Privacy Policy
Last Modified: 2 July 2026
Upcheck is a website and API monitoring service operated by Rekwiem (business registration no. 357-58-01022). This Privacy Policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have. It applies to our website, dashboard, and mobile apps worldwide. It is written to meet the Korean Personal Information Protection Act (PIPA) and includes additional disclosures for individuals in the European Economic Area (EEA), the United Kingdom, and California.
1. Scope and who we are
This policy applies to personal data we process as the controller (the party that decides why and how it is processed) when you use Upcheck. Rekwiem is the controller. Where we process data only on behalf of and under the instructions of a customer, we act as a processor and this policy is provided for transparency.
It does not cover third-party websites or services you reach through links from Upcheck; those are governed by their own privacy notices.
2. Region-specific disclosures
- If you are in Korea, the PIPA-mandated items throughout this policy apply, and the “Remedies for infringement” section lists the Korean bodies you can contact.
- If you are in the EEA or UK, see “Legal bases for processing” and “Your rights in the EEA and UK”.
- If you are in California, see “Your rights in California (CCPA/CPRA)”.
3. Personal data we collect
We collect the following categories of personal data, all limited to what is needed for the purposes described below.
| Category | Items | How collected |
|---|---|---|
| Account | Email address, password (stored hashed), email verification status | You provide at sign-up |
| Social sign-in | Provider account identifier and email from Apple or Google | When you sign in with Apple/Google |
| Monitoring data | Target URLs/hostnames and check settings you enter, plus check results, response metadata and logs | You provide when configuring monitors |
| Notifications | Email address and, for the app, device push token | You provide / generated by the app |
| Billing | Subscription status and plan, and a billing identifier from our payment provider | Generated when you subscribe |
| Support | The contents of messages you send us and our replies | You provide when you contact us |
| Usage and device | IP address, browser/device type, and access timestamps | Generated automatically on use |
We do not collect payment card numbers. Card and payment details are entered directly with our payment providers (Paddle, RevenueCat, Apple), who process them. We do not intentionally collect special-category/sensitive data or national identification numbers, and we ask that you not enter such data into monitor names or settings.
4. How we use personal data
- Create and manage your account, authenticate sign-in (email/password and Apple/Google), and verify your email address.
- Operate the monitoring service — run the checks you configure and store their results and history.
- Send service messages such as downtime, recovery, and email/push alerts, and important account or security notices.
- Process subscriptions, payments, and refunds for paid plans, and meet related tax and accounting obligations.
- Provide customer support and respond to your enquiries.
- Keep the service secure, detect and prevent abuse or fraud, and debug and improve reliability.
- Comply with applicable law and enforce our terms.
We do not use your personal data for behavioural advertising, and we do not sell it.
5. Legal bases for processing (EEA and UK)
If you are in the EEA or UK, we rely on the following legal bases under the GDPR / UK GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the account and monitoring service | Performance of a contract with you |
| Sending service and alert messages you configure | Performance of a contract with you |
| Push notifications on your device | Consent (device permission), which you can withdraw |
| Processing payments | Performance of a contract with you |
| Keeping accounting and transaction records | Compliance with a legal obligation |
| Security, abuse prevention, and service improvement | Our legitimate interests in running a safe, reliable service |
| Responding to support requests | Performance of a contract / our legitimate interests |
Where we rely on legitimate interests, we have weighed those interests against your rights. You may object to such processing as described in your rights section below.
6. How we share personal data
We do not sell your personal data. We share it only in these situations: (1) with the service providers (processors) listed below who operate Upcheck on our behalf; (2) with payment providers to complete a transaction you request; (3) where required by law, legal process, or to protect rights and safety; and (4) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply.
Each processor is bound by contract to protect personal data and to process it only on our instructions.
| Processor | Work performed | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, edge delivery | USA / global edge |
| Resend (Plus Five Five, Inc.) | Delivery of transactional and alert emails | USA |
| RevenueCat, Inc. | Subscription management and receipt validation | USA |
| Paddle.com Market Ltd. | Payment processing and merchant of record for web subscriptions | United Kingdom |
| Apple Inc. | In-app purchases and push notification delivery (iOS/macOS apps) | USA |
| Google LLC | Sign-in with Google (authentication) | USA |
7. International data transfers
Because our infrastructure and providers operate globally, your personal data may be transferred to and stored in countries outside your own, including the United States and the United Kingdom. We transfer only the minimum necessary for each purpose.
| Recipient (country) | Data transferred | Purpose |
|---|---|---|
| Cloudflare, Inc. (USA) | Account, monitoring and log data | Hosting, database, delivery |
| Resend (USA) | Email address, message content | Sending service emails |
| RevenueCat, Inc. (USA) | Billing identifier, subscription status | Subscription management |
| Paddle.com Market Ltd. (United Kingdom) | Billing and transaction data | Web payment processing |
| Apple Inc. (USA) | Purchase and push token data | App purchases and push |
| Google LLC (USA) | Sign-in identifier, email | Authentication |
For transfers of EEA/UK personal data to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with technical measures like encryption in transit. For Korean data subjects, these overseas transfers are disclosed above; you may object to the overseas transfer of your personal data, though some transfers are essential to provide the service and objecting may mean we can no longer provide it. To request a copy of the relevant safeguards or to object, contact team@rekwiem.com.
