Privacy policy

This describes what Infinity Curve LLC collects when you use Vitrina Engine, why we hold it, and what you can ask us to do with it. We are the data controller for it.

The short version: we collect what is needed to run monitoring for you and to bill you, we do not sell any of it, there is no advertising anywhere and no analytics inside the product at all, and we never see your card details. There is optional analytics on the public website, which is off until you turn it on.

What we collect

Account data

Your name, email address and password hash; your organisation name; the roles and workspace assignments of people you invite. Passwords are hashed, never stored in a readable form, and cannot be recovered — only reset.

What you configure

The hostnames, URLs, IP addresses and other targets you ask us to check, plus any credentials you attach to a check so that it can authenticate. Credentials and webhook signing secrets are encrypted with a key held outside the database, so a database backup on its own does not contain them.

What monitoring produces

Response times, status codes, TLS certificate details, DNS answers, error text, and the incidents and notifications derived from them. If a monitored endpoint returns personal data in an error message, that text will be stored in the check result and shown in the alert — so avoid pointing checks at endpoints that do that.

Status page subscribers

When somebody subscribes to one of your status pages we store their email address and their subscription state. Confirmation is always double opt-in: an unconfirmed address is sent nothing except its own confirmation. For those addresses you are the controller and we process on your behalf.

Technical data

Server logs containing IP address, user agent and request path, kept for 30 days for security and debugging. Session cookies, which are strictly necessary. We set no advertising cookies anywhere, ever.

The cookie policy lists every one by name, what it is for and how long it lasts. The short version: the public pages set nothing at all unless you allow analytics.

Website analytics

On the public website — the pages you are reading now, before you sign in — we use Google Analytics, through Firebase, to see which pages people find useful and where they arrive from. It sets cookies, so it does not run at all unless you allow it: not loaded, not fetched, nothing set. Declining is not a setting that hides the data from us afterwards; the code is never executed. You can change your mind at any time from “Analytics settings” in the footer of any public page, and declining changes nothing about how the site works.

It runs only on the public website. It is not present in the dashboard, and it is not present on status pages — including yours. A status page you publish carries no tag of ours, so your visitors are not measured by us and nothing about them reaches Google on our behalf. Google acts as our processor for what is collected, and may process it outside your country; the data is website usage, not anything from your monitoring.

Separately, Cloudflare counts page views for us on this website and on the dashboard, as part of the service that already sits in front of every request. It sets no cookies and stores no identifier that follows you between visits or between sites, which is why it is not behind the choice above — there is nothing on your device for you to refuse. It tells us how many people opened a page and roughly where in the world from, and nothing that identifies anybody. It does not run on status pages.

Payment data

None that identifies a card. Paddle.com Market Ltd is the merchant of record: the checkout is theirs, card details are entered on their systems, and we receive only a customer reference, the plan, the amount, the currency and the subscription status. There is no form anywhere in this product that accepts a card number.

Why we hold it, and on what basis

  • To provide the service — performance of our contract with you. This covers your account, your configuration and your monitoring history.
  • To bill you — performance of the contract and our legal obligation to keep transaction records.
  • To keep the service secure — our legitimate interest in preventing abuse. This covers logs and rate limiting.
  • To send service email — performance of the contract. Alerts, invitations and billing notices are not marketing and cannot be turned off while the account is open.

How long we keep it

  • Individual check results: for your plan’s raw retention period, then dropped.
  • Aggregated uptime history: for your plan’s history retention period.
  • Account and configuration data: until you delete the organisation, then 30 days.
  • Server logs: 30 days.
  • Transaction records: seven years, as required for tax.

Who we share it with

We use a small number of processors, and no others:

  • Paddle.com Market Ltd — payments, invoicing and tax.
  • Scaleway — sending transactional and alert email, in France.
  • Lettermint — sending marketing email, in the European Union, and only to people who asked for it. It never sees anything else.
  • Cloudflare — DNS, TLS termination, protection against attack, and the cookieless page-view counting described above.
  • Google — analytics, and only for visitors to the public website who allowed it. Never for the dashboard, and never for a status page.
  • Backblaze — off-site backup storage, in the EU. What they hold is encrypted before it leaves our servers, with a key they do not have.
  • Our hosting providers — the servers this runs on, in the European Union, and the hosts that run monitoring checks. The sub-processor list names them and says which are outside the EEA; personal data is never sent to those.

The sub-processor list names each of them, what data reaches them, where they process it and on what basis.

We do not sell personal data, we do not share it for advertising, and we disclose it to anybody else only where the law requires it.

Where it is processed

Your account data — organisations, users, monitors, incidents and their history — is stored and processed in the European Union, on servers operated by Contabo GmbH. Your email is sent from inside the EU as well.

Because that is inside the European Economic Area, the hosting itself involves no transfer out of it. What governs our relationship with the hosting provider is an Article 28 data processing agreement rather than standard contractual clauses.

We are established in Georgia, and we run the service from there. So although your data is stored in the EU, the people operating it reach it from outside the EEA — which is an international transfer, and we would rather say so than let “servers in the EU” imply something it does not. For customers in the EEA and the UK that transfer is covered by the European Commission’s standard contractual clauses, set out in our data processing agreement.

Checks run from several countries. Your personal data does not.

Monitoring means making requests to your systems from more than one place, so that an outage is confirmed from somewhere other than where we happen to be. Some of those vantage points are outside the EEA, and the set of them changes as we add and retire capacity.

Personal data is never sent to them. Where a check’s configuration could contain personal data — a request header, a request body — it is only ever run from inside the EEA. That is not a policy we ask people to follow: our scheduler will not place such a check anywhere else, and the restriction is tested against a real database on every build.

What a vantage point outside the EEA receives is the address being checked and whether it answered. It is never given a database credential, so there is nothing on one to lose beyond the checks it is running, and none of them stores anything.

We deliberately do not list the countries here. They change, and a list that is accurate today would quietly stop being accurate — which is worse than not publishing one. If you need to know exactly where checks against your systems run, including for your own compliance, ask us at privacy@vitrinaengine.com and we will tell you and keep you informed if it changes.

How it is protected

In transit everything is encrypted, including the leg between our own servers. Credentials you store with us — a webhook signing secret, an SMTP password — are sealed with AES-256-GCM under a key held separately. Backups are encrypted to a key that is on none of the servers, so a copy of a machine is not a copy of your data.

Our transfers to Paddle.com Market Ltd and Cloudflare are covered by the European Commission’s standard contractual clauses, and we will send you a copy on request. So is our own access from Georgia, under the data processing agreement. The servers holding your account data are in the EEA and need none for storage itself.

Your rights

You can ask us for a copy of your data, for it to be corrected, or for it to be deleted. You can object to processing based on legitimate interest, and you can ask for your data in a portable form. Most of it you can also simply export or delete yourself from the dashboard.

Email privacy@vitrinaengine.com and we will respond within 30 days. If you are in the EEA or the UK and are unhappy with our answer, you may complain to your local supervisory authority.

Security

Traffic is encrypted in transit. Stored credentials and channel secrets are encrypted with a key held outside the database. Access between customers is enforced at the query layer rather than by convention, and every API key is bound to the membership that created it, so removing somebody’s access removes their keys with it.

If you believe you have found a vulnerability, please email hello@vitrinaengine.com. We will not pursue anybody who reports one in good faith.

Changes and contact

We will email account owners before a material change takes effect. For anything here, contact:

Infinity Curve LLC
76 Vazha-Pshavela Ave, 0186 Tbilisi, Georgia
privacy@vitrinaengine.com

Last updated 31 August 2026.