Overview
PageLantern is built for authorized monitoring of websites, APIs, domains, certificates, DNS records, heartbeat jobs, incidents, alerts, reports, and public status pages. We operate the service for business and professional users. For some information, such as account, authentication, billing, website, security, audit, and aggregate operational data, PageLantern decides why and how the data is processed and acts as a controller (a business under US law). For other information, such as the monitor configurations, probe artifacts, alert destinations, and status-page subscriber lists that a customer sets up, PageLantern acts only as a processor or service provider on that customer's documented instructions, and the customer is the controller (or business) responsible for that content. This notice describes both roles. It also describes the limits of the service: monitoring results are informational and may be delayed, incomplete, or inaccurate, our security measures are designed to protect data but cannot guarantee absolute security, heartbeat tokens and status-page subscriber addresses are stored without field-level encryption, and the service must not be relied upon as the sole control for emergency, life-safety, or other safety-critical decisions. Where US state privacy laws apply, the disclosures here are provided to the extent those laws apply to PageLantern; providing them is not an admission that any particular law applies.
1. Scope and Roles (Controller vs. Processor)
This Privacy Notice applies to the PageLantern website, customer portal and dashboards, monitoring APIs and API keys, monitors and probes, operational telemetry and diagnostics, alerts and notifications, integrations and webhooks, incidents and reports, public status pages and their subscriber lists, the in-app feedback widget, and support communications. Throughout this notice, "PageLantern," "we," "us," and "our" refer to the operator of the PageLantern service; "customer" means the organization or person that holds a PageLantern account; and "you" means any individual whose personal information is processed in connection with the service.
PageLantern plays two different roles depending on the data, and the difference determines who is responsible for it. We act as a controller (and, under US state laws, a "business") for the data we decide the purposes and means of. We act as a processor (and, under US state laws, a "service provider" or "contractor") for the monitoring content a customer configures and pushes into the service, which we process only on that customer's documented instructions. For that customer-configured content, the customer is the controller or business and is responsible for determining why and how it is processed and for its lawful basis.
PageLantern's role as a processor and service provider is governed by our Data Processing Terms, published at pagelantern.com/dpa and incorporated into the customer agreement. They apply automatically to every customer on acceptance of the Terms of Service — no signature or separate request is needed — and contain the terms required by Article 28 of the GDPR and UK GDPR, the Standard Contractual Clauses and UK Addendum for international transfers, and the service-provider and contractor restrictions of the CCPA/CPRA and comparable US state laws. Together with the customer's configuration, they constitute the customer's documented processing instructions. This Privacy Notice does not itself grant either party rights as controller or processor.
Where individuals' personal information appears inside customer-controlled monitor configuration, probe artifacts, alert destinations, or status-page subscriber lists, requests to access, correct, or delete that information should be directed to the relevant customer, who controls it. PageLantern will assist that customer as its processor and as required by its agreements and applicable law.
- PageLantern acts as a controller / business for: account and identity data, authentication and session data, multi-factor authentication data, API key metadata, organization and membership data, billing and subscription records, audit logs, client IP and user-agent in our logs, in-app feedback submissions, client-side UI telemetry, website data, and aggregate operational data we use to run and secure the service.
- PageLantern acts as a processor / service provider on the customer's instructions for: monitor configurations (URLs, hosts, methods, headers, request bodies, environment variables, success criteria, scripts, TCP and DNS settings), authentication profiles and secrets used to run probes, probe results and operational telemetry tied to a customer's monitors, browser-check artifacts (screenshots, HAR captures, console logs), alert and webhook destinations the customer configures, public status pages and their subscriber email lists, and incident and report content the customer creates.
2. Who We Are and How to Contact Us
The monitoring service is operated by PageLantern LLC (d/b/a PageLantern). Our registered postal address is stated in the Contact section of this notice. You can reach our privacy team at privacy@pagelantern.com for any question or request relating to this notice or your personal information, and our security team at security@pagelantern.com to report a security concern.
We have not appointed a Data Protection Officer because PageLantern's core activities do not consist of large-scale, regular, and systematic monitoring of individuals or large-scale processing of special-category data within the meaning of Article 37 of the GDPR and UK GDPR. We nonetheless maintain a dedicated privacy contact point at privacy@pagelantern.com. If we appoint a Data Protection Officer in the future, we will publish their contact details in this notice.
3. Our EU and UK Representatives (Article 27)
Where PageLantern offers the service to, or monitors the behavior of, individuals in the European Economic Area or the United Kingdom without an establishment there, Article 27 of the GDPR and UK GDPR may require us to designate a representative in the EU and a separate representative in the UK. Appointment of an EU representative does not satisfy the separate UK requirement, and vice versa.
Where these requirements apply to us, the contact details of our EU Article 27 representative and our UK Article 27 representative will be published in this notice before a paid public launch in those regions. Until then, you may contact us about EU or UK data-protection matters at privacy@pagelantern.com, and individuals in the EU or UK may also lodge a complaint with their local supervisory authority as described in the section on supervisory authorities.
4. Information We Collect
We collect information that is needed to provide, secure, support, bill for, and improve the service. For information PageLantern collects as a controller, we limit collection to what is reasonably necessary for the purposes described in this notice. For monitoring content a customer configures, the volume and nature of what is captured is determined entirely by the customer's monitor configuration and targets; PageLantern does not control, and does not represent that such content is minimized, proportionate, or limited to what any law requires.
