Website Visitor? If you're here because you visited a website using VitalSentinel tracking, please see Section 5: Information for Website Visitors for information specifically about your data.
1. Introduction
mountain explorer, s. r. o. ("we", "us", or "our") operates the VitalSentinel website, application, and tracking scripts (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service.
This policy covers two types of data subjects:
- VitalSentinel Users: Individuals who create accounts and use our dashboard
- Website Visitors: End-users who visit websites that use our tracking scripts
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and other applicable data protection laws.
2. Data Controller Information
mountain explorer, s. r. o.
Karpatske namestie 7770/10A
83106 Bratislava
Slovakia (European Union)
Company ID: 53226119
VAT ID: SK2121306704
Email: privacy@vitalsentinel.com
3. Data Collection from VitalSentinel Users
3.1 Account Information
When you create an account, we collect:
- Email address (required)
- Password (stored securely encrypted)
- First name and last name (optional)
- Account creation and last login timestamps
- Email verification status
3.2 Authentication and Security Data
- Two-factor authentication (2FA) configuration
- Trusted device information (device name, browser, OS, location)
- Session data
- Login history
3.3 Workspace and Team Data
- Workspace names and settings
- Team member email addresses and roles
- Invitation records
3.4 Domain Configuration
- Website URLs you choose to monitor
- Alert rules and notification preferences
- Integration credentials (Google OAuth tokens for Google Search Console access)
3.5 Billing Information
- Stripe customer and subscription IDs
- Billing cycle and subscription status
- Payment history (processed by Stripe; we do not store full card details)
3.6 Support Communications
- Support ticket messages and attachments
- Feedback and feature requests
3.7 Consultation Services Data
If you use our consultation or expert services, we may additionally collect:
- Consultation scheduling data (via Google Calendar integration)
- Meeting notes and action items
- Project requirements and specifications
- Communication history related to consultations
3.8 Audit and Security Logs
For security and compliance purposes, we automatically log:
- Account changes and settings modifications
- Login attempts (successful and failed)
- API access and usage
- Data export requests
- Administrative actions within workspaces
4. Data Collection from Website Visitors (Via Tracking Scripts)
When VitalSentinel users install our tracking scripts on their websites, we collect data from their website visitors on their behalf. The website operator is the Data Controller for this data, and we act as the Data Processor.
4.1 Real User Monitoring (RUM) Script
The RUM script collects:
- Performance Metrics: Core Web Vitals (LCP, FCP, CLS, INP, TTFB), Long Animation Frames, resource timing
- Device Information: Browser window size. Where the website operator has enabled a storage level that requires consent, the script additionally reads screen dimensions, device capabilities, and timezone
- Browser Information: Browser type and version, and operating system
- Network Information: Connection type (4G, 3G, WiFi), effective bandwidth, round-trip time
- Navigation Data: Page URLs, referrer information, SPA route changes
- Error Data: JavaScript errors, unhandled promise rejections, and resource loading errors, with detected personal data patterns redacted
- Engagement Data (enabled by default, can be disabled): Scroll depth, click interactions, rage clicks (repeated rapid clicks), time on page and active time, and first-interaction and page-exit signals
- Element Context: Which element on the page an LCP, CLS, or INP measurement relates to, including a short extract of its visible text
- Form Interaction Signals: Which form fields were interacted with, how long a form took to complete, and whether it was submitted or abandoned. We never collect the values typed into form fields.
- Geographic Location: Country derived from IP address
- IP Address Handling: IP addresses are processed in memory to determine the visitor's country and to detect automated traffic, then discarded. They are not written to our analytics databases
- Session Identifier: Temporary session ID for grouping the pages of a single visit (not persistent across sessions)
The RUM script may collect additional technical data beyond what is listed above to ensure proper functionality. Data is encrypted in transit using TLS and encrypted at rest. Visitor data is pseudonymous, not anonymous: it is not anonymous data under the GDPR, and this policy applies to it in full.
4.2 Web Analytics Script
The Analytics script collects:
- Pageview Data: Page URLs, titles, and referrer sources
- Event Tracking: Custom events defined by the website operator
- User Identification: An optional user ID, where the website operator supplies one
- Session and Visitor Identifiers: Pseudonymous identifiers grouping the pages of one visit, and repeat visits
- Attribution Data: UTM parameters, referrer, and first-touch source
- Search Tracking: On-site search terms, read from the page address rather than from the search box itself
- Outbound Links: Clicks to external websites
- Ecommerce Data: Product views and purchases (for supported platforms like Shopify, WooCommerce, Magento, and Squarespace)
- Device and Browser Information: Device type, browser, and operating system. Where the website operator has enabled a storage level that requires consent, the script additionally reads screen and window dimensions and the browser language
- Language: The primary language your browser reports, for example
en-US - Network Information: Connection type, effective bandwidth, and round-trip time. Collected only where the website operator has enabled a storage level that requires consent
- Geographic Location: Country, derived from IP address
- IP Address Handling: IP addresses are processed in memory to determine the visitor's country, to detect automated traffic, and as one input to a pseudonymous visitor identifier, then discarded. They are not written to our analytics databases, and they are not used to build any long-term record of a visitor
- Engagement Data: Scroll depth, time on page, active time, and rage clicks, including which element was clicked. Not collected for visitors sending a Do Not Track or Global Privacy Control signal
The Analytics script may collect additional data beyond what is listed above depending on website configuration. Data is encrypted in transit using TLS and encrypted at rest. Visitor data is pseudonymous, not anonymous: it is not anonymous data under the GDPR, and this policy applies to it in full.
