Privacy Policy
This policy explains how JR Digital handles personal information through WebWatch at web-watch.uk, including the website, account area, monitoring service, security scans, public status pages, API and connected mobile app.
1. Who is responsible for your information
JR Digital, an Exeter-based web agency, operates WebWatch and is the controller of personal information described in this policy. References to "WebWatch", "we", "us" and "our" mean JR Digital.
For privacy questions, rights requests or complaints, email info@jj-digital.uk. Please do not send passwords, API tokens, webhook secrets or security verification tokens by email.
This policy is intended to meet the transparency requirements of the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended.
2. Information we collect
Account and profile information. Your name, email address, password hash, plan status, Premium purchase time, account preferences and any support-contact or escalation email address you provide. We do not store your plain-text password.
Sites and monitoring settings. The website URLs, labels, monitoring paths and optional keywords you provide, together with check frequency, alert rules, contact method, performance budgets, SSL warning thresholds, incident acknowledgements and related configuration.
Check and audit information. Results may include HTTP status, response and time-to-first-byte measurements, DNS and TCP timings, redirects, page size, page title, canonical URL, robots settings, selected page metadata, SSL certificate information, security-header presence, optional keyword results and compact SEO scores and summaries.
Security-scan information. For a saved site, we store the exact HTTPS origin, your versioned confirmation that you are authorised to scan it, confirmation time, a public ownership-challenge token, verification state, scan status, score and bounded findings. A scan may inspect a capped part of a public response and cookie attributes while it runs. WebWatch does not retain response bodies, cookie values, credentials, submitted forms or exploit payloads in the scan report.
Alert, integration and public-page information. We store outbound webhook URLs, HMAC signing secrets, delivery status, API-token hashes, iOS push device tokens, status-page titles and descriptions, and the sites you choose to publish on a public status page. A webhook signing secret is stored in a form WebWatch can use to sign deliveries. The raw value of an API bearer token is not retained after issue.
Payment information. Stripe receives payment-card and checkout information. WebWatch stores a Stripe customer identifier, Premium status and purchase time, and receives payment, refund and dispute status from Stripe. We do not receive or store full card details.
Support and communications. We process information in messages you send us and, when you use "Get help", the account address, chosen recipient, site details and a short health summary sent on your instructions.
Device, connection and usage information. We may process IP address, browser or app type, user-agent, request time, requested route, consent choice and security or rate-limit events. If you consent to analytics, Google Analytics may also collect page, device, browser, referrer and approximate-location information under Google's controls.
Please do not put special-category information, criminal-offence information, credentials or unnecessary personal information into a site label, URL, monitoring path, keyword, webhook URL, status-page description or support message.
3. Where the information comes from
- Directly from you when you register, configure a site, buy Premium, contact us or use an integration.
- From your browser or app when it communicates with WebWatch.
- From the public website and exact URLs you ask WebWatch to check.
- From Stripe about payment status and from Apple about push-delivery status.
- From a recipient endpoint when WebWatch attempts a webhook delivery.
If you provide somebody else's contact details, you must have a lawful reason to do so and tell them that WebWatch will use those details for the purpose you selected.
4. Why we use information and our lawful bases
We use different lawful bases for different purposes:
- Contract. To create and administer your account, provide checks, saved-site monitoring, alerts, security scans, status pages, API and app functions, process Premium access, provide support and enforce the Terms of Service.
- Legitimate interests. To secure WebWatch, prevent fraud and abuse, diagnose faults, maintain service reliability, keep proportionate operational records, understand non-cookie service performance and protect our rights and those of users and target-site operators. Our interests are running a safe, dependable and sustainable monitoring service. We assess these uses against the rights and reasonable expectations of affected people.
- Consent. To load Google Analytics and to request personalised advertising where you choose "Accept all". You can withdraw this choice as explained in section 6. Withdrawal does not make earlier processing unlawful.
- Legal obligation. To keep records or disclose information where tax, accounting, consumer, data protection, court or law-enforcement rules require it.
Strictly necessary storage and access technologies are used to provide and secure the service you request. Consent is sought for optional analytics and personalised advertising.
5. What happens when WebWatch checks a site
WebWatch makes automated network requests to URLs chosen by a user. The operator of a target site or its hosting provider can receive routine request information, including the WebWatch server's IP address, request time, requested path and request headers. Ordinary checks can follow a limited number of validated redirects. A security overview is restricted to one direct request to the exact saved HTTPS origin, and a verified security scan uses only the ownership challenge and fixed, bounded paths described in the service.
WebWatch does not use an external scanning vendor or AI provider to produce security reports. Scan results are generated within WebWatch. Security report pages use first-party assets, are marked private and no-store, and do not load advertising, analytics, remote fonts or content-delivery scripts.
6. Cookies, local storage, analytics and advertising
Necessary session cookie. WebWatch uses a signed session cookie for sign-in state, account security and request protection. It is HttpOnly and SameSite=Lax, and Secure in production. A normal session ends with the browser session. If you choose "Remember me", the session can remain for up to 14 days.
Consent preference. The banner saves an analytics and personalised-ad preference in your browser's local storage under webwatch_cookie_preferences_v3. This is not sent to the WebWatch database. It remains until browser storage is cleared or the preference is replaced.
- Accept all enables Google Analytics. For a free user, it also requests personalised advertising. Pages rendered while you are signed in to a paid account do not include ads.
- Reject optional keeps Google Analytics off and requests non-personalised advertising on eligible free content pages.
- Before a choice is stored, WebWatch does not ask Google Analytics to load and does not ask AdSense to render an advert.