Some information we collect directly from you when you create an account or use the service; some is generated by the service as it runs; and some is provided to us by our customers when they configure monitoring. Where we process personal information that we did not obtain directly from you, the source is generally the customer that operates the account (for example, where you are that customer's alert recipient, monitoring subject, or status-page subscriber), an identity provider you chose to sign in with, or a public or customer-specified target endpoint; in those cases PageLantern typically acts as the customer's processor, and the customer is responsible for any notice required under Article 14 of the GDPR and UK GDPR. The categories below describe the main types of information involved.
- Account and identity data: email address, display name, hashed password, email-verification status, and account lifecycle timestamps. Passwords are stored only as cryptographic hashes, never in clear text.
- Federated identity data: where you sign in with Google, Facebook, Apple, or Microsoft, the provider identifier, email, display name, and last-login time associated with that identity.
- Organization and membership data: organization names, slugs, plan names, and the roles linking users to organizations.
- Authentication and session data: server-side session records that store only a hash of the session token (never the raw token), expiry and revocation times, and a strictly necessary authentication cookie.
- Multi-factor authentication data: factor type (such as TOTP, SMS, email, or passkey), encrypted TOTP seeds, encrypted and masked SMS/email destinations, WebAuthn credential identifiers and public keys, and recovery codes stored only as hashes.
- API key data: a key prefix and a hash of the key (the full key is shown only once at creation), scopes, last-used time, and expiry or revocation status.
- Monitor configuration (customer-supplied): names, URLs, hosts, request methods, request bodies, headers, environment variables, success and assertion criteria, API step definitions, browser scripts, TCP host/port, DNS expectations, alert email and webhook settings, heartbeat tokens, and regions. Customers decide what to monitor and what credentials or payloads to include.
- Authentication metadata and secrets used to run probes: API auth profiles and monitor headers can contain tokens, bearer credentials, basic-auth values, or API keys that a customer chooses to embed so that probes can authenticate to the customer's targets.
- Operational telemetry and probe results: timestamps, status codes, response times, success/failure flags, error messages, TLS certificate details (subject, issuer, SAN, serial, fingerprint, chain), DNS record and resolver results, domain expiry data, heartbeat diagnostics, and a limited excerpt of the monitored target's response body (typically a few hundred characters, and for some monitor types up to roughly two thousand characters stored).
- Browser-check artifacts: screenshots, HAR network captures, and console logs from customer-specified targets, which may contain whatever appears on the monitored page or network.
- Alert, notification, and incident data: notification delivery records (which store only masked destinations), incident and report content, and report schedules.
- Status-page subscriber data: the email addresses of end users who subscribe to a customer's public status page, stored as part of that status page's records.
- Audit and security data: audit events recording the action, the acting user, client IP address, user-agent, and event details, plus application logs that include client IP and masked request paths.
- Billing and subscription data: plan, billing cadence, subscription status, billing period dates, invoice records and payment-method metadata such as card brand and last four digits. Payment is processed by Stripe; PageLantern does not receive or store full payment card numbers.
- In-app feedback data: your email, free-text message, the page URL and route, user-agent and viewport, selected page element, and a full-screen screenshot you submit through the feedback widget, which may capture whatever is on your screen at the time.
- Client-side UI telemetry: a random per-session identifier, route names, grouped and anonymized API endpoint paths (with numeric and hex identifiers removed), HTTP method and status, web-vitals and performance timings, JavaScript error types, and release version. This telemetry does not include user identifiers in its payload and can be disabled.
- Advertising measurement data: after you accept measurement cookies, the OpenAI Ads pixel may process the ChatGPT ad click reference (oppref), page origin, timestamp, browser/device and network signals, and a registration_completed event when account registration is verified. The Google tag may process Google ad-click attribution data and a purchase conversion only after Stripe confirms a completed, paid checkout; that event includes a value of USD 1 and the unique Stripe Checkout session identifier as a transaction ID so Google can deduplicate repeat visits. Neither explicit event sends registration form fields, an email address, or full payment-card details.
5. Statutory Categories of Personal Information (CCPA)
For the purposes of the California Consumer Privacy Act (CCPA), as amended by the CPRA, and to assist understanding under comparable US state laws, the list below maps the personal information described above to the statutory categories, identifying for each category the sources, the business or commercial purposes for which we process it (as further described in the "How We Use Information" section), the categories of recipients to whom we disclose it, and the default retention approach (as further described in the "Data Retention" section). We collect these categories from you, from your use of the service, from our customers (where you are their alert recipient, monitoring subject, or status-page subscriber), and from identity providers and public or customer-specified target endpoints. We disclose these categories only to the categories of recipients described in the sharing and sub-processor sections, namely our service providers and sub-processors, recipients a customer directs us to send data to, and, where reasonably necessary, legal, security, and corporate-transaction recipients. We do not sell or share any of these categories, including sensitive personal information, and we do not use them for cross-context behavioral advertising.
- Identifiers (name, email address, account and organization identifiers, IP address, online identifiers): collected from you, your use of the service, customers, and identity providers; used to create and secure accounts, authenticate users, operate the service, and maintain security and audit logs; disclosed to email, identity, logging, and (where applicable) payment sub-processors and customer-directed recipients; retained on the controller-role basis described in the retention section (for example, audit events for about 365 days by default; account identifiers until deleted, subject to the active-account standard).
- Customer records information (account credentials in protected form and contact details associated with an account): collected from you; used for authentication, account management, billing, and support; disclosed to email, billing, and logging sub-processors as needed; retained until the account is deleted, subject to the active-account standard.