4.3 Privacy Controls for Tracking Scripts
Our scripts include privacy-friendly features:
- Sampling Rate: The RUM script can be configured to collect data from only a percentage of visitors
- Automatic Redaction: Detected email addresses, payment card numbers, phone numbers, national ID numbers, and authentication tokens are redacted from error messages and URLs before they leave the browser
- Query Parameter Redaction: Values of URL parameters with sensitive names are replaced before transmission, and personal data patterns are redacted from the remaining parameter values
- Do Not Track and Global Privacy Control: Both our Web Analytics and RUM scripts read the browser's Do Not Track and Global Privacy Control signals in order to honor them. When either signal is present, we still record the page view, but the visitor is given no server-side identity and no engagement measurement runs for them – no scroll depth, active time, engagement score, or rage clicks. A signal sent by the browser overrides a consent grant made by the website operator's consent tool.
- Withdrawing consent: A website operator's consent tool can drop both scripts back to the default storage level at any time, and our Web Analytics script then clears what it stored on the device. Withdrawal applies from that point onward: measurements already collected are still transmitted, so a batch sent just after a withdrawal can still contain data gathered before it.
- Bot Detection: Excludes known bots and crawlers from tracking
- No Cookies or Storage in RUM: The RUM script sets no cookies and writes nothing to local or session storage, at any storage level
What our scripts read from your device in the default mode
In the default mode nothing is stored on, or read from, your device's storage – no cookie, no local storage, no session storage, no IndexedDB. Beyond the window size used to measure Core Web Vitals, the only things our scripts read from the browser are whether it reports itself as automated, so we can filter out bots, and whether you have set a Do Not Track or Global Privacy Control preference, so that it can be honored. Neither value is transmitted.
In the "session" and "persistent" storage levels, which the website operator must obtain consent for, our Web Analytics script reads and sends further device characteristics. Our RUM script stores nothing on your device at any level.
4.4 Synthetic Monitoring
Our synthetic monitoring service uses automated bots to test website performance from various locations. These bots:
- May capture screenshots of monitored pages for performance analysis
- Do not interact with or submit forms on monitored websites
- Do not consult a site's robots.txt Disallow rules before fetching it
The default synthetic monitoring location runs on Google's PageSpeed Insights infrastructure, so those page loads reach the monitored site from Google and carry Google's user agent rather than ours. Our scheduled monitoring services identify themselves with a user agent containing "VitalSentinel". The exact strings, what each service does, and how to stop its traffic are published at vitalsentinel.com/bot.
Screenshots captured during synthetic monitoring are stored securely and are only accessible to the domain owner within their VitalSentinel dashboard.
5. Information for Website Visitors
If you are visiting a website that uses VitalSentinel tracking scripts, this section is for you.
VitalSentinel provides performance monitoring tools to website operators. When you visit a website using our scripts, certain data about your visit may be collected to help the website owner understand and improve their site's performance.
What data may be collected:
- Page loading speed and performance metrics
- Device type (desktop, mobile, tablet) and screen size
- Browser type and operating system
- Network connection type (WiFi, 4G, etc.)
- Pages you visit and how you navigate the site
- General geographic location (country, derived from IP)
- JavaScript errors encountered during your visit
- Search terms from the page address when you use a site's search, so the website owner can see what visitors are looking for
- How you interact with the page, including scroll depth, clicks, repeated rapid clicks, and which form fields you interacted with – never what you typed into them
- On ecommerce sites, which products you viewed and the value of orders you completed
What we do NOT collect:
- Your name, email address, or contact details – we never ask for them
- Passwords or payment card details
- Your precise location or home address
- The values you type into form fields. Site search terms are read from the page address, not from the search box itself.
One important qualification. Our scripts do not read what you type into form fields, but what the website itself puts into its page addresses, its page titles, and the events it sends us reaches us as sent – and that can include personal data the site chose to put there, including something you typed. We replace recognizable patterns with placeholders as the data is collected: email addresses, payment card numbers, national ID numbers, authentication tokens, and long digit runs. That is pattern matching, not understanding. An ordinary name, a case reference, or a short order number in a page title or a web address is not recognized as personal, and it is stored. The website operator controls what their addresses, titles, and events contain.
