Privacy Policy
We are ALERTIS (Sole Proprietor Ivanchenko O., Ukraine — "we", "us", "the service"). This policy explains what data we collect, why we need it, who we share it with, and how you can control it. The document is written as plainly as possible. If anything is unclear — email [email protected] and we'll explain in human language.
1. Who we are and how to reach us
ALERTIS is an early-warning SaaS for marketers and business owners. We collect Google Analytics 4 metrics, detect anomalies, and send alerts to Telegram or email.
Data controller: Sole Proprietor Ivanchenko O., Ukraine. Privacy contact: [email protected].
2. What data we collect
We collect the minimum needed to operate the service:
Account data: your email, name (optional), company name, timezone, interface language.
Authentication data: if you sign in with Google — we receive only your email and basic profile (name, avatar). We never see your password.
GA4 access token: the read-only OAuth token you grant to ALERTIS. Stored encrypted. Revocable in Google in 5 seconds.
GA4 metrics: aggregated numbers (sessions, users, conversions, CR, bounce rate, AI traffic) sliced by date, channel, campaign, device, country. We do not receive any personal data of your site visitors.
Telegram chat_id: if you connected the bot, we store the chat ID to send alerts.
Payment data: processed by Stripe. We see only the last 4 digits of the card, type, country. Full card details are not in our database.
Technical data: IP, user-agent, actions in the interface (for security and debugging). Stored up to 90 days.
3. Why we collect it
Account and authentication data — so you can log in and receive personalized reports.
GA4 metrics — to compare against your individual baseline and detect anomalies. That's the product.
Telegram chat_id — to send alerts where you asked us to.
Payment data — for invoicing and accounting.
Technical data — for security (detecting brute-force attempts, blocking attacks) and debugging.
4. Lawful bases for processing (GDPR)
We process your data on the following lawful bases:
Performance of contract (Article 6(1)(b) GDPR) — without the data we cannot provide the service.
Consent (Article 6(1)(a) GDPR) — for some optional features (e.g., niche benchmarks).
Legitimate interest (Article 6(1)(f) GDPR) — for service security and fraud prevention.
Legal obligations — e.g., retention of tax records.
6. How long we keep data
Account data — while your account exists + 30 days after deletion (recovery window).
GA4 metrics — while the subscription is active. On GA4 disconnect — wiped within 14 days.
Access logs — 90 days.
Payment records — 7 years (tax law requirement).
7. Your rights
You have the right to:
Receive a copy of all data we hold about you (CSV/JSON export via account settings).
Correct inaccurate data.
Delete your account and all related data. One click in settings. We process the request within 14 days.
Restrict processing — e.g., pause analytics without deleting the account.
Port data to another service (data portability).
Withdraw consent at any time.
Lodge a complaint with the data protection authority of Ukraine or your country.
To exercise a right — write to [email protected], we respond within 30 days.
8. Security
Encryption at rest — AES-256.
Encryption in transit — TLS 1.3.
GA4 tokens stored encrypted in a separate vault.
Two-factor authentication available for all accounts.
We regularly update dependencies and monitor vulnerabilities. If you found one — write to [email protected], we appreciate it.
10. International data transfers
Some sub-processors are located in the US (Stripe, OpenAI). Data transfers happen under European Commission Standard Contractual Clauses (SCC).
We do not transfer data to countries lacking an adequate level of protection without additional safeguards.
11. Children
The service is not intended for persons under 16. If we learn we collected a minor's data without guardian consent — we erase it.
12. Changes to this policy
If we make material changes — we'll notify you by email and in the interface 14 days in advance. Minor edits (wording, typos) we may make without notice.