Uptime Basics logo
Home Services Pricing Guides Contact
Privacy Policy

How StackResolve handles personal information

This Privacy Policy explains what StackResolve collects through Uptime Basics, why we use it, who receives it, how long we keep it, and the choices and legal rights available to you.

Effective and last updated: August 23, 2026
Our core commitments

We collect information for defined service, security, billing, support, and legal purposes. We do not sell personal information, and optional public-site analytics remains off unless you allow it.

Contents 1. Scope and responsible organization 2. Our privacy roles 3. Information we collect 4. Sources 5. Purposes and legal bases 6. Automated protections 7. Disclosures and providers 8. Public pages and integrations 9. International processing 10. Retention and deletion 11. Security and breaches 12. Cookies and analytics 13. Your rights 14. Children 15. Changes 16. Contact and complaints

1. Scope and responsible organization

This policy applies to Uptime Basics websites, applications, dashboards, APIs, alerts, status pages, support services, and related services (the "Service"), including pages operated through uptimebasics.com and stackresolvehq.com.

Shane-Andrew Syring, carrying on business as StackResolve, a sole proprietorship registered in Ontario, Canada, is the organization responsible for personal information under its control and operates Uptime Basics. Shane-Andrew Syring is StackResolve's designated Privacy Officer. In this policy, "StackResolve," "Uptime Basics," "we," "us," and "our" refer to that business and its proprietor. "Customer" or "you" means an account holder, authorized user, website visitor, support requester, or other person whose information we process.

This policy does not govern a third party's independent handling of information, including Stripe checkout and billing pages, a customer's custom status-page analytics, monitored websites, or destinations connected through an integration.

2. Our privacy roles

StackResolve acts as a controller or responsible organization for account administration, billing records, security, abuse prevention, service analytics, communications, and support. A business customer generally controls the monitor configuration, alert recipients, public status-page content, and other information it submits for its own purposes. To the extent that information is personal data and StackResolve processes it only on that customer's documented instructions, StackResolve acts as a processor or service provider.

Business customers are responsible for providing notices, obtaining consents, establishing legal bases, and responding to individuals for personal data they place in the Service. Our Data Processing Addendum applies when StackResolve processes personal data on behalf of a business customer under the Terms of Service, unless the parties sign a different data processing agreement.

3. Information we collect

3.1 Account and contact information

We collect login email, verified contact emails and phone numbers, name, company or organization, time zone, country and region selections, account preferences, plan, subscription state, and communications preferences.

Before secure checkout, signup asks whether the billing address is in Canada, the United States, or another location and, for Canada, asks for the province or territory. We use this limited declaration to determine whether new-account service is available. Stripe separately collects the complete billing address needed for payment, tax, fraud prevention, and billing records.

3.2 Verification and security information

We process verification status, one-time code records, authentication events, multi-factor authentication status, session and token metadata, security events, IP address, browser and device information, and abuse-control results. We do not store your account password in readable form or store complete authenticator secrets in routine support records.

3.3 Billing, transaction, and tax information

Stripe processes payment methods. We receive identifiers and limited transaction information such as Stripe customer and subscription identifiers, payment status, invoice and credit-note identifiers, plan line items, amounts, currency, taxes, discounts, refunds, fees, settlement amounts, billing country, region and postal code, tax-registration details, masked tax identifiers, and partial payment-method details such as brand and last four digits. We do not store complete payment card numbers or card security codes.

To enforce one-trial eligibility and prevent abuse, we may retain one-way hashed identifiers derived from a verified email address and Stripe payment-method fingerprint, together with limited claim metadata. These identifiers are not used to reconstruct payment details.

3.4 Monitoring and diagnostic information

We collect monitor names, public HTTP or HTTPS URLs, schedules, timeouts, request methods, redirect settings, accepted status codes, optional headers and Basic Authentication settings, SSL and domain settings, resolved network addresses, timestamps, regional results, HTTP status, response time, error category, DNS, TCP, TLS and HTTP diagnostics, incident activity, availability summaries, and logs.

Saved request secrets are encrypted and write-only in customer and routine support views. You should not place personal or confidential information in a URL, monitor name, public description, or other field that does not expressly support secrets.

3.5 Alert and communication information

We collect verified destinations, channel settings, monitor-specific alert choices, message type, provider delivery identifiers, delivery status, timestamps, allowance usage, opt-in and opt-out state, and test-alert activity. We may process message content needed to send operational alerts.

