Privacy Policy

Last Modified: 2 July 2026

Upcheck is a website and API monitoring service operated by Rekwiem (business registration no. 357-58-01022). This Privacy Policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have. It applies to our website, dashboard, and mobile apps worldwide. It is written to meet the Korean Personal Information Protection Act (PIPA) and includes additional disclosures for individuals in the European Economic Area (EEA), the United Kingdom, and California.

1. Scope and who we are

This policy applies to personal data we process as the controller (the party that decides why and how it is processed) when you use Upcheck. Rekwiem is the controller. Where we process data only on behalf of and under the instructions of a customer, we act as a processor and this policy is provided for transparency.

It does not cover third-party websites or services you reach through links from Upcheck; those are governed by their own privacy notices.

2. Region-specific disclosures

  • If you are in Korea, the PIPA-mandated items throughout this policy apply, and the “Remedies for infringement” section lists the Korean bodies you can contact.
  • If you are in the EEA or UK, see “Legal bases for processing” and “Your rights in the EEA and UK”.
  • If you are in California, see “Your rights in California (CCPA/CPRA)”.

3. Personal data we collect

We collect the following categories of personal data, all limited to what is needed for the purposes described below.

CategoryItemsHow collected
AccountEmail address, password (stored hashed), email verification statusYou provide at sign-up
Social sign-inProvider account identifier and email from Apple or GoogleWhen you sign in with Apple/Google
Monitoring dataTarget URLs/hostnames and check settings you enter, plus check results, response metadata and logsYou provide when configuring monitors
NotificationsEmail address and, for the app, device push tokenYou provide / generated by the app
BillingSubscription status and plan, and a billing identifier from our payment providerGenerated when you subscribe
SupportThe contents of messages you send us and our repliesYou provide when you contact us
Usage and deviceIP address, browser/device type, and access timestampsGenerated automatically on use

We do not collect payment card numbers. Card and payment details are entered directly with our payment providers (Paddle, RevenueCat, Apple), who process them. We do not intentionally collect special-category/sensitive data or national identification numbers, and we ask that you not enter such data into monitor names or settings.

4. How we use personal data

  • Create and manage your account, authenticate sign-in (email/password and Apple/Google), and verify your email address.
  • Operate the monitoring service — run the checks you configure and store their results and history.
  • Send service messages such as downtime, recovery, and email/push alerts, and important account or security notices.
  • Process subscriptions, payments, and refunds for paid plans, and meet related tax and accounting obligations.
  • Provide customer support and respond to your enquiries.
  • Keep the service secure, detect and prevent abuse or fraud, and debug and improve reliability.
  • Comply with applicable law and enforce our terms.

We do not use your personal data for behavioural advertising, and we do not sell it.

5. Legal bases for processing (EEA and UK)

If you are in the EEA or UK, we rely on the following legal bases under the GDPR / UK GDPR:

PurposeLegal basis
Providing the account and monitoring servicePerformance of a contract with you
Sending service and alert messages you configurePerformance of a contract with you
Push notifications on your deviceConsent (device permission), which you can withdraw
Processing paymentsPerformance of a contract with you
Keeping accounting and transaction recordsCompliance with a legal obligation
Security, abuse prevention, and service improvementOur legitimate interests in running a safe, reliable service
Responding to support requestsPerformance of a contract / our legitimate interests

Where we rely on legitimate interests, we have weighed those interests against your rights. You may object to such processing as described in your rights section below.

6. How we share personal data

We do not sell your personal data. We share it only in these situations: (1) with the service providers (processors) listed below who operate Upcheck on our behalf; (2) with payment providers to complete a transaction you request; (3) where required by law, legal process, or to protect rights and safety; and (4) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply.

Each processor is bound by contract to protect personal data and to process it only on our instructions.

ProcessorWork performedLocation
Cloudflare, Inc.Application hosting, database, edge deliveryUSA / global edge
Resend (Plus Five Five, Inc.)Delivery of transactional and alert emailsUSA
RevenueCat, Inc.Subscription management and receipt validationUSA
Paddle.com Market Ltd.Payment processing and merchant of record for web subscriptionsUnited Kingdom
Apple Inc.In-app purchases and push notification delivery (iOS/macOS apps)USA
Google LLCSign-in with Google (authentication)USA

7. International data transfers

Because our infrastructure and providers operate globally, your personal data may be transferred to and stored in countries outside your own, including the United States and the United Kingdom. We transfer only the minimum necessary for each purpose.

