Privacy Notice

Effective 5 August 2026 · Drafted for compliance with the Digital Personal Data Protection Act, 2023 (India)

1. Who we are

StatusMirror (“we”, “us”) monitors the status of third-party services (Stripe, Slack, AWS, GCP, GitHub and others) and alerts your team when they go down. For the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), StatusMirror is the Data Fiduciary and you are the Data Principal. If you are located in the European Economic Area or the United Kingdom, the EU GDPR / UK GDPR also apply to our processing of your personal data; the rights and protections described in this notice are available to you under applicable law.

Contact / Grievance Officer: support@statusmirror.com. We aim to respond to requests within 7 working days and to resolve them within 30 days — this is an internal service commitment we hold ourselves to.

2. What personal data we collect

Account data: your email address (used for one-time-passcode sign-in — we never store passwords) and the workspace/organization name you choose.

Configuration data: which providers you monitor and the email addresses you nominate to receive outage alerts.

Billing metadata: if you subscribe to a paid plan, Razorpay processes your payment. We never see or store your card or bank details — we store only customer and subscription identifiers.

Technical data: standard server logs and error reports (Sentry) used to keep the service working and to debug failures. We do not currently run product analytics; if we introduce an analytics provider we will update this notice and obtain consent where required before doing so.

3. Why we process it (purpose limitation)

To authenticate you (consent — Section 6, DPDP Act): sending the sign-in code to your email is the core of how login works.

To deliver the service you signed up for (legitimate use — Section 7(a)): monitoring your selected providers and emailing outage alerts to addresses you configured.

To bill paid subscriptions, secure the service against abuse, and debug failures.

We do not sell personal data, do not use it for behavioural advertising, and do not process it for any purpose beyond those listed here.

4. Your rights under the DPDP Act

Right to access (Section 11): ask us for a summary of the personal data we hold about you and how it has been processed.

Right to correction and erasure (Section 12): ask us to correct inaccurate data or delete your account and all associated personal data. Erasure requests are completed within 30 days of verification. Erasure is executed through our deletion pipeline, which removes your user record, sessions, organization, monitoring configuration, and alert logs. To request erasure, email support@statusmirror.com from your registered email address.

Right to grievance redressal (Section 13): if you are unhappy with our response, escalate to our Grievance Officer (contact above). If still unresolved, you may complain to the Data Protection Board of India.

Right to nominate (Section 14): you may nominate another individual to exercise these rights on your behalf in case of death or incapacity.

To exercise any right, email support@statusmirror.com from your registered email address with the subject “DPDP request”.

5. Consent and withdrawal

By creating an account you consent to the processing described in this notice. You may withdraw consent at any time by requesting account deletion — withdrawal is as easy as giving consent (Section 6(4)). After withdrawal we stop processing your data except where retention is required by law.

6. Where your data goes (processors & cross-border transfer)

We use vetted Data Processors under contract: Convex (database & backend, USA), Vercel (hosting/CDN, USA), Resend (transactional email, USA), Razorpay (payments, India), and Sentry (error monitoring, USA/EU). A current list of processors and subprocessors is available on request.

Personal data may therefore be stored outside India. Section 16 of the DPDP Act permits such transfers except to countries restricted by the Central Government; we will comply with any future restriction notifications. Where the GDPR applies to you, we will ensure transfers outside the EEA/UK are made using a valid transfer mechanism (such as standard contractual clauses) with our processors.

7. Security safeguards

Reasonable security safeguards (Section 8(5)) include: TLS encryption in transit, encrypted storage at rest by our processors, cryptographically signed RS256 session tokens, hashed one-time codes (never stored in plaintext), rate-limited sign-in attempts, webhook signature verification, and a strict Content-Security-Policy on every request.

Session tokens are kept only in your browser — in local storage when you choose “Keep me signed in”, and otherwise only in memory for the current session; they are never readable by other websites.

Our Privacy Mode feature additionally masks sensitive values on screen (API keys, emails, URLs, metrics) and can be toggled from the app; on mobile it is on by default.

8. Breach notification

In the event of a personal data breach we will notify the Data Protection Board of India and each affected Data Principal as required by Section 8(6) of the DPDP Act and the DPDP Rules, without unreasonable delay. Where the GDPR applies to affected individuals, we will also notify the relevant supervisory authority and individuals as required.

9. Retention

Account and configuration data is kept while your account is active and deleted within 30 days of a verified erasure request. Alert delivery logs are retained for debugging and deduplication; we intend to purge them after 90 days (an automated purge job is pending implementation). Aggregated, non-personal status history (which provider was up or down) contains no personal data and may be retained indefinitely.

10. Children

StatusMirror is a business tool and is not directed at persons under 18. We do not knowingly process children's personal data (Section 9).

11. Changes

We will update this notice when our practices change and note the effective date below. Material changes will be announced by email to registered users.

Questions or requests: support@statusmirror.com · Terms of Service
Privacy Notice — StatusMirror | StatusMirror