3.6 Status pages, integrations, and API information

We collect status-page slugs, titles, descriptions, display settings, custom-domain configuration, ownership verification evidence, uploaded logos and favicons, style settings, analytics tag identifiers, API token metadata and scopes, webhook endpoints, selected event types, integration configuration, delivery history, and safe failure categories. Secret token values and protected integration credentials are not displayed after creation where the product identifies them as write-only.

3.7 Support requests and authorized access

Support tickets, ticket replies, verified reply address, workflow status, account notes, selected safe diagnostic context, and administrative access and change logs are retained for support, security, accountability, and dispute handling. Saved passwords, verification codes, complete payment details, and saved request-secret values are excluded from support context.

3.8 Website and technical information

We may collect request time, pages viewed, referring page, IP address, approximate location derived from IP, browser, operating system, device type, language, cookie or storage identifiers, consent choice, security challenge result, and error or performance data. Optional analytics data is collected only as described below.

3.9 Public and third-party technical information

We obtain public DNS, TLS certificate, HTTP response, and domain registration information, including RDAP data, to perform requested checks. This data can sometimes include registrar or administrative contact information made public by a registry or provider.

3.10 Separate verification purposes

Signup email verification, destination verification, authenticator-app two-factor authentication, and status-page ownership verification confirm different kinds of access or control. Completing one process does not complete the others.

4. Where information comes from

We receive information directly from you; from authorized users on your account; automatically from your browser, device, API client, or use of the Service; from monitored public endpoints and public registration systems; from alert and integration providers; from Stripe and other service providers; and from security, fraud-prevention, and support processes. If you provide another person's information, you are responsible for having authority to do so and for providing any required notice.

5. Why we use information and our legal bases

PurposeExamplesLegal basis where applicable
Provide the ServiceCreate accounts, run checks, show dashboards, maintain incidents, provide status pages, APIs, and integrationsContract; steps requested before contract
Send communicationsVerification, alerts, account, billing, support, legal, and security noticesContract; legal obligation; legitimate interests; consent where required
Process billing and taxesCheckout, subscriptions, invoices, refunds, reconciliation, tax recordsContract; legal obligation; legitimate interests
Protect the ServiceAuthentication, rate limits, fraud, trial and launch-location controls, abuse review, audit logs, incident responseLegitimate interests; legal obligation; contract
Support customersTickets, troubleshooting, authorized account access, requested monitor changesContract; legitimate interests; consent where appropriate
Improve reliabilityAggregate usage, performance, errors, product testing, capacity planningLegitimate interests; consent for optional analytics
Comply and defendLegal requests, tax and accounting duties, disputes, enforcement, record preservationLegal obligation; legitimate interests; legal claims

Where processing relies on legitimate interests, those interests include delivering and securing a reliable monitoring service, preventing fraud and misuse, supporting customers, improving operations, and protecting legal rights. We consider the nature of the data, reasonable expectations, necessity, and impact on individuals. Where consent is the legal basis, you may withdraw it without affecting earlier lawful processing.

6. Automated protections and eligibility decisions

Automated systems may detect repeated timeouts, excessive requests, unusual alert or diagnostic activity, suspected bot activity, trial eligibility, payment events, unavailable signup locations, or abuse indicators. They may temporarily adjust monitoring, rate-limit a request, pause a monitor, deny a duplicate trial, reject signup from a location that is not currently supported, or request additional verification. Customer-visible service changes are shown where reasonably practicable, while internal abuse and security thresholds are restricted to authorized operations staff.

Before certain plaintext monitor, URL, public status-page, or support fields are saved, local deterministic safeguards may reject high-confidence patterns associated with payment-card data, government identifiers, private keys, or credentials. This safeguard does not semantically profile ordinary text, inspect monitored response bodies for this purpose, send submitted field content to a third-party scanner, or create a retained copy or hash of the matched value. It is a safety aid rather than a guarantee that every sensitive value will be detected. Use only the designated protected Authentication and Custom request headers controls for authorized monitoring credentials.

These systems are designed to protect the Service and enforce published terms. They do not ordinarily make decisions that produce legal or similarly significant effects under data protection law. If you believe an automated protection or eligibility result is wrong, contact support for review. Stripe and other providers may independently apply their own fraud or security decisions under their policies.

