← CBWatch

Privacy Policy

Last updated 15 August 2026

CBWatch (cbwatch.co.uk) is operated by Connor Burton, a UK-based sole trader. This policy explains what data the service collects, why, who it's shared with, and what rights you have over it. Data protection law here is the UK GDPR — see "Your rights" below for what that means in practice.

1. The free scanner (no account needed)

Running a scan from the homepage doesn't require an account or any personal details. What's collected there:

2. Accounts and monitoring

Creating an account (to monitor a domain over time) collects more, tied to your email address:

3. Billing

Payment is handled entirely by Stripe. CBWatch never receives or stores your card details — Stripe's own hosted checkout collects them directly. What CBWatch does store is a Stripe customer reference ID, a subscription ID, and the subscription's status (active, past due, cancelled), which is what controls whether monitoring is active on your account. Stripe's own privacy practices apply to the payment data itself — see stripe.com/privacy.

4. Cookies and analytics

One cookie is used: a session cookie set after you log in, so the dashboard knows who you are on later requests. It's strictly necessary for the account features to work at all — there's no way to opt out of it and stay logged in — and it carries no advertising or tracking purpose.

The homepage also loads Cloudflare Web Analytics for aggregate traffic statistics (how many visits, which pages, roughly where from). It's cookieless by design and doesn't use any client-side storage, so it can't track you individually or across other sites.

5. What gets sent to third parties, and why

A scan itself involves a few outbound lookups. These are about the domain being scanned, not about you as a visitor:

WhoWhat's sentWhy
Have I Been PwnedTwo constructed addresses (info@, admin@) at the scanned domainCheck whether those addresses appear in known data breaches
Shodan (InternetDB)The scanned domain's resolved public IP addressCheck for known open ports / vulnerabilities
ResendYour email address, when you request a login link or receive a monitoring alertDelivers the actual email
StripeYour email address and payment details, at checkoutProcesses the subscription payment
RenderEverything, as the hosting provider the app runs onInfrastructure — servers, database

6. How long we keep data

Monitored domains and their scan history are kept for as long as your account exists. Free-scan frequency records (a domain name and a timestamp, not tied to any visitor) are currently kept indefinitely — there's no automated deletion process for these yet, as this is a young, single-person-run service. If you'd like something removed, email us (below) and it'll be handled by hand.

7. Your rights

Under UK GDPR you can ask to: see what data is held about you, correct it, have it deleted, restrict or object to its processing, or receive a copy in a portable format. Email the address below for any of these. You can also complain to the UK's data protection regulator, the ICO, at ico.org.uk, though we'd appreciate the chance to sort it out directly first.

8. Security

Login is passwordless and session tokens are signed; login-link tokens are stored only as a hash. All traffic to the site runs over HTTPS. No system is perfectly secure, and this policy doesn't promise otherwise — but the design deliberately avoids storing the kinds of credentials (like passwords) that make a breach catastrophic.

9. Changes to this policy

If this policy changes materially, the "last updated" date at the top will change, and — for account holders — we'll flag it by email rather than expecting you to check back.

10. Contact

Questions about this policy, or a request under section 7: conburton11@icloud.com.