Legal

Privacy Policy

Effective September 10, 2026

Status Bee is an uptime-monitoring and status-page service. This policy explains what personal data we collect when you visit statusbee.co, use the dashboard or API, subscribe to a status page we host, or are contacted through one, and what we do with it. It is written to be read; if anything is unclear, email us.

The short version

  • We never sell personal data and never share it for advertising. None of our surfaces run ad trackers.
  • We collect what the service needs: your account details, what you configure, monitoring results, and the contact channel a subscriber chooses.
  • For a hosted status page, the organization that runs the page is the data controller. We process subscriber data on its instructions.
  • Payments are handled by Paddle as merchant of record. We never see full card numbers.
  • You can access, export, correct or delete your data at any time. Subscribers can unsubscribe with one click, no login required.
  • Raw monitoring checks are kept for about 30 days, unconfirmed email subscriptions for 48 hours, and account data for as long as your account exists.

The summary is for orientation only. The full text below is what applies.

On this page
  1. 1. Who we are and what this policy covers
  2. 2. The three roles we play
  3. 3. Information we collect
  4. 4. How we use information, and on what legal basis
  5. 5. We do not sell your data
  6. 6. When we share information
  7. 7. International transfers
  8. 8. How long we keep data
  9. 9. Security
  10. 10. Your rights and choices
  11. 11. If you subscribed to a status page
  12. 12. Cookies and browser storage
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. Contact

1. Who we are and what this policy covers

The Service is operated by [Status Bee legal entity] ("Status Bee", "we", "us"), [Registered address]. We are the controller of the personal data described in sections 3.1, 3.2, 3.6, 3.7 and 3.8, and a processor of the data our customers collect through their status pages (section 2).

This policy applies to the website at https://statusbee.co, the dashboard at app.statusbee.co, our API, the status pages we host for customers (on our subdomains or on customers' own domains), the notifications we send on customers' behalf, and our support channels. It does not apply to the websites and systems we monitor on a customer's instruction, or to third-party services you connect to Status Bee, which have their own privacy policies.

Questions about this policy or your data: support@statusbee.co.

2. The three roles we play

Account holders and team members

When you create an account, join an organization or use the dashboard and API, we decide how and why your data is processed. For this data we are the controller.

Customers' status pages

A status page belongs to the organization that publishes it (the "customer"). The customer decides what is published, who may subscribe and which notifications go out; we store and deliver on its instructions. For subscriber data and page content we are a processor and the customer is the controller. Our data processing terms are available to customers on request and form part of our agreement with them.

If you subscribed to a customer's page, the customer is your primary point of contact for privacy requests. We help customers fulfil them, and we act ourselves when we are asked directly (section 11).

Visitors

If you simply read statusbee.co or a hosted status page, we process almost nothing about you: transient connection data for security, and anonymous daily view counts (section 3.5).

3. Information we collect

3.1 Account and profile

Email address, display name, avatar URL (when the sign-in provider offers one), preferred language, the time of your last sign-in, your roles and memberships in organizations and workspaces, and the email addresses of people you invite. Authentication is handled by Supabase Auth: we never store passwords in plain text, and if you sign in through a third-party identity provider we receive the identifier and profile fields that provider shares with us.

3.2 What you configure

Organization and workspace names; status pages (name, address, custom domain, timezone, visibility, theme and custom CSS); components and groups; incidents, updates and maintenance windows you write; message templates; monitors (target URLs, hostnames, ports, intervals and assertions); notification channels and outbound webhook endpoints; and API keys, of which we keep only a name, scopes, a short prefix and a one-way hash. The full key is shown once, at creation.

3.3 Monitoring data

For every check we record when it ran, from which region, whether it passed, the latency, the HTTP status code, an error message if there was one, and type-specific details such as TLS certificate issuer, subject and expiry dates, DNS records and resolved addresses. We do not store response bodies. Heartbeat monitors record only the time of the last ping. Raw checks are kept for about 30 days; after that only daily aggregates per component remain, for the history window of your plan.

3.4 Subscriber data (processed for customers)

The channel a subscriber chose and its destination: an email address, a phone number, a Telegram chat identifier, or a Slack, Discord, Microsoft Teams or generic webhook URL (webhook URLs are encrypted at rest). Alongside it: a one-way hash of the destination used to prevent duplicates, verification and unsubscribe tokens, language, the components subscribed to, verification and unsubscribe status, bounce or complaint status, and a record of each notification sent (channel, delivery status, provider message identifier, error, timestamps). Email subscriptions use double opt-in; subscriptions that are not confirmed are deleted after 48 hours.

3.5 Status page visitors

Your IP address and browser identification (user agent) are used in memory to rate-limit requests and prevent abuse. To count page views without cookies, we combine those two values into a shortened one-way hash that exists only for the current day; we retain nothing but daily totals of views and unique visitors per page. Where a customer turns on bot protection for the subscribe form, Cloudflare Turnstile verifies the challenge (including your IP address) under Cloudflare's privacy policy. Status pages set no cookies.

3.6 Billing

Paddle is our merchant of record: it sells the subscription to you, collects your payment method, billing address and tax identifiers, and processes the payment under its own terms and privacy policy. We receive and keep the Paddle customer and subscription identifiers, your plan, billing cycle, subscription status and relevant dates, and a log of billing events. We never receive full card numbers.

3.7 Communications and support

Emails and messages you send us, support requests and feedback; the transactional emails we send (invitations, verification, incident notifications, billing notices) and their delivery metadata (delivered, bounced, complained) as reported by our email provider.

3.8 Technical and audit data

Server logs (IP address, request path, time, user agent, response code) kept briefly for security and debugging; and an append-only audit log of actions taken in your organization (who did what, to which record, when and from which IP address) kept for accountability. Cookies and browser storage are described in section 12.

3.9 What we do not collect

We do not collect precise location, biometric data, government identifiers, or special categories of data such as health, religion or political opinions, and we ask you not to put such data into incident updates or component names. We do not buy data about you from anyone.

4. How we use information, and on what legal basis

We use personal data only for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each purpose is shown.

PurposeData involvedLegal basis
Providing the Service: accounts, workspaces, pages, monitoring, incident publishingAccount, configuration, monitoring dataPerformance of a contract
Sending notifications to a customer's subscribersSubscriber data, delivery recordsCustomer's instructions (we act as processor); the customer relies on the subscriber's consent
Billing, invoicing, tax and accountingBilling dataPerformance of a contract; legal obligation
Security, fraud and abuse prevention, rate limiting, audit trailsTechnical and audit data, IP addressesLegitimate interests in keeping the Service and its users safe
Understanding how our own sites are used and improving the productAggregated, non-identifying usage dataLegitimate interests
Support, service announcements, security noticesContact details, support correspondencePerformance of a contract; legitimate interests
Marketing emails about Status BeeEmail addressConsent, which you can withdraw at any time
Complying with law and enforcing our termsWhatever is necessary for the requestLegal obligation; legitimate interests

We do not use your data to train machine-learning models, we do not build advertising profiles, and we do not make decisions about you by automated means that have legal or similarly significant effects.

5. We do not sell your data

We do not sell personal data, and we do not share it with anyone for their own marketing. No advertising networks, cross-site trackers or data brokers are present on any surface we run: not the marketing site, not the dashboard, not the status pages we host, not our emails.

This is also true under the definitions of "sale" and "sharing" in the California Consumer Privacy Act and comparable United States state laws: we have not sold or shared personal information in the preceding twelve months, we do not do so today, and we have no plans to. We treat Global Privacy Control signals as an opt-out even though there is nothing to opt out of.

6. When we share information

Service providers acting on our instructions

We rely on a small number of providers to run Status Bee. Each is bound by a contract that limits its use of data to providing its service to us.

ProviderWhat it does for usData it handles
SupabaseAuthentication and hosted PostgreSQL databaseAccount credentials and identity, all application data
PaddlePayments, invoicing and tax as merchant of recordBilling and payment data
ResendTransactional and notification emailRecipient email addresses and message content
CloudflareNetwork security, bot protection on subscribe forms, TLS for custom domainsConnection data, challenge responses, hostnames
PreludeSMS delivery, when the SMS channel is enabledPhone numbers and message content
Cloud infrastructure providersCompute, storage, queues and cachesEncrypted application data in transit through our systems

We publish the current list of sub-processors on request and notify customers who have signed data processing terms before adding one.

Channels you or your subscribers choose

When a subscriber chooses Telegram, Slack, Discord, Microsoft Teams, SMS or a webhook, we hand the message to that service or endpoint. Those services receive the message under their own terms; they are recipients chosen by the customer or subscriber, not our sub-processors.

Our customers

Subscriber data is visible to the organization that runs the page the subscriber joined, together with the delivery records for that page.

Legal reasons

We disclose data when the law requires it, to respond to valid legal process, to enforce our terms, or to protect the rights, property or safety of Status Bee, our users or the public. We tell affected users about such requests unless the law forbids it.

Business transfers

If Status Bee is involved in a merger, acquisition or sale of assets, personal data may transfer as part of that transaction. This policy continues to apply and we notify account holders before their data becomes subject to a different one.

With your consent

In any other case, only with your explicit consent.

7. International transfers

We and our providers process data in the European Union and the United States. When personal data protected by the GDPR, the UK GDPR or Swiss law leaves those jurisdictions, we rely on an adequacy decision where one exists and otherwise on the European Commission's Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement where relevant), together with supplementary measures such as encryption in transit and at rest and strict access controls. A copy of the relevant transfer mechanism is available on request.