- Commercial information (plan, subscription, and billing-status records): collected from you and from billing administration; used for billing and subscription management; disclosed to an optional payment provider where billing is enabled; retained until deleted, subject to legal and accounting requirements.
- Internet or other electronic network activity information (session metadata, audit logs, login activity, probe telemetry, client-side UI telemetry, and request/response diagnostics): collected from your use of the service and from probes against customer-specified targets; used to operate, secure, and improve the service; disclosed to logging, storage, and email sub-processors and customer-directed recipients; retained per the default windows (for example, probe results about 90 days, notification delivery records about 180 days, browser-check artifacts about 14 days, audit events about 365 days).
- Geolocation data (approximate, coarse location that may be inferred from an IP address; we do not collect precise GPS location): collected from your use of the service; used for security, audit, and operational purposes; disclosed to logging sub-processors; retained with the associated audit or log records.
- Professional or employment-related information (organization name, role, and work email used in a business context): collected from you and your customer; used to operate organization accounts and memberships; disclosed to email and logging sub-processors; retained until the account or membership is deleted, subject to the active-account standard.
- Sensitive personal information (account log-in credentials and multi-factor authentication data, and any precise data a customer may choose to configure or that may appear in probe artifacts): collected from you and, for artifacts, from customer-specified targets; used only for the limited purposes permitted by law (providing the service, ensuring security and integrity, and preventing fraud) and not to infer characteristics about anyone; disclosed only to the sub-processors and customer-directed recipients needed to provide the service; retained per the relevant retention window (for example, browser-check artifacts about 14 days, MFA data until the factor or account is removed). We do not sell or share sensitive personal information and do not use it to infer characteristics; accordingly, no "Limit the Use of My Sensitive Personal Information" mechanism is required.
- Other information a customer directs us to process (personal information of third parties that may appear in monitor configurations, probe artifacts, alert destinations, or status-page subscriber lists): collected on the customer's instruction from customer-specified sources; processed only as a service provider to provide the service; disclosed only as the customer directs; retained per the applicable artifact or record retention window. The customer is the controller or business for this information.
6. How We Use Information (Purposes)
PageLantern uses information for service delivery, security, support, billing, legal compliance, and limited service improvement. We do not use information for purposes that are incompatible with those for which it was collected. Except as instructed by the customer or permitted by the customer's agreement, we do not use customer monitoring content for our own independent purposes.
- Creating and managing accounts, authenticating users, maintaining sessions, supporting multi-factor authentication and passkeys, and managing organizations and memberships.
- Configuring, running, scheduling, testing, pausing, resuming, and deleting monitors, and executing probes against customer-specified targets.
- Generating and displaying dashboards, probe history, charts, status pages, incidents, reports, and audit logs.
- Sending operational alerts, incident updates, fleet summaries, lifecycle and account emails (such as verification and password reset), report deliveries, and feedback confirmations, and delivering customer-directed notifications to configured destinations.
- Providing customer support and responding to feedback and inquiries.
- Securing the service: detecting, preventing, investigating, and remediating abuse, unauthorized access, fraud, spam, and security or reliability incidents, including by maintaining audit logs and applying probe-target restrictions.
- Billing and subscription administration where billing is enabled.
- Limited service improvement and reliability measurement using aggregated or de-identified operational and UI telemetry.
- Measuring whether ChatGPT ads lead to completed registrations and whether Google ads lead to confirmed purchases, where you have accepted measurement cookies.
- Complying with legal obligations, enforcing our Terms, establishing or defending legal claims, protecting rights and safety, and responding to lawful requests.
7. Legal Bases for Processing (GDPR / UK GDPR)
Where the EU or UK GDPR applies, we rely on a specific legal basis for each purpose rather than a single undifferentiated list. Where we rely on legitimate interests, the specific interests are securing and maintaining the integrity of the service, preventing fraud and abuse, ensuring network and information security, and limited service improvement; we have carried out a balancing assessment for these interests and will provide further information on request. For UK-facing processing, certain of these interests (such as network and information-system security and direct messaging to existing business contacts) may be treated as recognized legitimate interests under the UK Data (Use and Access) Act 2025 reforms.
Providing an email address and authentication credentials is a requirement to create and use a PageLantern account: this information is necessary to perform our agreement with you, and without it we cannot create or operate the account. Customers are responsible for establishing the legal basis for the personal information they configure or push into the service, including monitoring targets, payloads, alert recipients, and status-page subscribers, and for obtaining any consents required (for example, consent for status-page subscription emails).
- Performance of a contract: creating and operating your account, running the monitors and integrations you configure, delivering operational notifications, and providing support and billing.
- Legitimate interests: securing the service, preventing fraud and abuse, ensuring network and information security, maintaining audit logs, and improving reliability, as described above.
- Consent: where required, such as for non-essential first-party UI telemetry and certain optional communications, and for any non-essential cookies if introduced; consent can be withdrawn at any time without affecting prior lawful processing.
- Legal obligation: retaining certain records, responding to lawful requests, and meeting accounting, tax, and security obligations.
- Protection of vital interests or the public interest: only in the rare circumstances where applicable law permits or requires it.
8. Probe Targets, Network Restrictions, and Third-Party Data in Artifacts
Monitoring inherently captures data from the targets a customer specifies. Probe results store a limited excerpt of the monitored target's response body (typically a few hundred characters, and for some monitor types up to roughly two thousand characters), together with error messages, diagnostics, status codes, response times, certificate, DNS, and domain data, and, for browser checks, screenshots, HAR network captures, and console output. These probe artifacts are generated automatically from customer-specified targets and may incidentally contain personal data of third parties. PageLantern does not select, review, or control what those artifacts contain; the customer determines what is monitored and is responsible for that content.