Your choices:
- Both our scripts honor the "Do Not Track" (DNT) and "Global Privacy Control" (GPC) settings in your browser, and a signal from your browser overrides a consent choice recorded by the website's consent tool
- In its default mode, our Web Analytics script stores nothing on your device, and our RUM script stores nothing on your device in any mode
- To exercise your data rights, contact the website operator directly – they are the Data Controller for your data
- You can also contact us at privacy@vitalsentinel.com with questions about our data processing practices
- Opt-out: Enabling Do Not Track or Global Privacy Control in your browser stops us resolving any visitor or session identity for you on our servers, and stops all engagement measurement in both our scripts – how far you scrolled, how long you were active, where you clicked, and which form fields you interacted with. Your page view is still counted, and page performance data for that visit is still collected. To stop collection entirely on a particular website, contact that website's operator
Data Controller vs. Data Processor:
The website you visited is the Data Controller and decides what data to collect and why. VitalSentinel acts as a Data Processor, processing this data on their behalf according to their instructions.
6. Automatically Collected Information (Our Website)
When you access our website or dashboard, we automatically collect:
- Log Data: IP address, access times, pages viewed, referring URL
- Device Information: Browser type, operating system, device type
- Usage Data: Features used, actions taken within the dashboard
6.1 Free Tools
The free tools at vitalsentinel.com/tools need no account and no sign-in. When you run one, we record:
- Which tool ran, and when
- The hostname you entered, for example example.com. The path, the query string and any fragment are discarded before anything is written
- The country your request came from, as a two-letter code
- Whether the run succeeded, and how long it took
- A small number of figures describing the shape of the answer, such as how many redirects were followed or which letter grade a site scored. These are counts and our own classifications rather than content copied from the site you checked. The one value drawn from the page itself is in our schema validator, which records which schema.org types a page declared, and only those types that appear in the fixed list our rules cover
What we do not record, for every tool except the Inspector: the results of the check, the full URL, the content of any page, header or cookie we read, and your IP address. Because none of that is stored, this data cannot be used to contact you, to build a profile of you, or for personalized or targeted advertising, and there is nothing in this record to link one run to another. The Inspector page audit is the one exception, and it is deliberate rather than incidental: a report you can open and share is the whole point of it, so it stores the full address and the report. Section 6.2 sets out exactly what that means. It records no IP address either.
How the rate limits are counted: enforcing the published limits means telling one caller from another without knowing who they are. When a request arrives we take the IP address it came from, combine it with a secret value we hold, hash the result with SHA-256 and keep the first half of that hash. If the address is IPv6 we shorten it to its /64 network prefix before hashing – the smallest block an internet provider assigns to a single subscriber – so the value we count against is that network rather than your individual address; an IPv4 address is hashed whole. The secret is not optional: if it is ever unavailable to us, the tool declines to run rather than count you under a value anyone could reproduce. That hash, never the IP address itself, becomes the name of a counter held in Cloudflare KV whose contents are a number of runs, and Cloudflare's own rate limiting is keyed on the same value. An hourly counter expires about an hour after it is created and a daily counter shortly after midnight UTC, so within a single day the runs of one caller do count against one counter, and once it expires there is nothing left to count them with. A counter holds nothing about what was checked, and it is not part of the usage records above.
Why we collect it: to know how much each tool is used and whether it is working, to detect abuse of the tools and enforce the published rate limits, to decide which tools to keep building, and to produce aggregate research and marketing material such as industry benchmarks, for example "38% of the sites checked with our HSTS validator had no preload directive". Published figures are always aggregated across many sites and never name an individual domain that was checked. Our legal basis is legitimate interest under Article 6(1)(f) of the GDPR.
How long: 180 days, after which every record is deleted automatically by a scheduled job. Separately from that record, the result of a successful check is held in Cloudflare's edge cache for between five minutes and an hour depending on the tool, so that the same check repeated shortly afterwards does not hit the site again. What is held there is the complete report the tool produced, which for the Raw vs Rendered HTML and Cookie & Tracker Scanner checks includes the cookie and tracker names found and the differences between the served and the rendered page. That copy is stored under a hash rather than under the address you entered, and it is keyed on what was checked rather than on who checked it, so the same check run by anyone else inside that window is answered from it. It expires on its own and is not part of the usage records above. One supporting lookup is held longer: a domain's status on the public HSTS preload list is cached for up to a day, and that status is public information about the domain rather than anything about you.
Every tool runs on our servers rather than in your browser. When you start a check we request the address you entered from our own infrastructure, identifying ourselves with our published bot user agent, so the site being checked sees a request from us rather than from you and never receives your IP address.
