Skip to content
SutramX
  • All features
  • All guidesAll free toolsCompare SutramX
  • All use cases
  • Documentation
  • Integrations
  • Pricing
Sign inStart free
SutramX
Pricing
Docs & HelpIntegrations
Start freeSign in

Privacy Policy

Last Updated: October 10, 2026

This policy explains what personal data SutramX collects when you use our website and monitoring service, why we collect it, who we share it with, how long we keep it, and the rights you have. We have tried to keep it plain and specific.

1. Who we are

SutramX is operated by QuantumPlug Technologies LLP ("SutramX", "we", or "us"), registered at Darbhanga, Bihar, India. For personal data about our own account holders (for example, your login and billing contact details) we act as the data controller. For personal data that customers put into the service — for example, alert recipients' email addresses, or data contained in monitored responses — we act as a processor on the customer's behalf, under our Data Processing Addendum, which forms part of our Terms of Service.

2. Data we collect

  • Account data: name, email address, hashed password, workspace and team membership, time zone and notification preferences, and two-factor authentication settings.
  • Billing data: plan, billing country, subscription status, and invoice history. Card, UPI, and other payment details are collected and processed directly by our payment providers; we do not store full card numbers.
  • Monitor configuration: target URLs, hosts and ports, request settings, custom request headers, request bodies and credentials (encrypted at rest), check intervals, and alert channel details such as email addresses, chat webhooks, and integration keys.
  • Monitoring results: check outcomes, status codes, response timings, response snippets, certificate details, and incident history for the targets you monitor.
  • Status page subscribers: email addresses that visitors submit to a status page, kept only after they confirm by email; and Slack or webhook URLs that visitors subscribe with (encrypted at rest), kept only after a test message is delivered. An address that is never confirmed is deleted 7 days after the confirmation email, and an unsubscribed one 30 days after unsubscribing.
  • Logs: security and operational logs such as sign-in events and sessions (device, browser, IP address), user agents, API usage, audit events (for example invitations, API key changes, exports and deletion requests), and alert delivery records; and our internal event log of activity on accounts, such as emails we sent, payments and plan changes, and sign-ups, sign-ins or requests we refused or rate-limited, which can include the email address and IP address involved.
  • Mobile app: if you use the SutramX mobile app, your account email address, name and user ID, and a device identifier: the Expo push token for your device, with the device name or model, platform, operating system version and app version. We use them only to sign you in and deliver alerts to your phone, and to list the device among your signed-in sessions.
  • Website analytics: if you accept analytics cookies in the banner on sutramx.com, we use Google Analytics (provided by Google, loaded through Google Tag Manager), which sets the _ga cookies to recognise returning visits and records the pages you view, how you arrived, your approximate location (from your IP address, which Google does not store) and your device and browser. Google signals and ad personalisation are turned off.
  • Page performance: on sutramx.com our network provider Cloudflare measures how fast pages load with Cloudflare Web Analytics. It sets no cookies and uses no browser storage, does not recognise returning visitors and does not build a profile of you; it receives the page address, load timings and your browser details, and sees your IP address as part of the connection. It is not used in the SutramX dashboard or on status pages.
