Privacy Policy

Last updated: May 15, 2026

This Privacy Policy describes how PE Priymak Viacheslav Vasyliovych, trading as Status Harbor ("we", "us", "our"), collects, uses and protects your personal information when you use our uptime monitoring service ("Service").

1. Information We Collect

Account Information

  • Email address
  • Name (if provided)
  • Password (stored as a bcrypt hash - we never store plaintext passwords)
  • Google account information (if you register via Google OAuth)

Service Data

  • Monitor configurations (URLs, check intervals, expected responses)
  • Monitoring results and incident history
  • Status page configurations
  • Notification settings and integration tokens (Slack, Telegram, Webhook URLs)

Lighthouse Agent Data

If you choose to deploy a Lighthouse agent inside your own network, the agent connects to Status Harbor over outbound HTTPS and transmits the following data:

  • Agent identity - agent version and the hostname of the machine on which the agent runs (so the dashboard can display which host is running which Lighthouse).
  • Check transitions - for each state change (a check going from "up" to "down" or vice versa): the new state, the previous state, response time in milliseconds, status code (for HTTP / HTTPS checks), the error string returned by the failed probe and the timestamp at which the agent observed the result.
  • Heartbeats - a periodic message containing the agent version, a configuration cache identifier and a sparse map of the most recent latency observation for each running check.
  • Lifecycle events - a best-effort shutdown notification with a short reason string when the agent is stopped.
  • Discovery metadata (Kubernetes deployments only, when discovery is enabled) - for each Ingress and externally-facing Service the agent observes in the namespaces it is configured to watch: the resource kind (ingress / service), namespace, resource name, host, port and scheme. This is metadata describing what the agent could probe; no probing occurs and no monitor is created until you explicitly adopt a discovery in the dashboard. Discovery is on by default for the Helm install path and can be turned off with --set discovery.enabled=false.
  • Host and cluster metrics (collected by default when the Lighthouse runs in metrics mode; per-node Kubernetes coverage is opt-in via the chart's DaemonSet flavour) - aggregate counters derived from /proc on the host: CPU busy / user / system / iowait, memory used / available / swap, load average, disk used / free per mount and network bytes / packets / errors per interface. On Kubernetes, additionally per-node CPU / memory / disk / network and per-PVC disk capacity fetched from the kubelet. Identifying labels are limited to the hostname the agent reports and the Lighthouse identifier. No process lists, command lines, environment variables or per-PID data leave the host.

The agent does not transmit response bodies, request payloads, packet captures, the contents of internal services, process lists, command lines, environment variables, per-PID data from /proc, or any data beyond the keyword and header rules you explicitly configure on a check and the aggregate metrics described above. The configuration the agent applies - the URLs, hostnames and ports it probes - is set by you in Status Harbor and is part of the Service Data described above.

Payment Information

Payment details (credit card numbers, billing address) are collected and processed directly on the secure hosted page of our acquiring bank, Monobank (JSC "Universal Bank"). We do not store your full payment card details on our servers. We receive only a tokenized card reference, transaction reference, subscription status and a masked PAN (last four digits) from Monobank. Monobank's own privacy practices govern how it handles the card data it collects on its hosted page.

Automatically Collected Information

  • IP address
  • Browser type and version
  • Pages visited and usage patterns
  • Authentication tokens (JWT) stored in your browser

Diagnostic Data

When the Status Harbor console application encounters an unexpected frontend error, we send a diagnostic report to our error-tracking provider (Sentry). The report contains the stack trace, the URL the error occurred on, your browser type and version, and your account email and user ID so we can correlate the report to your account during triage. We use this data only to debug and fix issues. Reports are stored in the EU and retained in accordance with Sentry's defaults.

2. How We Use Your Information

  • To provide the Service - running monitors, sending alerts, managing your account
  • To process payments - managing subscriptions via Monobank acquiring
  • To send notifications - delivering alerts through your configured channels (email, Slack, Telegram, Webhooks)
  • To improve the Service - analyzing usage patterns to fix issues and develop features
  • To communicate with you - sending service updates, billing notifications and support responses

3. Third-Party Services

We share information with the following third-party services as necessary to operate the Service:

  • Monobank (JSC "Universal Bank") - card acquiring on its hosted payment page (receives billing and payment card information; returns a tokenized card reference for recurring charges)
  • Google - authentication (if you use Google OAuth sign-in)
  • Slack - notification delivery (if you configure Slack integration)
  • Telegram - notification delivery (if you configure Telegram integration)
  • Sentry - error tracking; receives stack traces, browser type and your account email when the console application hits an unexpected frontend error. EU-hosted.

We do not sell, rent or trade your personal information to third parties for marketing purposes.

4. Data Retention

  • Account data - retained for the lifetime of your account
  • Monitoring data - check results and incident history are retained for the duration of your active subscription
  • Metrics history - 7 days for all teams. Threshold-alert events and their resolution timestamps are retained independently for the duration of your active subscription
  • Notification logs - retained for 90 days
  • After account deletion - all personal data is deleted within 30 days, except where retention is required by law

5. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encrypted data transmission (TLS/HTTPS)
  • Hashed passwords (bcrypt)
  • Encrypted integration tokens at rest
  • Access controls and authentication for all systems

6. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate personal data
  • Delete your account and associated data
  • Export your monitoring data
  • Withdraw consent for optional data processing

To exercise these rights, contact us at [email protected] or use the account settings in the application.

7. Cookies, Local Storage and Analytics

We use JWT authentication tokens stored in your browser's local storage to maintain your session in the console application.

The marketing site at statusharbor.io uses Google Analytics 4 (GA4) to measure aggregate traffic - pages visited, referrer, approximate location derived from IP and device or browser type. GA4 sets first-party cookies (_ga, _ga_*) with a 13-month expiry. We use this data only to understand how visitors find the site and which content is useful; we do not use it to target individual users or share it with advertisers. The console application at console.statusharbor.io does not load Google Analytics.

You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by blocking the script in your browser's tracking-protection settings.

8. International Data Transfers

Your data may be processed in countries other than your own. We ensure that appropriate safeguards are in place for any international data transfers in compliance with applicable data protection laws.

9. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top reflects the most recent revision.

11. Contact and Operator

The Service is operated by PE Priymak Viacheslav Vasyliovych (the legal entity behind the "Status Harbor" trading name). For questions or concerns about this Privacy Policy, or to exercise any of the rights described in section 6, contact us at [email protected].