6.2 The Inspector Page Audit
The Inspector at vitalsentinel.com/tools/inspector is the only free tool that stores its result, because a report you can open later and send to someone else is what it is for. Everything in Section 6.1 still applies to it, with the additions below.
What we store: the full address you entered, including its path and query string; the device you chose; the report itself, which holds every measurement and finding from the run; a final capture of the page as it rendered; and the filmstrip frames recorded while it loaded. Alongside them we keep the time of the run, whether it succeeded, how long it took, the score and grade, the number of issues found, and the country the request came from as a two-letter code. We store no IP address, no email address and no value that links one audit to another.
How long, and who can see it: 30 days, after which the report, the capture and the filmstrip are all deleted automatically. The report is reachable only at its own link, whose identifier is 128 bits of randomness, so it is neither sequential nor guessable. That link is the only access control. Anyone who has it can open the report, so treat it the way you would treat any unlisted link, and do not paste it anywhere you would not paste the report itself. We publish no index of reports, report pages carry a noindex instruction and are excluded in our robots.txt, and nothing is gated: no account, no sign-in and no email address is asked for at any point.
Where it is stored: the report, the capture and the filmstrip are held in a Cloudflare R2 bucket created in the EU jurisdiction, which pins those objects to storage in the European Union. We want to be exact about what that covers and what it does not, because the shorter version would be false: the Worker that runs the audit and generates them executes at whichever Cloudflare location is nearest to whoever started it, which may be outside the EU, and the Lighthouse half of the run is performed by Google PageSpeed Insights on Google's own infrastructure, which receives the address being audited. So the stored artifacts are in the EU; the processing that produces them is not confined to it.
Why we may do this: our legitimate interest under Article 6(1)(f) of the GDPR in providing a free audit whose result the person who ran it can read, revisit and share. What we hold is material the audited site served publicly to an anonymous visitor at the moment of the audit.
Getting a report removed: if a page you own or operate appears in a report, email privacy@vitalsentinel.com with the report link, or with the address and the approximate date if you do not have it. The response window and what we can and cannot do are set out in Section 3.2 of our Terms and Conditions.
7. How We Use Your Information
We use the collected information to:
- Provide, operate, and maintain the Service
- Create and manage your account
- Process monitoring data and generate reports
- Send alerts and notifications based on your configured rules
- Process payments and manage subscriptions
- Respond to support inquiries
- Send administrative communications (security alerts, service updates)
- Analyze usage patterns to improve the Service
- Detect, prevent, and address security issues
- Comply with legal obligations
Aggregate Statistics for Research and Improvement
We may compute aggregate statistics across accounts, workspaces, and domains for:
- Improving our algorithms, models, and service quality
- Conducting research and analyses on web performance trends
- Creating industry benchmarks, statistics, and reports, including figures derived from the free-tool usage records in Section 6.1
- Training and improving AI-powered features (excluding data obtained from Google APIs, as detailed in Section 10)
- Developing new features and services
These are group-level figures. They are computed so that no individual user, website visitor, account, or domain is identified in the output. This applies to the account and service usage data for which we are the Data Controller. It does not extend to the personal data we process from your website visitors on your behalf: for that data we act only on your instructions as your Data Processor, as set out in Section 14.1 of our Terms and Conditions, and we do not use it for our own purposes.
8. Legal Basis for Processing (GDPR)
Under the GDPR, we process personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide the Service you requested
- Legitimate Interests: Improving our Service, security, fraud prevention, analytics, and the free-tool usage records in Section 6.1, which carry no identifier and are used to measure usage, prevent abuse and produce aggregate research, and the free-tool rate-limit counters in Section 6.1, which are pseudonymous, keyed on a salted and truncated hash rather than on the IP address itself, and expire within about a day
- Consent: For optional features, and for the newsletter where you subscribe to it
- Soft opt-in (ePrivacy Article 13(2)): For the onboarding and product emails described in Section 18.3, which are switched on when you create an account and can be stopped from any message or from your settings
- Legal Obligation: Compliance with applicable laws and regulations
For data collected via tracking scripts from website visitors, we process data as a Data Processor on behalf of our customers (the Data Controllers).
Data Processing Agreement (DPA): Section 14.1 of our Terms and Conditions is our Data Processing Agreement. It meets the requirements of Article 28(3) of the GDPR, applies to every customer on every plan, and takes effect when you accept the Terms, so no separate signature is needed. A countersigned standalone data processing agreement is available on Enterprise and custom plans only; request one at privacy@vitalsentinel.com.
9. Data Sharing and Sub-processors
We use the third-party providers below to deliver the Service. The full list, including what each one receives and whose data it is, is published and dated at vitalsentinel.com/subprocessors. We give at least 30 days' notice before adding or replacing a sub-processor, as described there and in Section 14.1 of our Terms and Conditions.