  • Product analytics: if you accept analytics cookies on sutramx.com (the SutramX dashboard follows that choice and never asks separately), we also use PostHog (provided by PostHog, Inc. and hosted in the United States), which sets ph_ cookies and local storage to recognise returning visits across sutramx.com and app.sutramx.com. It records the pages you view, the buttons and links you click, actions you take in the dashboard (for example creating a monitor or starting a checkout), how you arrived, your approximate location (from your IP address, which PostHog does not store), your device and browser, and recordings of how pages are used (session replays) in which everything you type into forms is hidden (in the dashboard, all text on screen is hidden too). In the dashboard these events are linked to your internal user ID and plan, never to your name or email address. Web addresses are stored without their query string, so links that carry a token are never recorded. Public status pages, the mobile app and SutramX staff acting on your account are never tracked. We keep analytics events for up to 12 months and session recordings for up to 30 days. We use it to see where people get stuck and to improve the product, never for advertising.
  • Your analytics choice: the legal basis for both is your consent; you can withdraw it at any time with “Cookie settings” in the website footer (the dashboard's settings link there), and the cookies are then deleted. Until you accept, neither script is loaded and nothing is sent to Google or PostHog; if you decline, they are never loaded. You choose once, on sutramx.com, and that choice covers the dashboard too. So that we can show what you chose, each Accept or Decline (and a choice made before October 2026, once, on your next visit) is also recorded on our servers under a random consent ID that your browser keeps with the choice (sx_consent_id). The record holds only that ID, whether you accepted, declined or withdrew, the version of the banner you saw, the time and, when you accept, PostHog's random visitor ID; never your IP address, browser details or location. PostHog events also carry the consent ID. Records are deleted 3 years after they are made.
  • How you found us: when you create an account we store, with it, the optional answer to “How did you hear about us?” (and any short text you type for “Other”), the campaign tags on the link you arrived through (utm_* and ref, for example a SutramX status page footer), the website that linked to you (its host and path, without query strings), the first page you opened and when, and whether you signed up with a password, Google or GitHub. We use it only to count which channels bring signups, never for advertising, and it is not shared with anyone. Without analytics consent the tags are held in the browser tab's memory only; with it they are kept in browser storage (sx_campaign on sutramx.com for the tab, sx_signup_attribution on app.sutramx.com for up to 30 days) so they survive a reload. The record is included in your data export and deleted with your account.
  • State of uptime newsletter: if you sign up on sutramx.com, we store your email address, whether you have confirmed or unsubscribed, which form you used, the version of the consent wording shown next to it, a keyed hash of your IP address (not the address itself) and the first 200 characters of your browser's user agent, as a record of your consent, with the times you signed up, confirmed or unsubscribed. We use the address only to confirm the sign-up and send the monthly issue, never for anything else, and nobody is added without clicking the confirmation link we email; SutramX customers are not added automatically. Every issue has a one-click unsubscribe link (and supports your email app's unsubscribe button). The newsletter goes out through the same email providers as our other email (see sub-processors), and an address on our email suppression list (it bounced or reported spam) is not emailed. The issues themselves contain only aggregate vendor status data, never information about any customer.
  • Communications: messages you send to support and related correspondence.
  • Referral visits: if you follow a partner's referral link, we record the referral code, the landing page, the referring site's host name and a salted hash of your IP address (not the address itself), and, if you sign up, which partner referred your account. The visit record is deleted after 13 months; a signup stays credited to the partner.

