Privacy Policy
How Status collects, uses and protects your information.
Last updated: September 28, 2026
Who we are
Status is operated by Netcode, Inc., Chatham, Ontario, Canada ("we", "us"). Netcode, Inc. is responsible for (the controller of) the personal information described in this policy.
Information we collect
We collect information you provide directly — your name, email address, account and billing details, and the configuration you create (checks, alert channels, webhook destinations, status pages) — plus operational data generated by monitoring your services (check results, latency, incident history) and standard usage information (log data, IP addresses).
Push notifications are available in our mobile apps once released; if you enable them we process a device token, the device platform and app version, so we can deliver alerts to it. You can remove a device at any time from the app or the dashboard.
How we use it
- To deliver the service: running checks from our regions, confirming failures, and dispatching email and webhook alerts, and mobile push notifications once our apps are released.
- To provide history and accountability: incident timelines, uptime reports, and delivery logs for your alert channels.
- To operate billing, send service notifications, and respond to support requests.
- To monitor platform health and prevent abuse.
Support access
Our support staff see nothing of your monitoring data unless you turn support access on: not your checks, results, incidents, alert channels, status pages, team members or activity log. Only you can turn it on; our staff cannot turn it on for you. While access is on, support can view that data, make changes to it, and sign in as your account's Owner to reproduce problems, until you turn it off. You can turn it off at any time from the Support access page in your dashboard, and doing so immediately ends any support session in progress. Every grant, revoke, change and support sign-in, and what support viewed, is recorded in your account's activity feed as "Status support" (the same view repeated within 30 seconds is recorded once). Whether access is on or off, we keep the records we need to run your subscription: your account name, status and timezone, the owner's name and email address, your plan, billing details (billing address, tax ID, card brand and last four digits) and invoices, a log of the account and billing emails we send (such as sign-in codes and receipts) and the address each went to, and simple counts such as how many checks you have. That never includes the contents of your monitoring.
Data security
Data in transit is encrypted with TLS. Sensitive check configuration — basic-auth credentials and custom webhook headers — is encrypted at rest with AES-256-GCM. Webhook deliveries can be signed (HMAC-SHA256, on by default for each webhook) so your receiving endpoint can verify they came from us, and every webhook destination is checked against private, loopback and cloud-metadata address ranges before we save it and before every delivery. API keys and probe tokens are stored as one-way hashes; we cannot recover the original value, only reissue a new one.
Data retention
How long we keep raw check results, rollups, incident/event history, and alert-delivery logs depends on your plan and is listed for each plan on our pricing page. When your trial ends, we automatically charge the card on file for your chosen plan; if that charge is declined, your checks are paused and the account is suspended right away (we retry the charge once, 24 hours later). Your configuration and monitoring data are not purged when this happens (stored check results still age out on our normal retention schedule), and your account and billing records are kept so you can resume later. If you never add a card at all, the signup is never activated. After 30 days we mark that account as deleted, which closes it and makes it unusable; this is a status change, so its records are not erased at that point (contact us as below to ask for erasure). A signup whose emailed code is never entered has no account yet, and its pending signup and user record are deleted after 48 hours. You can export your account's data on request.
Sharing
We do not sell your data. We share it only with the service providers required to run the service, each bound to process it solely on our behalf, and with our payment processor as described below. We do not share the content of your webhook payloads or alert destinations with anyone but you. These providers are:
- Hosting and email delivery providers, which store our data and send our emails (sign-in codes, alerts, reports, billing notices).
- Google Firebase Cloud Messaging (Google LLC), which will deliver mobile push notifications once our apps are released. Once available, using push means your device's push token and the content of each alert (for example the check name and its status) pass through Google to reach your device.
- Google Fonts (Google LLC). Our website loads its typeface from Google's servers, so your browser sends your IP address and browser details to Google when you visit these pages.
- PayPal, our payment processor, as described below.
Some of these providers process data outside Canada, including in the United States, where it may be subject to local laws.
Payments are processed by PayPal. When you add a card, those payment details go directly to PayPal, which stores them in its vault; we never receive or store your full card number or security code. It's card only — no digital wallet. PayPal acts as our payment processor and, for the payment details it collects and stores, as an independent controller under its own privacy statement. An account has one saved card, and adding a new one replaces (and deletes) the old one, here and in PayPal's vault. We email the account holder whenever the card is added, replaced or removed after signup. We keep only what we need to show, bill and support your saved card: PayPal's reference to it, your PayPal customer and payer IDs, the card's brand, last four digits and expiry date, and the result of any 3-D Secure verification your bank ran when you added it. To apply our free-trial limits (one per email identity and per card in 12 months, three per IP address in 30 days) we also keep one-way hashed fingerprints of your email address, your card and your IP address, from which the originals cannot be recovered. We also keep a record of each payment attempt and its outcome.
Your choices and requests
You can see and change most of your information in the dashboard. To ask for a copy of your data, a correction, or deletion of your account and its data, contact us as below. We may need to confirm you control the account first.
Contact
Privacy questions and requests go to Netcode, Inc. through our contact page — please start your message with "Privacy". Our mailing location is Netcode, Inc., Chatham, Ontario, Canada.