How that notice applies to the free tools. Four providers arrived with the free tools at vitalsentinel.com/tools: Cloudflare's Browser Rendering service, Cloudflare's public DNS resolver, hstspreload.org, and the domain registration lookup services (RDAP) published for each top-level domain. They are listed below and on the sub-processors page. None of them receives anything from your account or from the websites you monitor. Each receives only the address or hostname someone typed into a free tool: the full address for the three checks that load a page in a real browser, the hostname for the AI agent readiness lookup, the bare domain for the HSTS preload check, and the bare domain for the Inspector's registration lookup, which goes to the RDAP service IANA's bootstrap registry publishes for that top-level domain, so the recipient depends on the domain being audited and domains on a top-level domain with no RDAP service reach no registry at all. They therefore do not process customer data on our behalf, and the 30 days' notice above applies to sub-processors that do. That notice, and the right to object that goes with it, apply unchanged to every future addition.
9.1 Infrastructure and Hosting
- Contabo (Germany, EU) – Server hosting and infrastructure. Everything we store runs on these servers
- Cloudflare – Content delivery, object storage, and the hosting of this marketing website and the free tools on it. Our tracking script files are served through Cloudflare, so it sees the IP address of every visitor who downloads one. The measurements themselves are sent from the visitor's browser directly to our own servers and do not pass through Cloudflare. Cloudflare R2 also holds page screenshots and support ticket attachments, and Cloudflare D1 holds the free-tool usage records described in Section 6.1. Because the free tools run on Cloudflare Workers, Cloudflare also sees the IP address of everyone who uses them; Cloudflare KV holds the rate-limit counters described in Section 6.1; Cloudflare's Browser Rendering service loads the page for the three checks that need a real browser, so it receives the full address entered into them; a second R2 bucket, created in the EU jurisdiction, holds the Inspector reports and page images described in Section 6.2; and our agent readiness check looks up the hostname being checked through Cloudflare's public DNS resolver
- Bird.com (MessageBird) – Email delivery. Receives your email address and the full content of every message we send you. Our login notification email additionally contains the IP address and device description of the sign-in it is telling you about
9.2 Payment Processing
- Stripe – Payment processing, subscription management, and billing. Card details are entered directly with Stripe and never reach our servers
9.3 Analytics and Integrations
- Google – Google Search Console, CrUX, and PageSpeed Insights. Receives your Google account email, the property and page URLs you authorize us to read, and the parameters of the reports we request. The two free CrUX tools described in Section 6.1 also send Google the address entered into them, and any competitor addresses entered alongside it, with no account and no sign-in involved. The Inspector described in Section 6.2 sends Google the address being audited twice over, once to CrUX for field data and once to PageSpeed Insights, which runs the Lighthouse half of the audit on Google's own infrastructure. In both cases Google receives an address and nothing else about you
- Google Calendar – Consultation scheduling. Listed separately because it is the only provider that receives data about people who are not our users: when you book a consultation and add attendees, Google receives their names and email addresses and sends each of them the invitation on our instruction
- Cloudflare Turnstile – Protects sign-up, sign-in, and password reset from automated abuse, and the three free tools that load a page in a real browser: the Inspector, Raw vs Rendered HTML and the Cookie & Tracker Scanner. Receives the IP address of the person signing in, signing up, or running one of those three checks. On those three tool pages the widget is loaded into your browser from challenges.cloudflare.com, so that request reaches Cloudflare whether or not you go on to run the check
- Ahrefs – Web analytics for our marketing website only. Not used in the application, and it receives nothing about your monitored websites
- hstspreload.org – The HSTS preload list service run by the Chromium project. Our free HSTS validator asks it whether the domain being checked is on the list, so it receives that domain. It receives nothing about you and nothing about your account
- TLD registration lookup services (RDAP) – The registration databases run by domain registries. The Inspector asks the RDAP service that IANA's bootstrap registry publishes for the top-level domain being audited, for example rdap.verisign.com for .com, so it receives only that domain. Which registry answers depends on the top-level domain, and a top-level domain with no RDAP service is not queried at all. The registry receives nothing about you and nothing about your account
9.4 Geolocation Services
- MaxMind – IP-to-location database. We send no data to MaxMind. We download their database and perform country lookups on our own servers
9.5 Assistants and Applications You Connect Yourself
Our REST API and our MCP server let you connect an AI assistant, such as Claude or ChatGPT, or software of your own, to the data in your account. When you do, we send that data to the provider you chose, because you asked us to. From that point it is held by them under your agreement with them, and this Privacy Policy no longer governs it.
