Privacy policy
Last updated: 24 July 2026
Data controller
The controller of account and billing-related personal data is [[À COMPLÉTER : raison sociale / identité de l'éditeur]], [[À COMPLÉTER : forme juridique]], [[À COMPLÉTER : adresse du siège social]].
Privacy contact: [[À COMPLÉTER : email privacy / DPO]] (or [[À COMPLÉTER : email de contact (ex. contact@verifagent.com)]] if identical).
Data we process
Depending on how you use Verifagent, we may process:
- Account: email address, password hash (handled by Supabase Auth), preferred language (preferred_locale / verifagent_locale).
- Organization: organization name, members and roles.
- Monitors: name, expected period, grace period, ping tokens/URLs.
- Signals (pings): timestamps, durations, error messages and JSON metadata sent by your workflows.
- Incidents: open/resolve times and related status.
- Notification channels: destination emails, chat/webhook URLs (Slack, Discord, Teams), Telegram chat IDs, and PagerDuty routing keys. Bot tokens and routing keys are stored as secrets and redacted in the UI for non-managers.
- Billing: Stripe customer/subscription identifiers and related status fields. Card data is processed by Stripe, not stored by Verifagent.
Purposes and legal bases
- Providing the monitoring service and account (performance of a contract).
- Security, abuse prevention and service integrity (legitimate interests / legal obligations).
- Billing and tax records for paid plans (contract / legal obligation).
- Transactional emails — auth, alerts, billing reminders (contract / legitimate interests).
- Product analytics via Vercel Analytics in a privacy-oriented mode (legitimate interests; see Cookies policy).
Controller vs processor
For your account profile and our billing relationship, Verifagent acts as controller.
For personal data contained in your monitors’ ping metadata, incident context and notification destinations that you configure, you are typically the controller and Verifagent acts as processor. A Data Processing Agreement is available at /legal/dpa for business customers who need one.
Subprocessors
We use the following providers to operate Verifagent:
- Supabase — database and authentication (region: [[À COMPLÉTER : région du projet Supabase (ex. eu-west-1 / eu-central-1)]]).
- Vercel — application hosting and delivery.
- Resend — sending transactional and alert emails.
- Stripe — payment processing and customer billing portal.
- cron-job.org — external cron calling our notification dispatch endpoint.
Retention
Visible history follows plan limits: about 7 days on Solo and about 90 days on Studio for incident/history views, subject to product changes.
Operational logs and backups may retain residual data for a short additional period for security and continuity.
After account deletion (available in the product at /app/settings/account), your memberships are removed. Organizations you alone owned may be deleted with their monitors and channels. Stripe may retain invoicing records as required by law.
Your GDPR rights
Where GDPR applies, you may request access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with a supervisory authority.
To exercise rights, contact [[À COMPLÉTER : email privacy / DPO]] or use in-product account deletion at /app/settings/account when that meets your request.
Security
We use measures appropriate to a SaaS monitoring service (encrypted transport, access controls, hashed passwords via Supabase Auth, secret ping tokens). No method of transmission or storage is perfectly secure.
International transfers
If a provider processes data outside the EEA/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by that provider, unless an adequacy decision applies.
Children
Verifagent is intended for professional use and is not directed at children.
Changes
We may update this policy. The “Last updated” date will change.