7. When we disclose information

We disclose only what is reasonably necessary for the following purposes. Our current provider list is available at Sub-processors.

  • Service providers. Amazon Web Services for hosting, authentication, encrypted cloud services, databases, monitoring workers, email delivery, and SMS delivery when enabled; Stripe for payment and billing; Cloudflare Turnstile for bot and abuse protection; Google Analytics for consent-based measurement; domain, DNS, email, support-email, and other infrastructure providers; and providers supporting integrations you enable.
  • Authorized personnel and contractors. People who need access to operate, secure, support, account for, or improve the Service and who are subject to confidentiality and access restrictions.
  • Your organization and destinations. Authorized account users, verified alert recipients, public status-page visitors, API clients, webhook endpoints, and integrations configured by you.
  • Legal and safety recipients. Courts, regulators, law enforcement, affected providers, professional advisers, or other parties where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, or establish, exercise, or defend legal claims.
  • Business transactions. A prospective or actual buyer, investor, lender, insurer, adviser, successor, or transaction participant in a merger, financing, reorganization, sale, or transfer, subject to appropriate confidentiality and legal safeguards.

We do not sell personal information for money. We do not use personal information for cross-context behavioural advertising, and we do not knowingly share it for such advertising.

8. Public pages, monitored targets, and integrations

A public status page can disclose its title, description, monitored URL, monitor name, current status, uptime summaries, response information, incident information, uploaded branding, custom domain, and enabled analytics identifier. Anyone with access to the page can view or copy public information. Search indexing depends on page type and settings but no indexing choice makes a public page private.

Monitoring requests are sent to the target you configure and may identify Uptime Basics through network addresses, TLS connections, HTTP headers, authentication, or user agent. The target operator may log those requests.

When you enable an API, webhook, custom analytics tag, or third-party integration, you direct us to transmit selected information to that destination. Once received, the destination may process it under its own policy. Review recipients and permissions before enabling a public page or integration.

9. International processing and transfers

StackResolve is based in Canada. We and our providers may process information in Canada, the United States, and other countries where they operate. Those countries may have different privacy laws and lawful-access rules.

Where required, we rely on recognized adequacy decisions, contractual protections such as approved standard contractual clauses, provider data processing terms, or another lawful transfer mechanism. We also use access controls, encryption where appropriate, data minimization, and vendor review. You may contact us for more information about applicable transfer safeguards.

10. Retention and deletion

RecordNormal retention
Raw customer check logs30 days
Alert and notification delivery history14 days
Aggregated monitoring summariesUp to 400 days
Incident historyLife of the monitor
Free service-status raw checks24 hours
Incomplete signup and checkout recordsRemoved after the checkout session expires and cleanup completes
Consent evidenceWhile active and generally 7 years after account termination
Privacy-request recordsGenerally 6 years
Privacy-breach registerAt least 5 years
Billing, tax, refund, settlement, and accounting evidenceUp to 11 years

Paused, archived, and recently deleted monitoring data continues to age under the same periods. A deleted monitor is normally recoverable for 30 days unless permanent deletion is requested sooner; permanent background cleanup then removes its configuration and associated history. If Stripe Checkout is abandoned, the incomplete login, pending profile, temporary signup record, Stripe customer, and pre-checkout billing activity are removed after expiration and cleanup.

Free service-status raw checks are retained for 24 hours.

After an approved account-deletion request completes its reversible 30-day waiting period, operational account and monitoring data is permanently deleted. A legal hold, dispute, security need, fraud-prevention purpose, provider obligation, backup lifecycle, or longer mandatory period may delay deletion. Data may be de-identified and retained where it can no longer reasonably identify a person.

11. Security, access, and breaches

We use safeguards appropriate to the sensitivity and context of the information, including authenticated access, least-privilege roles, administrative separation, encryption in transit and at rest where applicable, encrypted secret storage, audit logging, rate limiting, provider controls, retention limits, monitoring, and incident procedures. No internet service is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

Privileged administrative views and changes are logged. Support monitor changes require a recorded reason. Saved request secrets are masked in routine technical support views. Support will never ask you to provide your password, authenticator code, verification code, or complete payment card or bank details.

If a breach of security safeguards creates a legally reportable risk, we will notify the appropriate regulator and affected individuals as required by applicable law. You should promptly report suspected account or data compromise to support.

