller; we are their processor and act on their instructions. If you subscribed to a status page and want your data removed, you can use the unsubscribe link in any message, or contact the organisation that runs the page — we will also help, and will pass your request on.
3. What we collect
3.1 Account and organisation data
- Your email address and, if you give one, your name. IsItStillUp has no passwords, so we store none — sign-in is a one-time link or your organisation’s SAML SSO.
- Your organisation: its name, slug, plan, members and their roles, invitations you send, and SSO/SCIM configuration where used.
- Billing records: plan, subscription status, renewal dates and the billing events Paddle reports to us. Card and bank details are entered on Paddle’s checkout and are never sent to or stored by us.
- Audit logs: who in your organisation did what and when (created an incident, rotated a key, changed a plan), with a timestamp and actor.
- Support correspondence: the emails you send us and our replies.
3.2 Content you publish
Page and component names, incident titles and updates, maintenance notices, postmortems, templates and branding. This is your content; it becomes public when you publish it, so please keep personal data out of it.
3.3 Subscriber data (processed for our customers)
Email addresses and, where SMS is used, phone numbers of the people who subscribe to a customer’s status page, along with their component preferences, verification and unsubscribe tokens, the source of the subscription (page form, import, API) and delivery results. We hold this on behalf of the customer whose page it belongs to and use it for nothing else — never to market IsItStillUp, never sold, never shared between customers.
3.4 Monitoring data
The endpoints, hostnames, heartbeat tokens and check settings you configure, and the results of those checks (status code, latency, error, region, timestamp). Endpoints are usually infrastructure addresses rather than personal data, but they are treated as your confidential data either way.
3.5 Public status pages: what we do NOT collect
Public status pages carry no visitor-level analytics. There is no advertising pixel, no third-party tracker, no fingerprinting and no per-visitor profile. There are exactly two measurements, and both are the same shape: a bare number per page per day, with nothing identifying a visitor stored alongside it.
- A daily count of views per page.
- A daily count of problem reports per page. If a status page shows an “I’m having issues” button and a visitor presses it, we add one to that day’s count. No IP address, no device information, no record of who pressed it, and nothing that could link two presses to the same person.
Two things about the problem-report count are worth stating plainly rather than leaving you to infer. First, the count is recorded whether or not the page’s operator has switched on the banner that can result from it — the operator’s setting controls whether an unusual number of reports is evershown to visitors, not whether the press is counted. Second, a report can only ever do two things: alert the operator privately, and — if they opted in — raise a banner on their own page saying visitors are reporting problems. It cannot open an incident, change a component’s status, or send anything to that page’s subscribers.
Requests do pass through our hosting providers, which keep short-lived operational logs containing IP addresses for security and abuse prevention.
3.6 Technical logs
Our application and infrastructure logs record request metadata, error traces and rate-limit counters, including IP addresses, for security, debugging and abuse prevention. They are kept short-term and are not used to build profiles.
4. Why we use it, and our legal bases
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the Service: accounts, publishing pages, running monitors, sending notifications | Account data, content, monitoring data, subscriber data | Performance of a contract (Art. 6(1)(b)); for subscriber data, processing on our customer's instructions (Art. 28) |
| Taking payment and meeting tax and accounting obligations | Billing records via Paddle | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, rate limiting, audit trails | Technical logs, audit logs | Legitimate interests (Art. 6(1)(f)) — keeping the Service and its tenants safe |
| Support and service messages about your account, incidents or plan | Account data, correspondence | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Improving reliability and capacity planning | Aggregate counts (page views per day, job and check volumes) | Legitimate interests (Art. 6(1)(f)) |
| Optional AI drafting of incident updates and postmortems | The incident content you submit to the feature | Contract (Art. 6(1)(b)) — the feature only runs when you ask it to |
| Product news and marketing email to account owners | Name and email | Consent (Art. 6(1)(a)) or soft opt-in; unsubscribe in one click at any time |
We do not use personal data for automated decision-making with legal or similarly significant effects, and we do not sell personal data.
5. Who we share it with
We share personal data only with the service providers below, each under a written contract that limits them to processing it for us, and with authorities where the law requires it. We give customers advance notice before adding a new subprocessor that touches their data.
| Provider | What it does for us | Data involved | Region |
|---|---|---|---|
| Paddle (Paddle.com Market Ltd / Paddle Payments Limited) | Merchant of Record: checkout, payments, tax, invoicing, refunds | Name, billing email, billing address and country, tax identifiers, payment method details (held by Paddle, never by us), transaction history | UK, EU, US |
| Microsoft Azure | Application hosting, Postgres database, object storage for rendered pages, backups | All account data, status-page content and subscriber records | India (Central India) primary; Southeast Asia for the replicated copy of rendered pages and backups |
| Cloudflare | Authoritative DNS for our domains. Not currently proxying traffic, so it does not see visitor requests | DNS query metadata only, resolved at its own resolvers; no request or visitor data passes through it today | Global anycast network |
| Resend | Transactional and notification email delivery | Recipient email address, message content, delivery and bounce events | US / EU |
| Twilio | SMS notification delivery (plans with SMS enabled) | Recipient phone number, message content, delivery status | US / EU |
| Anthropic | AI drafting of incident updates and postmortems, only when you use those features | The incident content you send for drafting: titles, updates, component names, timeline | US |
About the AI provider: content is sent to Anthropic only when someone in your organisation uses an AI feature — drafting an update or a postmortem. It is not used to train models, and the feature can be left unused; nothing is published without a person submitting it.