These providers are not our sub-processors. We do not choose them, and nothing reaches them until you connect one yourself. The 30 days' notice described at the top of this section covers sub-processors we engage to run the Service; it does not apply here, because the choice is yours rather than ours. If the data concerns your website's visitors, you are the one instructing the transfer, and Section 9 of our Data Processing Agreement sets out what that means for you.
What can leave this way is aggregated and configuration data: your Core Web Vitals and performance results, uptime and certificate status, search traffic and queries, indexing, robots.txt and sitemap status, analytics and ecommerce totals, audit results, alerts, and reports. Individual visitor records cannot. No API or MCP permission reaches session-level visitor data, and real-user monitoring results are redacted before they are returned. No permission grants a whole category of access at once, and none can create or delete a workspace or a domain, or touch a connected Google account.
We keep one record of each API and MCP request for 90 days: when it happened, which workspace it concerned, which credential made it, which route was called, whether it succeeded, and how many rows it returned. The route is recorded as a template rather than as the address actually requested, and we store no request bodies, no query strings, no IP addresses, and no user agents. This record exists so that you can answer a visitor who asks who received their data, which Article 15(1)(c) of the GDPR entitles them to know.
You choose which workspaces a connection may reach when you approve it, a connection can never do more than your own role in that workspace allows, that role is rechecked on every request, and you can revoke a connection at any time in the application under Settings, then Connected apps.
We may also share information when:
- Required by law, regulation, or legal process
- Necessary to protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of assets (with notice)
We do not sell personal information to third parties.
10. Google API Services User Data Policy
VitalSentinel's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10.1 Google Data We Access
When you connect your Google account, we may access:
- Google Search Console: Search performance data, indexing status, and search queries for your verified properties
- PageSpeed Insights API: Performance scores and recommendations for your URLs
- Chrome UX Report (CrUX): Real-world performance metrics from Chrome users
10.2 How We Use Google Data
We use data obtained from Google APIs solely to:
- Display your website analytics and search performance in your VitalSentinel dashboard
- Generate performance reports and alerts based on your configured thresholds
- Provide insights and recommendations to improve your website performance
- Correlate Google data with our own monitoring data to give you a complete picture
10.3 Google Data Protection and Prohibited Uses
We protect your Google data with the following measures:
- Google OAuth tokens are stored securely encrypted and are only used to fetch data on your behalf
- Access to Google data is limited to the minimum necessary to provide the Service
- We use encryption to protect your information during transmission and storage
- Security procedures are in place to protect the confidentiality of your data
We do NOT use Google user data for any of the following purposes:
- Selling to third parties, data brokers, or information resellers
- Targeted, personalized, retargeted, or interest-based advertising
- Determining creditworthiness or for lending purposes
- Training artificial intelligence (AI) or machine learning (ML) models
- Building user profiles for advertising purposes
- Any purpose other than providing or improving VitalSentinel's user-facing features
We do not transfer or disclose your Google user data to third parties except as necessary to provide and improve VitalSentinel's functionality (such as secure cloud hosting infrastructure).
10.4 Google Data Retention and Deletion
Google data is cached temporarily to improve performance and reduce API calls. You can revoke VitalSentinel's access to your Google data at any time by:
- Disconnecting the integration from your VitalSentinel dashboard settings
- Removing VitalSentinel from your Google Account's connected apps at myaccount.google.com/permissions
When you disconnect Google integrations or delete your account, all cached Google data is deleted within 30 days.
11. International Data Transfers
Your information may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards including:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with adequate data protection laws
- Other legally recognized transfer mechanisms
Our primary infrastructure is hosted in Germany (EU) via Contabo.
12. Data Retention
We retain data for different periods depending on the type:
- Account Data: Retained while your account is active and for 30 days after a deletion request
- RUM and Analytics Data: Retained according to your subscription plan (between 6 and 24 months depending on your plan)
- Audit Logs: Routine operational records are retained for 30 days. Records that evidence a privacy obligation – a data subject lookup or erasure, an account, workspace, or domain deletion, and similar actions – are retained for six years, because Article 5(2) of the GDPR requires us to be able to demonstrate that we carried them out. These records never store a visitor identifier itself
- API and MCP Request Records: One record of each request to our public API or MCP server, retained for 90 days. It stores no request bodies, no query strings, no IP addresses and no user agents, and records the route as a template rather than the address actually requested. Section 9.5 describes what it is for
- Support Communications: Retained for up to 3 years after resolution
- Billing Records: Retained as required by tax and accounting laws (typically 7-10 years)
- Screenshots and Filmstrip Frames (synthetic monitoring): Retained for up to 90 days
- In-app Notifications: Retained for up to 90 days
- Free Tool Usage Records (Section 6.1): Retained for 180 days, then deleted automatically. These records contain no account, no visitor identifier and no IP address. The rate-limit counters and the cached results described in Section 6.1 are held apart from these records and expire on their own: a counter within a day of being created, a cached result within an hour, and the one supporting lookup that is cached for longer, a domain's public HSTS preload status, within a day
Upon account deletion, we will delete or anonymize your data within 30 days, except where retention is required by law.
