PingStuff
  • How It Works
  • Pricing
  • Tools
Sign In

DraftComplete draft prepared for legal review — these terms have not yet been reviewed by counsel and may change before they become final.

Data Retention & Deletion Policy

How long PingStuff keeps each kind of data, and how you can export or permanently delete yours.

Status: draft for legal review · Last updated 3 August 2026

1. The short version

We keep data only as long as it is useful for running your monitoring, and we tell you exactly how long that is. You can export a copy of your organization’s core data as JSON at any time, and you can permanently delete your account — including every monitor, check result, incident and log — yourself, from inside the app. This policy explains how retention and deletion work at PingStuff (operated by 9950931 Canada Inc., carrying on business as PingStuff.com, 2240 University Ave E., Waterloo, Ontario N2K 0A9, Canada). What we collect in the first place is covered by our Privacy Policy.

2. Retention schedule

This table reflects what our systems actually do today. Where a behaviour is planned but not yet live, we say so.

DataHow long we keep itWhy
Account details — your email, optional first name, organization nameLife of your accountNeeded to sign you in and run your account. Account deletion removes all organization data and, if this was your only organization, your sign-in record too (section 6).
Alert contacts — label, email, phone numberLife of your accountSo we know who should receive SMS alerts — alert emails go to account owners and admins. Phone verification codes are stored only as a hash, never in plain text.
Monitors — the URLs and hostnames you choose to checkLife of your accountThis is the core of the service: we can only check what you tell us to check.
Raw check results — per-check DNS, TCP, TLS and HTTP details for your monitored sitesUp to about 14 monthsPowers incident history and trend charts. Raw checks are stored in monthly partitions; a month is deleted once all of it is more than 400 days old, so the oldest checks can persist up to about 14 months. Tighter per-plan retention is planned.
Aggregated statistics — hourly and daily uptime / response-time rollupsIndefinitelyLong-term trends stay useful for years. Rollups are summary numbers and contain no personal data.
Anonymous free checks — the URL you checked plus the result snapshot7 days, then auto-deletedKeeps the result (and its share link) available briefly. No account needed, so nothing else is kept.
Free-checker usage analytics — which website was checked (host + domain) and the result (outcome + score) — no IP, no visitor identity, no full report90 days, then pruned automaticallyLets us see aggregate usage of the free checker — which sites people check, and how often. It records the target website, never who checked it, so there is no personal data in it.
Email and SMS message logs — recipient, delivery status and subject — and, for SMS, the message content in both directionsUp to 13 months, then pruned automaticallyTroubleshooting delivery problems and investigating abuse. The SMS verification codes we send are never written to message logs, and we never ask you to text a code back.
SMS consent and opt-out (STOP) recordsIndefinitelyLegal proof that you consented — and proof of your STOP, so we never text a number that opted out. These survive account deletion, unlinked from the deleted account and keyed to the phone number alone (section 7).
Audit logs — administrative and security-relevant actions24 months, then pruned automaticallySecurity and accountability: who did what, and when.
Billing records — subscription status, quantity, billing period and our payment-processor (Stripe) customer and subscription identifiers (when billing is available)Life of your accountStripe processes payments; we never see or store card numbers. We also keep the raw event records Stripe sends us, so billing events are processed exactly once and can be audited.

3. IP addresses

Plain English: we use IP addresses to stop abuse, and we deliberately avoid keeping the full address wherever we can.

  • IP addresses are used transiently for rate limiting — to slow down or block sources that hammer the service.
  • Access logs for shared reports and our abuse ledger store only a coarsened network address (the /24 network for IPv4 addresses, the /48 network for IPv6 — never the full address), so a specific device cannot be identified from them.
  • Two exceptions: the IP address recorded at the moment you consent to SMS alerts is kept with the consent record, as compliance proof that the consent was real; and when you sign in, the full IP address and browser (user-agent) details of that sign-in are stored with your session record for security. Sign-in session records exist for as long as your account does and are deleted with the account.