SutramX mobile app. Push alerts are sent through Expo's push notification service, which passes them to Apple or Google for delivery (see sub-processors). The app contains no advertising or analytics SDKs, and nothing it collects is used for tracking or advertising. To stop, turn off notifications for SutramX in your phone's settings, sign out of the app (which removes the device's push token), or delete your account in the app under Settings → Delete account.

3. How we use data, and our legal basis

We use personal data only for the purposes below. Under the EU and UK GDPR, each purpose rests on the legal basis shown next to it.

PurposeLegal basis
Creating and running your account and workspaces: sign-in, checks, alerts, reports, status pages, the mobile app and supportContract: needed to provide the service you signed up for (Art. 6(1)(b))
AI incident summaries, postmortems and status updates, on request or automatically on plans that include themContract: a feature of your plan (Art. 6(1)(b))
Payments, invoices, tax and accounting recordsContract, and legal obligation to keep tax and accounting records (Art. 6(1)(b) and (c))
Service and account emails: billing notices, plan-limit notices and security alertsContract (Art. 6(1)(b)); for security alerts also our legitimate interest in protecting your account (Art. 6(1)(f))
Keeping the service secure: sign-in and audit logs, fraud and abuse prevention, error diagnosticsLegitimate interests in protecting our users and the service (Art. 6(1)(f))
Occasional product news emails to account holdersLegitimate interests in telling customers about the service (Art. 6(1)(f)); you can opt out with the link in every such email or in your notification settings
Learning how people find SutramX: the optional "How did you hear about us?" answer and the campaign tags on the link you signed up fromLegitimate interests in knowing which channels bring customers (Art. 6(1)(f)); the answer is optional, and the tags are stored on your device only with your analytics consent
The State of uptime newsletter, if you sign up for itConsent, given by confirming your address, which you can withdraw at any time with the one-click unsubscribe link in every issue (Art. 6(1)(a)); the record of that consent, to show that we have it (Art. 6(1)(c) with Art. 7(1))
Crediting a partner for a referralLegitimate interests in running the partner programme (Art. 6(1)(f)); the referral cookie itself only with your consent
Analytics: Google Analytics on the marketing website, and PostHog product analytics on the website and in the dashboardConsent, which you can withdraw at any time (Art. 6(1)(a)); the record of your choice, to show that we have your consent (Art. 6(1)(c) with Art. 7(1))
Answering legal requests and enforcing our termsLegal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f))

Under India's DPDP Act, we process your personal data with the consent you give when you sign up or submit it, and for the legitimate uses the Act allows, such as data you provide voluntarily for a specified purpose and complying with the law. Where we rely on legitimate interests, you can object (section 8). For data we process as a processor for a customer, such as alert recipients or status page subscribers, the customer decides the purpose and legal basis.

We do not sell personal data, and we do not use monitoring data for advertising.

4. Where your data is stored

  • Primary hosting and processing: the application, API, database, monitoring workers, marketing website and our internal admin console run on Amazon Web Services in Frankfurt, Germany (EU, AWS region eu-central-1), behind Cloudflare.
  • Backups: encrypted database backups are stored with Amazon Web Services in the USA (AWS region us-east-1, N. Virginia).
  • Operational logs: application logs, which can include IP addresses and request details, are kept with Amazon Web Services in the USA (AWS region us-east-1) for 14 days.
  • Data exports: an export you request is stored temporarily with Cloudflare R2 and deleted 7 days after it is created; download links expire after 1 hour.
  • Checks: checks run from our checker locations, currently Frankfurt, Germany (hosted on AWS), Arizona, USA (hosted by Hostinger) and Mumbai, India (hosted by Hostinger). A checker receives the settings it needs to run your checks and sends back the results.

5. Sub-processors

We share data with the following providers only as needed to run the service. The same list, with notice of changes, is published at sutramx.com/subprocessors.

