Skip to content

Privacy Policy

Last updated July 8, 2026

Holter is built to collect as little as practical. This page explains what we collect, why we collect it, who helps us operate the service, and how you can control optional cookies and tracking.

Who we are

Holter is operated by Wonderful Software LLC, a Delaware limited liability company ("Holter," "we," "us," or "our"). Contact us at [email protected].

What we collect

Account data: name, email address, authentication provider identifiers, team membership, role, plan, and account settings.

Monitoring configuration: URLs, hostnames, IPs, ports, DNS records, certificate settings, heartbeat settings, alert channels, status-page settings, and related configuration you provide.

Check results and operational data: statuses, response times, certificate and DNS data, incident history, signal history, heartbeat events, and records of alerts we attempted to send.

Status-page subscriber data: email addresses and subscription preferences for visitors who choose to subscribe to one of your status pages.

Billing data: handled by Stripe. We receive subscription status, plan information, invoice metadata, and limited payment-related metadata. We do not store full card numbers.

Usage, device, cookie, and diagnostic data: IP address, browser/device data, pages viewed, events clicked, approximate location inferred from IP, performance data, logs, errors, and diagnostic traces. Some of this is collected only if you allow optional cookies or tracking.

We do not ask for your server credentials, cloud credentials, private keys, or source code. If you use agent-assisted setup, your local agent reads your code locally; Holter receives only the monitor configuration or heartbeat URLs you choose to create.

How we use data

We use data to provide, secure, maintain, debug, and improve Holter; authenticate users; run monitoring checks; process heartbeats; deliver alerts; publish status pages; process billing; prevent abuse; provide support; understand product usage; measure marketing performance where permitted; and comply with legal obligations.

We do not sell personal information for money. Some analytics, advertising, or conversion-measurement tools may be considered a "sale," "sharing," or targeted-advertising use under certain privacy laws. Where required, we provide controls to reject or opt out of those uses.

Legal bases for processing

Where data-protection law such as the GDPR or UK GDPR applies, we process personal data on these bases: to perform our contract with you (providing accounts, monitoring, alerts, status pages, and billing); our legitimate interests in securing, maintaining, improving, and measuring the service and preventing abuse; your consent for optional analytics and marketing cookies and tools, which you can withdraw at any time; and to meet our legal obligations. Where we rely on consent, withdrawing it does not affect processing already carried out.

Cookies and tracking

Necessary cookies are required for security, login sessions, CSRF protection, consent preferences, and core service behavior. These stay on because the service cannot work properly without them, and include your language preference (holter_locale).

Analytics cookies and tools help us understand which public pages, product flows, and features are working, and to capture errors so we can fix them. These may include PostHog and similar tools.

Marketing cookies and tools help us measure ads, landing pages, campaigns, conversions, and retargeting. These may include Google Ads (Google's conversion-tracking and remarketing tags, which set cookies such as those beginning _gcl_), advertising pixels, conversion APIs, campaign attribution cookies, and similar tools.

Cross-site attribution. When you move from our marketing site (holter.sh) to the Holter app (app.holter.sh) — for example, by selecting "Sign in" or "Start" — we may pass along limited campaign and analytics identifiers so we can understand which pages and campaigns lead to signups and measure conversions across both sites. If you create an account, we may associate that context with your account. We do this only when you have allowed the relevant optional cookies, and not when your browser sends a Global Privacy Control signal.

Session replay or diagnostic tools, if enabled, help us find broken flows and product issues. We configure these tools to avoid collecting sensitive input where practical, but you should not enter secrets into Holter except where the product explicitly asks for a token or configuration value needed to provide the service.

We do not load optional analytics or marketing tools, and we do not set Holter's marketing attribution cookie, unless you allow the relevant optional categories. You can change choices using the cookie settings link in the footer. If your browser sends a Global Privacy Control signal, we treat it as an opt-out of optional marketing attribution and tracking where applicable.

Who we share data with

We share data only as needed to operate, secure, support, improve, and measure Holter, or as required by law. Recipients may include:

  • hosting, infrastructure, database, storage, CDN, and network providers;
  • email, notification, and alert-delivery providers;
  • payment, billing, tax, and subscription-management providers;
  • authentication providers, if you choose to sign in with them;
  • analytics, diagnostics, observability, and error-monitoring providers, where allowed;
  • advertising, attribution, and conversion-measurement providers, where allowed;
  • probe-network or monitoring infrastructure providers used to perform checks from selected locations;
  • professional advisors, legal/compliance providers, and service providers who help us operate the business.

We may also disclose data if required by law, to enforce our terms, to protect rights, safety, or security, to investigate abuse, or in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.

A current subprocessor list is available on request.

International processing

We and our providers may process data in the United States and other countries. If privacy law requires a transfer mechanism, we rely on appropriate safeguards such as contractual commitments or Standard Contractual Clauses where applicable.

Retention

We keep account and configuration data while your account is active or as needed to provide the service. Operational logs, check results, signals, and diagnostic data are kept for limited periods that may vary by data type and plan. We may retain limited records longer where needed for security, fraud prevention, legal compliance, dispute resolution, backups, or legitimate business records.

Your choices and rights

You can access, correct, export, or delete certain data in your account or by contacting us. Depending on where you live, you may have rights to know, access, correct, delete, port, restrict, object, withdraw consent, opt out of sale/share/targeted advertising, or appeal a privacy decision. We will not discriminate against you for exercising privacy rights.

To make a request, email [email protected]. We may need to verify your request before acting on it. If you are acting for a status-page subscriber or another person, we may require proof of authorization.

Security

We use technical and organizational safeguards designed to protect data, including encryption in transit, access controls, and least-privilege practices. No system is perfectly secure. You are responsible for protecting your account, team access, webhook URLs, heartbeat URLs, and ingest tokens.

Children

Holter is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child provided data, contact us and we will take appropriate steps.

Changes and contact

We may update this policy from time to time. The updated version will be posted here with a new date. Questions or privacy requests: [email protected].