If IsItStillUp is ever involved in a merger, acquisition or sale of assets, personal data may transfer to the buyer; we would give notice and the buyer would remain bound by this policy or one no less protective.
6. How long we keep it
- Account, organisation and content data — for as long as your account is active. After you delete an organisation, we keep it for 30 days (so an accidental deletion can be undone), then remove it from production systems; encrypted backups age out within a further 30 days.
- Subscriber records — until the subscriber unsubscribes, the customer deletes them, or the customer’s account is deleted. Unsubscribes take effect immediately.
- Suppression list — when an address hard-bounces, files a spam complaint or asks for erasure, we keep an irreversible SHA-256 hash of it, and nothing else, so that we can never mail it again. The address itself is not retained. Hashes are kept indefinitely, because forgetting them would defeat their only purpose.
- Audit logs — retained for the life of the organisation as a security and compliance record.
- Monitoring results — raw check results are kept for recent history and then summarised into daily uptime rollups, which are kept for as long as the page exists.
- Billing records — retained by us and by Paddle for as long as tax and accounting law requires, typically 7 years.
- Technical logs — short-term, typically 30 days.
7. International transfers
Our providers operate in the UK, the EU, the US and on global edge networks, so personal data may be transferred outside your country. Where data leaves the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), on adequacy decisions where they exist, and on the technical measures described in clause 9. A copy of the relevant transfer safeguards is available on request at support@isitstillup.com.
8. Your rights
Subject to local law, you can ask us to:
- Access the personal data we hold about you, and get a copy of it;
- Rectify data that is wrong or incomplete;
- Erase data we no longer have a reason to keep (“right to be forgotten”);
- Port the data you gave us to another provider in a structured, machine-readable format — the dashboard can also export pages, incident history and subscribers directly;
- Restrict or object to processing based on our legitimate interests, including any direct marketing, which you can stop at any time;
- Withdraw consent where we relied on it, without affecting processing done before you withdrew it.
Write to support@isitstillup.com from the address on the account and we will respond within 30 days, free of charge. We may need to verify your identity first. If you subscribed to a customer’s status page, send the request to that organisation — as their processor we will forward it and assist them.
If you are in the UK or EEA and think we have handled your data badly, you can complain to your national supervisory authority. We would rather you told us first so we can put it right.
9. How we protect it
- Tenant isolation in the database. Every organisation-scoped table is protected by Postgres row-level security, and application queries run inside an organisation context — so one customer’s rows are not merely filtered out of a query, they are invisible to it.
- Encryption. Traffic is encrypted in transit with TLS; data at rest in the database, object storage and backups is encrypted by our hosting provider.
- No passwords to steal. We never store passwords — sign-in is a one-time emailed link or your own SAML identity provider. API keys are stored hashed, shown once, and scoped to read or write.
- Least privilege and auditability. Access to production is limited to the people who need it, and state-changing operations are written to an append-only audit log.
- Outbound webhooks are signed, and private pages are gated by short-lived signed cookies rather than guessable URLs.
No system is perfectly secure. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours where required, and tell affected customers without undue delay. Security issues can be reported to support@isitstillup.com; a written summary of our security practices is available on request from the same address.
10. Cookies
IsItStillUp uses strictly necessary cookies only. There are no advertising cookies, no analytics cookies and no third-party trackers anywhere on the dashboard or on the public status pages, which is why you are not greeted by a consent banner.
| Cookie | What it does | Lifetime |
|---|---|---|
| beacon_session | Keeps you signed in to the dashboard after you use a sign-in link. Strictly necessary. | Until sign-out or expiry |
| beacon_org | Remembers which organisation you last worked in, when you belong to several. | Persistent, until cleared |
| beacon_page | Remembers which status page you last worked on, when your organisation has several. | Persistent, until cleared |
| beacon_sso_state | Single-use anti-forgery value protecting a SAML sign-in round trip. | Minutes |
| beacon_page_{page} | Signed proof that a visitor entered the correct password for a private status page. | Session / short-lived |
| beacon_aud_{token} | Signed proof of access to an audience-specific status page. | Session / short-lived |
Paddle’s checkout, which opens when you buy a subscription, sets its own cookies under Paddle’s privacy policy — see our Terms & Conditions for the Merchant of Record relationship.
11. Children
IsItStillUp is a tool for businesses and developers. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to support@isitstillup.com and we will delete it.
12. Changes to this policy
We update this policy when the Service or the law changes. The “Last updated” date at the top always reflects the current version, and we will notify account owners by email before a material change takes effect.
13. Contact
Nancy Sahu
Bengaluru, Karnataka, India
Email: support@isitstillup.com
Web: https://www.isitstillup.com