How we handle your data

Privacy Policy

How Crystade collects, uses, and protects your data.

Last Updated: July 28, 2026

Your privacy is important to us. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have - all in plain language.

By using Crystade ("Service"), you agree to the collection and use of information as described below.

1Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Display name
  • Email address

You sign in through your Google or GitHub account via Firebase Authentication. We do not collect or store passwords.

1.2 Payment Information

Payment information (credit card details, billing address) is processed and stored exclusively by our payment processor, Paddle, who acts as the Merchant-of-Record for all paid transactions. We do not have access to or store your credit card details.

We keep a local copy of subscription, transaction, and customer data synced from Paddle so we can display billing information and maintain service continuity. We also maintain team-scoped credit balances, credit transaction records, and any auto-applied discount records.

1.3 Service Data

When you use our cron jobs, monitoring, status page, and incident management services, we collect and process:

  • Cron jobs: Job settings (name, schedule, target URL, HTTP method, headers, body, timeout) and execution logs (request and response snapshots, status codes, timing details).
  • Monitors: Monitor settings (name, protocol, target, check interval, check scripts) and check logs (request and response data, timing metrics, multi-location results).
  • Incidents: Incident records (title, severity, status, reporter, timestamps) and responses.
  • Status pages: Page settings (title, slug, visibility, branding assets like favicon and banner), linked monitors, and subscriber settings.
  • Alert webhooks: Webhook channel definitions (platform, URL) and delivery logs.
  • Managed groups: Configuration state for resources managed via the Integration API.
  • Exchange Secrets: Secret metadata (creation date, linked resources). The actual secret value cannot be retrieved after creation.
  • API keys: Key metadata (name, description, permissions, expiry, revocation status). The key itself is shown only once at creation.
  • Team settings: Team name, member roles (Member, Owner), billing admin designation, and audit logs of resource changes.

1.4 Usage and Diagnostic Data

We collect standard usage data such as IP addresses, browser type, and access timestamps to operate, secure, and improve the platform.

1.5 Status Page Visitor and Subscriber Data

If you subscribe to receive notifications from a status page, we collect your email address. Email subscriptions require double opt-in confirmation. To prevent spam and abuse, we may use invisible tracking techniques and check email domains against known spam and threat lists.

Teams may also enable Google Analytics (GA4) on their status pages, which collects standard visitor data subject to Google's Privacy Policy.

1.6 Referral Data

Each user receives a unique referral code on sign-up. We collect referral relationships (who referred whom) and associated reward transactions to operate the referral program.

2How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our cron job, monitoring, status page, and incident management services
  • Execute your scheduled jobs and perform availability checks
  • Deliver alerts and notifications through your configured channels
  • Manage incidents and display status pages
  • Authenticate API requests and enforce access controls
  • Process payments, manage subscriptions, and apply credits
  • Operate the referral program
  • Communicate with you about your account, security, billing, and policy updates
  • Analyze usage patterns to improve the platform
  • Detect, prevent, and address technical issues, fraud, or security threats
  • Comply with legal obligations and enforce our terms of service

We do not use your data for advertising, and we do not sell your personal data to third parties.

3Data Sharing and Third-Party Services

We share data with the following categories of trusted service providers, solely for the purpose of providing and improving our services:

  • Firebase Authentication (Google): Handles sign-in via Google and GitHub OAuth. Subject to Google's Privacy Policy.
  • Paddle (Merchant-of-Record): Processes all paid transactions, handles checkout, invoicing, tax compliance, payment recovery, and payment method management. Acts as the reseller of the Service and handles local taxes in 40+ countries. Subject to Paddle's Privacy Policy and Paddle's Terms.
  • Cloud Infrastructure Providers (Hetzner, Google Cloud Platform, Cloudflare): Our primary data is stored and processed in the European Union using Hetzner and Google Cloud Platform (GCP) infrastructure. Cloudflare provides content delivery (CDN), DDoS protection, and SSL/TLS certificate management. A small copy of data is distributed to nodes globally outside the EU to power multi-region monitoring probes. All providers operate under data processing agreements that restrict use of your data. Subject to Hetzner's Privacy Policy and Cloudflare's Privacy Policy.
  • Monitoring and Observability Tools: Used internally for platform performance and diagnostics. Only anonymized or aggregated data is processed.
  • Google Analytics: If a team enables Google Analytics on their status page, Google collects visitor data subject to Google's Privacy Policy.

