Privacy Policy

Last updated 2026-09-20

Vitals HQ ("we", "us") provides website monitoring and maintenance software for agencies and the teams who manage websites on behalf of their clients. This policy explains what we collect, how we use it, and the choices you have.

Who this applies to

This policy covers visitors to our website and account holders (agencies and their team members). Where an agency monitors sites for its own clients, that agency controls the client data and we act as its processor.

Information we collect

  • Account data: your name, email, organization name, and password (stored only as a salted hash).
  • Monitored assets: the site URLs you add and the results we generate — uptime, response times, SSL and domain expiry, Core Web Vitals, and platform health.
  • Connection credentials: tokens and keys you provide for deep checks (the WordPress companion plugin token, Shopify Admin API token) and, optionally, your own AI provider key. Secrets are encrypted at rest (AES-256-GCM) and are never shown again after entry.
  • Client & CRM records: the contacts, notes and support tickets you choose to store about your clients.
  • Usage & device data: log data, IP address and browser information needed to operate and secure the service.
  • Cookies: a small number of strictly necessary cookies for authentication and security. We do not use advertising cookies.

How we use your information

  • Provide monitoring, alerting, reporting and maintenance features.
  • Send transactional email such as alerts, reports and account messages.
  • Secure the service, prevent abuse, and troubleshoot issues.
  • Respond to your support and account requests.

We do not sell your personal information.

Service providers

We share data only with providers that help us run the service, under contract: hosting and database infrastructure; transactional email delivery; Google PageSpeed Insights and Safe Browsing for performance and malware checks; Stripe for billing where enabled; and your chosen AI provider (for example Anthropic or OpenAI) for optional AI features, using the key you supply and billed to your own provider account.

Data retention

We keep account and monitoring data for as long as your account is active, with check history retained on a rolling basis to power trends and reports. When you delete a site, client or your account, the associated data is removed or anonymized within a reasonable period, except where we must retain it to meet legal obligations.

Security

We encrypt data in transit (TLS) and encrypt sensitive secrets at rest. Access to production data is restricted and logged. No system is perfectly secure, but we protect your information using industry-standard safeguards.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights. Where we process data on behalf of an agency, we will refer such requests to that agency.

International transfers

We may process data in countries other than your own and, where required, use appropriate safeguards for those transfers.

Children

The service is intended for business use and is not directed to children.

Changes

We may update this policy from time to time. Material changes are reflected by the "Last updated" date shown above.

Contact

Questions about privacy or your data? Reach us through our contact page.