Last updated: August 12, 2026
StatusDrop ("we," "us," or "our") operates the statusdrop.dev website, dashboard, embeddable widget, hosted status pages, and related APIs (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable data protection laws.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
StatusDrop is an independent software product operated from Romania, within the European Union. Full legal and registration details of the operator are available on request.
For the personal data of our own account holders, described in section 4, StatusDrop is the data controller. We decide why and how that data is processed.
Where an account holder uses the status page subscribers feature, the email addresses of their subscribers belong to that account holder's own audience. In respect of that data, the account holder is the controller and StatusDrop acts solely as their processor. We process subscriber data only on the account holder's documented instructions, only to deliver the notifications they configure, and never for our own purposes. See section 4.7 for details. A Data Processing Agreement is available on request.
We have not appointed a Data Protection Officer, as we are not required to do so under GDPR Article 37. Data protection enquiries are handled directly by the operator at the address above.
We process your personal data under the following legal bases as defined by GDPR Article 6:
When you create an account through our authentication provider (Clerk), we collect:
When you use the dashboard, we collect data related to your use of the Service:
Payment processing is handled entirely by Clerk (via Stripe). We do not directly store credit card numbers, CVVs, or full payment card details. We receive and store:
When you access the Service, we may automatically collect:
We fetch publicly available status page data from third-party services (e.g., Stripe, AWS, GitHub) that you add to your stacks. This data includes service health indicators, component statuses, and response times. This is not personal data; it is publicly available information retrieved from official status page APIs.
If you submit a support request or feedback through our platform, we collect the content of your message, your email address, and any attachments you provide.
Our customers may enable email subscriptions on their status page. Where they do, we process the following on their behalf, as their processor and not as controller:
Subscription uses double opt-in: an address is not confirmed until the person clicks the confirmation link we email them. Every notification email includes a one-click unsubscribe link. We use subscriber addresses only to send the incident and maintenance notifications configured by the customer who owns that status page. We never use them for our own marketing, never sell them, and never share them beyond the processors listed in section 7. If you are a subscriber and wish to exercise your rights, contact the operator of the status page you subscribed to, or write to us at hello@statusdrop.dev and we will forward your request.
We use PostHog (hosted in the European Union) to understand how the StatusDrop marketing site and dashboard are used, so we can improve them. PostHog collects:
Analytics are deliberately limited in scope. They run only on statusdrop.dev itself, only in production, and are explicitly disabled on public status pages (both /s/ URLs and customer custom domains)and in the embeddable widget. Visitors to a customer's status page or to a site carrying the StatusDrop widget are never tracked by us. We also use Vercel Analytics and Vercel Speed Insights, which collect aggregated, cookieless page performance metrics.
The legal basis for product analytics is our legitimate interest in understanding and improving the Service (Art. 6(1)(f)), and, where required by the ePrivacy rules of your jurisdiction, your consent for the storage of analytics identifiers on your device. You can opt out at any time by enabling Do Not Track or Global Privacy Control in your browser, by blocking analytics domains, or by writing to hello@statusdrop.dev.
We use Sentry to capture application errors so we can fix them. When an error occurs, Sentry receives the error message and stack trace, the URL where it happened, browser and operating system details, and, for signed-in users, an account identifier. A sample of performance traces (10% in production) is also collected. Session Replay is not enabled. The legal basis is our legitimate interest in keeping the Service secure and functional (Art. 6(1)(f)).
We use the data we collect for the following purposes:
The StatusDrop embeddable widget is a standalone JavaScript bundle that customers embed on their websites using a <script> tag. It is important to understand what the widget does and does not do:
/api/widget/[slug])The widget communicates exclusively with our API to retrieve status data for the configured stack. No visitor data is transmitted in these requests beyond the standard HTTP headers sent by the browser (such as IP address and User-Agent in server logs). We do not log or store visitor-level data from widget API requests beyond what is necessary for rate limiting and abuse prevention.
For website owners embedding the widget: The StatusDrop widget is designed to be privacy-friendly and does not require cookie consent banners or GDPR consent mechanisms on its own, as it does not process personal data of your website visitors.
