star-1
star-2

Effective date: 20 August, 2026

This Privacy Policy explains how Dane Commercial Services Ltd, trading as Funny Monitors (“Funny Monitors,” “we,” “us,” or “our”), collects, uses, shares, stores, and protects personal data when you visit funnymonitors.com, create or use an account, configure monitoring and notifications, purchase a subscription or add-on, use a status page, contact support, or otherwise interact with our websites, applications, APIs, and related services (collectively, the “Services”).

Dane Commercial Services Ltd is a company registered in England and Wales under company number 16193091, with registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ. For the personal data described in this Privacy Policy, we generally act as the controller, unless Section 3 explains that we process data on a customer’s behalf.

We are registered with the UK Information Commissioner’s Office (“ICO”) under registration number ZB896242.

This Privacy Policy should be read together with our Terms of Service, Refund Policy, and any cookie notice, data processing addendum, or other privacy information presented when personal data is collected.

Table of contents

  1. Who this policy applies to
  2. Our role under data-protection law
  3. Customer-controlled data
  4. Personal data we collect
  5. How we obtain personal data
  6. How and why we use personal data
  7. Cookies and similar technologies
  8. How we share personal data
  9. Service providers and subprocessors
  10. International transfers
  11. Status pages and notifications
  12. Data retention and account cancellation
  13. Data security
  14. Your data-protection rights
  15. Marketing choices
  16. Children
  17. Automated decision-making
  18. Third-party websites and services
  19. Changes to this Privacy Policy
  20. Contacting us and making a complaint

1. Who this policy applies to

This Privacy Policy applies to personal data relating to:

  • visitors to our websites;
  • account owners, administrators, and team members;
  • customers and prospective customers;
  • people designated to receive monitoring alerts or incident notifications;
  • people who subscribe to updates from a status page;
  • users of our APIs, integrations, support services, and communications;
  • newsletter subscribers and other marketing contacts; and
  • representatives of suppliers, partners, and other organizations that interact with us.

The Services are intended for people aged 18 or over and are not directed to children.

2. Our role under data-protection law

We act as a controller when we decide why and how personal data is processed—for example, account registration information, billing and transaction records, website analytics, support communications, security logs, and our own marketing contacts.

We may act as a processor when a customer submits or configures personal data through the Services and determines the purposes and means of that processing—for example, alert-recipient contact details, team-member information, monitor request data, incident content, or status-page subscriber data. In those circumstances, the customer is normally the controller and is responsible for providing required privacy information, identifying a lawful basis, handling rights requests, and ensuring that its instructions comply with law.

Where required, our processing on behalf of a customer will be governed by a data processing addendum (“DPA”) or other written data-processing terms. To request a DPA, contact [email protected].

3. Customer-controlled data

Customers choose what they monitor, which data they submit, who receives alerts, which integrations they enable, and what they publish on status pages. This may result in us processing personal data contained in:

  • monitor names, URLs, hostnames, request headers, payloads, authentication values, keywords, or response content;
  • incident reports, maintenance notices, status-page content, logos, and public subscriber lists or records;
  • team-member names, email addresses, roles, access permissions, and activity;
  • notification recipient names, email addresses, telephone numbers, webhook destinations, and delivery records;
  • integration configuration and data exchanged with customer-selected services; and
  • support material, diagnostic information, screenshots, logs, or files supplied by a customer.

Customers must not submit special-category, highly sensitive, health, biometric, payment-card, government-identifier, or similarly regulated personal data unless the relevant Service is expressly designed for it and appropriate written terms are in place.

If you believe a Funny Monitors customer has submitted your personal data, contact that customer first where practicable because they determine how the data is used. You may also contact us at [email protected], and we will assist the customer as required by applicable law and our contractual obligations.

4. Personal data we collect

The personal data we collect depends on how you interact with the Services and may include:

Account and identity data

Names, email addresses, password hashes or authentication credentials, organization details, account identifiers, roles, permissions, settings, and records of account creation, acceptance of legal terms, login, and account changes.

Team-member data

Names, email addresses, roles, permissions, invitations, authentication records, and activity associated with team members added to an account. Team members are unlimited across all plans, but each team member must have individually authorized access.

Billing and transaction data

Billing name and address, company information, tax information, subscription and add-on selections, invoices, transaction identifiers, payment status, refunds, disputes, and limited payment-method details supplied by our payment processor. Full card numbers are processed by Stripe and are not stored on our servers.

Monitoring and Service data

Monitor configurations, URLs, domains, IP addresses, ports, endpoints, certificates, DNS information, request and response metadata, timestamps, availability and performance results, incident history, maintenance windows, reports, status-page data, API usage, and other information generated by or submitted to the Services.

