Operator and contact
The website incidentbot.com and the IncidentBot service are operated by IncidentBot. For any question about this policy or your data, write to [email protected].
Data from signup
When you create an account or write to us, we collect the data you give us and some technical data about the request.
- Work email address.
- Team size you select.
- Plan interest, such as the plan and billing period you clicked.
- Source of the signup, such as the page or button you used.
- Campaign parameters in the link you arrived from (UTM source, medium and campaign) and the referring page.
- IP address and browser user agent, used for security and to prevent abuse.
Verification code email
To confirm that the address belongs to you, we send a six-digit verification code by email. We store a secure hash of the code, its expiry time and the number of attempts, not the code in plain text.
Data from using the service
When your workspace is in use, we process the data needed to run it: names and contact details of responders and stakeholders, paging preferences and phone numbers for SMS and voice, on-call schedules, alert payloads sent by your monitoring tools, incident records and timelines, status page content, postmortems and action items. Your organisation decides what is sent to the service and is the controller of that data. We process it on your behalf.
Billing data
Subscriptions are billed per responder seat, monthly or annually. Payments are handled by our payment provider. We receive the billing details needed for invoices and the status of payments. We do not store full card numbers.
Purposes and legal bases
- To create and secure your account and verify your email address (performance of a contract and legitimate interest in security).
- To provide the service, including paging, incident coordination, status pages and reports (performance of a contract).
- To bill your subscription and keep accounting records (performance of a contract and legal obligation).
- To answer your questions sent to [email protected] (legitimate interest).
- To understand which pages and campaigns bring signups, using the source and campaign parameters (legitimate interest).
- To send service emails about your account. We send marketing emails only where the law allows it, and you can unsubscribe at any time.
How long we keep data
Signup data is kept while your account exists or while we are in contact about a subscription, and deleted when it is no longer needed. Workspace data is kept for the duration of the subscription, or according to custom retention on Enterprise, and deleted after the account is closed, except where the law requires us to keep records such as invoices.
How we protect data
Data is encrypted in transit and at rest, staff access is limited on a least-privilege basis, and access to production is logged. More detail is on the security page.
Rights under GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format and withdraw consent where processing is based on consent. You can also complain to your local data protection authority.
Rights under CCPA
If you are a California resident, you have the right to know what personal data we collect and how we use it, to request deletion and correction, and to opt out of the sale or sharing of personal data. We do not sell or share personal data in that sense. We do not discriminate against you for exercising these rights.
How to exercise your rights
Write to [email protected] from the address linked to your account. We may ask you to confirm your identity before acting on the request. For workspace data, we may refer you to your organisation, which controls that data.
Changes to this policy
We update this policy when our practices change. The date at the top shows the latest version. For material changes that affect account holders, we notify them by email.