Legal
Privacy policy
How Pingio collects, uses, and protects personal data.
Last updated: 1 August 2026
1. Who we are
Pingio operates an uptime monitoring service available at pingio.io. In this policy, "we" and "us" refer to the operator of that service, acting as the data controller for the personal data described below.
You can reach us about any privacy question at [email protected].
2. Data we collect
We collect only the data needed to run the service and bill for it.
- Account data: email address, password hash, display name, and team membership.
- Monitoring configuration: the URLs, hostnames, ports, and assertions you ask us to check.
- Check results: status codes, response times, error messages, and the region each check ran from.
- Billing data: plan, invoice history, and payment references supplied by our payment provider. We never see or store your card or wallet credentials.
- Technical data: IP address, browser type, and timestamps recorded in server logs for security and abuse prevention.
3. How we use data
We use your data to operate monitoring, deliver notifications, display dashboards and status pages, issue invoices, respond to support requests, and protect the service from abuse.
We do not sell personal data, and we do not use your monitoring data to train models or to build advertising profiles.
4. Legal basis
Where the GDPR applies, we process account, configuration, and monitoring data to perform our contract with you; billing records to comply with legal obligations; and security logs on the basis of our legitimate interest in keeping the platform available and secure.
5. Cookies
We use only functional cookies: a session identifier, a language preference, and a flag that tells the site whether you are signed in. We do not run third-party advertising or cross-site tracking cookies.
6. Sharing and processors
We share data with a small number of processors that are necessary to run the service: our hosting providers, our email delivery provider, and our payment provider. Each of them is bound by a data processing agreement and may use the data only on our instructions.
7. Retention
Account data is kept while your account is active. Check results and incident history are kept for the retention window of your plan. Invoices are kept for as long as accounting law requires. When you delete your account, personal data is removed or irreversibly anonymised within 30 days, except where we must keep it by law.
8. Your rights
You may request access to your data, correction, deletion, restriction of processing, or a portable export, and you may object to processing based on legitimate interest. Write to [email protected] and we will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
9. Security
Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. The database is not reachable from the public internet, and administrative access is restricted to named accounts with key-based authentication.
10. Changes to this policy
If we make a material change we will update the date at the top of this page and notify account owners by email before the change takes effect.