By configuring a monitor, the customer represents and warrants that it is authorized to monitor each target and to cause the requests, payloads, and authentication it configures, and that doing so does not violate any law, contract, or the rights of any third party. PageLantern does not verify authorization and disclaims responsibility for any monitoring a customer is not authorized to perform. PageLantern may throttle, suspend, or remove monitors that it reasonably believes are unauthorized, abusive, unlawful, or a threat to the security or availability of any system. Any indemnity for unauthorized or unlawful monitoring is set out in our separate Terms.
To help protect networks and reduce misuse, the service applies controls intended to restrict probe targets. By default it refuses requests that resolve to private, internal, loopback, or link-local addresses, blocks known cloud-metadata endpoints (such as the link-local metadata address and metadata.google.internal), permits only HTTP and HTTPS schemes, and re-validates each redirect hop against these restrictions. These controls are a security measure and not a guarantee; such restrictions can be incomplete or bypassable, and the customer remains responsible for the targets it configures and for its authorization to monitor them.
Customers should configure monitors against test environments or non-sensitive endpoints wherever possible and must not direct PageLantern to capture special-category or other sensitive personal data. Where customers cause PageLantern to process third parties' personal data, the customer is responsible for providing any required notice to those individuals and for establishing a lawful basis for that processing.
9. Monitor Secrets and Credential Handling
Some monitor configuration includes secrets so that probes can authenticate to a customer's targets. We handle this configuration with the protections actually implemented in the service, and we describe them accurately so that customers can make informed choices about what to store.
API keys are stored only as cryptographic hashes with a non-secret prefix; the full key is shown once at creation and cannot be retrieved afterward. Multi-factor authentication secrets and SMS/email MFA destinations are encrypted at rest, and API authentication-profile secrets are stored encrypted with a masked copy used only for display. The credential-bearing monitor-configuration fields a customer enters — request header values, request bodies, environment variables, API step definitions, browser scripts, and alert webhook URLs — are also encrypted at rest with AES-256-GCM, on every plan, using a versioned envelope that permits key rotation. Sensitive headers, tokens, and destinations are additionally masked in the interface and in logs.
Heartbeat tokens are the one exception and are stored unencrypted. An inbound heartbeat ping is authenticated by matching the token value it presents, which requires the stored value to be readable. Customers should treat a heartbeat URL as a bearer secret, keep it out of public repositories and client-side code, and rotate it if it may have been exposed.
PageLantern does not provide transparent, database-wide encryption at rest, and encryption of the fields listed above is not a substitute for the customer's own judgment about what to store. Where a long-lived credential is required for a check, customers should prefer the dedicated API authentication-profile mechanism, which is purpose-built for it, keeps a masked copy for display, and is scoped to reuse across endpoints.
10. Alerts, Webhooks, and Customer-Directed Disclosures
When a customer configures email recipients, webhooks, chat integrations such as Slack, Microsoft Teams, or Discord, paging tools, API clients, or other alert and export destinations, PageLantern transmits the relevant alert, incident, and monitor content to those destinations at the customer's direction. The customer is responsible for the security and lawful use of every destination it configures, and these transmissions are disclosures made on the customer's instruction, not disclosures by PageLantern for its own purposes.
Notification delivery records retain only masked destination information and delivery metadata; raw recipient addresses are not stored in those delivery records. Masking applies to those delivery records, however, and not to the underlying configuration: raw destinations persist where the customer configures them. Status-page subscriber email addresses are stored in plain text within the relevant status-page records, and some integration settings, including webhook URLs, integration keys, and alert email addresses, may be stored in plain text in the browser's local storage on the device used to configure them, in addition to any server-side storage needed to deliver notifications.
11. Public Status Pages and Subscriber Emails
Customers can publish public status pages and send status updates by email to a subscriber list. A visitor may enter their own email address on a public page and choose updates for the whole page or specific components; a customer's owners and administrators may also add an address from inside their workspace. The customer remains the controller of the list and is responsible for the lawfulness of the status communications it publishes. Subscriber email addresses and component preferences are processed by PageLantern on the customer's behalf as part of that status page's records.
Status-page emails include a per-subscriber unsubscribe link and the corresponding List-Unsubscribe and List-Unsubscribe-Post headers, so a subscriber can remove themselves in one click without contacting anyone; a subscriber can also ask the customer that operates the status page to remove them. The customer is solely responsible for having a lawful basis and any required consent to collect subscriber addresses and to send status-page communications, for the accuracy of sender identity and required unsubscribe and physical-address disclosures in those communications, and for promptly honoring unsubscribe requests. Customers are responsible for ensuring their status-page communications comply with applicable email and consent laws, including CAN-SPAM, CASL, and UK PECR.
PageLantern provides the technical means to send these communications on the customer's behalf and at the customer's direction and does not independently verify the lawfulness of any subscriber list. PageLantern may suspend or remove a status page or subscriber list that it reasonably believes violates applicable law or our terms. Subscriber email addresses are stored in plain text within the relevant status-page records and do not have an automated deletion schedule; customers should remove subscribers they no longer have a basis to contact.