Recipient (country)Data transferredPurpose
Cloudflare, Inc. (USA)Account, monitoring and log dataHosting, database, delivery
Resend (USA)Email address, message contentSending service emails
RevenueCat, Inc. (USA)Billing identifier, subscription statusSubscription management
Paddle.com Market Ltd. (United Kingdom)Billing and transaction dataWeb payment processing
Apple Inc. (USA)Purchase and push token dataApp purchases and push
Google LLC (USA)Sign-in identifier, emailAuthentication

For transfers of EEA/UK personal data to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with technical measures like encryption in transit. For Korean data subjects, these overseas transfers are disclosed above; you may object to the overseas transfer of your personal data, though some transfers are essential to provide the service and objecting may mean we can no longer provide it. To request a copy of the relevant safeguards or to object, contact team@rekwiem.com.

8. Cookies and similar technologies

We use a session cookie that is strictly necessary to keep you signed in. We do not use advertising, cross-site tracking, or third-party analytics cookies, so no cookie-consent banner is required. You can block or delete cookies in your browser settings, but doing so will sign you out and may prevent parts of the service from working.

9. Children under 14

Upcheck is a service for developers and businesses and is not directed to children. We do not knowingly collect personal data from children under 14 (or under the minimum age in your jurisdiction). If we learn we have, we will delete it without delay.

10. Retention and use period

We keep personal data only as long as needed for the purpose it was collected for, then destroy it — unless a law requires longer retention.

DataRetention period
Account and profileUntil you delete your account, then destroyed without delay
Monitoring configuration and resultsWhile your account is active; deleted with the account
Usage and access logsRetained for a limited period for security, then deleted
Records on contracts / withdrawal of subscription5 years (Act on Consumer Protection in Electronic Commerce)
Records on payment and supply of goods5 years (Act on Consumer Protection in Electronic Commerce)
Records on consumer complaints or disputes3 years (Act on Consumer Protection in Electronic Commerce)

11. Destruction of personal data

When the retention period ends or the purpose is achieved, we destroy the data without delay. Electronic files are deleted so they cannot be recovered; any printed materials are shredded or incinerated.

12. Security measures

  • Passwords are stored hashed, and traffic is encrypted in transit (TLS).
  • Access to personal data is limited to authorized personnel on a need-to-know basis.
  • We rely on established infrastructure providers and apply access controls and logging.
  • We take technical and administrative measures appropriate to the risk to reduce the chance of unauthorized access, alteration, or loss.
  • No method of transmission or storage is completely secure; we cannot guarantee absolute security.

13. Your rights and choices

Wherever you are, you may request access to, correction of, or deletion of your personal data, and you may object to or ask us to restrict certain processing. You can update your email or delete your account directly in your account settings; for anything else, contact team@rekwiem.com and we will respond without undue delay. You may act through a legal representative or an authorized agent, and we will not disadvantage you for exercising your rights.

14. Your rights in the EEA and UK

If you are in the EEA or UK, you also have the rights under the GDPR / UK GDPR to:

  • Access a copy of your personal data.
  • Rectify inaccurate data and complete incomplete data.
  • Erasure of your data (“right to be forgotten”) where applicable.
  • Restrict or object to processing, including processing based on our legitimate interests.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where we rely on consent, without affecting prior processing.
  • Lodge a complaint with your local supervisory authority.

15. Your rights in California (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to or deletion of it, to correct inaccurate information, and to be free from discrimination for exercising these rights.

We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the CPRA. We therefore do not offer a “Do Not Sell or Share” mechanism because we do not engage in that activity. The categories we collect, our purposes, and the parties we disclose to are described in the sections above. You may submit a request, including through an authorized agent, at team@rekwiem.com; we will verify your request before acting on it.

16. Third-party links

Upcheck may link to third-party sites and services. We are not responsible for their privacy practices, and we encourage you to read their privacy notices.

17. Data Protection Officer and contact

The controller is Rekwiem (business registration no. 357-58-01022). We have appointed a Data Protection Officer responsible for handling personal data and any related complaints or requests. For any question, request, or complaint about how we handle personal data, use the contact below.

  • Data Protection Officer: SeungMin Lee
  • Contact: team@rekwiem.com

18. Remedies for infringement

If you cannot resolve a privacy concern with us, you may contact the following bodies. Korean data subjects may use the Korean authorities; EEA/UK residents may complain to their local data protection authority.

  • Personal Information Dispute Mediation Committee (Korea) — kopico.go.kr (1833-6972)
  • Personal Information Infringement Report Center (Korea) — privacy.kisa.or.kr (118)
  • Supreme Prosecutors’ Office Cybercrime (Korea) — spo.go.kr (1301)
  • National Police Agency Cybercrime (Korea) — ecrm.police.go.kr (182)
  • EEA residents: your national data protection authority (see edpb.europa.eu for the list)
  • UK residents: the Information Commissioner’s Office — ico.org.uk

19. Changes to this policy

If we change this policy, we will post the updated version here and update the date above. Where a change is significant, we will give notice in advance through the service before it takes effect.