Legal
Privacy Policy
Last updated: March 2026
CheckHost ("we", "us", "our") operates the website check-host.com and provides uptime monitoring services. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service. CheckHost is operated by Netvolo Provence, based in France.
1. Information We Collect
Account Information: When you create an account, we collect your email address, name, and password (hashed). If you use OAuth (Google or GitHub), we receive your public profile information from those providers.
Usage Data: We automatically collect information about how you use our Service, including pages visited, features used, monitors created, and interaction patterns.
Technical Data: We collect your IP address, browser type and version, operating system, device type, timezone, and referring URL.
Payment Data: Payment processing is handled by Stripe. We do not store your credit card details. Stripe may collect billing information as described in their privacy policy.
Monitoring Data: Data generated by your monitors (response times, uptime records, incident logs) is stored as part of the Service functionality.
2. How We Use Your Information
- To provide, maintain, and improve our monitoring services
- To process your account registration and manage your subscription
- To send you alerts and notifications about your monitors
- To process payments through Stripe
- To send service-related communications (account changes, security notices)
- To analyze usage patterns and improve user experience via analytics
- To detect and prevent fraud, abuse, or security threats
- To comply with legal obligations
3. Analytics & Tracking
We use the following analytics services to understand how our Service is used:
| Service | Purpose | Data Collected |
|---|---|---|
| Google Analytics 4 | Usage analytics, conversion tracking | Page views, events, anonymized IP, device info |
| Matomo | Self-hosted analytics | Page views, sessions, anonymized IP |
Both analytics services are subject to your cookie consent preferences. You can manage your preferences at any time through our cookie consent banner or on our Cookie Policy page.
4. Third-Party Services
We use the following third-party services that may process your data:
- Stripe — Payment processing (PCI DSS compliant)
- Google OAuth / GitHub OAuth — Authentication (if you choose to sign in via OAuth)
- Bunny CDN — Content delivery and media storage
- SMTP Provider — Transactional email delivery (alerts, verification emails)
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. Monitoring data retention is configurable in your account settings, ranging from 30 to 365 days.
- Account data: Retained until account deletion
- Monitoring data: 30–365 days (configurable, default 90 days)
- Analytics data: Aggregated and anonymized after 26 months
- Payment records: Retained as required by law (typically 7 years)
- Audit logs: Retained for 1 year
6. Your Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have the following rights under GDPR:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Portability: Request your data in a structured, machine-readable format
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for analytics tracking at any time
To exercise any of these rights, contact us at contact@check-host.com. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Passwords hashed using industry-standard algorithms
- Two-factor authentication (2FA) available for all accounts
- Rate limiting and DDoS protection
- Regular security audits and monitoring
- Access controls and audit logging
9. Children's Privacy
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information.
10. International Data Transfers
Your data may be processed in countries outside the EEA. When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will send you an email notification.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:
