Privacy Policy
PingVault ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you use PingVault ("Service") at pingvault.live.
1. Information We Collect
Account information: When you register, we collect your email address and a hashed password. We do not store plaintext passwords.
Monitoring configuration: URLs, monitor names, check intervals, and alert preferences that you configure within the Service.
Check results: Response times, HTTP status codes, and uptime data generated by monitoring your configured endpoints.
Billing information: Payments are processed by Paddle. We do not store credit card numbers. We receive confirmation of subscription status and plan type from Paddle.
Usage data: We may collect basic usage analytics such as pages visited, features used, and session duration to improve the Service.
Log data: Our servers automatically record information including your IP address, browser type, and timestamps when you access the Service.
2. How We Use Your Information
- To operate and deliver the Service — running monitors, delivering alerts, and displaying dashboards
- To send transactional emails — downtime alerts, recovery notifications, and weekly digest reports
- To manage your subscription and billing through Paddle
- To respond to support requests and communicate important service updates
- To detect and prevent abuse, fraud, or violations of our Terms of Service
- To improve the Service through aggregated, anonymised usage analysis
3. Data We Do Not Collect
- We do not read the content of the pages or APIs you monitor
- We do not store request bodies or response bodies from your monitored endpoints
- We do not sell, rent, or trade your personal data to any third party
- We do not use your data for advertising purposes
4. Data Sharing
We share your data only with the following trusted third-party services required to operate PingVault:
- Paddle — payment processing and tax compliance (Merchant of Record)
- Amazon Web Services (AWS SES) — transactional email delivery
- MongoDB Atlas / Neon — managed database hosting
- Redis Cloud / Upstash — job queue and caching infrastructure
All third-party providers are bound by their own privacy policies and data processing agreements. We do not share your data with any other parties.
5. Data Retention
- Monitor check results: Retained for 7 days (Hobby), 90 days (Pro), or 1 year (Team). Older data is automatically deleted.
- Account data: Retained for the duration of your account. Deleted within 30 days of account deletion upon request.
- Billing records: Retained as required by applicable tax and financial regulations (typically 7 years).
6. Cookies
We use only essential cookies required to maintain your authenticated session. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. You may disable cookies in your browser, but this will prevent you from logging in to the Service.
7. Security
We implement industry-standard security measures including HTTPS encryption for all data in transit, bcrypt hashing for passwords, short-lived JWT access tokens, and hashed refresh tokens. While we take security seriously, no system is completely immune to breaches. We will notify affected users promptly in the event of a data breach.
8. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Export: Request an export of your monitoring data in a machine-readable format
- Objection: Object to processing of your data for specific purposes
To exercise any of these rights, contact us at support@pingvault.live. We will respond within 30 days.
9. Children's Privacy
PingVault is not directed at children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
10. International Users
PingVault is operated from India. If you access the Service from outside India, your data may be transferred to and processed in India or the country where our infrastructure providers operate. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before material changes take effect. The "last updated" date at the top of this page will always reflect the most recent version.
12. Contact
For privacy-related questions or requests, contact us at:
Email: support@pingvault.live
Website: pingvault.live