Legal Hold: Notwithstanding the above retention periods, we may retain data for longer periods if required by law, legal proceedings, regulatory investigations, or to preserve evidence in connection with actual or anticipated disputes.
13. Cookies and Tracking Technologies
A full, itemized account of what this website stores in your browser, what our tracking scripts store on a customer's website, and how to change or withdraw your choice is published at vitalsentinel.com/cookie-policy. The summary follows.
13.1 Essential Cookies
- Authentication: Secure cookies to keep you logged in to the application at app.vitalsentinel.com
- Security: Cookies to protect against unauthorized actions
These apply to the application. We set no cookies on this marketing website: what it stores, it stores in your browser's local storage. Two of our free tool pages load a Cloudflare anti-abuse challenge into your browser, and the site as a whole is served through Cloudflare's network, so code that is Cloudflare's rather than ours also runs on our pages. Whether it stores anything on your device is governed by Cloudflare, not by us; we do not read it and it is not used to measure you.
13.2 Analytics on Our Marketing Website
- Your cookie choice: When you answer our cookie banner we record your answer in local storage under
vs_cookie_consent, so we do not ask again. It is the only thing we ourselves store before you choose anything; the Cloudflare check described below loads before any choice as well, and whatever it stores is Cloudflare's doing rather than ours. - Our own analytics: We run our own RUM and Web Analytics scripts on this website. Both are first-party and, by default, store nothing in your browser. If you accept, our Web Analytics script is raised to its "persistent" level and stores a visitor identifier and related entries in local storage so we can recognize returning visitors; declining, or later withdrawing, clears them again.
- Third-party analytics: We use Ahrefs Web Analytics to understand how visitors use our marketing website.
- Verification check on two tool pages: The Raw vs Rendered HTML and Cookie & Tracker Scanner tools show a Cloudflare Turnstile challenge before they run, and its widget is loaded into your browser from challenges.cloudflare.com as soon as the page opens, whether or not you have answered our banner, so Cloudflare receives your IP address. It is not analytics, and the only thing reported back to us is whether the check passed. What the widget itself stores on your device is Cloudflare's and outside our control, and we do not read it.
13.3 Our Tracking Scripts
The RUM script sets no cookies and writes nothing to browser storage, at any level. What the Analytics script stores depends on the storage level the website operator selects:
- "none" (the default): Nothing at all is written to or read from the visitor's device storage
- "session": A session identifier in session storage, cleared when the browser closes
- "persistent": A visitor identifier lasting 180 days, a session identifier, the first-visit timestamp, and first-touch attribution, all in local storage. Where the website operator configures a cookie domain in order to track across their subdomains, the visitor identifier is also set as a cookie with the same lifetime
The default is "none", under which the Analytics script stores nothing in the visitor's browser. We still record the page view, and we still compute an identifier on our servers so that the pages of one visit hang together. That identifier is scoped to a single website and is regenerated regularly, so it cannot link a visitor across days or across sites. Raising the level to "session" or "persistent" requires the website operator to obtain consent from their visitors first.
14. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of data processing. We handle restriction requests manually: we will suspend the processing you object to while we work through the request. We do not currently have an automated mechanism that marks an account as storage-only, so tell us specifically what you want stopped
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@vitalsentinel.com. A person reads that address. We will respond within one month of receiving your request, as required by Article 12(3) of the GDPR. If we need to verify your identity, that pauses the clock from the moment we ask until you answer – it does not delay the point at which it starts. These requests are serviced by hand rather than through a self-service tool.
What an account erasure reaches. Deleting your account also anonymizes your customer record at our payment processor rather than deleting it, because invoices are statutory accounting records we are required to keep; revokes our access to your Google account, so we no longer appear there as an authorized application; and deletes workspace invitations addressed to your email address.
For website visitors: If you visited a website using VitalSentinel tracking, please contact that website operator directly to exercise your rights, as they are the Data Controller for that data.
Visitor-level requests, and their limits. If a website operator supplies us with a specific visitor or session identifier, we can assemble or delete the records carrying it for that website. What we cannot do is work out the identifier from a person, an email address, an IP address, or a description of a visit, because it is not reconstructable after the fact. How far one identifier reaches also depends on the storage level the website operator chose: in the default cookieless mode it addresses about a day of records, in "session" mode it addresses none, and only in "persistent" mode does it reach back, up to 180 days. Aggregated report tables hold no visitor identifier at all. One consequence is worth stating plainly: if we search and find nothing, that is not proof that we hold nothing about you.