Notification and add-on data

Alert-recipient names and contact details, email addresses, telephone numbers, notification preferences, delivery attempts, delivery status, voice-call and SMS usage, notification-seat or capacity assignments, and add-on credit balances and transaction history.

Technical and usage data

IP address, approximate location derived from IP address, browser type, device type, operating system, language, referring page, pages or features viewed, timestamps, session identifiers, cookie identifiers, API requests, diagnostic records, and security and activity logs.

Communications and support data

The content of support requests, live-chat messages, emails, surveys, feedback, complaints, and other communications, together with related contact details, attachments, and support history.

Marketing and preference data

Newsletter registration, marketing consent, communication preferences, campaign engagement, and records of consent or opt-out choices.

Public status-page subscriber data

Email addresses or other contact details used to subscribe to status-page updates, confirmation and unsubscribe records, and notification-delivery information.

Fraud, compliance, and dispute data

Information used to investigate suspicious activity, enforce the Terms, verify transactions, respond to chargebacks, establish or defend legal claims, and comply with lawful requests. This may include payment logs, IP logs, Service-access records, communications, and relevant account activity.

We do not intentionally collect special-category personal data or criminal-offence data as part of the ordinary operation of the Services.

5. How we obtain personal data

We obtain personal data:

  • directly from you, when you register, purchase, configure the Services, communicate with us, join a team, subscribe to updates, or choose preferences;
  • from account owners or administrators, when they invite team members, add notification recipients, configure status pages, or submit support information;
  • automatically, when you use our websites, dashboard, applications, APIs, monitors, or integrations;
  • from service providers, including payment, fraud-prevention, communications, support, consent-management, hosting, and analytics providers;
  • from customer-selected integrations, when a customer authorizes an integration to exchange information with the Services; and
  • from public or technical sources, such as public DNS, certificate, domain, endpoint, and network information required to perform customer-configured monitoring.

Where personal data is required to create an account, deliver a purchased Service, process payment, secure the platform, or comply with law, failure to provide it may mean that we cannot provide some or all of the Services.

6. How and why we use personal data

We process personal data only where we have an appropriate lawful basis. The bases most relevant to our activities are performance of a contract, compliance with a legal obligation, our legitimate interests or those of a third party, and consent.

PurposeTypical personal dataUK GDPR lawful basis
Create, administer, authenticate, and secure accountsAccount, identity, team-member, technical, and security dataContract; legitimate interests in operating and securing the Services
Provide monitoring, reports, APIs, status pages, integrations, and configured alertsAccount, monitoring, notification, integration, and technical dataContract; where we act as processor, the customer’s documented instructions
Process subscriptions, monthly or annual plans, prorated first invoices, and monthly add-onsAccount, billing, transaction, subscription, and add-on dataContract; legal obligation; legitimate interests in payment administration and fraud prevention
Deliver email, SMS, and voice notificationsContact details, configuration, content, delivery, usage, and credit dataContract; legitimate interests in delivering and documenting requested communications
Provide support and respond to enquiriesAccount, communications, support, monitoring, and diagnostic dataContract; legitimate interests in customer service and Service improvement
Maintain availability, troubleshoot, prevent abuse, and protect the ServicesTechnical, usage, security, monitoring, and fraud dataLegitimate interests in security, reliability, abuse prevention, and protecting users and third parties; legal obligation where applicable
Improve features and understand Service useUsage, technical, support, feedback, and aggregated dataLegitimate interests in improving and developing the Services; consent where required for cookies or similar technologies
Send newsletters and promotional communicationsContact, preference, and engagement dataConsent, or legitimate interests where permitted by electronic-marketing law
Maintain legal, financial, and compliance recordsAccount, transaction, invoice, tax, acceptance, dispute, and communications dataLegal obligation; legitimate interests in record-keeping and establishing or defending legal claims
Enforce agreements and handle fraud, complaints, payment disputes, or legal claimsAccount, transaction, monitoring, communications, technical, and security dataContract; legal obligation; legitimate interests in protecting our business and legal rights
Complete a corporate transactionRelevant account, customer, supplier, and business recordsLegitimate interests in organizing, financing, selling, or restructuring our business; legal obligation where applicable

Where we rely on legitimate interests, we assess whether those interests are necessary and balanced against the rights and freedoms of the people concerned. You may contact us for information about that assessment.

We will obtain consent where required. You may withdraw consent at any time, without affecting processing that took place before withdrawal.

7. Cookies and similar technologies

We and our service providers may use cookies, pixels, local storage, tags, and similar technologies to:

  • keep you signed in and remember settings;
  • protect accounts and prevent fraud;
  • provide core website and Service functionality;
  • remember consent and communication choices;
  • understand website and product usage;
  • diagnose errors and improve performance; and
  • measure communications or marketing where permitted.

