1. Who is responsible for your data
This website and service are operated as an independent project by Nbal Jabr, a private individual based in Sweden. I am the data controller responsible for the personal data processed through upwhisper.com. For questions about this privacy policy or to exercise your data protection rights, contact us at contact page.
2. What we collect
Account data: your name, email address, and password (stored as a salted hash, never in plain text) when you sign up, plus your role and company/account membership.
Billing data: if you're on a paid plan, Stripe processes and stores your payment details on our behalf - we never see or store your full card number ourselves, only the subscription status and billing history Stripe returns to us.
Domain and monitoring data: the hostnames you add for monitoring, and the check results we collect for them (SSL, DNS, registration, email-security, and HTTP data) - this is customer content you control, not personal data about you specifically, unless a hostname itself happens to identify a person.
Technical and abuse-prevention data: Vercel processes request logs as our hosting provider. The application also stores short-lived rate-limit records keyed by data such as an email address, user, account, domain, or source IP, depending on the action being protected. We use Vercel Analytics for aggregate page-view data (see “Cookies and analytics” below).
Communications: anything you send us via the contact form or email support, including the content of your message.
3. Why we process it, and our legal basis
To provide the Service you've signed up for (running checks, sending alert emails, billing your subscription) - necessary to perform our contract with you (GDPR Art. 6(1)(b)).
To keep the Service secure (rate-limiting, abuse and fraud prevention) and to improve it - our legitimate interest (Art. 6(1)(f)), balanced against your rights.
To comply with legal obligations, such as retaining billing records for tax purposes (Art. 6(1)(c)).
Where we ever ask for it separately (for example, optional marketing communications), your consent (Art. 6(1)(a)), which you can withdraw at any time.
5. How long we keep it
Account data: while the account is active and afterward only as needed to handle a deletion request, resolve disputes, or meet legal obligations. Contact us to request account deletion; self-service account deletion is not currently available.
Domain data: until you delete the domain or request account deletion. Deleting a domain also deletes its associated check history.
Full check results: automatically expire after 90 days, even while a domain remains monitored.
Password-reset links expire after one hour and email-confirmation links after 24 hours. Their token records are removed shortly after expiry.
Application rate-limit records expire after one hour. Hosting, email, analytics, and billing providers apply their own retention periods.
Billing records: for as long as needed to administer subscriptions and meet applicable accounting or legal obligations.
6. Your rights under the GDPR
You have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure (“right to be forgotten”), request that we restrict or object to certain processing, and request a portable copy of your data in a structured, machine-readable format.
Where processing is based on consent, you can withdraw it at any time without affecting processing carried out before the withdrawal.
To exercise any of these rights, reach us through our contact page. We'll respond within one month, as required by the GDPR.
If you're not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the data protection authority in your own EU/EEA country of residence.
8. Security
Passwords are hashed, never stored in plain text. Authentication cookies use security attributes including httpOnly, and sensitive two-factor secrets are encrypted at rest. We rate-limit sensitive and expensive actions, and monitoring targets are screened to reject private or internal addresses identified before connection.
No system is perfectly secure, but we design and review the Service with these protections as a baseline, not an afterthought.
9. Children's privacy
The Service is intended for business use and isn't directed at children. We don't knowingly collect personal data from anyone under 16.
10. Changes to this policy
We'll update this page and its effective date if how we handle personal data changes.
11. Contact
Questions about this policy or your data? Reach us through our contact page.