All third-party providers are contractually bound to process your data only for the purposes we specify and in accordance with applicable privacy laws.

4Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption in transit: All communications use TLS. All status page subdomains get SSL/TLS certificates.
  • Encryption at rest: Sensitive data, including secret values, is encrypted at rest.
  • Outbound request protection: All outbound connections made on your behalf (job execution, monitoring checks) are validated against a blocklist of restricted network address ranges. Redirect responses are validated the same way.
  • Secret management: Secret values are never shown again after creation. They are used for cryptographic signing of outbound requests.
  • API key security: API keys are returned only once at creation. Every request is verified for validity, permissions, and revocation status.
  • Access control: Role-based access (Member, Owner, Billing Admin) is enforced at the API level for all team resources and billing operations.
  • Subscriber protection: Subscriber management tokens are private and do not require authentication to use (e.g., for unsubscribing). Spam and suspicious email domains are blocked.

No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security. We will notify you and any applicable regulator of a breach where we are legally required to do so.

5Data Retention

Account and Team Data

  • Active accounts: Retained as long as your account is active.
  • Team data: Retained for the lifetime of the team.

Service Data

  • Cron job and monitor configurations: Retained while the resource exists in your team.
  • Execution and check logs: Retained regardless of plan; visibility is governed by your plan tier (Free: 30 days, Starter: 90 days, Standard: 365 days).
  • Incident records: Retained for the lifetime of the team (incidents cannot be deleted).
  • Status page configurations: Retained while the page exists in your team.
  • Managed group state: Retained while the group exists in your team.

Subscriber Data

Retained until the subscriber unsubscribes, the subscription expires, or the status page is removed.

Security and Audit Data

  • Exchange Secret and API key metadata: Retained while the resource exists, or for audit purposes after revocation or expiry.
  • Audit logs: Retained per operational requirements.

Billing Data

  • Subscription and transaction records: Retained for the lifetime of the team and as required for billing reconciliation.
  • Credit and discount records: Retained for audit and reconciliation purposes.

Referral Data

Retained for audit and fraud prevention purposes.

When legal retention requirements conflict with our standard retention periods, legal requirements take precedence.

6Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update inaccurate or incomplete data (most account data can be updated directly via your identity provider or dashboard).
  • Deletion: Request deletion of your account and associated personal data.
  • Portability: Request an export of your configurations, definitions, and execution data in a structured format.
  • Objection / Restriction: Object to or request restriction of certain processing activities where permitted by law.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law.

Upon receiving a verified deletion request, we will:

  • Delete your personal data from our active systems within 30 days
  • Remove your data from backup systems within 90 days
  • Notify relevant service providers to delete your data
  • Provide confirmation once deletion is complete

Note: Certain data (e.g., billing and transaction records, incident history, referral records) may be retained to comply with legal obligations even following a deletion request.

7International Data Transfers

Your personal data is primarily stored and processed in the European Union using Hetzner and Google Cloud Platform infrastructure. However, to provide multi-location monitoring from regions around the world, a small copy of data is distributed to nodes globally outside the EU.

Where we transfer personal data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.

8Children's Privacy

Our services are not directed to individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.

9Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. If we make material changes, we will notify you via email or a prominent notice on the platform at least 14 days before the changes take effect (except where required by law, in which case notice will be given as soon as practicable). Your continued use of the Service after changes take effect constitutes acceptance.

10Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

[email protected]

Get in touch

We'd love to hear from you

Have questions about Crystade, want to share feedback, or need help getting started? Reach out - we're happy to help.

Contact support

Have questions or need assistance? Reach out to us.

[email protected]

Email Support