Privacy Policy
The data controller is Zubco Mihail (details on the
company details page). This
policy is part of the Terms of Service.
1. What we process
- Account: email address, name, password (stored only as an argon2id hash), interface language and timezone.
- Monitoring configuration: check and integration settings, including alert destinations (email addresses, chat identifiers, webhook URLs).
- Technical ping data: source IP address, user-agent, request method and the ping body. Ping bodies may contain arbitrary customer data, so they are encrypted at rest at the application level.
- Payment data: handled by the payment providers (section 3); we never receive or store full card details.
2. Why we process it
- running the monitoring service (ping ingestion, status computation);
- delivering alerts to the channels you configure;
- billing and issuing payment receipts;
- customer support;
- security (rate limiting, incident investigation).
3. Processors
Each provider receives only what its function requires:
- Unisender Go — transactional email delivery (recipient address, message content);
- Paddle — international payments, acting as the merchant of record;
- YooKassa (NBCO YooMoney) — payments for the Russian contour;
- Cloudflare — traffic delivery and DDoS protection (transit network data);
- Hetzner Online GmbH — server hosting (EU: Germany/Finland) where the service data lives.
We do not sell your data and do not share it with anyone else,
except where the law explicitly requires it.
4. Retention
- ping and event history — within your plan's retention (30 days on Free, 1 year on Pro, 2 years on Business), then deleted;
- account data — until the account is deleted;
- payment records — for the periods required by tax law.
5. Your rights
You may request information about the processing of your data,
ask for correction, restriction or erasure, and withdraw
consent by writing to support@cronalive.com.
Export and deletion are self-service: in the app under
Security you can
export your data as JSON and delete the account — deletion is
irreversible and destroys the associated data.
6. Security
All traffic is HTTPS-only; passwords are hashed with argon2id;
API keys are stored as hashes; ping bodies and sensitive
configuration fields are encrypted at rest. Staff access to
data is limited to operational necessity.
7. Changes
A new revision is published on this page and takes effect upon
publication.