You have the right to lodge a complaint with a supervisory authority. For users in the EU, this is typically the authority in your Member State of residence. For users in the UK, this is the Information Commissioner's Office (ICO). For users in Slovakia, this is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky).
15. Automated Decision Making
We use automated analysis, including machine learning models, that may involve automated processing of your data. All of it runs on our own servers. In accordance with GDPR Article 22, we disclose the following:
15.1 How AI is Used
- Performance Analysis: Statistical and machine learning analysis of your website performance data identifies issues and suggests improvements
- Anomaly Detection: Models running on our servers detect unusual patterns in your traffic and search data that may trigger automated alerts
- Insights Generation: Our own systems generate reports and recommendations from the data collected for your account
- Content Analysis: Our own systems analyze error messages, page content, and other technical data to produce suggestions, and that analysis runs on our servers. No content is sent to an external AI provider. The only data that reaches one is what we return to an assistant you connect yourself, on your instruction, which Section 9.5 describes
15.2 Human Oversight
While automated analysis assists in data analysis and alert generation, significant decisions affecting your account (such as account suspension or termination) involve human review. You may request human review of any automated decision that significantly affects you by contacting us at privacy@vitalsentinel.com.
15.3 Your Rights
You have the right to: (1) obtain information about the logic involved in automated processing; (2) request human intervention; (3) express your point of view; and (4) contest decisions made through automated processing.
16. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: We do not sell personal information, so this right does not apply
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact us at privacy@vitalsentinel.com. We will verify your identity before processing your request.
Categories of personal information collected: Identifiers (email, name, IP address, device identifiers, and the salted hash that keys the free-tool rate-limit counters described in Section 6.1), commercial information (subscription data), internet activity (usage data), and geolocation data (country level). We list that hash because a salted, truncated hash of an IP address can still count as a probabilistic identifier, although it is pseudonymous, holds nothing but a number of runs, and expires within about a day.
17. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit, using TLS on every connection that reaches us from outside – your browser, your website, and the third-party APIs we call
- Encryption at rest
- Secure password storage
- Two-factor authentication (2FA) support
- Secure session management
- An isolated internal network with restricted access between services
- Access controls and activity logging
- Encrypted backups
One point of precision, because security claims should be testable. "Encrypted in transit" describes the connections between you and us. We do not describe the Service as end-to-end encrypted, and we do not claim that data held by us would be unintelligible to us. No method of transmission or storage is completely secure.
Breach Notification: Where we act as Data Controller and become aware of a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, in accordance with Article 33 of the GDPR, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of the GDPR. Where we act as Data Processor for a customer, we will notify that customer without undue delay after becoming aware of a breach affecting their data, and we will not notify their supervisory authority or their data subjects unless they instruct us in writing to do so. An initial notification may be incomplete while we investigate, and is not an admission of fault or liability.
18. Email Communications
We send the following types of emails:
18.1 Transactional Emails (Required)
- Account verification and password reset
- Security notifications (login from new device, 2FA changes)
- Billing confirmations and invoices
- Service announcements and critical updates
18.2 Alert Notifications (Configurable)
- Domain monitoring alerts (uptime, performance, SSL)
- Weekly domain summary reports (enabled by default, can be turned off per domain in your settings)
18.3 Onboarding and Product Emails
- A series of onboarding messages helping you set up and get value from the Service
- Product updates and new feature announcements
- Tips and best practices for web performance
- Promotional offers and discounts
These emails are switched on when you create an account, and we want you to know that at the point you give us your address rather than after the first one arrives. We send them on the basis of Article 13(2) of the ePrivacy Directive: you gave us your email address while signing up for this product, and these messages are about that product. You can object at any time, and stopping them takes one click.
Every one of these messages carries an unsubscribe link that works without signing in, and you can turn them off at any time in your account settings. This preference is separate from the one covering transactional email, so switching off product email never stops the account, billing, and security messages described in Section 18.1. If you would rather not receive them at all, switch them off in settings after signing up, or email privacy@vitalsentinel.com and we will do it for you.
You can manage all notification preferences in your account settings.
18.4 Email Analytics
Our newsletter and marketing emails include a tracking pixel and redirected links so we can measure how many recipients opened an email and which links they clicked. When you open or click, we record the event together with your IP address and user agent. Transactional and alert emails are not tracked this way. You can prevent open tracking by disabling remote images in your email client, and you can unsubscribe from marketing emails at any time.
19. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected data from a child under 18, please contact us immediately.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending email notification for significant changes
We encourage you to review this Privacy Policy periodically.
21. Contact Us
If you have questions about this Privacy Policy or our data practices:
Email: privacy@vitalsentinel.com
Address:
mountain explorer, s. r. o.
Karpatske namestie 7770/10A
83106 Bratislava
Slovakia (European Union)