Privacy Policy
Last updated: 16 August 2026
1. Who we are, and who is responsible
Walters Sentinel is a website and infrastructure monitoring service operated by Lewis Walters, a sole trader trading as Walters Sentinel, based in the United Kingdom. Under UK data protection law we are the data controller for the personal data described in this policy.
You can reach us at contact@walterssentinel.com. We answer privacy requests at the same address.
Where you use Walters Sentinel to monitor your own systems, and that monitoring involves personal data belonging to other people, you are the controller of that data and we act as your processor.
2. What we collect
| What | Why we have it |
|---|---|
| Your email address and password | To create your account and sign you in. Passwords are stored as a one-way hash, never as text, so we cannot read yours. |
| Your name, company name and profile picture | Optional. Shown to your own teammates so they can tell who is who. |
| Organization names and logos you upload | Shown in your dashboard, in alert emails, and on your public status page if you enable one. |
| The addresses you ask us to monitor, and how you configure each check | This is the service. It includes any custom headers, request bodies and expected responses you set. |
| Credentials you give us for your own systems | If you monitor a page behind a login, you may give us a username and password, a bearer token, or an API key. We need these to make the check. They are encrypted before storage using AES-256-GCM, are never returned to your browser once saved, and are never shown to us in readable form in any interface. |
| Alert recipient email addresses | So we can email the people you nominate when something breaks. If you add somebody else's address, you are responsible for having a basis to do so. |
| Messages you send us | Through the contact form on our website, or by emailing us. This includes your name, email address, any company name you give, and whatever you write. |
| Billing records | Which plan you bought, when, how much, and Stripe's reference for it. We never see or store your card details - those go directly to Stripe. |
| Technical records | Your IP address and browser type when you use the service, kept in server logs, and used to rate-limit abuse. Check results and response times for the addresses you monitor. |
3. Our lawful basis for each of these
| Purpose | Lawful basis |
|---|---|
| Running your account and performing the monitoring you paid for | Performance of a contract |
| Sending alerts, sign-in codes and service notices | Performance of a contract |
| Taking payment and keeping billing records | Performance of a contract, and legal obligation for tax records |
| Replying to your messages | Legitimate interests - answering somebody who contacted us |
| Keeping the service secure, rate-limiting abuse, investigating misuse | Legitimate interests - protecting the service and its users |
| Keeping records we are required to keep | Legal obligation |
We do not sell your data, we do not use it for advertising, and we do not profile you.
4. Who else handles your data
We use a small number of suppliers to run the service. Each is bound to process data only on our instructions.
| Supplier | What they handle | Where |
|---|---|---|
| Turso | Our database. All account, organization, monitoring and message data. | EU / UK |
| Render | Hosting for the application and its server logs. | EU / US |
| Stripe | Payments. They receive your card details directly; we receive only the result. | EU / US |
| Resend | Sending our outbound email, including alerts and sign-in codes. | EU / US |
| Titan Mail (Hostinger) | Our own mailboxes, which receive messages you send to us. | EU |
| 123-reg | Hosting for our marketing website. | UK |
We will also disclose data if we are legally required to, or where it is necessary to establish or defend a legal claim.
5. Data leaving the UK
Some of the suppliers above process data outside the UK. Where that happens, the transfer is covered by the UK International Data Transfer Addendum, Standard Contractual Clauses, or an adequacy decision, depending on the supplier and the country.
6. How long we keep things
| What | How long |
|---|---|
| Your account | Until you delete it, or we terminate it under the Terms |
| Monitors, their settings and their check history | Until you delete the monitor or the organization it belongs to. Deleting either destroys the history with it, immediately and permanently. |
| Stored credentials for your monitored systems | Deleted with the monitor they belong to |
| Messages sent to contact@walterssentinel.com | Deleted after 15 days |
| Mail sent to noreply@walterssentinel.com | Deleted automatically. That inbox is not monitored. |
| Billing records | Six years, as UK tax law requires |
| Server logs | Up to 30 days |
7. How we protect it
- Everything travels over HTTPS.
- Passwords are stored as a one-way hash. Nobody at Walters Sentinel can read your password.
- Credentials you give us for your own systems are encrypted at rest with AES-256-GCM, and are never sent back to a browser once saved.
- Signing out of everywhere invalidates every session on every device at once.
- Access to production data is limited to those who need it to run the service.
No system is perfectly secure. If a breach affects your rights, we will tell you and the Information Commissioner's Office within the timescales the law requires.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you, and get a copy.
- Rectification - have inaccurate data corrected. Most of it you can correct yourself in Settings.
- Erasure - ask us to delete your data. You can delete your own account and organizations at any time; note that this is immediate and permanent, and we do not keep a backup copy for you.
- Restriction - ask us to stop processing while a dispute is resolved.
- Portability - receive your data in a structured, machine-readable format.
- Object to processing we carry out on the basis of legitimate interests.
- Withdraw consent at any time, where we relied on consent.
Email contact@walterssentinel.com and we will respond within one month. There is no charge.
If you think we have got something wrong, you can complain to the Information Commissioner's Office at ico.org.uk, or call 0303 123 1113. We would rather you told us first so we can put it right.
9. Cookies and local storage
We use a single cookie to keep you signed in, and browser local storage to remember your theme. That is all. There is no advertising, no analytics tracking you across sites, and no third-party cookies - which is why you are not being asked to accept anything.
10. Children
Walters Sentinel is a business tool for adults. We do not knowingly collect data from anyone under 16, and accounts are not intended for them.
11. Changes to this policy
If we change how we handle your data we will update this page and the date at the top. Where a change materially affects you, we will email you about it rather than relying on you noticing.