Privacy Policy
This policy explains what data Vantield Monitor collects, why, and how it is handled. It applies to the marketing site at www.vantield.com and the monitoring application at monitor.vantield.com. The data controller is Vantield LLC (contact: privacy@vantield.com).
1. Data we collect
Account data
When you create an account we collect your email address and a bcrypt hash of your password. Supabase Auth handles authentication and stores session tokens. We do not store plaintext passwords.
Team data
When you create or join a team we store the team name, your role (admin, member, or viewer), and your membership status. If you invite someone by email, their email address is stored as a pending invitation until they accept or the invitation is removed.
Monitor configuration
For each monitor you create we store the URL, HTTP method, expected status code, check interval, timeout threshold, and optional fields such as a request body, custom request headers, a body match string, a custom User-Agent, and a dependency URL. These values are provided entirely by you. If the URLs or request bodies you configure contain personal data (for example, query parameters or API payloads), that data is stored as part of the monitor configuration.
Check results
Every check records the timestamp, outcome(available, unavailable, or dependency unavailable), HTTP status code, and response time in milliseconds. When a check fails, we additionally capture the request headers sent, the response headersreceived, and up to 10 KB of the response body to aid debugging. Response bodies are not captured on successful checks. Check result data is automatically deleted after 180 days.
Alert recipients
Alert policies can include one or more email addresses as recipients. These are stored and used only to deliver alert notifications.
Integration credentials
If you configure a custom SMTP server or a PagerDuty integration, the associated credentials (host, port, username, password, and API key) are stored encrypted in our database. They are used only to deliver notifications on your behalf.
What we do not collect
We do not collect IP addresses, browser fingerprints, or device identifiers. We do not handle payment data. The marketing site sets no cookies and loads no analytics or tracking scripts.
2. How we use your data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide and operate the service | Account data, monitor configuration, check results | Performance of a contract (Art. 6(1)(b)) |
| Send alert notifications | Alert recipient emails, monitor name and URL | Performance of a contract (Art. 6(1)(b)) |
| Authenticate users and manage sessions | Email address, password hash, session tokens | Performance of a contract (Art. 6(1)(b)) |
| Deliver integration notifications (PagerDuty, custom SMTP) | Monitor name, URL, status, integration credentials | Performance of a contract (Art. 6(1)(b)) |
| Enforce data retention and cleanup | Check result timestamps | Legitimate interest - minimising stored data (Art. 6(1)(f)) |
We do not use your data for advertising, profiling, or sale to third parties.
3. Third-party processors
We share data with the following processors only to the extent necessary to operate the service. Each is bound by a data processing agreement.
| Processor | Role | Data received | Location |
|---|---|---|---|
| Supabase | Database and authentication | All stored data (account, team, monitor, check results) | US / EU (region configurable) |
| Resend | Transactional email | Recipient email addresses, monitor name, URL, and status | US |
| PagerDuty | Incident alerting (optional) | Monitor name, URL, and status on incident open/resolve | US |
| Vercel | Marketing site hosting | HTTP request metadata (standard web server logs) | US / global edge |
| Railway | Backend API hosting | HTTP request metadata, application logs | US |
| Cloudflare | DNS | DNS query metadata only | US / global |
4. Data retention
| Data | Retained for |
|---|---|
| Check results (status, response time, diagnostics) | 180 days - deleted automatically by a nightly cleanup job |
| Account and team data | Until you delete your account |
| Monitor configuration | Until you delete the monitor or your account |
| Alert recipient addresses | Until removed from the alert policy or account deleted |
| Integration credentials | Until the integration is removed or account deleted |
5. International data transfers
Several of our processors (Supabase, Resend, Vercel, Railway, Cloudflare) are based in the United States. Where personal data is transferred outside the UK or European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards to ensure adequate protection.
6. Your rights
Under GDPR and equivalent laws, you have the following rights regarding your personal data:
- Access - request a copy of the personal data we hold about you.
- Rectification - request correction of inaccurate data.
- Erasure - request deletion of your data ("right to be forgotten").
- Portability - receive your data in a structured, machine-readable format.
- Restriction - request that we limit how we process your data.
- Objection - object to processing based on legitimate interest.
- Withdraw consent - where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy@vantield.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
7. Cookies
Marketing site (www.vantield.com): No cookies are set. No analytics or tracking scripts are loaded.
Monitoring application (monitor.vantield.com): Supabase Auth sets a session cookie when you log in. This cookie is strictly necessary to maintain your authenticated session. It is not used for tracking or advertising and is deleted when you log out or your session expires.
8. Changes to this policy
If we make material changes to this policy, we will update the effective date at the top of this page and, where appropriate, notify you by email. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
9. Contact
Questions about this policy or requests related to your personal data can be sent to privacy@vantield.com.