Skip to content
IncidentBot

Privacy policy

Last updated: September 23, 2026. This policy explains what personal data IncidentBot collects when you visit incidentbot.com, create an account and use the service, why we collect it, who processes it for us and what rights you have.

Operator and contact

The website incidentbot.com and the IncidentBot service are operated by IncidentBot. For any question about this policy or your data, write to [email protected].

Data from signup

When you create an account or write to us, we collect the data you give us and some technical data about the request.

  • Work email address.
  • Team size you select.
  • Plan interest, such as the plan and billing period you clicked.
  • Source of the signup, such as the page or button you used.
  • Campaign parameters in the link you arrived from (UTM source, medium and campaign) and the referring page.
  • IP address and browser user agent, used for security and to prevent abuse.

Verification code email

To confirm that the address belongs to you, we send a six-digit verification code by email. We store a secure hash of the code, its expiry time and the number of attempts, not the code in plain text.

Data from using the service

When your workspace is in use, we process the data needed to run it: names and contact details of responders and stakeholders, paging preferences and phone numbers for SMS and voice, on-call schedules, alert payloads sent by your monitoring tools, incident records and timelines, status page content, postmortems and action items. Your organisation decides what is sent to the service and is the controller of that data. We process it on your behalf.

Billing data

Subscriptions are billed per responder seat, monthly or annually. Payments are handled by our payment provider. We receive the billing details needed for invoices and the status of payments. We do not store full card numbers.

Purposes and legal bases

  • To create and secure your account and verify your email address (performance of a contract and legitimate interest in security).
  • To provide the service, including paging, incident coordination, status pages and reports (performance of a contract).
  • To bill your subscription and keep accounting records (performance of a contract and legal obligation).
  • To answer your questions sent to [email protected] (legitimate interest).
  • To understand which pages and campaigns bring signups, using the source and campaign parameters (legitimate interest).
  • To send service emails about your account. We send marketing emails only where the law allows it, and you can unsubscribe at any time.

We do not sell personal data

We do not sell personal data and we do not share it for cross-context behavioural advertising. We share data only with service providers that process it on our instructions.

  • Hosting and infrastructure providers that run the application and store data.
  • Email delivery providers that send verification codes and service emails.
  • Messaging providers that deliver SMS and voice pages.
  • A payment provider that processes subscription payments.

We may disclose data where the law requires it or to protect the rights and safety of users and the service.

International transfers

Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as standard contractual clauses. Enterprise customers can choose data residency in the United States or the European Union for workspace data.

How long we keep data

Signup data is kept while your account exists or while we are in contact about a subscription, and deleted when it is no longer needed. Workspace data is kept for the duration of the subscription, or according to custom retention on Enterprise, and deleted after the account is closed, except where the law requires us to keep records such as invoices.

How we protect data

Data is encrypted in transit and at rest, staff access is limited on a least-privilege basis, and access to production is logged. More detail is on the security page.

Rights under GDPR

If you are in the European Economic Area or the United Kingdom, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format and withdraw consent where processing is based on consent. You can also complain to your local data protection authority.

Rights under CCPA

If you are a California resident, you have the right to know what personal data we collect and how we use it, to request deletion and correction, and to opt out of the sale or sharing of personal data. We do not sell or share personal data in that sense. We do not discriminate against you for exercising these rights.

How to exercise your rights

Write to [email protected] from the address linked to your account. We may ask you to confirm your identity before acting on the request. For workspace data, we may refer you to your organisation, which controls that data.

Cookies we use

We keep cookies to a minimum: a session cookie that keeps the site working while you browse and a security token that protects forms from abuse. We do not use advertising cookies.

Changes to this policy

We update this policy when our practices change. The date at the top shows the latest version. For material changes that affect account holders, we notify them by email.