Who we are
Canary9 is an uptime and synthetic monitoring platform built and operated by Canary Monitoring, Inc. ("we", "us"). This policy covers the marketing website at canary9.com and the Canary9 application at app.canary9.com. Questions about this policy or your data can go to privacy@canary9.com at any time.
What we collect
Account information. When you register we collect your name, email address, and a password. Passwords are stored only as salted hashes, never in plain text. If you enable two-factor authentication, we store the data needed to verify your second factor.
Billing information. Payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers; we keep your plan, subscription status, and invoice history.
Monitoring configuration. We store the endpoints you monitor, your alert policies, and the notification integrations you configure. Integration configuration can include addresses and credentials you provide, such as a webhook URL, routing key, phone number, or the email addresses that should receive alerts. We store these to deliver your notifications and for no other purpose.
Check results. Running your checks produces uptime, response-time, and diagnostic data about the endpoints you chose to monitor. This data belongs to your organization and is retained according to your plan's retention period.
Logs. Operating the service produces operational and security logs. For example, requests to canary9.com are logged with the time, source IP address, request method, host, path, status code, query string, and a request ID; these website logs deliberately exclude cookies, referrers, and user agents. Application and security logs similarly record request and authentication activity, including login IP addresses. Log access is limited to restricted operations roles, and we treat source IP addresses as potentially personal data. We retain logs only as long as they are useful for operations, security, and audit, and reserve the right to retain them for up to 7 years.
Cookies. The marketing site sets no cookies and runs no third-party analytics or advertising trackers. Website analytics is first-party and privacy-respecting. The application uses a session token for the sole purpose of keeping you signed in.
How we use data
- To operate the service: run your checks, evaluate alerts, and deliver the notifications you configure.
- To send transactional email, such as account verification and alert notifications, from noreply@canary9.com.
- To bill for paid plans and maintain accurate accounting records.
- To respond to support requests and investigate abuse of the platform or the probe network.
We do not sell personal data, we do not share it for targeted advertising, and we do not use your data for advertising of any kind.
Who we share data with
We use a small number of service providers to run Canary9:
- Amazon Web Services: infrastructure hosting, in the United States.
- Stripe: payment processing.
- Microsoft: delivery of transactional email.
- Twilio: delivery of SMS alerts.
When you configure a notification integration, alert content is sent to the service you chose, such as Slack, PagerDuty, or your own webhook endpoint. You control which integrations exist and what they receive, and you can remove them at any time.
Retention and deletion
Account and monitoring configuration data is kept while your account is active. Check results are retained for your plan's retention window. When you close your account, or ask us to, we delete your personal data, with two narrow exceptions:
- Records we are legally required to keep, such as billing history.
- A minimal set of operational records kept to prevent fraud and abuse and to preserve the integrity of business operations: endpoint and check data, your user and organization identifiers, and login location data. These are no longer connected to your name or email once your personal data is deleted.
Security
Data is encrypted in transit everywhere, passwords are stored as salted hashes, stored objects such as screenshots and log archives are encrypted at rest, two-factor authentication is available on every plan, and access to production systems is restricted. No system is perfectly secure, and we encourage reporting anything that looks wrong to privacy@canary9.com.
Your rights
Wherever you live, we extend the same set of rights, including those defined by the GDPR, the CCPA/CPRA, and US state privacy laws such as the Minnesota Consumer Data Privacy Act:
- Access and portability: ask what personal data we hold about you and receive a copy in a usable format.
- Correction: fix inaccurate account information, either in the application or by asking us.
- Deletion: have your personal data deleted, subject to the narrow retention exceptions above.
- Opt out of sale and targeted advertising: nothing to opt out of; we do not sell personal data or share it for targeted advertising.
- Non-discrimination: exercising a privacy right never affects your service.
- Appeal: if we decline a request, you may appeal by replying to our decision, and we will have someone not involved in the original decision review it.
To exercise any of these, email privacy@canary9.com. We verify requests against the account email and respond within the timelines the applicable law requires.
Enterprise plans add more granular control over data residency, retention, and deletion workflows, backed by dedicated infrastructure. If your organization has requirements beyond this policy, contact sales@canary9.com.
Where data lives
Canary9 is hosted in the United States. If you use the service from elsewhere, your data is transferred to and processed in the United States.
Changes to this policy
If we make a material change to this policy, we will update the effective date above and, for significant changes, notify account holders by email before the change takes effect.