On eligible free content pages, the Google AdSense library is requested when the page loads, before a preference is recorded. That request can disclose routine connection information such as IP address and user-agent to Google. Ad rendering waits until a choice is stored. Google Analytics is requested only after "Accept all".
Some ordinary pages also request fonts or interface files from Google Fonts, cdnjs or jsDelivr. Those providers receive routine connection information when the resource is requested. Security pages and public status pages are deliberately more restricted and do not load those resources.
To change the saved banner choice, clear WebWatch's cookies and site data in your browser, including local storage, then revisit the site and choose again. Browser controls and extensions may also block third-party requests. Clearing the necessary session cookie signs you out.
Google controls information it receives through Analytics and AdSense under its own terms and privacy information. You can also review Google Ads Settings.
7. Who receives information
We do not sell personal information. We disclose only what is reasonably needed to:
- Stripe, to create checkout and process payment, refund, reversal and dispute events.
- Apple Push Notification service, to deliver alerts to an iOS device you register.
- Google Analytics and Google AdSense, according to the actual choices and loading behaviour explained in section 6.
- Hosting, database, email, font and content-delivery providers, to run, secure and deliver WebWatch.
- A webhook or support recipient chosen by you, to send the event payload or health summary you requested.
- A target website or its infrastructure provider, as an unavoidable part of making the requested check.
- Professional advisers, courts, regulators, law enforcement or a buyer of the business, where disclosure is lawful and necessary. A buyer would be required to protect the information and use it consistently with applicable law.
Recipients such as Stripe, Apple and Google also determine some purposes and means of their own processing. Their privacy information applies to that activity.
8. International transfers
Some providers may process information outside the United Kingdom. Where a restricted transfer is made, we must use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses, together with any required data protection assessment. Contact us if you want information about the safeguard relevant to a particular provider.
9. How long we keep information
- Detailed monitoring result JSON: kept for 6 hours, then replaced with an empty payload. Summary metric columns remain for 7 days and are then deleted.
- Resolved monitoring incidents: kept for up to 90 days so status pages and recent incident history can work.
- Security history: completed, failed and cancelled scan records and their bounded findings are normally kept for up to 180 days. Earlier pruning also applies after 50 visible scans or 20 ownership checks per site.
- SEO history: compact score, grade and summary records are kept while the saved site and account remain active, unless the site or account is deleted.
- Account, saved-site, alert, status-page, token and integration information: kept while needed to provide the account or until you remove the item or delete the account.
- Consent preference: kept in local storage until you clear or replace it.
- Support correspondence, security logs and legal or payment records: kept only for as long as reasonably needed for support, security, dispute, accounting or legal purposes. Provider-held payment records follow the provider's and applicable legal retention requirements.
Retention periods may be shortened where records are no longer needed, or extended where a legal hold, dispute, fraud investigation or statutory obligation requires it. We limit any extension to the relevant records and purpose.
10. Account and site deletion
Deleting a saved site removes its WebWatch monitoring results, incidents, site-specific webhooks, public-status-page links, SEO history, security authorisation, security scans and findings from the live application database.
Deleting your account from Settings removes the account and its saved sites, monitoring results, incidents, webhooks, status pages, SEO history, security records, API-token records and push-token records from the live application database, then clears the browser session. This action cannot be undone within WebWatch.
The account-deletion control does not recall messages or webhook payloads already delivered, erase a public page from somebody else's cache, or delete records independently held by Stripe, Apple, Google, an email provider or a recipient you selected. We may also retain narrowly limited records where law, fraud prevention or a live legal claim requires it.
11. Security
WebWatch uses measures designed to protect personal information, including password hashing, HTTPS, secure production cookies, request-forgery protection, rate limits, target-address checks, restricted security-report pages and access controls. API tokens are stored as hashes. Security scans are bounded and their persisted evidence is redacted.
No online service can guarantee absolute security. You are responsible for using a unique password, protecting API and webhook secrets, securing devices and endpoints, and telling us promptly if you suspect unauthorised access.
12. Your data protection rights
Depending on the circumstances, you may have the right to:
- ask for a copy of your personal information;
- correct inaccurate or incomplete information;
- ask for deletion or restriction;
- object to processing based on legitimate interests;
- receive information you provided in a portable format where the right applies; and
- withdraw consent for future analytics or personalised-ad processing.
These rights are not absolute and legal exemptions may apply. We may ask for proportionate proof of identity. Rights requests are normally free and answered within one month, although the law permits an extension for a complex request.
Email info@jj-digital.uk to exercise a right or make a privacy complaint. Please contact us first so we have an opportunity to resolve it. You also have the right to complain to the Information Commissioner's Office through its complaints service.
13. Children
WebWatch is designed for website owners and operators, not children. We do not knowingly collect personal information from a child under 13. A person under 18 should use WebWatch only with permission and supervision from a parent, guardian or responsible adult, and must not buy Premium or authorise a security scan unless legally able to do so. Contact us if you believe a child has provided personal information inappropriately.
14. Scores and automated decisions
WebWatch automatically calculates monitoring states, SEO scores, security scores and alert events. These outputs help explain a site's technical state. They are not used by JR Digital to make a solely automated decision about a person that produces legal or similarly significant effects.
15. Changes to this policy
We may update this policy when the service, providers or law changes. We will publish the new version here and change the "Last updated" date. If a change materially affects how registered users' personal information is handled, we will also use a proportionate notice, such as an account notice or email, before the change takes effect where reasonably practicable.
16. Contact
JR Digital, Exeter, England. Email: info@jj-digital.uk. Website: jj-digital.uk.