Privacy Policy

Last updated: August 11, 2026

The data controller for personal data processed through cronalive.com and app.cronalive.com is CronAlive, operated by an individual entrepreneur. Contact for any privacy matter: support@cronalive.com. This policy is part of the Terms of Service.

1. What we process

  • Account: email address, name, password (stored only as an argon2id hash), interface language and time zone.
  • Monitoring configuration: check and integration settings, including alert destinations (email addresses, chat identifiers, webhook URLs).
  • Technical ping data: source IP address, user-agent, request method and the ping body. Ping bodies may contain arbitrary data you choose to send, so they are encrypted at rest at the application level.
  • Payment data: handled entirely by Paddle (section 4). We never receive or store card details — only the subscription status and an invoice reference.
  • Support correspondence: what you write to us and our replies.

We do not use tracking cookies on this website, run no advertising and build no cross-site profiles.

2. Why we process it, and on what legal basis

Purpose Legal basis (GDPR Art. 6)
Running the service: ping ingestion, status computation, alert deliveryperformance of a contract (b)
Billing, invoices and refundscontract (b) and legal obligation (c)
Customer supportcontract (b)
Security: rate limiting, abuse prevention, incident investigationlegitimate interests (f)
Aggregate, cookieless website statisticslegitimate interests (f)

3. Where data is stored

Service data lives on servers in the European Union (Hetzner: Germany and Finland). Backups are encrypted and kept with object-storage providers under contract. Where a processor operates outside the EEA, transfers rely on the European Commission’s Standard Contractual Clauses or on an adequacy decision.

4. Processors

Each provider receives only what its function requires:

  • Paddle.com Market Ltd — Merchant of Record: payment processing, invoicing, tax and refunds (the billing details you enter at checkout);
  • Hetzner Online GmbH — server hosting in the EU, where the service data lives;
  • Cloudflare, Inc. — traffic delivery, DDoS protection and cookieless website analytics (transit network data);
  • Unisender Go — transactional email delivery (recipient address, message content);
  • the alert channels you configure (Telegram, Slack, Discord, your webhook endpoint) — they receive the alert text you asked us to send there.

We do not sell personal data and do not share it with anyone else, except where the law requires it.

5. Retention

  • ping and event history — within your plan’s retention window (30 days on Free, 1 year on Pro, 2 years on Business), then deleted automatically;
  • account data — until you delete the account;
  • invoices and payment records — for the period required by tax law;
  • support correspondence — up to 3 years.

6. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing relies on it.

Two of these are self-service: in the app under Security you can export your data as JSON and delete your account — deletion is irreversible and destroys the associated data. For anything else write to support@cronalive.com; we answer within 30 days.

You also have the right to lodge a complaint with your local data protection authority.

7. Cookies and website analytics

This website uses Cloudflare Web Analytics. It is cookieless by design: it sets no cookies, stores no identifier in your browser and builds no cross-site profile. We see aggregate counts — page views, referrers, countries — and nothing that identifies you. That is also why there is no cookie banner: there is nothing to consent to.

The application itself (app.cronalive.com) sets only the session and CSRF cookies without which signing in is impossible. They are strictly necessary and are cleared on sign-out or on expiry.

8. Security

All traffic is HTTPS-only; passwords are hashed with argon2id; API keys are stored as hashes; ping bodies and sensitive configuration fields are encrypted at rest. Staff access to data is limited to operational necessity.

9. Changes

A new revision is published on this page with its date. Material changes are announced by email to account holders before they take effect.