Skip to content

legal — privacy

privacy policy.

Last updated: August 6, 2026

This Privacy Policy describes how Cofactor, LLC, doing business as niceuptime, collects, uses, discloses, retains, and protects personal information.

It also explains the distinction between information we process for our own purposes and information we process on behalf of niceuptime customers.

1. Scope

This Privacy Policy applies to personal information handled through:

  • The niceuptime marketing website;
  • Account registration and authentication;
  • The niceuptime application and workspaces;
  • Pulse heartbeat monitoring;
  • Probe HTTP and HTTPS monitoring;
  • Incidents and monitoring history;
  • Public, unlisted, and private status pages;
  • Status-page subscriptions and access controls;
  • Alerting and on-call functions;
  • APIs, MCP capabilities, and other automation;
  • Billing, support, documentation, and communications; and
  • Related services provided by Cofactor.

This Privacy Policy does not govern the privacy practices of a website, API, system, or other resource that a customer chooses to monitor. It also does not govern independent third-party services or integrations that have their own privacy policies.

2. Our roles

When Cofactor acts as a controller or business

Cofactor generally determines the purposes and means of processing information relating to:

  • Website visitors;
  • Account holders and Users;
  • Workspace administration;
  • Billing and subscriptions;
  • Support and sales inquiries;
  • Security and abuse prevention;
  • Product analytics;
  • Legal compliance; and
  • Our own business communications.

For those activities, Cofactor generally acts as the “controller,” “business,” or equivalent entity under applicable privacy law.

When Cofactor acts for a customer

A niceuptime customer generally determines why and how the following information is processed:

  • Monitor targets and configurations;
  • Pulse payloads;
  • Probe observations and response evidence;
  • Incident and status-page content;
  • Status-page subscriber information;
  • Private-page viewer information;
  • Workspace invitations;
  • On-call and notification-recipient information; and
  • Other Customer Data submitted to the Service.

For that processing, the customer generally acts as the controller or business, and Cofactor generally acts as its processor or service provider.

The customer’s own privacy notice and agreement with the individual govern the customer’s processing. Individuals seeking to exercise rights concerning information controlled by a niceuptime customer should ordinarily contact that customer first. We will assist customers as required by applicable law and an applicable contract.

3. Information we collect

Account and workspace information

We may collect:

  • First and last name;
  • Work or account email address;
  • Authentication information, including password hashes;
  • Organization and workspace name;
  • Workspace role and permissions;
  • Time zone and preferences;
  • Team invitations and invitation status;
  • Session information;
  • Account status;
  • Plan and entitlement information; and
  • Records of account and administrative actions.

Billing and transaction information

For paid services, we may collect:

  • Billing name and email address;
  • Billing address;
  • Organization information;
  • Tax location and tax-exemption information;
  • Subscription plan and term;
  • Transaction identifiers;
  • Invoice and payment status;
  • Payment dates and amounts; and
  • Limited payment-method information, such as card brand, expiration date, and last four digits.

Payment-card information is collected and processed by our payment processor. We do not store full payment-card numbers in the niceuptime application.

Monitoring and incident information

Depending on Customer’s configuration, we may process:

  • Monitor names and descriptions;
  • HTTP and HTTPS target URLs;
  • HTTP methods, expected-response rules, and intervals;
  • Selected monitoring regions;
  • Pulse tokens and heartbeat requests;
  • Heartbeat payloads;
  • Status codes;
  • Response timing and latency;
  • DNS, connection, TLS, and request-result information;
  • Response metadata and limited response content used for configured assertions;
  • Monitor state;
  • Failure and recovery thresholds;
  • Incident start, update, and resolution information;
  • Availability calculations;
  • Observation history; and
  • Customer-entered notes or other incident content.

Monitor targets, URLs, payloads, headers, and response content may contain information about Customer’s systems. Customers must avoid submitting personal information, credentials, or sensitive information unless necessary, lawful, and supported by a Service feature designed for that information.

Status-page information

We may process:

  • Status-page titles and slugs;
  • Component names and ordering;
  • Current and historical component status;
  • Incident information;
  • Logos and other uploaded files;
  • Custom-domain hostnames and verification records;
  • Page visibility settings;
  • Password or access-control configuration;
  • Permitted email domains;
  • Invited-viewer email addresses;
  • Status-page subscriber email addresses;
  • Subscription and unsubscribe status;
  • Access-link requests; and
  • Cookies or tokens used to maintain private-page access.

Alerting and on-call information

We may process:

  • Recipient names and email addresses;
  • Notification preferences;
  • Alert-rule configuration;
  • On-call rotation names;
  • Time zones;
  • Assignment and override periods;
  • Audit reasons;
  • Delivery status;
  • Failure and retry information; and
  • Records of sent operational communications.

