Scope and controller
This Privacy Policy explains how SystemVitals collects, uses, shares, and protects personal data when you use our websites, applications, APIs, MCP integrations, monitoring infrastructure, and related services (the “Service”).
SystemVitals is the controller of account and product-usage data. An organization may be the controller of data it submits to the Service, with SystemVitals acting as its processor or service provider.
Data we collect
- Account data: email address, encrypted password credentials, Google account identifiers when used, organization memberships, roles, and preferences.
- Monitoring data: check names, target URLs, hostnames, IP addresses, heartbeat events, response metadata, incidents, status-page content, and alert configuration.
- Integration data: notification destinations, webhook configuration, API-token metadata and permissions. Secret token values are shown only when created and are stored as hashes.
- Telegram connection data: Telegram destination identifiers, titles, and topic identifiers, connection commands, and notification delivery results. We process connection commands used to set up a destination, not ordinary group messages. Alert content is shared with Telegram for delivery.
- Billing data: plan, subscription status, billing identifiers, and transaction metadata. Stripe receives and processes full payment-card details; SystemVitals does not store them.
- Technical data: IP address, user agent, request logs, timestamps, error reports, security events, and approximate location inferred from IP where available.
- Communications: messages and support requests you send to us.
Monitoring targets and payloads may contain personal data depending on how you configure them. Do not submit sensitive data that is not necessary for monitoring.
How we use data
We process data to:
- provide checks, incident history, alerts, status pages, APIs, and MCP access;
- authenticate users and administer organizations, roles, plans, and billing;
- secure the Service, prevent abuse, investigate incidents, and enforce our terms;
- support users and communicate service, security, and policy updates;
- measure reliability and improve features using aggregated or de-identified data; and
- meet tax, accounting, legal, and regulatory obligations.
We do not sell personal data or use monitoring data for third-party behavioral advertising.
Legal bases
Where a legal basis is required, we rely on performance of our contract to provide the Service; legitimate interests in operating, securing, and improving it; compliance with legal obligations; and consent where specifically requested. You may withdraw consent at any time without affecting earlier processing.
Retention
We retain account and configuration data while your account is active and as needed to provide the Service. Monitoring events and operational logs are retained according to plan limits, security needs, and reasonable backup cycles.
After deletion, data may remain temporarily in backups and may be retained longer where required for fraud prevention, dispute resolution, accounting, or law. We delete or de-identify it when the applicable purpose and retention period end.
Security
We use administrative, technical, and organizational safeguards designed to protect data, including access controls, encryption in transit, credential hashing, secret minimization, logging, and infrastructure isolation.
No system is completely secure. You are responsible for securing your account, limiting token permissions, revoking unused tokens, and protecting notification destinations and monitored systems.
International transfers
Our providers may process data in countries other than yours. Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy decisions, or another lawful transfer mechanism.
Your privacy rights
Depending on your location, including under Brazil’s LGPD or the European GDPR, you may have rights to confirm processing; access, correct, export, delete, or anonymize data; restrict or object to processing; withdraw consent; and receive information about sharing.
Send requests to support@systemvitals.link. We may verify your identity and authority before acting. You may also complain to your local data-protection authority. If your organization controls the data, contact its owner first; we will assist the organization as required.
Children
The Service is intended for people who can legally enter a contract and is not directed to children under 13. If local law requires a higher minimum age for independent consent, that age applies. Contact us if you believe a child provided personal data improperly.
Changes and contact
We may update this policy as the Service or law changes. We will post the revised version, update the effective date, and provide reasonable notice of material changes.
Questions, complaints, and data requests can be sent to support@systemvitals.link.
Questions about these terms?
Contact us at support@systemvitals.link.