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting of the application, API, database, monitoring workers, the marketing website, our internal admin console and the Frankfurt checker; outgoing email (Amazon SES) for transactional, alert and newsletter emails, and the delivery reports it returns (delivered, bounced, marked as spam); encrypted database backups; operational logs (kept 14 days)Germany (eu-central-1, Frankfurt); backups and operational logs in the USA (us-east-1, N. Virginia)
HostingerHosting of the Arizona and Mumbai checkers; outgoing email (SMTP) for transactional and alert emailsCheckers in the USA (Arizona) and India (Mumbai); email per provider
CloudflareDNS, network security, and content delivery for our websites and API; cookieless page-load measurement on the marketing website (Cloudflare Web Analytics)Global edge network
Cloudflare R2Temporary storage of data exports you request (deleted after 7 days)Global (Cloudflare R2)
Dodo PaymentsUSD payments; acts as merchant of recordPer provider
RazorpayINR payments, including UPI autopayIndia
Google Web RiskScreening monitor target URLs for known malicious sites; receives only the scheme, host and path, never the query string, credentials, headers or bodiesUnited States
Globalping (jsDelivr)Last-mile checks on plans that include them: measures your monitored host from home and mobile networks; receives only the host name, port and path, never headers, credentials or bodiesGlobal (probe network)
Google Analytics (Google)Visitor analytics for the marketing website sutramx.com, only if you accept analytics cookies; not used in the SutramX dashboard or appsUnited States
PostHogProduct analytics for the marketing website and the SutramX dashboard, only if you accept analytics cookies: page views, feature usage and session recordings with everything you type hidden; linked to your user ID, never your name or email; not used on public status pages or in the mobile appUnited States
TwilioSMS and voice call alerts, and WhatsApp alerts sent through TwilioUnited States
Meta (WhatsApp Business Platform)WhatsApp alerts sent through the WhatsApp Cloud APIGlobal
Microsoft (Azure Bot Service)Delivering alerts through the SutramX app for Microsoft Teams, when a customer adds it to Teams: receives the alert text and the Teams conversation it goes toGlobal (Microsoft cloud)
Google (Google Chat API)Delivering alerts through the SutramX app for Google Chat, when a customer adds it to a Chat space: receives the alert text and the space it goes toGlobal (Google cloud)
TelegramTelegram alerts sent through the SutramX Telegram botGlobal
OpenAI (OpenAI API)Drafting AI incident summaries, postmortems and status page updates, from redacted incident facts (no alert recipients, names, request headers or bodies, or full monitored URLs): on request, and automatically for incidents open more than 5 minutes on plans that include AI incident summaries. OpenAI does not use API data to train its models.United States
SentryError diagnostics for the API; error reports are scrubbed of credentials and request bodiesUnited States
Expo (Expo push notification service)Delivering push alerts to the SutramX mobile app, through Apple Push Notification service and Firebase Cloud Messaging; receives the device push token and the alert textUnited States
Browser push services (Google, Mozilla, Apple, Microsoft)Delivering encrypted browser push alerts you turn onPer browser vendor

If you connect third-party services yourself (such as Slack, Discord, Microsoft Teams and Google Chat incoming webhooks, Mattermost, PagerDuty, Opsgenie, GitHub, custom webhooks, and Google or GitHub sign-in), data is sent to those services on your instruction and is governed by their own terms.

6. Retention

  • Raw check results (every individual check) are kept for 90 days.
  • Aggregated daily uptime history is kept for 90 days on the Free plan, 12 months on Starter and 24 months on Growth and Pro. If a paid plan ends, its longer history is kept for 30 more days before the new plan's limit applies. Incidents and status page history are kept while your workspace exists.
  • Incident timelines are kept for about 13 months after the incident is resolved.
  • Alert delivery logs are kept for about 90 days, and other operational logs for limited periods appropriate to their purpose.
  • Data exports are deleted 7 days after they are created.
  • Account data is kept while your account is active. Your account security log (password, two-factor, email and sign-in method changes and session revocations) is kept for 2 years and is deleted with your account. The owners of the workspaces you belong to see these changes in their workspace activity log, without your IP address.
  • Sign-in sessions (device, browser and IP address) are deleted 90 days after they end (sign-out, revocation or expiry). Email change requests are deleted 90 days after they were used, cancelled or expired; the change itself stays in your account security log.
  • Workspace activity logs are kept for 2 years, including after the workspace is deleted (without the names, email addresses and IP addresses of deleted accounts; see section 7).
  • Our internal event log (see Logs in section 2) is kept for 180 days.
  • State of uptime newsletter: an address that is never confirmed is deleted 7 days after the confirmation email, and an unsubscribed one 30 days after unsubscribing. A confirmed address is kept until you unsubscribe.
  • Records of your analytics choice (a random consent ID, the choice, the banner version and the time; no IP address) are kept for 3 years after each choice.
  • Billing records (payments, invoices, alert-credit and lifetime-deal purchases and tax documents) are kept while your account exists and, after you delete it, until 8 years after the end of the Indian financial year (April to March) they belong to, as Indian tax and company law requires; they are then deleted automatically. Each record keeps the buyer details (name, email, billing address, tax ID and country) as they were when it was created. Records created before we started keeping that copy in October 2026 carry the details as they were on that date instead.
  • Backups: deleted data can remain in our encrypted database backups until they expire, within about 40 days.

