OnCallAlerting
Docs
Color theme
LEGAL

Privacy policy

This policy explains what personal data OnCallAlerting collects, why, who it is shared with, where it is stored, how long it is kept and the rights you have.

Last updated 16 September 2026.
  1. Who we are
  2. Controller and processor
  3. What we collect and why
  4. Legal bases
  5. Who we share data with
  6. Where data is stored
  7. How long we keep data
  8. Cookies
  9. Security
  10. Your rights
  11. Changes to this policy
  12. Contact

1. Who we are

OnCallAlerting is a service provided by AlertKick Ltd (company number 17201100), registered in England and Wales. In this policy "we" and "us" mean AlertKick Ltd. Contact us about anything in this policy at [email protected].

2. Controller and processor

Two different roles apply, depending on the data:

  • As controller for data about the people who use an account: names, email addresses, sign-in records, on-call schedules and the settings you create.
  • As processor for the alert content your monitoring tools send us. You decide what your systems put in an alert; we receive it, turn it into an incident and notify the person on call.

3. What we collect and why

Account and profile

Your name, email address, role in the organization, time zone and password. The password is stored only as a one-way hash, never in a form we can read. Used to sign you in, decide what you can change and show the right times for your rota.

On-call configuration

Your organization name, rosters and their layers, escalation policies, notification channels, alert sources and heartbeats. This is the working content of the product.

Alert and incident data

What your monitoring tools send to your intake endpoints, and the incidents made from it: titles, details, severity, deduplication keys, timestamps, who was notified, who acknowledged or resolved, and notes added by your team. We do not choose what your alerts contain.

Connected accounts

If you sign in with Google or GitHub we receive your name and email address from them to match you to a member of your organization. If you connect Slack we store the workspace and channel identifiers and a bot token, which is encrypted before it is written to the database.

Operational records

Sign-in sessions, invitations, delivery attempts for Slack messages and outbound webhooks, heartbeat pings and a record of configuration changes, so an organization can see who changed what.

4. Legal bases

  • Contract: to provide the service to you and your organization.
  • Legitimate interests: to keep the service secure, prevent abuse, and fix faults. Sign-in attempts are rate limited for this reason.
  • Legal obligation: where we have to keep records or respond to a lawful request.

5. Who we share data with

We do not sell personal data and we do not use it for advertising. Data reaches these parties only because the product needs them to work:

  • Slack, when your organization connects it: the notification text, which names the person on call.
  • Google and GitHub, if you choose to sign in with them. They act as independent controllers for your account with them.
  • Our mail server, to send invitation emails to the address being invited.
  • Cloudflare, which serves the website and proxies requests to our servers.

6. Where data is stored

The application and its database run on servers in the European Union, and your account and incident data stay there. The website is served through Cloudflare's global network, so a request may be handled at a location near you before it reaches our servers.

7. How long we keep data

Some records expire on their own. Others stay until you or your organization delete them.

DataKept for
Sign-in sessionsExpire automatically
Sign-in state for Google and GitHubMinutes, then deleted automatically
Rate-limit records for sign-in attemptsExpire automatically
Raw intake requestsExpire automatically
Outbound webhook delivery records30 days
Internal queue messages24 hours
Rosters, policies, sources, heartbeats, invitationsUntil you delete them
Incidents, notifications and configuration historyKept for the life of the account
Account and organization recordsUntil the account is closed

We do not currently delete old incidents automatically. If you need them removed sooner, ask us and we will do it.

8. Cookies

The site sets two cookies and neither is used for analytics, advertising or tracking across sites. There is no third-party tracking on this site.

  • Session cookie: keeps you signed in. It is HttpOnly, restricted to this site and sent only over HTTPS in production.
  • Sign-in state cookie: set for a few minutes while you sign in with Google or GitHub, to protect that exchange. It is removed when the sign-in finishes.

9. Security

Passwords are stored as one-way hashes. Slack tokens are encrypted before storage. Traffic to the site and the API is served over HTTPS. Alert intake endpoints use per-source keys, and outbound webhooks are signed so your receiver can verify them. We describe the controls we actually operate; we do not hold a security certification.

10. Your rights

Under UK data protection law you have the right to ask for a copy of your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Email [email protected] from the address on your account and we will respond within one month.

If your data was sent to us by an organization using the product, ask them first: they decide what happens to it, and we will help them act on your request.

You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can put it right.

11. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use personal data, we will tell account owners by email before it takes effect.

12. Contact

AlertKick Ltd (company number 17201100)
[email protected]

OnCallAlerting

On-call scheduling and alert escalation for teams that already have monitoring. Give every alert an owner, and everyone else their evening back.

Sign in

Product

  • On-call rotations
  • Escalation policies
  • Alert sources
  • What it does
  • Pricing

Resources

  • Documentation
  • Writing
  • Press and brand assets

Legal

  • Privacy policy
  • Terms of service
OnCallAlerting is a service provided by AlertKick Ltd, registered in England and Wales (17201100).
Color theme