We maintain records of safeguard breaches as required by applicable law, including breaches that are assessed as not reportable. These records are access restricted and are designed to use categories, counts, and decision summaries instead of unnecessary copies of affected personal information.

12. Cookies, browser storage, and analytics

Essential cookies and browser storage support sign-in, security, fraud prevention, consent records, preferences, and core application functions. Disabling them may prevent the Service from working.

Google Analytics is optional on public and marketing pages and remains disabled unless you select Allow analytics. If allowed, it helps measure page traffic and improve the Service. Advertising storage and personalized advertising signals remain disabled. You can decline or change the choice using the Privacy choices control. Withdrawing consent does not affect processing that occurred before withdrawal.

Cloudflare Turnstile may process IP address, browser and device characteristics, challenge results, and related technical data to distinguish legitimate requests from automated abuse. It normally operates without interaction but may present a challenge.

Our Cookie and Device Storage Notice identifies the essential and optional browser-storage categories, typical durations, customer status-page analytics behavior, and steps for changing a choice.

13. Your privacy rights and choices

Depending on your location and applicable law, you may have rights to know or access personal information, obtain a copy, correct inaccurate information, request deletion, restrict processing, object to certain processing, withdraw consent, receive portable data, opt out of sale or targeted advertising, appeal a denied request, or complain to a regulator. These rights are subject to legal exceptions, identity verification, and the roles described above.

13.1 Canada

You may request access to and correction of personal information under our control and challenge our compliance. For requests governed by PIPEDA, we respond as soon as possible and no later than 30 days after receipt, unless a permitted extension applies and notice is provided within the initial period. You may withdraw consent subject to legal or contractual limits and reasonable notice. You may complain to the Office of the Privacy Commissioner of Canada or another applicable provincial privacy regulator.

13.2 European Economic Area and United Kingdom

Where applicable, you may request access, rectification, erasure, restriction, portability, or objection; withdraw consent; and lodge a complaint with your local supervisory authority. You may object to direct marketing at any time. We generally respond within one month, subject to permitted extensions and verification. You may ask about transfer safeguards.

13.3 United States

Residents of states with applicable privacy laws may have rights to access, correct, delete, and obtain portable copies of personal information; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data uses; appeal a decision; and receive equal service without unlawful discrimination. StackResolve does not sell personal information or use it for targeted advertising as those concepts are generally defined by U.S. state privacy laws.

13.4 Exercising a right

Signed-in customers can use Account > Support > Privacy and data rights to submit and track a request, or contact the Privacy Officer at privacy@uptimebasics.com. Describe the request and the account or email involved. We may request information reasonably necessary to verify identity or authority before disclosure or a material data change. We do not request government identification by default. Authorized agents may be required to provide proof of authority. We will not discriminate for exercising a legal right.

We may deny or limit a request where law permits, including to protect another person's rights, preserve security or fraud records, comply with tax or legal duties, or establish or defend claims. If we deny a request, we will explain the basis and available appeal or complaint options where required.

14. Children

The Service is intended for adults and business or website operators and is not directed to anyone under 18. We do not knowingly collect personal information from children. Contact us if you believe a child provided information so we can investigate and delete it where required.

15. Changes to this policy

We may update this policy to reflect service, provider, legal, or operational changes. We will post the revised policy and update the effective date. For material changes, we will provide reasonable advance notice by email, in-product notice, website notice, or another appropriate method where required. If consent is legally required for a new purpose, we will request it before that processing.

16. Privacy contact and complaints

Questions, requests, or complaints should be directed to our Privacy Officer:

Shane-Andrew Syring, Privacy Officer
StackResolve
65 Leitch Avenue
North York, Ontario M3J 0E2
Canada

Email: privacy@uptimebasics.com
Customer support: support@uptimebasics.com
Company website: https://stackresolvehq.com
Service website: https://uptimebasics.com

We will investigate privacy complaints and explain our response. You may also contact the Office of the Privacy Commissioner of Canada, an applicable provincial privacy regulator, an EEA or UK supervisory authority, or another regulator with jurisdiction over your complaint.

Uptime Basics logo
Reliable monitoring for small businesses, agencies, and founders that want clear visibility without enterprise overhead.
Made in Canada.

Product

ServicesGuidesPublic Status PagesPricingF.A.Q.

Company

ContactSecurityAccessibility

Legal

Legal & TrustPrivacy PolicyTerms of ServiceSub-processors