7. Deletion and export

Anyone with an account can download a JSON copy of their own personal data from the dashboard (Settings, Danger zone, Download my data). Workspace owners can also export a whole workspace and delete the workspace and account there, or ask us by email. When you delete your workspace or account, it is scheduled for deletion; you can cancel within 30 days, after which the data is permanently deleted. At that point we also delete your sign-in history, queued emails, alert delivery records and the entries about your account in our internal event log, and remove your email address, name, IP address and browser details from support tickets and workspace activity logs; the text of support conversations and the activity entries themselves are kept without them. We also ask PostHog to delete the analytics events and session recordings linked to your user ID. Status page subscribers can unsubscribe with the link in every email, Slack message or webhook delivery.

After your account is deleted we keep only the following, each for a limited purpose:

What we keepWhy (legal basis)How long
Billing records: payments, invoices, alert-credit and lifetime-deal purchases and tax documents, with the buyer details on them (name, email, billing address, tax ID, country)Indian tax and company law requires us to keep accounting records (legal obligation, Art. 6(1)(c))8 years after the end of the Indian financial year (April to March) each record belongs to, then deleted automatically
Our email suppression list: your email address and why we stopped emailing it (it bounced, you marked an email as spam, or you unsubscribed)So that we never email an address that bounced, complained or opted out again (legitimate interests, Art. 6(1)(f), and respecting your objection)No fixed period: as long as we send email. Ask us to remove it if you want; we may then email that address again
Our staff audit log: actions SutramX staff took, including on your account (it can name your email address)Accountability for, and the security of, staff access to customer accounts (legitimate interests, Art. 6(1)(f))2 years
Payment notifications from Razorpay or Dodo Payments, which can include your name, email and billing detailsDetecting duplicate or forged payment events and resolving payment questions (legitimate interests, Art. 6(1)(f))180 days (configurable between 90 days and 2 years)
Security records in our internal event log of sign-ups, sign-ins or requests we refused or rate-limited: unlinked from your account and with your email address removed (the IP address involved stays)Preventing abuse of the service and protecting accounts (legitimate interests, Art. 6(1)(f))Up to 180 days from when they were recorded
Delivery, bounce and spam-complaint reports from our email provider, with the recipient addressKeeping our email deliverable and handling abuse reports (legitimate interests, Art. 6(1)(f))90 days
Safety checks of monitored URLs that we blocked as malicious or unsafe: the URL and the verdict, no longer linked to you or your accountPreventing abuse of the service (legitimate interests, Art. 6(1)(f))No fixed period
The text of your support conversations, without your email address, name, IP address or browser details (anything you wrote in a message stays in it)Our support history and establishing or defending legal claims (legitimate interests, Art. 6(1)(f))No fixed period; ask us and we will delete it unless we need it for a claim

Deleted data can also remain in encrypted backups until they expire (see section 6). If another customer added your email address to their workspace (as a team invitation, alert recipient, status page subscriber or on-call member), or their workspace activity log names you, that data is theirs: it stays until they remove it or delete their workspace.

8. Your rights

Depending on where you live, including under the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to nominate a person to exercise your rights. You also have the right to complain to your local data protection authority or the Data Protection Board of India. If we process your data as a processor for one of our customers, please contact that customer first; we will help them respond.

9. International transfers

Your data is hosted in Germany, backed up in the USA, and processed by the sub-processors and checker locations listed above, so it may be processed outside your country of residence. Where required, we rely on appropriate safeguards for transfers of personal data: the European Commission's standard contractual clauses (Decision (EU) 2021/914), with the UK Addendum and Swiss amendments where they apply, as set out in our Data Processing Addendum.

