Privacy Policy
Effective Date: July 18, 2026
1. Introduction
CertWatch.io (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our certificate and uptime monitoring service.
2. Information We Collect
2.1. Information You Provide
- Account Information: Email address, name, company name (authentication is managed by our identity provider, Clerk; CertWatch.io does not store your password)
- Payment Information: Processed by Stripe, our payment processor; we never receive or store card numbers
- Monitoring Configuration: Domain names, endpoints, alert preferences, notification channels
- Support Communications: Messages you send to our support team
2.2. Information Automatically Collected
- Usage Data: API calls, feature usage, performance metrics
- Log Data: IP addresses, browser type, access times, pages viewed
- Monitoring Data: Certificate details, uptime status, response times for the domains you configure
- Discovered Subdomains: When subdomain discovery is enabled for a domain you configure, we enumerate and store the subdomains found for that domain in your organization’s inventory
- Device Information: Operating system, browser version
2.3. Information We Do NOT Collect
- SSL/TLS private keys
- Website content or user data from monitored sites
- Passwords or authentication credentials for monitored services
3. How We Use Your Information
We use collected information to:
- Provide and maintain the monitoring service
- Process transactions and send billing notifications
- Send alerts about certificate expirations and downtime
- Respond to support requests and questions
- Improve service performance and features
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information. We may share information:
4.1. With Service Providers
- Clerk — identity and authentication
- Stripe — payment processing and billing
- Cloudflare — core infrastructure (application hosting, databases, queues) and, in some configurations, email delivery
- Amazon Web Services (AWS) — certificate scanning and subdomain discovery processing
- Resend — email delivery for alerts and notifications
4.2. For Legal Reasons
- To comply with legal obligations
- To protect our rights and safety
- To investigate fraud or security issues
- In response to lawful requests by public authorities
4.3. Business Transfers
- In connection with a merger, acquisition, or sale of assets
5. Data Security
We implement appropriate technical and organizational measures:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits
- Incident response procedures
6. Data Retention
- Account Data: Retained while your account is active. When your account is closed, it is deactivated; you may request full deletion of your data (see below)
- Monitoring Check History (certificate and uptime checks): Retained for the life of your account
- Discovered Subdomain Inventory: Retained for the life of your account
- Alert and Notification History: Deleted 60 days after an alert is resolved
- Security Audit Logs: Retained for 90 days, then deleted
- Billing Records: Payment data is held by Stripe; we store only Stripe customer and subscription identifiers. Invoice records are retained for 7 years (legal requirement)
To request deletion of your data, contact [email protected]. We process deletion requests within 30 days.
7. Your Rights
You have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt-out of marketing communications
- Lodge a complaint with supervisory authorities
To exercise these rights, contact: [email protected]
8. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
9. Cookies and Tracking
Cookies on CertWatch.io are limited to the authentication and session cookies set by our identity provider, Clerk, for signing in and keeping your session secure.
We do not use analytics cookies, advertising cookies, or any third-party tracking.
10. Children’s Privacy
Our Service is not intended for children under 16. We do not knowingly collect personal information from children.
11. California Privacy Rights
California residents have additional rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to equal service and price
12. European Privacy Rights
If you’re in the EEA, UK, or Switzerland, you have rights under GDPR:
- Legal basis for processing is contract performance and legitimate interests
- Right to data portability
- Right to restrict processing
- Right to object to processing
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new policy on our website
- Sending an email notification
- Displaying a notice in the dashboard
14. Contact Information
For privacy-related questions or concerns:
Data Protection Officer CertWatch.io Email: [email protected]