Skip to content

Legal

Privacy policy

How Pingio collects, uses, and protects personal data.

Last updated: 1 August 2026

1. Who we are

Pingio operates an uptime monitoring service available at pingio.io. In this policy, "we" and "us" refer to the operator of that service, acting as the data controller for the personal data described below.

You can reach us about any privacy question at [email protected].

2. Data we collect

We collect only the data needed to run the service and bill for it.

  • Account data: email address, password hash, display name, and team membership.
  • Monitoring configuration: the URLs, hostnames, ports, and assertions you ask us to check.
  • Check results: status codes, response times, error messages, and the region each check ran from.
  • Billing data: plan, invoice history, and payment references supplied by our payment provider. We never see or store your card or wallet credentials.
  • Technical data: IP address, browser type, and timestamps recorded in server logs for security and abuse prevention.

3. How we use data

We use your data to operate monitoring, deliver notifications, display dashboards and status pages, issue invoices, respond to support requests, and protect the service from abuse.

We do not sell personal data, and we do not use your monitoring data to train models or to build advertising profiles.

Where the GDPR applies, we process account, configuration, and monitoring data to perform our contract with you; billing records to comply with legal obligations; and security logs on the basis of our legitimate interest in keeping the platform available and secure.

5. Cookies

We use only functional cookies: a session identifier, a language preference, and a flag that tells the site whether you are signed in. We do not run third-party advertising or cross-site tracking cookies.

6. Sharing and processors

We share data with a small number of processors that are necessary to run the service: our hosting providers, our email delivery provider, and our payment provider. Each of them is bound by a data processing agreement and may use the data only on our instructions.

7. Retention

Account data is kept while your account is active. Check results and incident history are kept for the retention window of your plan. Invoices are kept for as long as accounting law requires. When you delete your account, personal data is removed or irreversibly anonymised within 30 days, except where we must keep it by law.

8. Your rights

You may request access to your data, correction, deletion, restriction of processing, or a portable export, and you may object to processing based on legitimate interest. Write to [email protected] and we will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

9. Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. The database is not reachable from the public internet, and administrative access is restricted to named accounts with key-based authentication.

10. Changes to this policy

If we make a material change we will update the date at the top of this page and notify account owners by email before the change takes effect.