Privacy policy
This policy explains what personal data OnCallAlerting collects, why, who it is shared with, where it is stored, how long it is kept and the rights you have.
Last updated 16 September 2026.1. Who we are
OnCallAlerting is a service provided by AlertKick Ltd (company number 17201100), registered in England and Wales. In this policy "we" and "us" mean AlertKick Ltd. Contact us about anything in this policy at [email protected].
2. Controller and processor
Two different roles apply, depending on the data:
- As controller for data about the people who use an account: names, email addresses, sign-in records, on-call schedules and the settings you create.
- As processor for the alert content your monitoring tools send us. You decide what your systems put in an alert; we receive it, turn it into an incident and notify the person on call.
3. What we collect and why
Account and profile
Your name, email address, role in the organization, time zone and password. The password is stored only as a one-way hash, never in a form we can read. Used to sign you in, decide what you can change and show the right times for your rota.
On-call configuration
Your organization name, rosters and their layers, escalation policies, notification channels, alert sources and heartbeats. This is the working content of the product.
Alert and incident data
What your monitoring tools send to your intake endpoints, and the incidents made from it: titles, details, severity, deduplication keys, timestamps, who was notified, who acknowledged or resolved, and notes added by your team. We do not choose what your alerts contain.
Connected accounts
If you sign in with Google or GitHub we receive your name and email address from them to match you to a member of your organization. If you connect Slack we store the workspace and channel identifiers and a bot token, which is encrypted before it is written to the database.
Operational records
Sign-in sessions, invitations, delivery attempts for Slack messages and outbound webhooks, heartbeat pings and a record of configuration changes, so an organization can see who changed what.
4. Legal bases
- Contract: to provide the service to you and your organization.
- Legitimate interests: to keep the service secure, prevent abuse, and fix faults. Sign-in attempts are rate limited for this reason.
- Legal obligation: where we have to keep records or respond to a lawful request.
5. Who we share data with
We do not sell personal data and we do not use it for advertising. Data reaches these parties only because the product needs them to work:
- Slack, when your organization connects it: the notification text, which names the person on call.
- Google and GitHub, if you choose to sign in with them. They act as independent controllers for your account with them.
- Our mail server, to send invitation emails to the address being invited.
- Cloudflare, which serves the website and proxies requests to our servers.
6. Where data is stored
The application and its database run on servers in the European Union, and your account and incident data stay there. The website is served through Cloudflare's global network, so a request may be handled at a location near you before it reaches our servers.
7. How long we keep data
Some records expire on their own. Others stay until you or your organization delete them.
| Data | Kept for |
|---|---|
| Sign-in sessions | Expire automatically |
| Sign-in state for Google and GitHub | Minutes, then deleted automatically |
| Rate-limit records for sign-in attempts | Expire automatically |
| Raw intake requests | Expire automatically |
| Outbound webhook delivery records | 30 days |
| Internal queue messages | 24 hours |
| Rosters, policies, sources, heartbeats, invitations | Until you delete them |
| Incidents, notifications and configuration history | Kept for the life of the account |
| Account and organization records | Until the account is closed |
We do not currently delete old incidents automatically. If you need them removed sooner, ask us and we will do it.
8. Cookies
The site sets two cookies and neither is used for analytics, advertising or tracking across sites. There is no third-party tracking on this site.
- Session cookie: keeps you signed in. It is HttpOnly, restricted to this site and sent only over HTTPS in production.
- Sign-in state cookie: set for a few minutes while you sign in with Google or GitHub, to protect that exchange. It is removed when the sign-in finishes.
9. Security
Passwords are stored as one-way hashes. Slack tokens are encrypted before storage. Traffic to the site and the API is served over HTTPS. Alert intake endpoints use per-source keys, and outbound webhooks are signed so your receiver can verify them. We describe the controls we actually operate; we do not hold a security certification.
10. Your rights
Under UK data protection law you have the right to ask for a copy of your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Email [email protected] from the address on your account and we will respond within one month.
If your data was sent to us by an organization using the product, ask them first: they decide what happens to it, and we will help them act on your request.
You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can put it right.
11. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we use personal data, we will tell account owners by email before it takes effect.
12. Contact
AlertKick Ltd (company number 17201100)
[email protected]