CBWATCH
← CBWatch

Privacy Policy

Last updated 26 August 2026

CBWatch (cbwatch.co.uk) is operated by Connor Burton, a UK-based sole trader. This policy explains what data the service collects, why, who it's shared with, and what rights you have over it. Data protection law here is the UK GDPR — see "Your rights" below for what that means in practice.

1. The free scanner (no account needed)

Running a scan from the homepage doesn't require an account or any personal details. What's collected there:

2. Accounts and monitoring

Creating an account (to monitor a domain over time) collects more, tied to your email address:

3. Billing

Payment is handled entirely by Stripe. CBWatch never receives or stores your card details — Stripe's own hosted checkout collects them directly. What CBWatch does store is a Stripe customer reference ID, a subscription ID, and the subscription's status (active, past due, cancelled), which is what controls whether monitoring is active on your account. Stripe's own privacy practices apply to the payment data itself — see stripe.com/privacy.

4. Cookies and analytics

One cookie is used: a session cookie set after you log in, so the dashboard knows who you are on later requests. It's strictly necessary for the account features to work at all — there's no way to opt out of it and stay logged in — and it carries no advertising or tracking purpose.

The homepage also loads Cloudflare Web Analytics for aggregate traffic statistics (how many visits, which pages, roughly where from). It's cookieless by design and doesn't use any client-side storage, so it can't track you individually or across other sites.

5. What gets sent to third parties, and why

A scan itself involves a few outbound lookups. These are about the domain being scanned, not about you as a visitor:

WhoWhat's sentWhy
Have I Been PwnedTwo constructed addresses (info@, admin@) at the scanned domainCheck whether those addresses appear in known data breaches
Shodan (InternetDB)The scanned domain's resolved public IP addressCheck for known open ports / vulnerabilities
Browserless.ioThe scanned domain's own public webpage, rendered server-sidePowers the optional "Scan for hidden AI-targeted content" button on a monitored, verified domain — looks for text hidden from a human but readable by a machine. Only runs when you click it; never automatic, and never on the free anonymous scan.
ResendYour email address, when you request a login link or receive a monitoring alertDelivers the actual email
StripeYour email address and payment details, at checkoutProcesses the subscription payment
RenderEverything, as the hosting provider the app runs onInfrastructure — servers, database
GitHubAn encrypted daily backup of the full database, including account emailsDisaster recovery if Render's database is ever lost — the backup is encrypted before it leaves the process that creates it, and kept for 30 days

6. How long we keep data

Monitored domains and their scan history are kept for as long as your account exists. Removing a domain from your dashboard yourself stops it being monitored immediately, but its past scan history is kept, not erased — email us if you'd like a domain's history permanently deleted rather than just deactivated. Free-scan frequency records (a domain name and a timestamp, not tied to any visitor) are currently kept indefinitely — there's no automated deletion process for these yet, as this is a young, single-person-run service. A daily encrypted backup of the full database is also kept for up to 30 days for disaster recovery; data removed from the live database — including at your request — may still exist in one of these backups until it ages out. If you'd like something removed, email us (below) and it'll be handled by hand.

You don't have to email us to delete your whole account, though — your dashboard has a Delete my account option. It sends a confirmation link to your email (the same one-time-link pattern used for logging in, expiring after 30 minutes) so an account can't be deleted by someone who's only guessed or intercepted a session, not actually you. Clicking it immediately and permanently deletes your account, every monitored domain, and their full scan history, and cancels any active subscription — this isn't a soft delete or a grace period, and it can't be undone from within the product. As with any deletion, a copy may still exist in a rolling encrypted backup for up to 30 days afterward, per the paragraph above.

7. Your rights

Under UK GDPR you can ask to: see what data is held about you, correct it, have it deleted, restrict or object to its processing, or receive a copy in a portable format. Email the address below for any of these. You can also complain to the UK's data protection regulator, the ICO, at ico.org.uk, though we'd appreciate the chance to sort it out directly first.

8. Security

Login is passwordless and session tokens are signed; login-link tokens are stored only as a hash. All traffic to the site runs over HTTPS. No system is perfectly secure, and this policy doesn't promise otherwise — but the design deliberately avoids storing the kinds of credentials (like passwords) that make a breach catastrophic.

9. Changes to this policy

If this policy changes materially, the "last updated" date at the top will change, and — for account holders — we'll flag it by email rather than expecting you to check back.

10. Contact

Questions about this policy, or a request under section 7: support@cbwatch.co.uk.