8. Cookies and similar technologies
We use a session cookie that is strictly necessary to keep you signed in. We do not use advertising, cross-site tracking, or third-party analytics cookies, so no cookie-consent banner is required. You can block or delete cookies in your browser settings, but doing so will sign you out and may prevent parts of the service from working.
9. Children under 14
Upcheck is a service for developers and businesses and is not directed to children. We do not knowingly collect personal data from children under 14 (or under the minimum age in your jurisdiction). If we learn we have, we will delete it without delay.
10. Retention and use period
We keep personal data only as long as needed for the purpose it was collected for, then destroy it — unless a law requires longer retention.
| Data | Retention period |
|---|---|
| Account and profile | Until you delete your account, then destroyed without delay |
| Monitoring configuration and results | While your account is active; deleted with the account |
| Usage and access logs | Retained for a limited period for security, then deleted |
| Records on contracts / withdrawal of subscription | 5 years (Act on Consumer Protection in Electronic Commerce) |
| Records on payment and supply of goods | 5 years (Act on Consumer Protection in Electronic Commerce) |
| Records on consumer complaints or disputes | 3 years (Act on Consumer Protection in Electronic Commerce) |
11. Destruction of personal data
When the retention period ends or the purpose is achieved, we destroy the data without delay. Electronic files are deleted so they cannot be recovered; any printed materials are shredded or incinerated.
12. Security measures
- Passwords are stored hashed, and traffic is encrypted in transit (TLS).
- Access to personal data is limited to authorized personnel on a need-to-know basis.
- We rely on established infrastructure providers and apply access controls and logging.
- We take technical and administrative measures appropriate to the risk to reduce the chance of unauthorized access, alteration, or loss.
- No method of transmission or storage is completely secure; we cannot guarantee absolute security.
13. Your rights and choices
Wherever you are, you may request access to, correction of, or deletion of your personal data, and you may object to or ask us to restrict certain processing. You can update your email or delete your account directly in your account settings; for anything else, contact team@rekwiem.com and we will respond without undue delay. You may act through a legal representative or an authorized agent, and we will not disadvantage you for exercising your rights.
14. Your rights in the EEA and UK
If you are in the EEA or UK, you also have the rights under the GDPR / UK GDPR to:
- Access a copy of your personal data.
- Rectify inaccurate data and complete incomplete data.
- Erasure of your data (“right to be forgotten”) where applicable.
- Restrict or object to processing, including processing based on our legitimate interests.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time where we rely on consent, without affecting prior processing.
- Lodge a complaint with your local supervisory authority.
15. Your rights in California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to or deletion of it, to correct inaccurate information, and to be free from discrimination for exercising these rights.
We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the CPRA. We therefore do not offer a “Do Not Sell or Share” mechanism because we do not engage in that activity. The categories we collect, our purposes, and the parties we disclose to are described in the sections above. You may submit a request, including through an authorized agent, at team@rekwiem.com; we will verify your request before acting on it.
16. Third-party links
Upcheck may link to third-party sites and services. We are not responsible for their privacy practices, and we encourage you to read their privacy notices.
17. Data Protection Officer and contact
The controller is Rekwiem (business registration no. 357-58-01022). We have appointed a Data Protection Officer responsible for handling personal data and any related complaints or requests. For any question, request, or complaint about how we handle personal data, use the contact below.
- Data Protection Officer: SeungMin Lee
- Contact: team@rekwiem.com
18. Remedies for infringement
If you cannot resolve a privacy concern with us, you may contact the following bodies. Korean data subjects may use the Korean authorities; EEA/UK residents may complain to their local data protection authority.
- Personal Information Dispute Mediation Committee (Korea) — kopico.go.kr (1833-6972)
- Personal Information Infringement Report Center (Korea) — privacy.kisa.or.kr (118)
- Supreme Prosecutors’ Office Cybercrime (Korea) — spo.go.kr (1301)
- National Police Agency Cybercrime (Korea) — ecrm.police.go.kr (182)
- EEA residents: your national data protection authority (see edpb.europa.eu for the list)
- UK residents: the Information Commissioner’s Office — ico.org.uk
19. Changes to this policy
If we change this policy, we will post the updated version here and update the date above. Where a change is significant, we will give notice in advance through the service before it takes effect.