Support, contact, and communications information

We collect information when a person:

  • Submits a contact form;
  • Requests support;
  • Reports a security issue;
  • Sends us an email;
  • Participates in a survey;
  • Gives feedback; or
  • Otherwise communicates with us.

This information may include name, email address, organization, message content, attachments, support history, and related technical details.

Device, usage, and security information

We may automatically collect:

  • IP address;
  • Approximate location derived from IP address;
  • Browser and device type;
  • Operating system;
  • Referrer and requested page;
  • Date and time of access;
  • Session and cookie identifiers;
  • Authentication and logout events;
  • API and MCP request metadata;
  • Rate-limit activity;
  • Application actions;
  • Audit events;
  • Error and diagnostic records;
  • Security alerts;
  • Suspected abuse indicators; and
  • Network and server logs.

Information from other sources

We may receive information from:

  • Workspace owners and administrators;
  • A person inviting another User;
  • Status-page owners;
  • Payment processors;
  • Customer-selected integrations;
  • Authentication providers;
  • Email and notification providers;
  • Security and fraud-prevention providers; and
  • Publicly accessible monitored targets, when acting on a customer’s instructions.

4. How we use information

We may use personal information to:

  • Create, authenticate, and administer accounts and workspaces;
  • Provide Pulse and Probe monitoring;
  • Process observations and derive monitor status;
  • Open, update, and resolve incidents;
  • Publish and secure status pages;
  • Manage private-page access and custom domains;
  • Send alerts, invitations, access links, status notifications, and other operational messages;
  • Maintain on-call schedules and notification routing;
  • Provide APIs, MCP capabilities, and automation;
  • Process subscriptions, payments, taxes, and invoices;
  • Provide support and respond to inquiries;
  • Personalize account settings and product behavior;
  • Monitor performance, reliability, usage, and capacity;
  • Diagnose errors and improve the Service;
  • Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
  • Enforce our agreements and protect legal rights;
  • Comply with law, legal process, and regulatory requirements;
  • Communicate product, security, billing, and legal updates;
  • Send marketing communications where permitted; and
  • Create and use aggregated or de-identified information for analytics, security, planning, benchmarking, and product development.

We do not use Customer monitoring content or status-page subscriber information for unrelated advertising.

5. Legal bases for processing

Where European Economic Area, United Kingdom, Swiss, or similar law requires a legal basis, we rely on one or more of the following:

Contract

We process information when necessary to provide an account, subscription, monitoring, status pages, alerts, support, billing, or another service requested by a person or customer.

Legitimate interests

We process information when reasonably necessary for legitimate interests such as:

  • Securing the Service;
  • Preventing fraud and abuse;
  • Maintaining reliability;
  • Supporting customers;
  • Understanding product usage;
  • Improving the Service;
  • Managing our business;
  • Enforcing agreements; and
  • Communicating with existing users.

We consider the nature of the information and the impact on individuals before relying on legitimate interests.

Consent

We rely on consent where required, including for certain optional cookies, certain marketing communications, or another activity for which applicable law requires consent. Consent may be withdrawn at any time without affecting earlier lawful processing.

Legal obligations

We process information when necessary to comply with tax, accounting, legal, regulatory, security, and law-enforcement obligations.

Customer instructions

When we act as a processor, we process personal information on the customer’s documented instructions and under the applicable agreement.

6. How we disclose information

We may disclose personal information in the following circumstances.

Within a workspace

Information may be visible to workspace owners, administrators, and other authorized Users according to their roles and permissions.

A customer controls which Users have access and is responsible for configuring those permissions.

Public status pages

Information selected for a public status page is disclosed publicly. It may be viewed and copied by any person and may be indexed or cached by third parties.

Service providers and subprocessors

We use service providers that assist with functions such as:

  • Infrastructure and hosting;
  • Data storage and databases;
  • Email delivery;
  • Payment processing;
  • Customer support;
  • Error monitoring;
  • Security;
  • Authentication;
  • Analytics;
  • Domain and certificate management; and
  • Professional services.

These providers may process information only as needed to perform services for us and are subject to contractual restrictions appropriate to their functions.

Customer-directed integrations

When a customer enables an integration or directs us to send information to a third party, we disclose the information necessary to carry out that instruction. The third party’s own terms and privacy policy apply to its independent processing.

Legal, safety, and security matters

We may disclose information where we reasonably believe disclosure is necessary to:

  • Comply with law, legal process, or a valid governmental request;
  • Enforce our agreements;
  • Investigate fraud, abuse, or unlawful activity;
  • Protect the rights, property, security, or safety of Cofactor, customers, Users, or the public; or
  • Establish, exercise, or defend legal claims.

Where legally permitted and appropriate, we may notify the affected customer before disclosing Customer Data.

