Legal

Privacy Policy

What we collect, why, who sees it and how long it stays. Written for the people who have to review it, not to bury them.

Effective 20 September 2026 · Last updated 20 September 2026

At a glance

  • We collect what we need to run your account and bill you, and nothing for advertising. We never sell personal data.
  • We use PostHog analytics with one first-party cookie, Do Not Track honoured, to see which pages lead to sign-ups. No advertising trackers anywhere.
  • Your telemetry is yours. We process it as your processor, only to provide the Service, and staff access is limited and logged.
  • Payments go through Paddle; we never see full card numbers.
  • Telemetry is kept for your plan’s retention period, then deleted. After a subscription ends it is kept for 30 days, then it is deleted.
  • You can access, correct, delete or export your data by emailing support@polartrace.io.

This summary is for convenience only. The numbered sections below are the binding text.

1.Scope and our two roles

This Privacy Policy explains how [Registered company name], trading as Polartrace (Polartrace, we, us), handles personal data when you visit https://polartrace.io, use the console at https://console.polartrace.io or your workspace subdomain (<workspace>.polartrace.io), install our agents, or contact us. It should be read with our Terms of Service.

We act in two different roles, and this policy is organised around them:

  • Data controller for the personal data we collect about you and your team directly: website visits, accounts, billing, security logs and support correspondence (sections 2 to 4).
  • Data processor for the telemetry your applications send to your workspace (Customer Data). Your organisation decides what to send and is the controller; we process it only on your instructions (section 5).

2.Personal data we collect as a controller

Visitors to polartrace.io

The marketing site uses PostHog, a product-analytics service, to record the pages you view, the links and buttons you click, your device and browser type, your approximate location derived from your IP address, and, for a sample of visits, a replay of how the page was used with everything you type masked. It sets one first-party analytics cookie (section 10) and honours your browser’s Do Not Track setting. There are no advertising or cross-site tracking scripts. Our servers and Cloudflare, which sits in front of every Polartrace host, record standard request logs (IP address, user agent, requested URL, timestamp, and referrer if your browser sends one) to serve the site and protect it from abuse. If you email us from the contact page, we keep that correspondence.

Account and workspace data

  • Identity: your name, email address, a salted hash of your password (never the password itself), your email verification status, and, if you sign in with Google, the name, email address and profile picture Google shares with us.
  • Workspace: the organisation name and subdomain, your role and team memberships, invitations you send or accept, and settings such as environments, services, monitors and alert routes.
  • Keys and integrations: API keys and agent keys for your workspace, and the configuration of integrations you connect, such as the Slack destination for alerts.

Billing data

Paddle, our merchant of record, collects and processes your payment details under its own privacy policy; we never receive full card numbers. We store your billing name and address, tax ID if you enter one, plan and subscription status, Paddle transaction and invoice references, and the usage records (gigabytes ingested and billable hosts per month) that determine your usage charges.

Security and audit data

To keep accounts safe we log sign-in attempts and outcomes with the IP address and user agent, count failed sign-ins so we can lock an account under attack, and keep an audit log of administrative actions in each workspace (who changed what, and when).

Communications

When you write to support@polartrace.io we keep the thread so we can help you and refer back to it.

3.How we use it and our legal bases

PurposeData usedLegal basis (GDPR)
Provide the Service: sign you in, run your workspace, store and display telemetry, send alertsAccount, workspace, keys and integrationsPerformance of a contract
Bill you: meter usage, invoice through Paddle, handle refunds and disputesBilling and usage recordsPerformance of a contract; legal obligation for tax records
Keep accounts and the Service secure: detect abuse, lock attacked accounts, investigate incidentsSecurity and audit data, request logsLegitimate interest in security
Tell you things you need to know: verification, invitations, sign-in alerts, usage alerts, billing notices, changes to termsEmail addressPerformance of a contract; legitimate interest in security
Answer support requestsCommunications, account dataPerformance of a contract; legitimate interest
Understand how the site and console are used (pages, clicks, the path from first visit to sign-up) and improve themAnalytics data: pages, clicks, device, approximate location, analytics cookie idLegitimate interest in improving the Service; consent where your local law requires it for analytics cookies
Comply with law and enforce our termsWhatever is relevant to the obligation or claimLegal obligation; legitimate interest

We do not send marketing email without your consent, and every email that is not strictly necessary to operate your account will include a way to opt out. We do not make automated decisions about you that have legal or similarly significant effects.

4.Sharing and sub-processors

We do not sell personal data and we do not share it with advertisers or data brokers. We share personal data only with the providers below, who process it on our behalf under contracts that restrict their use of it; with professional advisers when needed; with authorities when the law requires it, after challenging requests we consider improper; and with a successor if Polartrace is acquired or merged, in which case this policy continues to apply.

Sub-processorWhat it does for usWhen it is involved
CloudflareDNS, content delivery and edge security in front of every Polartrace hostAlways
Amazon Web ServicesCloud infrastructure and object storage (Asia Pacific, Mumbai region)Always
MongoDB AtlasDatabase for account, workspace, billing and configuration recordsAlways
ClickHouseColumnar database that stores telemetry (traces, logs, host and Kubernetes metrics)Always
PaddleMerchant of record: checkout, payment processing, invoicing, sales tax and VATPaid plans
PostHogProduct analytics: page views, clicks and masked session replays on the site and consoleAlways (honours Do Not Track)
ResendTransactional email (verification, invitations, usage and billing notices, alerts)Always
GoogleSign in with Google (OAuth)Only if you sign in with Google
SlackDelivery of monitor alerts to a Slack workspace you connectOnly if you connect Slack

We will update this list before adding a sub-processor that handles Customer Data. If you have a data processing agreement with us, we will notify you of additions as it provides.