We use the following third-party service providers (data processors) to operate the Service. Each processor has committed to data protection obligations consistent with GDPR requirements:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Clerk | Authentication, session management, billing (via Stripe) | Email, name, profile picture, session tokens, payment data | United States |
| Convex | Database, backend functions, cron jobs | Account data, stacks, services, status checks, configurations | United States |
| Vercel | Application hosting, edge functions, CDN | HTTP request data, server logs | Global (edge network) |
| Upstash Redis | Caching, rate limiting, status check deduplication | Cached status data, rate limit counters (IP-based) | United States |
| Resend | Transactional email delivery | Email addresses, email content (status alerts, notifications, subscriber confirmations) | United States |
| PostHog | Product analytics (marketing site and dashboard only) | Pageviews, device and browser data, IP-derived location, and for signed-in users: user ID, email, name, subscription status | European Union |
| Sentry | Error and performance monitoring | Error messages, stack traces, URLs, browser and OS data, account identifier | United States |
| Cloudflare | Optional Domain Connect flow for custom status page domains | Domain name and DNS record data, only when you choose to use this flow | Global |
Vercel Analytics and Vercel Speed Insights are provided by Vercel as part of the hosting relationship listed above, and collect aggregated, cookieless performance metrics.
Where you configure webhook notifications, we send status information to the endpoint you specify at Slack, Discord, or Telegram. Those platforms are recipients you have chosen, and their handling of that data is governed by their own terms and privacy policies.
We have Data Processing Agreements (DPAs) or equivalent contractual protections in place with each processor. This list also serves as our list of subprocessors for customer data processed under section 4.7. We will give notice of material changes to this list before a new subprocessor begins processing. We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
Our Service and most of our third-party processors are based in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data may be transferred to and processed in the United States or other countries outside your jurisdiction.
We ensure that such transfers are carried out in compliance with GDPR by relying on one or more of the following safeguards:
You may request a copy of the safeguards in place by contacting us at hello@statusdrop.dev.
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under GDPR Articles 13 through 22. You may exercise any of these rights by contacting us at hello@statusdrop.dev.
We will respond to your request within 30 days. In certain cases, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for the delay. If we cannot comply with your request, we will provide an explanation.
We use a small number of cookies and equivalent browser storage on statusdrop.dev: those that are strictly necessary to sign you in and keep the Service secure, and a first-party product analytics identifier. We do not use advertising, marketing, or cross-site tracking cookies, and we do not share cookie data with advertising networks.
| Cookie Type | Provider | Purpose | Duration |
|---|---|---|---|
| Session cookie | Clerk | Authentication and session management. Required to keep you signed in. | Session / 7 days |
| CSRF token | Clerk | Protects against cross-site request forgery attacks. | Session |
| Analytics identifier | PostHog (EU) | First-party cookie and browser storage holding a pseudonymous ID, so repeat visits to statusdrop.dev can be recognised for product analytics. Not set on status pages or in the widget. | 12 months |
The Clerk cookies are classified as "strictly necessary" under GDPR and ePrivacy regulations. They do not require consent because the Service cannot function without them. The PostHog analytics identifier is not strictly necessary; you can refuse or remove it by blocking third-party analytics in your browser, using a privacy extension, clearing site data, or contacting us at hello@statusdrop.dev. Refusing it does not affect your ability to use the Service.
Embeddable widget: The StatusDrop widget embedded on customer websites does not set, read, or use any cookies whatsoever, and carries no analytics.
Hosted status pages: Public status pages, whether served at statusdrop.dev/s/ or on a customer custom domain, carry no analytics and set no analytics cookies. A status page protected by a password sets a single session cookie once you enter the correct password, so you are not asked for it again on every visit; that cookie is strictly necessary for the feature to work.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly. If you believe we may have collected data from a child under 16, please contact us at hello@statusdrop.dev.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining strong protections and responding promptly to any security concerns.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
For any questions, concerns, or requests related to this Privacy Policy or our data processing practices, please contact us:
We aim to respond to all data protection inquiries within 30 days. For GDPR-related requests, we will confirm receipt and provide a substantive response within the timeframes required by applicable law.
If you are located in the EEA or the United Kingdom and believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities and their contact details is available at the European Data Protection Board website.
We encourage you to contact us first so we can attempt to resolve your concern directly.