CronFender Privacy Policy
Effective Date: July 15, 2025
This Privacy Policy describes how CronFender ("we", "us", or "our") collects, uses, stores, and protects your personal data when you use our web application and services (the "Service").
We are committed to protecting your privacy and handling your data transparently. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Service: The CronFender web application, including all monitoring, management, and alerting services for cron jobs.
- User: Any individual or entity accessing or using the Service.
- Job Data: Information related to the cron jobs configured by the User, including URLs, HTTP methods, cron expressions, headers, bodies, and execution logs.
- Usage Data: Data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (e.g., duration of a page visit).
- Data Controller: The natural or legal person who (alone or jointly with others) determines the purposes and means of processing personal data. For this Privacy Policy, we are the Data Controller of your Personal Data.
2. Information We Collect
We collect several different types of information for various purposes to provide and improve our Service to you.
2.1 Personal Data
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information may include, but is not limited to:
- Identity Data: First name, last name.
- Contact Data: Email address.
- Account Data: Clerk User ID, Stripe Customer ID, subscription details (plan type, status, period end).
- Communication Data: Any information you provide when contacting us (e.g., via our contact form, support emails).
2.2 Job Data
When you configure cron jobs, we collect data necessary for the Service to function:
- Job Configuration: URL, HTTP method (GET, POST, PUT, DELETE), cron expression, custom headers (which may contain sensitive information if you include API keys or tokens), and request body.
- Alert Preferences: Email recipients, Slack webhook URLs.
- Execution Logs: Timestamps of runs, HTTP status codes, duration, response bodies (truncated), and any error messages.
Important Note on Sensitive Data in Job Configurations: While CronFender is designed to process HTTP requests, we strongly advise against including highly sensitive personal data or credentials directly in job URLs, headers, or bodies unless absolutely necessary and properly secured (e.g., encrypted by you before sending to us). We process this data as part of your job configuration and execution.
2.3 Usage Data
We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device ("Usage Data").
This Usage Data may include information such as your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
2.4 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.
Cookies are files with a small amount of data that may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
3. How We Use Your Data
CronFender uses the collected data for various purposes:
- To Provide and Maintain the Service: This includes managing your jobs, executing scheduled requests, and delivering alerts.
- To Manage Your Account: To create and manage your user account, including authentication via Clerk.
- To Process Payments: To manage your subscriptions and process payments through Stripe.
- To Send Alerts and Notifications: To send you email or Slack alerts regarding job failures, recoveries, or other critical events.
- To Improve Our Service: To understand how our Service is used, analyze trends, and develop new features.
- To Monitor Usage: To detect, prevent, and address technical issues.
- To Communicate with You: To provide customer support, respond to your inquiries, and send you service-related announcements.
- To Enforce Our Terms & Conditions: To ensure compliance with our legal agreements.
4. Legal Basis for Processing Personal Data (GDPR)
If you are from the European Economic Area (EEA), our legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.
We may process your Personal Data because:
- We need to perform a contract with you (e.g., to provide the Service you subscribed to).
- You have given us permission to do so (e.g., for optional marketing communications).
- The processing is in our legitimate interests and it's not overridden by your rights (e.g., for service improvement, security).
- To comply with the law (e.g., tax regulations).
5. Sharing Your Data
We do not sell your Personal Data. We may share your data with third-party service providers only to the extent necessary to operate and improve our Service:
- Authentication: Clerk (for user authentication and management). We share your email and basic profile information with Clerk.
- Database: Supabase (our backend database). Your Job Data, User Data, and execution logs are stored here.
- Payment Processing: Stripe (for handling subscriptions and payments). When you make a payment, your billing information is processed directly by Stripe. We receive limited information from Stripe (e.g., customer ID, subscription status) to manage your plan.
- Email Sending: Resend (for sending transactional emails and alerts). Your email address and alert content are shared with Resend for delivery.
- Analytics: We may use third-party analytics tools (e.g., Google Analytics) to understand Service usage. These tools may collect data about your interactions with the Service.
- Legal Requirements: We may disclose your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation.
- Protect and defend the rights or property of CronFender.
- Prevent or investigate possible wrongdoing in connection with the Service.
- Protect the personal safety of Users of the Service or the public.
- Protect against legal liability.
6. Data Security
The security of your data is important to us. We implement reasonable technical and organizational measures designed to protect your Personal Data against unauthorized access, disclosure, alteration, and destruction. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
7. Data Retention
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.
- Account Data: We retain your account information as long as your account is active. If you close your account, we will delete or anonymize your Personal Data within a reasonable timeframe, unless retention is required by law or for legitimate business purposes (e.g., dispute resolution, fraud prevention).
- Job Data & Execution Logs:
- Free Plan: Logs are retained for 7 days.
- Pro Plan: Logs are retained for 90 days.
- Business Plan: Logs are retained for 365 days.
- After these periods, logs are automatically deleted.
- Communication Data: We retain communications for as long as necessary to resolve your inquiries and for audit purposes.
8. Your Data Protection Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
- The right to access: You have the right to request copies of your Personal Data.
- The right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The right to erasure ("right to be forgotten"): You have the right to request that we erase your Personal Data, under certain conditions.
- The right to restrict processing: You have the right to request that we restrict the processing of your Personal Data, under certain conditions.
- The right to object to processing: You have the right to object to our processing of your Personal Data, under certain conditions.
- The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- The right to withdraw consent: You also have the right to withdraw your consent at any time where CronFender relied on your consent to process your personal information.
Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
9. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top of this Privacy Policy.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: support@cronfender.com