5.Telemetry: Customer Data we process for you

The Polartrace agents and integrations send your workspace:

  • Traces and spans: service and endpoint names, timings, status codes, database statements (literal values are scrubbed to placeholders by the Node.js PostgreSQL integration), and attributes your code adds.
  • Request logs: log lines and their metadata, which may include user identifiers, IP addresses, email addresses or anything else your application writes to its logs.
  • Host metrics: hostnames, CPU, memory and similar resource figures.
  • Kubernetes data: node, pod and workload names and states, and cluster events, from the read-only cluster agent.

Before data leaves your servers the Node.js agent replaces passwords, tokens, API keys, authorisation headers, cookies and card fields with [REDACTED], and the Python agent redacts credential-like fields in request bodies and span attributes. They cannot recognise every sensitive value, so you remain responsible for what your applications emit. We process Customer Data only to provide the Service to your workspace, to keep it secure, and as the law requires. People in your workspace with the right role can read and search it; Polartrace staff access it only to support you or to investigate abuse or incidents, and that access is logged.

If you are an individual whose data appears in a customer’s telemetry, please contact that organisation first; it controls the data and decides how to respond. We will help it do so.

6.Where data is stored and international transfers

Our primary hosting region is [Primary hosting region, e.g. Asia Pacific (Mumbai)]. Some sub-processors listed above operate in other countries, including the United States and the United Kingdom. Where data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism, and we can provide copies on request.

7.How long we keep data

DataRetention
Telemetry (Customer Data)The retention period of your plan, currently 3 to 30 days on self-serve plans and as agreed on Enterprise, deleted on a rolling basis. After a paid subscription ends, agents can keep sending for 7 days and data is kept for 30 days (resubscribe to regain access), then it is deleted.
Account and workspace dataFor as long as your workspace exists. When the owner asks us to close a workspace we delete it within 30 days, except records we must keep by law.
Billing and usage recordsFor as long as tax, accounting and audit laws require, typically several years after the transaction.
Security and audit logsFor as long as reasonably necessary to detect and investigate abuse or incidents, then deleted.
Request logs (site and console)A short period sufficient to operate and secure the Service, then deleted or aggregated.
Support correspondenceFor as long as needed to help you and to keep a record of what was agreed.

Deleted data may persist for a limited period in encrypted backups, which we use only for disaster recovery and never to restore data a customer has asked us to delete.

8.How we protect data

  • All traffic to the site, the console, the API and the collector endpoints is encrypted in transit with TLS.
  • Passwords are stored as salted hashes. Sessions use HTTP-only, secure cookies, and accounts lock temporarily after repeated failed sign-ins.
  • Access inside a workspace is governed by roles you assign, and administrative actions are recorded in an audit log.
  • API and agent keys are scoped to a single workspace and can be revoked at any time from the console.
  • Staff access to production systems and Customer Data is limited to what is needed to operate and support the Service.
  • Agents redact credential fields at the source, before data reaches us (section 5 says exactly what each agent redacts).

No system is perfectly secure. If we become aware of a breach affecting your personal data or Customer Data, we will notify you without undue delay and tell you what we know and what we are doing. We do not currently hold a third-party security certification; ask us at support@polartrace.io if you need more detail for a vendor review.

9.Your rights

Depending on where you live, laws such as the EU and UK GDPR, the California Consumer Privacy Act and India’s Digital Personal Data Protection Act, 2023 give you rights over your personal data. Wherever you are, you can ask us to:

  • access the personal data we hold about you and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data, subject to records we must keep by law;
  • restrict or object to processing based on legitimate interests;
  • receive data you gave us in a portable format;
  • withdraw consent where processing is based on it, without affecting earlier processing.

Email support@polartrace.io from the address on your account. We will verify the request, respond within 30 days, and never discriminate against you for exercising a right. You may also complain to your data protection authority; we would appreciate the chance to address your concern first. Requests about data inside a customer’s telemetry should go to that customer, as explained in section 5.

California residents: we do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months.

10.Cookies and similar technologies

polartrace.io sets one first-party analytics cookie from PostHog (named ph_…_posthog, on .polartrace.io, kept for up to a year) that gives your browser a random id so we can count visits and see which pages lead to sign-ups. It is shared with the console for the same reason. We honour the Do Not Track setting, and blocking or deleting the cookie does not affect the site.

The console uses only strictly necessary cookies: an access token and a refresh token that keep you signed in, both HTTP-only, secure and restricted to our domains, and a short-lived state cookie during Google sign-in to prevent request forgery. They are not used for advertising or cross-site tracking. Beyond these and the PostHog analytics cookie above, there are no third-party cookies. Because the sign-in cookies are essential, the console cannot work without them; signing out clears them.

11.Children

The Service is for business use by people aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe we have, tell us at support@polartrace.io and we will delete it.

12.Changes to this policy

We will post any changes at https://polartrace.io/privacy with a new effective date, and email workspace owners at least 30 days before a change that materially affects how we use personal data.

13.Contact

[Registered company name], trading as Polartrace
[Registered office address]
support@polartrace.io