CBWatch (cbwatch.co.uk) is operated by Connor Burton, a UK-based sole trader. This policy explains what data the service collects, why, who it's shared with, and what rights you have over it. Data protection law here is the UK GDPR — see "Your rights" below for what that means in practice.
Running a scan from the homepage doesn't require an account or any personal details. What's collected there:
Creating an account (to monitor a domain over time) collects more, tied to your email address:
Payment is handled entirely by Stripe. CBWatch never receives or stores your card details — Stripe's own hosted checkout collects them directly. What CBWatch does store is a Stripe customer reference ID, a subscription ID, and the subscription's status (active, past due, cancelled), which is what controls whether monitoring is active on your account. Stripe's own privacy practices apply to the payment data itself — see stripe.com/privacy.
One cookie is used: a session cookie set after you log in, so the dashboard knows who you are on later requests. It's strictly necessary for the account features to work at all — there's no way to opt out of it and stay logged in — and it carries no advertising or tracking purpose.
The homepage also loads Cloudflare Web Analytics for aggregate traffic statistics (how many visits, which pages, roughly where from). It's cookieless by design and doesn't use any client-side storage, so it can't track you individually or across other sites.
A scan itself involves a few outbound lookups. These are about the domain being scanned, not about you as a visitor:
| Who | What's sent | Why |
|---|---|---|
| Have I Been Pwned | Two constructed addresses (info@, admin@) at the scanned domain | Check whether those addresses appear in known data breaches |
| Shodan (InternetDB) | The scanned domain's resolved public IP address | Check for known open ports / vulnerabilities |
| Resend | Your email address, when you request a login link or receive a monitoring alert | Delivers the actual email |
| Stripe | Your email address and payment details, at checkout | Processes the subscription payment |
| Render | Everything, as the hosting provider the app runs on | Infrastructure — servers, database |
Monitored domains and their scan history are kept for as long as your account exists. Free-scan frequency records (a domain name and a timestamp, not tied to any visitor) are currently kept indefinitely — there's no automated deletion process for these yet, as this is a young, single-person-run service. If you'd like something removed, email us (below) and it'll be handled by hand.
Under UK GDPR you can ask to: see what data is held about you, correct it, have it deleted, restrict or object to its processing, or receive a copy in a portable format. Email the address below for any of these. You can also complain to the UK's data protection regulator, the ICO, at ico.org.uk, though we'd appreciate the chance to sort it out directly first.
Login is passwordless and session tokens are signed; login-link tokens are stored only as a hash. All traffic to the site runs over HTTPS. No system is perfectly secure, and this policy doesn't promise otherwise — but the design deliberately avoids storing the kinds of credentials (like passwords) that make a breach catastrophic.
If this policy changes materially, the "last updated" date at the top will change, and — for account holders — we'll flag it by email rather than expecting you to check back.
Questions about this policy, or a request under section 7: conburton11@icloud.com.