13. Sub-Processors
We engage sub-processors to perform parts of the service under written terms requiring confidentiality and data-protection obligations consistent with this notice. A current named list of the sub-processors we use — with each provider's purpose, the personal data involved, and its region where known — is published at pagelantern.com/subprocessors, alongside the categories described below. When we plan to add or replace a sub-processor that processes personal data, we will update that page and give account owners at least 30 days' advance notice by email before the new sub-processor begins processing, except where a change must be made on shorter notice for security or legal reasons, in which case we will give notice as soon as reasonably practicable. To object to a new sub-processor, email privacy@pagelantern.com; where a customer's data processing agreement provides for advance notice and a right to object, we will honor that mechanism as set out in that agreement.
The categories of sub-processors and customer-directed recipients we currently use include the following.
- Transactional and alert email delivery: an email-delivery provider (an HTTP email API by default, with an SMTP fallback that may route through a third-party mail provider) processes recipient addresses and the content of alerts, incident notices, summaries, lifecycle and verification emails, and feedback confirmations.
- SMS / telephony delivery: Twilio receives the recipient phone number and the message content in order to deliver SMS monitor and incident alerts on paid plans, and one-time verification codes where SMS-based multi-factor authentication is enabled.
- Identity providers for social login: Google, Facebook, Apple, and Microsoft process identity assertions (provider subject identifier, email, display name) when a user chooses to sign in with them. On the public homepage, Google Identity Services may first display an account-selection prompt mediated by Google and the browser; PageLantern receives the Google identity assertion only after the user chooses to continue.
- Object storage for browser-check artifacts: an optional S3-compatible object-storage provider stores screenshots, HAR captures, and console logs, which may contain third-party page content. By default, artifacts are stored on the operator's own filesystem.
- Customer-configured outbound webhook and chat targets: Slack, Microsoft Teams, Discord, generic webhooks, and configurable paging tools receive alert and incident content at the customer's direction.
- Observability and logging infrastructure: a self-hosted logging and observability stack run by the operator processes application logs that include client IP addresses, masked request paths, and event metadata.
- Payment provider: Stripe processes checkout, payment methods, subscriptions, invoices and refunds for paid plans. No full card number is processed within the PageLantern service itself.
- Feedback destination mailbox: feedback submissions, including the submitter's email, message, page URL, and screenshot image, are delivered by email to a support mailbox operated by PageLantern, which is hosted by a third-party email provider.
- Website, application, and Google Ads measurement: Google Analytics 4 receives usage measurement data — page or screen viewed, referrer, approximate location derived from a truncated IP address, device and browser characteristics, and, once you accept measurement cookies, a randomly generated analytics identifier. Google Ads receives limited ad-click attribution data and, after a server-confirmed purchase, the conversion label, USD 1 value and a unique transaction ID. Ad personalization is disabled and we do not send enhanced-conversion identity data.
14. No Sale, Sharing, or Cross-Context Behavioral Advertising
Within the meaning of the CCPA/CPRA and other US state privacy laws, PageLantern does not sell personal information and does not share it for cross-context behavioral advertising, and has not knowingly done so. Where any look-back disclosure is required of us under applicable law, it will be provided once the service has a corresponding operating history.
We do not use customer monitor configuration, probe results, alert destinations, status-page content, subscriber lists, incident data, or support communications to train, fine-tune, or develop machine-learning models, except for de-identified or aggregated operational data used solely to operate, secure, and improve the service.
Because we do not sell or share personal information, there is nothing to opt out of, and no "Do Not Sell or Share My Personal Information" or "Limit the Use of My Sensitive Personal Information" mechanism is required. We still honor recognized opt-out preference signals as described below, and you may contact us to exercise any applicable right. We do not disclose personal information to third parties for those third parties' own direct-marketing purposes. Accordingly, the California "Shine the Light" law does not require us to provide a separate accounting.
15. Opt-Out Preference Signals and Global Privacy Control
Several US state privacy laws require businesses to honor universal opt-out mechanisms such as the Global Privacy Control (GPC), which can be enabled at the browser or device level without creating an account or taking any further step. Because PageLantern does not sell or share personal information, there is no sale or sharing to opt out of.
To the extent the Global Privacy Control or another recognized opt-out preference signal is technically applicable to our service, we will treat any such signal as a confirmed opt-out and will honor it automatically, without requiring you to create an account or take additional action. Because PageLantern does not sell or share personal information, such a signal does not change how we process your information.
17. Security Measures (No Guarantee)
The measures below describe the service as configured for production operation; certain protections (for example, marking the session cookie Secure and requiring database TLS) are configuration-dependent and are enforced in production by a startup hardening check. Our current measures include, and may change over time as we improve them: hashing of passwords with a strong, salted, iterated algorithm; storing session tokens, API keys, verification and reset tokens, WebAuthn credential identifiers, and MFA recovery codes only as hashes; encrypting MFA secrets, MFA destinations, API authentication-profile secrets, and the credential-bearing monitor-configuration fields (request header values, request bodies, environment variables, API step definitions, browser scripts, and alert webhook URLs) at rest with AES-256-GCM under a versioned, rotatable key envelope; masking secrets in logs and interfaces; an httpOnly, SameSite session cookie so the client never holds the raw token; default restrictions on probing private, internal, loopback, or cloud-metadata network targets; an audit trail that records actor, client IP, and user-agent with safe client-IP resolution; configurable data-retention jobs; and a production-hardening check that prevents startup with default development secrets.
Not all data is hashed or encrypted. As described in the section on monitor secrets, heartbeat tokens are stored in plain text at rest because an inbound ping is matched by token value rather than by hash, and status-page subscriber email addresses are stored in plain text within the relevant status-page records. Probe results, incident text, and monitoring history are stored without field-level encryption. The specific mechanisms described reflect our current implementation and may be updated, replaced, or removed as the service evolves; we will maintain measures appropriate to the risk but do not guarantee that any particular control remains in place.
No method of transmission over the internet or method of electronic storage is completely secure, and PageLantern does not warrant or guarantee absolute security. We do not claim that all data is encrypted at rest. If you believe a PageLantern account, API key, alert destination, or integration has been compromised, contact security@pagelantern.com promptly.
18. Service Limitations and No Reliance for Safety-Critical Use
Monitoring results, status codes, response times, certificate and DNS data, screenshots, and diagnostics are provided for informational and operational purposes only. They may be delayed, incomplete, or inaccurate and are not a guarantee of a target's actual availability, security, or correctness.
The service is not designed for use where the failure, delay, or inaccuracy of monitoring data could lead to death, personal injury, or severe environmental or property damage. Customers must not rely on the service as the sole control for emergency, life-safety, or other safety-critical decisions.
19. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this notice, after which we delete or de-identify it, subject to legal, security, audit, billing, and dispute-resolution requirements. Different data types are retained for different periods based on operational need, product settings, and legal requirements. Retention windows are operator-configurable, so the default periods below are starting points rather than fixed guarantees: they may be lengthened, shortened, or, for some categories, disabled by the operator. Where automated deletion is disabled or is not configured for a category, we retain that data only for as long as the account or the relevant configuration remains active and for a reasonable period afterward, we may delete or de-identify inactive data, and we do not commit to retaining any data indefinitely.
Some data does not have an automated deletion schedule and persists until it is manually deleted or until the active-account standard above applies, including account, organization, monitor, monitor-header, API authentication-profile, API key, MFA, feedback (including screenshots), and billing and status-page subscriber records. Customers can delete much of this content through the service, and you may contact us about deletion as described in the rights sections. On termination, customer data is deleted or returned in accordance with the applicable agreement, subject to backups and legal-hold obligations.
- Probe results: deleted after about 90 days by default.
- Audit events: deleted after about 365 days by default.
- Notification delivery records: deleted after about 180 days by default.
- Browser-check artifacts (screenshots, HAR captures, console logs): deleted after about 14 days by default.
- Account, organization, monitor, credential, billing, feedback, and status-page subscriber records: retained until deleted or until the active-account standard applies, subject to legal and operational requirements.
- Session and verification/reset tokens: limited by their own expiry timestamps.
- Free plan inactivity: after 45 consecutive days with no sign-in, monitoring and notifications for the account are paused, following reminder emails at 30, 40 and 44 days. The pause itself deletes nothing, and any sign-in resumes monitoring and restarts the period. A Free plan account may, however, be terminated as described in Section 11 and Section 17 of the Terms of Service — including on at least 30 days' notice where it remains inactive for an extended period — after which the post-termination export and deletion timetable described in this section applies.
- After an account is closed: access ends immediately and status pages are unpublished; data remains exportable for 30 days; it is then deleted from active systems within 30 days and from backups within 90 days. Where we terminate for unauthorized monitoring, prohibited data, or acceptable-use breach, deletion may be immediate with no export window.
20. International Data Transfers
PageLantern and its service providers may process and store information in countries other than the one in which you are located, including for hosting, email delivery, SMS/telephony delivery, identity, storage, and support. This means your information may be transferred across borders.
Where personal data is transferred out of the European Economic Area or the United Kingdom to a country that does not benefit from an applicable adequacy decision (such as transfers to a recipient certified under the EU-US Data Privacy Framework and its UK extension, where available), we rely on appropriate safeguards, such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. You may request information about, and a copy of, the safeguards we rely on by contacting privacy@pagelantern.com.
21. Your Privacy Rights
Depending on where you live and which laws apply, you may have some or all of the rights below. These rights are subject to verification and to the exceptions and limits permitted by applicable law (for example, where we must retain data to comply with a legal obligation, for security, or to establish or defend legal claims), and we will respond to the extent and in the manner required by law. Erasure and other rights are not absolute and may not apply where an exception is available.
Where the personal information at issue is customer-controlled monitor configuration, probe artifacts, alert destinations, or status-page subscriber data, we act as a processor. Where we can reasonably identify the customer that controls the relevant data, we will refer or forward your request to that customer and assist as required by law and our agreements. Because the same personal information may appear in multiple customers' configurations, or may not be attributable to a specific customer, we may be unable to locate or act on processor-role data without sufficient identifying information, and in such cases we will direct you to contact the relevant customer directly.
- Access or know: obtain confirmation of, and access to, the personal information we hold about you, and information about how it is processed.
- Rectification or correction: correct inaccurate or incomplete personal information.
- Erasure or deletion: request deletion of your personal information, subject to legal exceptions.
- Restriction and objection: restrict or object to certain processing, including processing based on legitimate interests.
- Portability: receive certain personal information in a portable format.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Opt out of sale, sharing, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects: although, as explained in this notice, PageLantern does not engage in these activities.
- Limit the use of sensitive personal information: although, as explained above, we use sensitive personal information only for the limited purposes the law permits, so no limitation mechanism is required.
- Obtain a list of specific third parties: where a state law such as Oregon's provides it, request a list of the specific third parties (or, at our option where permitted, categories of third parties) to which we have disclosed personal information.
- Non-discrimination: you will not receive discriminatory treatment for exercising your rights.
- Appeal: where a US state law provides it, appeal a decision on your request as described below.
- Lodge a complaint: complain to a data-protection or supervisory authority, as described in the supervisory-authorities section.
22. How to Exercise Your Rights, Verification, and Appeals
You can exercise your rights by contacting privacy@pagelantern.com and, where available, by using in-product account and data controls. PageLantern operates exclusively online and maintains a direct relationship with its account holders, so we designate an email address and online methods rather than a toll-free telephone line. We will respond to verifiable requests within the timeframes required by applicable law; for most US state privacy laws this is within 45 days of receipt, extendable by an additional period (typically 45 days) where reasonably necessary and permitted, and for the EU and UK GDPR generally within one month, extendable where the law allows.
We may take reasonable steps to verify your identity before acting on a request, and we may decline requests that are manifestly unfounded or excessive or charge a reasonable fee where the law allows. An authorized agent may submit a request on your behalf; we may require the agent to provide proof of written authorization and may require you to verify your own identity directly and confirm the authorization. Where a US state law permits an appeal, you may appeal a decision free of charge by emailing privacy@pagelantern.com with the subject line "Privacy Appeal"; we will respond to the appeal within the period the applicable law requires (commonly within 45 or 60 days), and if we deny your appeal you may contact the Attorney General or relevant regulator in your state.
We do not offer financial incentives or price or service differences in exchange for the retention or processing of personal information, so no notice of financial incentive applies. Where we publish request metrics because a legal threshold applies to us, we will do so as required; we do not assert that any such metrics report currently exists. For UK-facing processing, you may complain to us directly about how we handle your personal data, and we will acknowledge complaints within the period required by applicable law.
23. Automated Decision-Making and Profiling
PageLantern's automated alerting and incident detection compare monitoring results against the success criteria a customer configures and generate notifications accordingly. This is operational notification and does not produce legal or similarly significant effects on individuals.
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects on individuals within the meaning of Article 22 of the GDPR and UK GDPR or that is subject to a profiling opt-out under US state privacy laws. Where a state law provides a right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, there is no such profiling to opt out of. If this changes, we will update this notice and provide the additional information, opt-out, and safeguards the law requires.
24. Sensitive Data and Children's Data
The service is not designed to process special-category data (such as data revealing health, racial or ethnic origin, or similar categories) or other sensitive personal information beyond the account credentials and authentication data needed to operate the service. Customers must not configure monitors, alerts, or status pages to capture special-category or other sensitive personal data; if a customer does so, the customer acts as controller and is solely responsible.
PageLantern is intended for business and professional users. It is not directed to children, and we do not knowingly collect personal information from anyone under 16, or, within the meaning of the US Children's Online Privacy Protection Act (COPPA), from any child under 13. We do not sell or share the personal information of minors or use it for targeted advertising. If we learn that we have collected personal information from someone under 16 (or under 13 under COPPA) other than on a customer's instruction, we will take steps to delete it.
25. Personal Data Breaches
We maintain measures designed to detect and respond to personal data breaches. Where PageLantern acts as a controller and a breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within the timeframe required by law, and we will notify affected individuals where the law requires.
Where PageLantern acts as a processor for customer-configured data, we will notify the affected customer (as controller) without undue delay after becoming aware of a personal data breach affecting that data, so that the customer can meet its own notification obligations.
For customer-configured data where PageLantern acts as a processor, the customer, as controller, is responsible for any required notifications to supervisory authorities and to affected individuals; PageLantern's obligation is limited to notifying the customer and providing reasonable assistance. Nothing in this notice obliges PageLantern to notify regulators or individuals regarding breaches of data for which it is not the controller.
27. Changes to This Notice
We may update this notice from time to time. When we do, we will revise the effective and last-updated dates and, for material changes, provide reasonable notice through the service or other appropriate means. We may make non-material changes (such as clarifications, formatting, or contact-detail updates) at any time without separate notice by posting the revised notice with an updated date. Your continued use of the service after the effective date of a change constitutes acknowledgment of the updated notice to the extent permitted by law. Changes apply prospectively from the stated effective date; we do not apply material changes retroactively to previously collected information without notice where notice is required.
Each provision of this notice is intended to be severable. If any provision is held unenforceable, the remainder continues in effect, and the notice should be read consistently with applicable law. This Privacy Notice describes our data practices; it does not form part of, and does not import liability caps, indemnities, arbitration, or class-action waivers from, our separate Terms.
28. Contact
For privacy questions, rights requests, appeals, or security reports, contact PageLantern using the details below. Please include enough information for us to understand and verify your request.
- Privacy questions and rights requests
- privacy@pagelantern.com
- Security reports
- security@pagelantern.com
- Acceptable Use Policy
- pagelantern.com/acceptable-use
- SMS consent and message flow
- pagelantern.com/sms-consent
Postal mail: PageLantern LLC (d/b/a PageLantern), PO Box 340351, Lakeway, TX 78734.
Change Log
- August 31, 2026: Added consent-gated Google Ads purchase conversion measurement. Sections 4, 6, 12, 13, and 16 now describe the Google ad-click attribution data, the server-confirmed purchase boundary, the USD 1 conversion value, the Stripe Checkout session identifier used for duplicate prevention, and the continued prohibition on ad personalization and enhanced-conversion identity data.
- August 27, 2026: Added the consent-gated OpenAI Ads measurement pixel used to attribute completed registrations to ChatGPT ads. Sections 4, 6, 12, and 16 now describe the limited click-reference and registration-event data involved, the USD 0 conversion value, the shared measurement-cookie choice, and OpenAI's role as measurement provider. The current sub-processor list was updated at the same time.
- August 17, 2026: Updated Section 11 for the launch of public status-page self-subscription. Visitors can now provide their own email address and choose updates for the whole page or named components; PageLantern stores that preference with the customer's status-page record, sends confirmation and customer-facing incident or maintenance updates, and includes a one-click unsubscribe link in every message. Customer owners and administrators can still manage subscriber addresses from the workspace.
- August 16, 2026: Corrected the description of how status-page subscriber lists are built. Section 11 said customers can "allow end users to subscribe to status updates by email," which reads as public self-subscription. The service has never offered that: a published status page carries no sign-up form, and the only route that adds a subscriber requires an owner or administrator signed in to the workspace. Section 11 now states plainly that the customer supplies the list, which is also why the customer — not the subscriber's own opt-in — is the party responsible for having a lawful basis to contact them. The one-click unsubscribe available to every subscriber is unchanged. No processing changed; this corrects the description, not the practice.
- August 14, 2026: Added the PageLantern SMS Alerts disclosures required at the point of opt-in: an explicit statement that mobile numbers and messaging consent are not shared with third parties or affiliates for marketing or promotional purposes, the purpose-limited disclosure to Twilio and mobile carriers for delivery, message-frequency and data-rate notices, and a link to the public SMS consent and message-flow page. The authenticated SMS integration now requires a separate affirmative consent control and records the disclosure version, timestamp, and acting user with the channel.
- August 11, 2026: Revised the Free-plan inactivity disclosure. The notice previously stated that nothing is deleted because of inactivity; it now states that the 45-day pause itself deletes nothing, and separately that a Free plan account may be terminated under the Terms of Service — including on at least 30 days' notice where it remains inactive for an extended period — after which the standard post-termination export window and deletion timetable apply. The Terms of Service (version 2.2.0) and Refund and Cancellation Policy were updated on the same date to state the same rule. The pause behaviour, the reminder schedule, and the deletion timetable itself are unchanged.
- August 7, 2026: Corrected the encryption-at-rest disclosure, which had been wrong in our own disfavour. Sections 9 and 17 stated that monitor request headers, request bodies, environment variables and other credential-bearing configuration fields were stored in plain text. That stopped being true when field-level AES-256-GCM encryption shipped for those columns; only heartbeat tokens are genuinely stored unencrypted, and only because an inbound ping is authenticated by matching the token value. Both sections now describe what the service actually does, name heartbeat tokens as the single exception and explain why, and continue to state plainly that we do not provide transparent database-wide encryption at rest. No processing changed — this corrects the description, not the practice. Also recorded the addition of a contract-assent log (the account, timestamp, IP, user agent and document version recorded when a user accepts our terms) under Sections 4 and 19.
- August 4, 2026: Disclosed Google Analytics 4, which now measures usage of our website and application. Section 16 previously stated that we set no third-party analytics cookies; it now describes the tag, the consent defaults that keep it from writing analytics cookies until a visitor accepts, the lawful bases, the "Cookie preferences" control for withdrawing consent, and the _ga cookies themselves. Google is described as the analytics sub-processor in Section 13 and on the Sub-processors page. We use no advertising features and continue not to sell or share personal information.
- August 3, 2026: Corrected three statements that had fallen out of step with the running service, and aligned the notice with the new legal document set. The separate data processing agreement this notice referenced now exists and is published at pagelantern.com/dpa, applying automatically to every customer; the status-page unsubscribe description was corrected because per-subscriber unsubscribe links and RFC 8058 List-Unsubscribe headers now ship; and billing and SMS were updated from "optional" and "not yet engaged" to name Stripe and Twilio, which are live. Added the operating entity and its postal address, the Free-plan 45-day inactivity pause (which deletes nothing), and the post-termination export and deletion timetable, stated identically here, in Section 18 of the Terms of Service, and in Section 12 of the Data Processing Terms.
- June 18, 2026: Comprehensive revision of the PageLantern Privacy Notice. Expanded to fully address EU and UK GDPR, California CCPA/CPRA, and other US state privacy laws (including Virginia, Colorado, Connecticut, Texas, and Oregon); clarified the controller/processor and business/service-provider split and anchored it to a separate data processing agreement; mapped statutory categories to sources, purposes, recipients, and retention; corrected the response-excerpt size and disclosed heartbeat tokens and other monitor-configuration fields as plain text at rest; added an SMS/telephony sub-processor and a third-party feedback mailbox; described SSRF and cloud-metadata probe restrictions and redirect re-validation; replaced the unsubscribe wording with an accurate account of status-page email handling; added customer authorization warranties, a present-practice no-sale/no-model-training statement, an active-account retention standard, response and appeal timeframes, source disclosures, a frictionless Global Privacy Control statement, COPPA under-13 and no-minor-sale language, an Oregon third-party-list right, a processor-role breach carve-out, and a legal-entity and postal-address placeholder.
Important Note
This Privacy Notice is a practical, accuracy-first baseline describing how the PageLantern service currently operates. It is not legal advice and does not create rights or obligations beyond those required by applicable law. Privacy and data-protection requirements vary by jurisdiction and change over time, and one disclosure here — the appointment and contact details of our EU and UK Article 27 representatives — is still outstanding and will be published before we offer the service to individuals in those regions. Regulated, multi-jurisdiction, high-volume, or otherwise high-risk deployments should be reviewed by qualified privacy counsel, and PageLantern's customers remain responsible for their own compliance with the laws that apply to the data they configure and process through the service.
