Legal
Privacy Policy
Last updated 21 August 2026
The short version
- We collect what we need to run your account and your monitors, and not much else.
- No advertising trackers, no third-party analytics, and no tracking cookies.
- We do not sell your personal data, and we never will.
- Card details go straight to Stripe. We never see or store your full card number.
- You can get a copy of your data, correct it, or have it deleted, by emailing us.
1. Who we are
Tesseract Hosting, a sole trader business in the United Kingdom, is the data controller for the personal data described here.
Contact for any privacy matter, including exercising your rights: [email protected].
This policy covers our website at tesseracthosting.co.uk and our products, including lookout.host.
2. What we collect
Information you give us
- Account details — your email address and password (stored only as a cryptographic hash, never in a readable form).
- Monitoring configuration — the URLs and endpoints you ask us to check, and your settings for them.
- Alert destinations — the email addresses, webhook URLs and chat integrations you want alerts sent to. Where you add a colleague’s address, you are responsible for having a basis to share it with us.
- Correspondence — anything you email us, and our replies.
Information created by using the service
- Monitoring results — check outcomes, status codes, response times, certificate details and incident history for the endpoints you configure.
- Technical logs — IP address, browser type and timestamps, recorded when you use the site or dashboard, for security and diagnostics.
Information we get from others
- Billing information from Stripe — your subscription status, and limited card metadata such as the last four digits, card brand and expiry, so we can show you what you are paying with. Stripe handles the card number itself; it never reaches our systems.
3. Why we use it, and our lawful basis
Under UK GDPR we must have a lawful basis for each use. Ours are:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | You cannot use the service without one | Performance of a contract |
| Run your checks and send your alerts | It is the service you asked for | Performance of a contract |
| Take payment and handle refunds | To charge for paid plans | Performance of a contract |
| Reply to your emails | To support you | Performance of a contract, or legitimate interests |
| Keep the service secure and diagnose faults | To prevent abuse and fix problems | Legitimate interests |
| Send service notices — outages, security, changes to terms | You need to know | Legitimate interests, or legal obligation |
| Keep financial records | Tax and accounting law | Legal obligation |
| Send optional product updates | Only if you opt in | Consent — withdrawable at any time |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and concluded it is not. You can object — see section 9.
4. Cookies and similar technologies
We do not use advertising cookies, and we do not run third-party analytics on our sites. There is no Google Analytics, no advertising pixel, and no cross-site tracking of any kind.
What we do use:
- An authentication cookie or token, so that you stay signed in to the dashboard. Strictly necessary; without it the service cannot work.
- Local storage in your browser, to remember interface preferences such as whether you chose the light or dark theme. This never leaves your device and we cannot read it.
Because these are strictly necessary or purely local, no cookie consent banner is required, which is why you have not been shown one.
5. Who else touches your data
We keep the list of third parties deliberately short. Each one processes data on our instructions, under a contract:
| Provider | What for | What they receive |
|---|---|---|
| Stripe | Payment processing | Your email, billing details and card data, which you enter directly with them |
| Cloudflare | Hosting, content delivery, and the monitoring stations themselves | Technical request data such as IP address; the endpoints being checked |
| Purelymail | Email for our own addresses | The contents of correspondence with us |
| Alert destinations you choose | Delivering your alerts | Only what is in the alert. If you send alerts to Slack, Discord or Telegram, their own privacy policies apply to what arrives there. |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever restructured — for instance incorporated as a limited company — or sold, data may transfer with it, and this policy will continue to apply until you are told otherwise.
We do not sell personal data, and we do not share it for anyone else’s marketing.
6. Where your data goes
We are based in the United Kingdom. Some of our providers process data outside the UK, including in the United States, and our monitoring stations are distributed worldwide by design — that is the point of them.
Where data leaves the UK we rely on the safeguards the law provides, such as UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses. You can ask us for detail on any specific transfer.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account details | While your account is open, then deleted within 30 days of closure |
| Monitoring configuration and history | Per your plan’s retention period; deleted within 30 days of account closure |
| Technical and security logs | Up to 12 months |
| Support correspondence | Up to 24 months after the matter is closed |
| Financial and transaction records | 6 years, as UK tax law requires |
Backups are overwritten on a rolling cycle, so deleted data may persist in a backup for a short period after removal from live systems — normally no more than 30 days.
8. Security
All traffic to our services runs over HTTPS. Passwords are stored as salted hashes, never in a readable form. Access to production systems is limited to those who need it, which at present is one person. Card data is handled entirely by Stripe, a PCI DSS Level 1 provider.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and tell you without undue delay where the risk is high.
9. Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, where we have no overriding reason to keep it.
- Restriction — have us pause processing while a concern is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, where we relied on consent.
Email [email protected] and we will respond within one month. There is no charge. We may need to verify who you are first, which normally means replying from the address on the account.
You can delete your account yourself at any time — see Delete your account.
10. Children
The service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, tell us and we will remove it.
11. Changes to this policy
We will update this page when our practices change, and change the date at the top. If a change is significant, we will email account holders rather than relying on you to notice.
12. Complaints
Please raise anything with us first at [email protected] — most things are a misunderstanding we can clear up quickly.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk