1. Who we are and what this policy covers
The Service is operated by [Status Bee legal entity] ("Status Bee", "we", "us"), [Registered address]. We are the controller of the personal data described in sections 3.1, 3.2, 3.6, 3.7 and 3.8, and a processor of the data our customers collect through their status pages (section 2).
This policy applies to the website at https://statusbee.co, the dashboard at app.statusbee.co, our API, the status pages we host for customers (on our subdomains or on customers' own domains), the notifications we send on customers' behalf, and our support channels. It does not apply to the websites and systems we monitor on a customer's instruction, or to third-party services you connect to Status Bee, which have their own privacy policies.
Questions about this policy or your data: support@statusbee.co.
2. The three roles we play
Account holders and team members
When you create an account, join an organization or use the dashboard and API, we decide how and why your data is processed. For this data we are the controller.
Customers' status pages
A status page belongs to the organization that publishes it (the "customer"). The customer decides what is published, who may subscribe and which notifications go out; we store and deliver on its instructions. For subscriber data and page content we are a processor and the customer is the controller. Our data processing terms are available to customers on request and form part of our agreement with them.
If you subscribed to a customer's page, the customer is your primary point of contact for privacy requests. We help customers fulfil them, and we act ourselves when we are asked directly (section 11).
Visitors
If you simply read statusbee.co or a hosted status page, we process almost nothing about you: transient connection data for security, and anonymous daily view counts (section 3.5).
3. Information we collect
3.1 Account and profile
Email address, display name, avatar URL (when the sign-in provider offers one), preferred language, the time of your last sign-in, your roles and memberships in organizations and workspaces, and the email addresses of people you invite. Authentication is handled by Supabase Auth: we never store passwords in plain text, and if you sign in through a third-party identity provider we receive the identifier and profile fields that provider shares with us.
3.2 What you configure
Organization and workspace names; status pages (name, address, custom domain, timezone, visibility, theme and custom CSS); components and groups; incidents, updates and maintenance windows you write; message templates; monitors (target URLs, hostnames, ports, intervals and assertions); notification channels and outbound webhook endpoints; and API keys, of which we keep only a name, scopes, a short prefix and a one-way hash. The full key is shown once, at creation.
3.3 Monitoring data
For every check we record when it ran, from which region, whether it passed, the latency, the HTTP status code, an error message if there was one, and type-specific details such as TLS certificate issuer, subject and expiry dates, DNS records and resolved addresses. We do not store response bodies. Heartbeat monitors record only the time of the last ping. Raw checks are kept for about 30 days; after that only daily aggregates per component remain, for the history window of your plan.
3.4 Subscriber data (processed for customers)
The channel a subscriber chose and its destination: an email address, a phone number, a Telegram chat identifier, or a Slack, Discord, Microsoft Teams or generic webhook URL (webhook URLs are encrypted at rest). Alongside it: a one-way hash of the destination used to prevent duplicates, verification and unsubscribe tokens, language, the components subscribed to, verification and unsubscribe status, bounce or complaint status, and a record of each notification sent (channel, delivery status, provider message identifier, error, timestamps). Email subscriptions use double opt-in; subscriptions that are not confirmed are deleted after 48 hours.
3.5 Status page visitors
Your IP address and browser identification (user agent) are used in memory to rate-limit requests and prevent abuse. To count page views without cookies, we combine those two values into a shortened one-way hash that exists only for the current day; we retain nothing but daily totals of views and unique visitors per page. Where a customer turns on bot protection for the subscribe form, Cloudflare Turnstile verifies the challenge (including your IP address) under Cloudflare's privacy policy. Status pages set no cookies.
3.6 Billing
Paddle is our merchant of record: it sells the subscription to you, collects your payment method, billing address and tax identifiers, and processes the payment under its own terms and privacy policy. We receive and keep the Paddle customer and subscription identifiers, your plan, billing cycle, subscription status and relevant dates, and a log of billing events. We never receive full card numbers.
3.7 Communications and support
Emails and messages you send us, support requests and feedback; the transactional emails we send (invitations, verification, incident notifications, billing notices) and their delivery metadata (delivered, bounced, complained) as reported by our email provider.
3.8 Technical and audit data
Server logs (IP address, request path, time, user agent, response code) kept briefly for security and debugging; and an append-only audit log of actions taken in your organization (who did what, to which record, when and from which IP address) kept for accountability. Cookies and browser storage are described in section 12.
3.9 What we do not collect
We do not collect precise location, biometric data, government identifiers, or special categories of data such as health, religion or political opinions, and we ask you not to put such data into incident updates or component names. We do not buy data about you from anyone.
4. How we use information, and on what legal basis
We use personal data only for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each purpose is shown.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Providing the Service: accounts, workspaces, pages, monitoring, incident publishing | Account, configuration, monitoring data | Performance of a contract |
| Sending notifications to a customer's subscribers | Subscriber data, delivery records | Customer's instructions (we act as processor); the customer relies on the subscriber's consent |
| Billing, invoicing, tax and accounting | Billing data | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention, rate limiting, audit trails | Technical and audit data, IP addresses | Legitimate interests in keeping the Service and its users safe |
| Understanding how our own sites are used and improving the product | Aggregated, non-identifying usage data | Legitimate interests |
| Support, service announcements, security notices | Contact details, support correspondence | Performance of a contract; legitimate interests |
| Marketing emails about Status Bee | Email address | Consent, which you can withdraw at any time |
| Complying with law and enforcing our terms | Whatever is necessary for the request | Legal obligation; legitimate interests |
We do not use your data to train machine-learning models, we do not build advertising profiles, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. We do not sell your data
We do not sell personal data, and we do not share it with anyone for their own marketing. No advertising networks, cross-site trackers or data brokers are present on any surface we run: not the marketing site, not the dashboard, not the status pages we host, not our emails.
This is also true under the definitions of "sale" and "sharing" in the California Consumer Privacy Act and comparable United States state laws: we have not sold or shared personal information in the preceding twelve months, we do not do so today, and we have no plans to. We treat Global Privacy Control signals as an opt-out even though there is nothing to opt out of.
7. International transfers
We and our providers process data in the European Union and the United States. When personal data protected by the GDPR, the UK GDPR or Swiss law leaves those jurisdictions, we rely on an adequacy decision where one exists and otherwise on the European Commission's Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement where relevant), together with supplementary measures such as encryption in transit and at rest and strict access controls. A copy of the relevant transfer mechanism is available on request.
8. How long we keep data
We keep personal data for as long as it is needed for the purpose it was collected for, and then delete or anonymize it. The main windows are:
| Data | Retention |
|---|---|
| Account and organization data | While the account exists; deleted or anonymized within 30 days of account deletion, except records we must keep for tax or legal reasons |
| Pages, components, incidents and other content | While the workspace exists; uptime history is shown for the window your plan includes |
| Raw monitoring checks | About 30 days, then daily aggregates only |
| Subscribers | Until they unsubscribe or the customer deletes them; unconfirmed email subscriptions are deleted after 48 hours; after unsubscribing we keep only the hash needed to keep honoring the unsubscribe |
| Notification delivery records | 90 days |
| Audit logs | While the organization exists, and up to two years after it is deleted |
| Billing records | As long as tax and accounting law requires, typically seven to ten years |
| Server logs | Up to 30 days |
| Support correspondence | Up to three years after the conversation ends |
| Backups | Encrypted backups roll off within 35 days of deletion in the live systems |
9. Security
All traffic to and from Status Bee is encrypted with TLS. Stored secrets such as webhook URLs and channel tokens are encrypted at rest with AES-256-GCM; API keys are stored only as one-way hashes; passwords never reach our servers in plain text. Every tenant's data is scoped by organization and workspace in the application layer, access inside the company follows least privilege, and every change made through the dashboard or API is written to an append-only audit log. Our infrastructure providers maintain independently audited security programs, and our databases are backed up continuously.
No system is perfectly secure. If we learn of a breach that affects your personal data we will notify you and, where required, the competent supervisory authority without undue delay and within the deadlines the law sets (72 hours under the GDPR).
10. Your rights and choices
Everyone
You can access the data we hold about you, correct it, have it deleted, receive a copy in a machine-readable format, object to or restrict certain processing, and withdraw any consent you gave. Most account data can be changed in the dashboard; for anything else email us and we will respond within 30 days (extendable where the law allows, in which case we tell you). We may ask you to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
European Economic Area, United Kingdom and Switzerland
You have the rights set out in Articles 15 to 22 of the GDPR (and the UK GDPR), including the right to object to processing based on legitimate interests. You also have the right to lodge a complaint with your local supervisory authority; in the UK that is the Information Commissioner's Office.
California and other United States states
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon or another state with a comprehensive privacy law, you have the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct inaccuracies, to opt out of sale, sharing and targeted advertising (we do none of these), to limit the use of sensitive personal information (we use none beyond what the Service strictly needs), and not to be discriminated against for exercising your rights. In the last twelve months we collected the categories of personal information described in section 3 (identifiers, commercial information, internet activity, professional information and inferences drawn only for security purposes), from you, your devices and the organizations you belong to, for the purposes in section 4, and disclosed them only to the service providers in section 6. You may use an authorized agent; we will verify the agent's authority. If we decline a request you may appeal by replying to our decision, and we will answer within the period your state's law sets.
Brazil, Canada, Australia and elsewhere
Wherever you are, you can exercise the rights described above by contacting us, and we will apply the protections your local law grants (including the LGPD, PIPEDA and the Australian Privacy Principles).
11. If you subscribed to a status page
Every email we send on a customer's behalf contains a one-click unsubscribe link that works without logging in. Telegram subscribers can stop updates from the bot; Slack, Discord and Teams subscribers can remove the webhook or ask the page owner to remove it. Unsubscribing stops all further messages for that page.
To have your subscription record deleted entirely, contact the organization that runs the page or write to us; we delete or anonymize it within 30 days and keep only the minimum needed to keep honoring your choice. If your address bounces or you report a message as spam, we automatically stop sending to it.
13. Children
Status Bee is a professional tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We update this policy when our practices change. The effective date at the top always shows the current version. If a change materially reduces your rights or expands what we do with your data, we email account holders at least 14 days before it takes effect and, where the law requires it, ask for your consent.
15. Contact
Privacy requests and questions: support@statusbee.co.
Postal address: [Status Bee legal entity], [Registered address].
Customers who need data processing terms, our sub-processor list or a transfer impact assessment can request them at the same address.