Privacy Policy
Last updated July 8, 2026
Holter is built to collect as little as practical. This page explains what we collect, why we collect it, who helps us operate the service, and how you can control optional cookies and tracking.
Who we are
Holter is operated by Wonderful Software LLC, a Delaware limited liability company ("Holter," "we," "us," or "our"). Contact us at [email protected].
What we collect
Account data: name, email address, authentication provider identifiers, team membership, role, plan, and account settings.
Monitoring configuration: URLs, hostnames, IPs, ports, DNS records, certificate settings, heartbeat settings, alert channels, status-page settings, and related configuration you provide.
Check results and operational data: statuses, response times, certificate and DNS data, incident history, signal history, heartbeat events, and records of alerts we attempted to send.
Status-page subscriber data: email addresses and subscription preferences for visitors who choose to subscribe to one of your status pages.
Billing data: handled by Stripe. We receive subscription status, plan information, invoice metadata, and limited payment-related metadata. We do not store full card numbers.
Usage, device, cookie, and diagnostic data: IP address, browser/device data, pages viewed, events clicked, approximate location inferred from IP, performance data, logs, errors, and diagnostic traces. Some of this is collected only if you allow optional cookies or tracking.
We do not ask for your server credentials, cloud credentials, private keys, or source code. If you use agent-assisted setup, your local agent reads your code locally; Holter receives only the monitor configuration or heartbeat URLs you choose to create.
How we use data
We use data to provide, secure, maintain, debug, and improve Holter; authenticate users; run monitoring checks; process heartbeats; deliver alerts; publish status pages; process billing; prevent abuse; provide support; understand product usage; measure marketing performance where permitted; and comply with legal obligations.
We do not sell personal information for money. Some analytics, advertising, or conversion-measurement tools may be considered a "sale," "sharing," or targeted-advertising use under certain privacy laws. Where required, we provide controls to reject or opt out of those uses.
Legal bases for processing
Where data-protection law such as the GDPR or UK GDPR applies, we process personal data on these bases: to perform our contract with you (providing accounts, monitoring, alerts, status pages, and billing); our legitimate interests in securing, maintaining, improving, and measuring the service and preventing abuse; your consent for optional analytics and marketing cookies and tools, which you can withdraw at any time; and to meet our legal obligations. Where we rely on consent, withdrawing it does not affect processing already carried out.
Who we share data with
We share data only as needed to operate, secure, support, improve, and measure Holter, or as required by law. Recipients may include:
- hosting, infrastructure, database, storage, CDN, and network providers;
- email, notification, and alert-delivery providers;
- payment, billing, tax, and subscription-management providers;
- authentication providers, if you choose to sign in with them;
- analytics, diagnostics, observability, and error-monitoring providers, where allowed;
- advertising, attribution, and conversion-measurement providers, where allowed;
- probe-network or monitoring infrastructure providers used to perform checks from selected locations;
- professional advisors, legal/compliance providers, and service providers who help us operate the business.
We may also disclose data if required by law, to enforce our terms, to protect rights, safety, or security, to investigate abuse, or in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.
A current subprocessor list is available on request.
International processing
We and our providers may process data in the United States and other countries. If privacy law requires a transfer mechanism, we rely on appropriate safeguards such as contractual commitments or Standard Contractual Clauses where applicable.
Retention
We keep account and configuration data while your account is active or as needed to provide the service. Operational logs, check results, signals, and diagnostic data are kept for limited periods that may vary by data type and plan. We may retain limited records longer where needed for security, fraud prevention, legal compliance, dispute resolution, backups, or legitimate business records.
Your choices and rights
You can access, correct, export, or delete certain data in your account or by contacting us. Depending on where you live, you may have rights to know, access, correct, delete, port, restrict, object, withdraw consent, opt out of sale/share/targeted advertising, or appeal a privacy decision. We will not discriminate against you for exercising privacy rights.
To make a request, email [email protected]. We may need to verify your request before acting on it. If you are acting for a status-page subscriber or another person, we may require proof of authorization.
Security
We use technical and organizational safeguards designed to protect data, including encryption in transit, access controls, and least-privilege practices. No system is perfectly secure. You are responsible for protecting your account, team access, webhook URLs, heartbeat URLs, and ingest tokens.
Children
Holter is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child provided data, contact us and we will take appropriate steps.
Changes and contact
We may update this policy from time to time. The updated version will be posted here with a new date. Questions or privacy requests: [email protected].