10. Security

Data is encrypted in transit (HTTPS), and sensitive fields such as monitor credentials (request headers, request bodies and credential query parameters) and integration secrets are encrypted at rest. Access is restricted to authorised systems and staff. Passwords are hashed, API keys and invitation tokens are stored as digests, and two-factor authentication is available. To report a vulnerability, email security@sutramx.com. See our Security page for details. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as required by law. We keep an internal record of every personal data breach: what happened, its effects and what we did about it.

11. Cookies

We use strictly necessary cookies and local browser storage, such as the cookies that keep you signed in and protect sign-in and two-factor verification. The only optional cookie is the referral cookie (sx_ref): if you arrive through a partner's referral link and choose to have it remembered, it stores the referral code for up to 60 days (or the partner programme's window, never more than 365 days) so the partner can be credited if you sign up later. It is set only with your consent; if you decline, nothing is stored and a signup in the same visit is still credited through the link itself. Our legal basis for the related attribution is our legitimate interest in running the partner programme. We use no advertising cookies, and analytics cookies (Google Analytics on the marketing website, PostHog on the website and in the dashboard) only if you accept them (see section 2). See our Cookie Policy.

12. Children

SutramX is a service for businesses and professionals and is not directed at children. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account or use the service. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact support@sutramx.com and we will delete it.

13. Changes to this policy

We may update this policy as the service changes. We will post the new version here with a new date and, for material changes, notify account holders by email.

14. Contact

For privacy questions or to exercise your rights, contact our grievance and privacy officer at support@sutramx.com. We respond within 30 days. You can also write to QuantumPlug Technologies LLP, Darbhanga, Bihar, India. Data subjects in the EU, the UK or Switzerland can contact us directly at the same address for any question about their personal data or to exercise their rights.

SutramX

Uptime, API and cron monitoring from 3 probe regions, with SSL and domain expiry reminders. On paid plans, failures are confirmed across regions before anyone is paged.

  • Get it onGoogle Play
  • Coming soon on theApp Store

State of uptime: a monthly email of the vendor outages SutramX confirmed.

One email a month. Unsubscribe in one click. How we handle your address.

  • Start free
  • Pricing
  • Sign in
  • System status
  • Documentation
  • support@sutramx.com

Product

  • Why This Alert
  • Vendor Outage Detection
  • Indian ISP Checks
  • MCP Server Monitoring
  • Uptime Monitoring
  • SSL Certificate Monitoring
  • API Monitoring
  • Public Status Pages
  • Alerting & Escalation
  • Multi-Region Probes
  • Ping, Port, UDP & Cron
  • Reliability Insights
  • Integrations
  • All features

Free Tools

  • SLA Uptime Calculator
  • Downtime Cost Calculator
  • On-Call Cost Calculator
  • Percentile Calculator
  • Check Interval Planner
  • HTTP Status Code Reference
  • All tools

Use Cases

  • SaaS Platforms
  • E-Commerce
  • Developers & Indie Hackers
  • All use cases

Guides

  • What Is Uptime Monitoring?
  • Uptime Monitoring Services Compared
  • Reducing False Alerts
  • Monitor Blocked by Firewall
  • Incident Response Basics
  • Status Page Best Practices
  • All guides

Compare

  • UptimeRobot alternative
  • Freshping alternative
  • Better Stack alternative
  • Pingdom alternative
  • Opsgenie alternative
  • All comparisons

Solutions

  • How We Check
  • Uptime Monitoring India
  • WhatsApp Uptime Alerts
  • Uptime on Your Phone
  • Status Page Features
  • Developers & API
  • Switch to SutramX
  • Switch From Freshping
  • Switch From UptimeRobot

Company

  • About SutramX
  • Contact
  • FAQ
  • Changelog

© 2026 SutramX. All rights reserved.·Powered by QuantumPlug Technologies

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookie Policy
  • Data Processing Addendum
  • Sub-processors
  • Uptime Target
  • Security Center

We'd like to use analytics cookies (Google Analytics and PostHog) to understand how sutramx.com and the SutramX app are used. They are only set if you accept. See our Cookie Policy.