Business transactions

Information may be disclosed in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. A recipient will be required to handle personal information consistently with applicable law and any commitments that continue to apply.

Professional advisers

We may disclose information to lawyers, accountants, auditors, insurers, financial advisers, and similar professionals subject to confidentiality obligations.

With permission

We may disclose information for another purpose when the relevant person or customer directs or authorizes us to do so.

7. Public and private status pages

A customer decides whether to publish a status page and what information appears on it.

Public pages

Public status-page information is intentionally public. It may include component names, availability history, incident information, timestamps, messages, logos, and other customer-selected content.

Search engines, archives, browsers, recipients, and other third parties may retain copies after the customer changes or removes the page.

Unlisted and private pages

An unlisted page is not necessarily confidential.

Private pages may use passwords, email-domain restrictions, invited-viewer lists, access links, or access cookies. These controls reduce public accessibility but cannot prevent an authorized viewer from forwarding, copying, or capturing information.

Customers should not publish secrets or highly sensitive information on any status page.

Subscribers and viewers

When a person subscribes to a customer’s status page or requests access to a private page, we process the person’s information for that customer. The customer generally controls that information.

Subscribers may use the unsubscribe method included in applicable notifications. Private-page viewers may contact the status-page owner regarding access or privacy questions.

8. Cookies and similar technologies

We use cookies and similar technologies that are necessary to:

  • Authenticate Users;
  • Maintain sessions;
  • Prevent forgery and abuse;
  • Protect account security;
  • Remember preferences;
  • Maintain private status-page access; and
  • Operate account and application functionality.

We may use optional analytics technologies to understand website and product usage. Where applicable law requires consent, we will obtain consent before setting nonessential cookies.

Browser settings may allow a person to block or delete cookies. Blocking necessary cookies may prevent account access or other Service functions.

We recognize legally valid opt-out preference signals where required by applicable law. Because we do not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, such a signal does not change our current advertising practices.

We do not rely on a browser’s general “Do Not Track” setting where no uniform legal or technical standard applies.

9. Sale, sharing, targeted advertising, and financial incentives

We do not sell personal information for monetary or other valuable consideration.

We do not share personal information for cross-context behavioral advertising as “sharing” is defined by California privacy law.

We do not process personal information for targeted advertising as that term is defined by applicable United States state privacy laws.

As of the Last Updated date, we have not sold or shared personal information for these purposes during the preceding 12 months.

We do not offer financial incentives or price differences in exchange for permission to sell or share personal information.

Service providers receiving information from us may use it only for contracted services and not for their own unrelated advertising.

10. Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Service, maintaining security, complying with law, resolving disputes, and enforcing agreements.

Our retention criteria include the nature and sensitivity of the information, the purpose for which it is processed, plan and product settings, legal obligations, security requirements, and whether the information is needed to establish or defend a claim.

Typical retention practices include:

InformationRetention approach
Account and workspace informationRetained while the account or workspace is active and for a reasonable period afterward for support, security, dispute resolution, and legal compliance.
Monitoring observations and incident historyRetained according to the applicable plan and Documentation. The current ordinary maximum retention period is 365 days unless a longer period is agreed in writing or continued retention is required for security or legal reasons. A plan’s visible-history period may be shorter than the storage period.
Status-page contentRetained while the page or workspace is active and until deleted in the ordinary course. Copies outside our control may remain in caches, archives, browsers, or recipients’ systems.
Subscriber, viewer, and recipient informationRetained while the subscription, access authorization, notification configuration, or customer relationship remains active and for a limited period afterward for suppression, security, or compliance purposes.
Billing and transaction recordsRetained for the periods required by tax, accounting, financial, and legal obligations.
Support and communications recordsRetained as reasonably needed to respond, maintain support history, improve service, and resolve disputes.
Security, API, audit, and diagnostic logsRetained according to operational and security needs and may be retained longer when associated with suspected abuse, an incident, or a legal obligation.
BackupsResidual copies may remain until overwritten through standard backup rotation and may be isolated from ordinary use.
Aggregated or de-identified informationMay be retained without a fixed period where it no longer identifies an individual or customer.

A deletion request does not require us to delete information that we must retain to complete a transaction, protect security, prevent fraud, comply with law, maintain suppression records, exercise legal rights, or satisfy another lawful exception.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include access controls, credential protections, tenant isolation, logging, restricted administrative access, security monitoring, and vendor-management practices appropriate to the information and Service.

No internet service, storage system, or transmission method is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or lost without authorization.

Customers and Users are responsible for protecting their passwords, API keys, MCP credentials, Pulse tokens, private-page credentials, email accounts, devices, and monitored systems.

Suspected account compromise should be reported promptly to support@niceuptime.com. Security vulnerabilities should be reported to security@niceuptime.com.