8. How long we keep data

We keep personal data for as long as it is needed for the purpose it was collected for, and then delete or anonymize it. The main windows are:

DataRetention
Account and organization dataWhile the account exists; deleted or anonymized within 30 days of account deletion, except records we must keep for tax or legal reasons
Pages, components, incidents and other contentWhile the workspace exists; uptime history is shown for the window your plan includes
Raw monitoring checksAbout 30 days, then daily aggregates only
SubscribersUntil they unsubscribe or the customer deletes them; unconfirmed email subscriptions are deleted after 48 hours; after unsubscribing we keep only the hash needed to keep honoring the unsubscribe
Notification delivery records90 days
Audit logsWhile the organization exists, and up to two years after it is deleted
Billing recordsAs long as tax and accounting law requires, typically seven to ten years
Server logsUp to 30 days
Support correspondenceUp to three years after the conversation ends
BackupsEncrypted backups roll off within 35 days of deletion in the live systems

9. Security

All traffic to and from Status Bee is encrypted with TLS. Stored secrets such as webhook URLs and channel tokens are encrypted at rest with AES-256-GCM; API keys are stored only as one-way hashes; passwords never reach our servers in plain text. Every tenant's data is scoped by organization and workspace in the application layer, access inside the company follows least privilege, and every change made through the dashboard or API is written to an append-only audit log. Our infrastructure providers maintain independently audited security programs, and our databases are backed up continuously.

No system is perfectly secure. If we learn of a breach that affects your personal data we will notify you and, where required, the competent supervisory authority without undue delay and within the deadlines the law sets (72 hours under the GDPR).

10. Your rights and choices

Everyone

You can access the data we hold about you, correct it, have it deleted, receive a copy in a machine-readable format, object to or restrict certain processing, and withdraw any consent you gave. Most account data can be changed in the dashboard; for anything else email us and we will respond within 30 days (extendable where the law allows, in which case we tell you). We may ask you to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.

European Economic Area, United Kingdom and Switzerland

You have the rights set out in Articles 15 to 22 of the GDPR (and the UK GDPR), including the right to object to processing based on legitimate interests. You also have the right to lodge a complaint with your local supervisory authority; in the UK that is the Information Commissioner's Office.

California and other United States states

If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon or another state with a comprehensive privacy law, you have the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct inaccuracies, to opt out of sale, sharing and targeted advertising (we do none of these), to limit the use of sensitive personal information (we use none beyond what the Service strictly needs), and not to be discriminated against for exercising your rights. In the last twelve months we collected the categories of personal information described in section 3 (identifiers, commercial information, internet activity, professional information and inferences drawn only for security purposes), from you, your devices and the organizations you belong to, for the purposes in section 4, and disclosed them only to the service providers in section 6. You may use an authorized agent; we will verify the agent's authority. If we decline a request you may appeal by replying to our decision, and we will answer within the period your state's law sets.

Brazil, Canada, Australia and elsewhere

Wherever you are, you can exercise the rights described above by contacting us, and we will apply the protections your local law grants (including the LGPD, PIPEDA and the Australian Privacy Principles).

11. If you subscribed to a status page

Every email we send on a customer's behalf contains a one-click unsubscribe link that works without logging in. Telegram subscribers can stop updates from the bot; Slack, Discord and Teams subscribers can remove the webhook or ask the page owner to remove it. Unsubscribing stops all further messages for that page.

To have your subscription record deleted entirely, contact the organization that runs the page or write to us; we delete or anonymize it within 30 days and keep only the minimum needed to keep honoring your choice. If your address bounces or you report a message as spam, we automatically stop sending to it.

12. Cookies and browser storage

Marketing site (statusbee.co): no cookies, no analytics scripts, no advertising tags.

Dashboard: strictly necessary storage only: your sign-in session (kept in your browser by Supabase Auth so you stay logged in), your theme preference, and security tokens that protect forms. Paddle's checkout, which opens inside the dashboard when you buy a plan, sets its own cookies under Paddle's privacy policy.

Hosted status pages: no cookies. Page views are counted with the cookieless method described in section 3.5.

Because we use only storage that is essential to what you asked for, we do not show a cookie banner. You can clear browser storage at any time; doing so signs you out of the dashboard.

13. Children

Status Bee is a professional tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Changes to this policy

We update this policy when our practices change. The effective date at the top always shows the current version. If a change materially reduces your rights or expands what we do with your data, we email account holders at least 14 days before it takes effect and, where the law requires it, ask for your consent.

15. Contact

Privacy requests and questions: support@statusbee.co.

Postal address: [Status Bee legal entity], [Registered address].

Customers who need data processing terms, our sub-processor list or a transfer impact assessment can request them at the same address.