Skip to content
Alertira
ProductDemoIntegrationsSecurityPricingSign inStart free
Alertira homePrivacy

How Alertira handles data

A practical description of the information Alertira needs to run scheduled checks, deliver evidence, manage subscriptions, and support customers.

Effective and last updated: 4 September 2026 · Version 2026-09-04
Trust centrePrivacyTermsRefundsSecurityContact
Pre-commercial availability

Alertira is currently available for product evaluation. Paid live checkout remains disabled until the contracting entity, registered address, registration details, and governing jurisdiction are published here.

1. Our roles

Alertira is the controller for account, billing, support, and product-usage information used to operate this service. When a customer configures a monitored journey, the customer controls that target and its business data; Alertira processes configured synthetic-check data to provide the requested monitoring. Questions about processing terms can be sent to support@alertira.com.

2. Information we process

  • Account and workspace details: name, work email, role, organisation name, settings, and authentication records.
  • Monitoring configuration: target URLs, permitted selectors, synthetic field names, check intervals, expected outcomes, and named provider connections. Test values are generated by Alertira and are not stored in path configuration.
  • Integration credentials: provider access tokens, webhook URLs, API secrets, and signing secrets supplied by workspace admins. These are authenticated-encrypted before database storage, are not returned through the product API, and are erased from the active record when the connection is removed.
  • Operational evidence: check status, timings, sanitised response metadata, redacted provider record identifiers, incident timelines, delivery state, and private evidence assets.
  • Billing data: plan, entitlement, Dodo customer/subscription identifiers, invoice status, and verified webhook state. Alertira does not store full card numbers.
  • Support and contact messages, audit events, rate-limit identifiers stored as one-way hashes, and error diagnostics.

3. Why we use it

Provide the serviceAccount access, scheduled checks, incidents, notifications, reports, and billingContract
Protect the serviceAbuse prevention, tenant isolation, rate limits, audit trails, and debuggingLegitimate interests
Billing and recordsPayments, taxes, refunds, disputes, and accounting recordsContract / legal obligation
Improve the productPseudonymous, curated product events only when PostHog is configuredLegitimate interests or consent where required

4. Providers and transfers

Alertira may use Railway for application/database hosting, Cloudflare Turnstile for bot checks and R2 for private evidence, Resend for email, Sentry for redacted error diagnostics, PostHog for pseudonymous product events, and Dodo Payments as Merchant of Record. When a workspace admin connects Slack, HubSpot, Calendly, Shopify, GA4, or a generic webhook, Alertira sends the minimum configured test or operational request to that provider. A provider receives information only when that service is configured and needed. Provider locations and transfer safeguards follow the relevant customer agreement and data-processing terms.

5. Data minimisation and retention

Synthetic form values are redacted from check results. Passwords, payment fields, file uploads, and consent fields are refused. Query strings, cookies, authorisation headers, and likely secrets are excluded from evidence. Evidence assets expire after 30 days. Check history is retained for 30, 90, or 180 days according to plan. Expired authentication tokens are removed after a short safety period, rate-limit buckets at expiry, minimal Resend webhook metadata after 90 days, and contact messages after 24 months. Account, incident, audit, billing, and legal-acceptance records may be retained while an account exists and longer where needed for security, disputes, accounting, or law. Backups age out under hosting-provider schedules.

6. Your choices and rights

Depending on applicable law, you may ask for access, correction, deletion, restriction, portability, or objection. You may withdraw consent where consent is the basis. Contact support@alertira.com; we may verify identity and authority before acting. You may also complain to the data-protection authority applicable to your location. Alertira does not use monitored data for legally significant automated decisions.

7. Cookies and analytics

Alertira uses a secure HTTP-only session cookie for signed-in accounts. Server-side product analytics is disabled unless configured and is designed not to include names, emails, customer target URLs, form contents, screenshot keys, or raw errors. Non-essential browser analytics and session recording are not enabled in the paid beta.

8. Children and changes

Alertira is a business service and is not directed to children. Material policy changes will be dated here and communicated through a reasonable account or email notice when appropriate.

Alertira

Quiet, evidence-led protection for the paths that turn visitors into customers.

© 2026 Alertira. All rights reserved.
ProductCoverageProduct tourIntegrationsPricing
CompanySecurityContactsupport@alertira.comSign in
LegalPrivacyTermsRefund & cancellationSecurity