12. International processing and transfers

Cofactor is based in the United States. Personal information may be processed in the United States and in other countries where our service providers operate.

Those countries may have privacy laws different from the law where an individual lives. Where applicable law requires safeguards for an international transfer, we use an appropriate lawful mechanism or contractual protection.

13. Privacy rights and choices

Depending on applicable law and the nature of our role, a person may have rights to:

  • Confirm whether we process personal information;
  • Access or obtain a copy of personal information;
  • Correct inaccurate personal information;
  • Delete personal information;
  • Obtain portable information in a usable format;
  • Restrict or object to processing;
  • Withdraw consent;
  • Opt out of sale, sharing, targeted advertising, or qualifying profiling;
  • Appeal a denial of a privacy request; and
  • Receive equal service without unlawful discrimination for exercising a privacy right.

We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects concerning an individual.

Making a request

Submit a request to privacy@niceuptime.com and describe the request and the account, workspace, or interaction involved.

We may verify identity and authority by asking the requester to:

  • Respond from an email address associated with the account;
  • Sign into the account;
  • Confirm information associated with prior interactions; or
  • Provide other information reasonably necessary to prevent unauthorized disclosure or deletion.

We will use verification information only to process the request.

An authorized agent may submit a request where permitted by law. We may require proof of authorization and may verify the individual’s identity directly.

If we deny a request, the requester may appeal by replying to the decision or emailing privacy@niceuptime.com with the subject “Privacy Appeal.”

Customer-controlled information

When a request concerns Customer Data for which a niceuptime customer is the controller or business, we may direct the requester to the customer. We will assist the customer where required by applicable law and contract.

Marketing choices

A person may unsubscribe from marketing email using the link in the message. This does not prevent account, billing, security, legal, or other transactional communications.

A status-page subscriber may unsubscribe using the method included in the applicable status notification.

14. United States state privacy disclosures

To the extent applicable state privacy law applies, the following supplemental disclosures cover our practices during the 12 months preceding the Last Updated date.

We may have collected these categories of personal information:

  • Identifiers, such as name, email address, IP address, account identifiers, device identifiers, and transaction identifiers;
  • Customer-record information, such as contact and billing information;
  • Commercial information, such as subscription plan, transaction history, and product usage;
  • Internet or electronic-network activity, such as browser information, logs, sessions, API activity, and interactions with the Service;
  • Approximate geolocation, derived from an IP address where used for localization or security;
  • Professional or employment-related information, such as organization, role, and work email;
  • User-generated content and communications, such as support messages, incident content, monitor configuration, and status-page content; and
  • Sensitive personal information, principally account log-in credentials and security information.

The sources of these categories are described in Section 3. The business purposes are described in Section 4. The categories of recipients are described in Section 6.

We use sensitive personal information only as reasonably necessary to authenticate Users, secure accounts, provide the requested Service, prevent fraud and abuse, comply with law, and perform other purposes permitted without offering a separate right to limit its use. We do not use sensitive personal information to infer characteristics about a person.

We do not sell or share these categories for cross-context behavioral advertising. We do not use them for targeted advertising. We do not knowingly sell or share personal information of individuals under 16.

Where applicable, individuals may exercise rights to know, access, correct, delete, obtain portability, opt out, limit qualifying sensitive-information use, and avoid discrimination by using the request process in Section 13.

15. European, United Kingdom, and Swiss rights

Where applicable, individuals in the European Economic Area, United Kingdom, or Switzerland may have rights to access, correction, deletion, portability, restriction, objection, and withdrawal of consent.

An individual may object to processing based on legitimate interests. We will stop the processing unless we demonstrate compelling legitimate grounds or need the information for legal claims.

An individual may lodge a complaint with the data-protection authority in the individual’s country or region.

Where we process information for a customer, the customer is ordinarily responsible for responding to these requests, and we will assist as required.

16. Children

niceuptime accounts are not available to individuals under 18.

The Service is not directed to children, and we do not knowingly collect personal information directly from children for account creation or marketing.

Customers may not knowingly use the Service to collect or process children’s personal information in violation of applicable law.

A parent or guardian who believes a child provided personal information to us may contact privacy@niceuptime.com.

17. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in the Service, law, vendors, or our practices.

We will post the revised version with an updated date. For a material change, we will provide additional notice where required, such as through the Service or by email.

An earlier version continues to govern processing that occurred before a change to the extent required by law.

18. Contact

Cofactor, LLC

Attn: Privacy

4301 S Flamingo Road

Suite 106 PMB 610

Davie, Florida 33330

United States

Privacy requests and questions: privacy@niceuptime.com

Security reports: security@niceuptime.com

Account support: support@niceuptime.com