Strictly necessary technologies may operate without consent where permitted by law. We will request consent before using non-essential analytics, advertising, or similar technologies where consent is legally required.

You can review or change non-essential cookie choices through Consent Preferences on our website. Browser settings may also allow you to block or delete cookies, but some features may then operate incorrectly.

CookieCategoryRequirementDurationPurpose
__Secure-funnymonitorscom-sessionFunctionalMandatorySessionMaintains the application session and is required for the application to operate
XSRF-TOKENFunctionalMandatorySessionHelps protect the application and user session against cross-site request-forgery attacks
__stripe_midFunctionalMandatorySessionSupports Stripe payment functionality and is required for the application to collect payments

These mandatory functional cookies are necessary to provide the application, maintain sessions, protect requests, and process payments. Disabling them may prevent the Services or checkout from functioning correctly.

8. How we share personal data

We do not sell personal data. We may share it only as reasonably necessary:

  • with service providers and subprocessors that host, support, secure, analyze, communicate, or process payments for the Services;
  • with customer-authorized users and integrations, according to account permissions and customer configuration;
  • with payment networks, banks, and fraud-prevention providers, to process transactions and manage disputes;
  • with professional advisers, such as lawyers, accountants, auditors, insurers, and security consultants, under appropriate duties of confidentiality;
  • with authorities or other parties when required by law, court order, regulatory request, or valid legal process;
  • to protect rights and safety, where reasonably necessary to prevent fraud, abuse, security incidents, or harm, or to establish, exercise, or defend legal claims;
  • in connection with a corporate transaction, such as a merger, financing, restructuring, sale of assets, insolvency, or acquisition, subject to appropriate safeguards; and
  • with your consent or at your direction.

We may use or share information that has been aggregated or de-identified so that it does not identify an individual. We will not attempt to re-identify such information except where needed to test our de-identification processes or as permitted by law.

9. Service providers and subprocessors

We currently identify the following providers in connection with the Services:

ProviderPurpose
StripePayment processing, subscription billing, transaction management, and fraud prevention
TermlyCookie consent, privacy notices, and preference management
TwilioVoice-call and SMS notification delivery
MailgunTransactional email, system notification, and email-delivery services
ZendeskCustomer-support query management and support communications
BrevoCustomer-sales query management and sales communications
SentryError and bug logging, diagnostics, and application monitoring
Google FontsLoading and displaying custom website fonts
CloudflareDNS, content delivery, security, and storage of screenshots and backups

We may replace providers or appoint additional providers as the Services evolve. We may use additional infrastructure, hosting, storage, security, database, backup, logging, and similar technical providers without publicly identifying each provider, where permitted by applicable law. Such providers are permitted to process personal data only for agreed purposes and subject to contractual privacy, confidentiality, and security obligations appropriate to their role.

Where we act as a processor, the provider list also serves as notice of relevant subprocessors, subject to any additional terms in a DPA.

10. International transfers

Personal data may be stored, processed, or accessed in the United Kingdom, the European Union, North America, and Australia, including in locations where our service providers and subprocessors operate. Where a transfer is subject to UK data-protection restrictions, we will use an approved transfer mechanism as required, which may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another lawful safeguard or exception available under applicable law.

We will assess transfers and apply supplementary contractual, organizational, or technical safeguards where appropriate. You may request information about the safeguards relevant to your personal data by contacting [email protected].

11. Status pages and notifications

Customers may publish public status pages and may configure alerts or status updates for team members, contacts, or subscribers. Information placed on a public status page is intentionally public and may be indexed, cached, copied, or redistributed by third parties. Customers should not publish personal data, secrets, credentials, or confidential information on public status pages.

Where a person subscribes to status-page updates, we may process the subscriber’s contact details, consent or confirmation record, subscription preferences, and delivery information to provide those updates. Subscribers can unsubscribe using the method included in the relevant communication or status page.

Customers are responsible for having authority to provide recipient contact details and for ensuring that monitoring and incident communications comply with law. Notification providers may receive the recipient details and message content needed to deliver email, SMS, or voice alerts.

12. Data retention and account cancellation

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, meeting legal and accounting obligations, resolving disputes, preventing fraud and abuse, and establishing or defending legal claims. Retention depends on the nature of the data, why it is processed, sensitivity, risk, and applicable legal requirements.

Immediate deletion when a subscription is cancelled

As stated in our Terms of Service, selecting and confirming “Cancel Subscription” takes effect immediately. At that moment, access ends and operational account and Customer Data—including monitors, configurations, monitoring history, reports, status pages, incidents, integrations, contact and notification settings, API credentials, and related Service data—is permanently deleted from our active servers and Services. Monitoring and alert delivery stop immediately, and deleted operational data cannot be restored or recovered.

You must export anything you wish to retain before confirming cancellation.

Records retained after cancellation

Immediate operational deletion does not apply to the limited records that we are required or permitted to retain for legal, tax, accounting, fraud-prevention, payment-dispute, security, or legal-claims purposes. These may include invoices, transaction records, payment status, contract-acceptance evidence, chargeback evidence, and relevant communications or access logs. Such records:

  • are no longer available through the cancelled account;
  • are not used to continue providing monitoring or alerts;
  • are restricted to the applicable retention purpose; and
  • are deleted or anonymized when the relevant obligation or lawful purpose ends.

UK accounting and tax records may generally need to be retained for up to six years or longer in limited circumstances. Other records are retained according to documented operational and legal criteria.

Other retention periods

  • Marketing data is retained until you opt out or the data is no longer needed, subject to retaining a minimal suppression record so we can respect your choice.
  • Support and complaint records are retained for as long as reasonably needed to resolve the matter and protect legal rights.
  • Security and access logs are retained for a limited period based on security, fraud, diagnostic, and legal needs.
  • Cookie and consent records are retained for the duration stated in our cookie information or as needed to demonstrate your choices.
  • Customer Personal Data contained on the central backup server is automatically deleted or overwritten no later than three days after subscription cancellation or the applicable deletion instruction. During that limited period, it is isolated from ordinary use and retained only for disaster recovery, security, or legal compliance.
  • Where we process Customer Data as a processor, retention and deletion may also be governed by the customer’s instructions and any DPA.

13. Data security

We use appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls, credential protections, logging and monitoring, provider due diligence, data minimization, and incident-management procedures.

No online service can guarantee absolute security. You are responsible for using unique credentials, protecting authentication information and API keys, assigning appropriate team permissions, and notifying us promptly at [email protected] if you suspect unauthorized account access.

If a personal-data breach occurs, we will assess it and notify affected controllers, individuals, or regulators where required by applicable law.

14. Your data-protection rights

Depending on the circumstances and applicable law, you may have the right to:

  • request confirmation of whether we process your personal data and obtain a copy;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • receive personal data you provided in a structured, commonly used, machine-readable format and, where applicable, have it transmitted to another controller;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time where processing is based on consent; and
  • complain to the ICO or another competent supervisory authority.

Your right to object: You have the right to object to processing based on our legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims. If you object to direct marketing, we will stop using your personal data for that purpose.

Rights are not absolute and may be subject to legal conditions or exemptions. We may request information reasonably necessary to verify your identity and authority. We normally respond within the period required by applicable law and do not ordinarily charge a fee, although the law may permit a reasonable fee or refusal for manifestly unfounded or excessive requests.

To exercise a right, email [email protected]. If we process the data solely on behalf of a customer, we may direct the request to that customer or assist them in responding.

15. Marketing choices

You can unsubscribe from promotional email by using the unsubscribe link in the message or contacting [email protected]. You may also change cookie choices through Consent Preferences.

Opting out of marketing does not stop Service communications such as account notices, invoices, security messages, monitoring alerts, status updates you requested, support responses, or legal notices. We may retain a minimal suppression record to ensure that marketing is not sent after you opt out.

16. Children

The Services are not directed to children, and you must be at least 18 years old or the age of legal majority where you live to create an account. We do not knowingly collect personal data from children through the Services. If you believe a child has provided personal data to us, contact [email protected].

17. Automated decision-making

We do not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

The Services do automatically perform customer-configured monitoring, generate results, send alerts, apply usage or security controls, and may identify potentially fraudulent or abusive activity. These operational processes do not ordinarily constitute solely automated decision-making with legal or similarly significant effects. If that changes, we will provide the information and safeguards required by law.

18. Third-party websites and services

The Services may contain links to or integrate with third-party websites and services. Their handling of personal data is governed by their own privacy notices, not this Privacy Policy, except to the extent we receive and process data from them. Review the privacy information of any third party before enabling an integration or providing personal data.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, our Services, providers, or processing practices. We will post the revised policy and update the “Last updated” date.

If a change materially affects how we use personal data or reduces privacy protections, we will provide reasonable advance notice through email, the Services, or another appropriate method where required or practicable. We will seek consent where required by law. Previous versions may be made available on request.

20. Contacting us and making a complaint

For questions, rights requests, or privacy complaints, contact:

Dane Commercial Services Ltd
Company number: 16193091
61 Bridge Street
Kington
United Kingdom
HR5 3DJ
Email: [email protected]
ICO registration number: ZB896242

We do not currently publish separate contact details for a Data Protection Officer. Privacy enquiries should be sent to [email protected].

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. We encourage you to contact us first so we can try to resolve the concern.

Information Commissioner’s Office: https://ico.org.uk/make-a-complaint/