Privacy Policy
Effective: July 25, 2026 — Version 2
Last published version from our content management systemPrivacy Policy
Effective date: 2026-07-25.
This policy describes what data howlops.com collects, how it is processed, and the rights you have under GDPR and equivalent regimes. It covers both the web platform and the HowlOps iOS mobile app.
1. Data we collect
- Account data: email, name, workspace name, password hash, MFA factors.
- Operational data: monitor configurations, incidents, alert deliveries, audit log.
- Billing data: Stripe customer ID, last 4 digits of payment instrument, invoice metadata.
- Mobile app data: when you use the HowlOps iOS app and enable notifications, a push notification device token (issued by Apple Push Notification service) so we can deliver alert, incident and on-call push notifications, including critical alerts that can bypass silent mode when you opt in. The token identifies the device install, not you personally, and is removed when you sign out or disable notifications.
- Diagnostics: server logs (90 days), request rate metrics (1 year aggregated), and standard crash/diagnostic data from the mobile app needed to keep it working.
We do not use any advertising SDK, do not track you across other apps or websites, and do not sell personal data.
2. How we use it
- To operate the platform, deliver alerts (web, email, SMS, voice and mobile push), and bill paid subscriptions.
- To investigate abuse or security incidents.
- To improve the product (aggregated, never individually identifiable).
3. Sharing
We do not sell personal data. We share data with sub-processors strictly to operate the service: Hetzner (EU hosting), Amazon SES (transactional email delivery), Cloudflare (network and CDN), Stripe (billing), Twilio (SMS and voice alerts, only when you configure it), Apple (APNs push-notification delivery for the mobile app), Expo/EAS (mobile app build and over-the-air update service), Google Analytics (consent-gated product analytics), and GitHub (source code and CI). A full, current sub-processor list is published at /legal/subprocessors.
4. Mobile application (iOS)
The HowlOps iOS app is an optional companion to the web platform. It processes the same account and operational data described above, plus the push notification device token described in section 1. Push notifications — including critical alerts that can bypass silent mode / Do Not Disturb when you opt in — are delivered on a best-effort basis via Apple Push Notification service. Your rights on mobile are unchanged: you can access, export, correct or delete your personal data via Settings → Account (web or app), and deleting your account removes the device tokens with it. Push notifications are optional and can be turned off at any time in iOS Settings.
5. Your rights
You can access, export, correct or delete your personal data at any time via Settings → Account. Workspace owners can export the entire workspace via the data-export endpoint.
6. Retention
Monitoring data — check results and heartbeat pings — is retained according to your plan, from 7 days on the Free plan up to 365 days on higher plans; verbose diagnostic logs are retained for 90 days; screenshots are retained on your plan's data-retention schedule. Closed accounts are scrubbed within 30 days of confirmation.
7. Contact
Privacy questions: [email protected].
Data controller
The data controller for personal data processed through HowlOps is the operator identified in our Imprint. For data-protection requests, contact [email protected].
Legal bases for processing (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) — operating your account, running your monitors, delivering alerts, and billing.
- Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, keeping audit logs, and improving reliability, balanced against your rights.
- Consent (Art. 6(1)(a)) — optional analytics cookies, optional mobile push notifications (granted in the OS permission prompt, withdrawable any time), and any marketing communications.
- Legal obligation (Art. 6(1)(c)) — retaining invoicing/tax records where the law requires.
International transfers
Customer data is hosted in the European Union by default (Nuremberg and Helsinki). Where a sub-processor processes data outside the EEA (for example Apple, Stripe or Twilio), the transfer is covered by the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework, or an equivalent safeguard. See our Sub-processors and Data Processing Agreement.
Your right to complain
You have the right to lodge a complaint with a data-protection supervisory authority. In the Czech Republic this is the Úřad pro ochranu osobních údajů (ÚOOÚ), https://uoou.gov.cz. You may also contact the authority in your EU country of residence.
Questions? Contact [email protected]. See also: Terms of Service | Cookie Policy