4. Anonymous free checks — 7-day auto-delete

The free instant check on our homepage needs no account. We store the URL you checked and a snapshot of the result so the report page (and its share link) works; that snapshot is automatically deleted after 7 days, and there is nothing to export or delete manually — it removes itself. Separately, we keep a small usage record of which website was checked and the result — with no IP and nothing that identifies you — for up to 90 days (the “Free-checker usage analytics” row in the table above), so we can understand how the free checker is used.

5. Export your data

You can download a copy of your organization’s core data — organization details, members, monitors, incident history, alert contacts, daily uptime statistics and your subscription summary — as a single JSON file, self-serve, at any time, from pingstuff.com/app/export. The export includes your most recent records in each category (up to 1,000 monitors, 2,000 incidents, 1,000 contacts and 5,000 daily statistics rows) and does not include raw per-check results or message logs. If you need something the export does not cover, ask us via the contact form at pingstuff.com/contact. The export is scoped to your own organization; no one can export another organization’s data.

6. Delete your account

Plain English: the account owner can delete the account from inside the app. There is a 30-day safety window in case of mistakes, and after that everything is permanently gone. Here is exactly what happens:

  • You request deletion in-app. Only the organization owner can do this.
  • A 30-day grace period starts. The account immediately becomes inoperable and all monitoring stops — no more checks, no more alerts. During these 30 days the owner can cancel the deletion and restore the account exactly as it was.
  • After 30 days, we permanently delete all organization data — the organization itself, monitors, check results, incidents, contacts, message logs, reports and settings. This is a hard purge, not a “hide”.
  • Sign-in identities are erased too. For each member whose only organization this was, we also delete their sign-in identity: the user record (email, name, verified phone), sign-in sessions (which include the sign-in IP address and browser details), authentication accounts and phone-verification records. A member who also belongs to another organization keeps their sign-in record for that organization.
  • Backups follow as they rotate. Nightly backups on our own server rotate after 14 days, and encrypted off-site backup copies are kept for up to 30 days — so purged data disappears from every backup within roughly 30 days of the purge.

A few narrow categories survive deletion:

  • SMS consent and opt-out (STOP) records (see section 7) — kept as legally required compliance proof, unlinked from the deleted organization and keyed to the phone number rather than your account.
  • The global SMS STOP suppression list — so we never text a number that opted out, even after the account it belonged to is gone.
  • Raw payment-processor (Stripe) event records, where billing was used — these are not keyed to your organization and are kept so billing events are processed exactly once and can be audited.
  • Copies in backups, until they rotate out — after 14 days for backups on our own server, and up to 30 days for encrypted off-site copies.

7. Records we keep indefinitely

Two kinds of records are kept without a scheduled end, each for a specific reason:

  • SMS consent and STOP (opt-out) records — kept as legal proof that consent existed and, just as importantly, that an opt-out was honoured. Keeping the STOP record is what guarantees we never text a number that told us to stop. If your account is deleted, these records are kept but unlinked from the deleted organization — keyed to the phone number alone.
  • Aggregated statistics — hourly and daily rollups of uptime and response times. These are summary numbers about website behaviour and contain no personal data.

8. Backups

We take nightly backups of our database so we can recover from failures. Backups on our own server rotate after 14 days, and encrypted off-site backup copies are kept for up to 30 days — which is why deleted data leaves every backup within about 30 days of being purged (section 6). Backups are used only for disaster recovery — we do not restore deleted customer data from backups except to recover from a system failure.

9. Questions

Questions about retention or deletion can go to privacy@pingstuff.com, or — the most reliable channel — the contact form at pingstuff.com/contact.

PingStuff

Know when your website breaks. Know what to do next.

Product

  • How It Works
  • Pricing
  • Tools
  • About
  • Contact

Resources

  • Guides
  • Announcements
  • Security

Legal

  • Terms
  • Privacy
  • Trial & Billing
  • SMS Terms
  • Acceptable Use
  • Cookies
  • Data Retention
  • Subprocessors
  • Law Enforcement

SMS alerts are powered by AIUCAAS, a Canadian communications platform, over a Fibernetics carrier route.