Privacy policy

In effect from 8 August 2026. JourneyPing is operated by Gerald Labs.

This describes what personal data JourneyPing collects, why, where it is kept and how to get it removed. It covers this website and the JourneyPing application. It is written to be read, not to be survived.

Who is responsible

Gerald Labs operates JourneyPing and is the data controller for the personal data described here.

Where a customer uses JourneyPing to monitor websites, Gerald Labs acts as a processor for whatever personal data those monitoring results happen to contain, and the customer is the controller of it.

What is collected, and why

When you ask for a demo

The form collects your name, work email address, company name, an optional message and the plan you selected. It is used to contact you about JourneyPing and for nothing else. The lawful basis is our legitimate interest in responding to a business enquiry you initiated, and you can object to that at any time. Reply to us or email the address below and we will stop and delete the enquiry. These submissions are stored and read by hand: there is no automated marketing system behind them, and you are not added to a mailing list.

When you have an account

An account holds your email address, your name if you provide one, the workspace you belong to and your role within it. Sign-in is by email link through Firebase Authentication. The lawful basis is performance of the contract to provide the service. If someone invited you to a workspace, we received your name and email address from them rather than from you.

When the service runs

Monitoring produces results, screenshots and recordings of the websites a customer has asked us to check. These are of public web pages, but a screenshot can incidentally capture personal data if a monitored page contains any. Customers control what is monitored; we do not use this material for anything except providing the service.

Security and abuse prevention

Public forms are protected by Cloudflare Turnstile, which assesses whether a submission is automated. Our infrastructure providers log requests, including IP addresses, for security and operational purposes, and Cloudflare may set a cookie as part of that. The lawful basis is our legitimate interest in keeping the service secure and available. These logs are kept for the period set by the provider concerned.

What is not collected

There is no analytics, advertising or tracking on this website, and nothing is stored in your browser for those purposes. The application sets the cookies it needs to keep you signed in, and stores a few things locally in your browser because the interface needs them: your light or dark theme preference, the sites you looked at most recently, and, while you are signing in, the email address you asked for the link to be sent to.

No decision affecting you is made automatically, and there is no profiling in the sense the GDPR uses the word.

Where it is stored

Application data is held in Google Cloud Firestore and processed by Google Cloud Run in the europe-west1 region, in the European Union. The website is served by Cloudflare, and authentication uses Firebase.

Some of these providers are US-headquartered and may process or access data outside the EU. Where that happens we rely on the safeguards in each provider’s data processing terms: the European Commission’s adequacy decision for certified US providers where it applies, and the Commission’s standard contractual clauses otherwise. Email us and we will tell you which applies to a particular provider.

How long it is kept

  • Demo enquiries. Deleted twelve months after our last contact with you, or sooner if you ask.
  • Account data. Kept while the account exists and removed when it is closed, except records we are required to keep for accounting purposes, which we keep for as long as bookkeeping law requires.
  • Failure recordings and screenshots. Kept for 7 days, 30 days or 90 days depending on the plan, then deleted automatically.
  • Monitoring results. Kept while the account exists so that reports and history remain meaningful, and deleted or returned when the customer whose data it is asks us to.

Who else sees it

The service is built on Google Cloud, Firebase and Cloudflare, which process data on our behalf under contract. When a customer configures alerts to Slack, Discord, Microsoft Teams, Google Chat, a webhook or their own endpoint, the alert content they have chosen is sent to that destination at their instruction.

Nothing is sold, and nothing is shared for advertising.

Your rights

Under the GDPR you can ask for a copy of your personal data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable form. You can also complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).

How to exercise them: We handle these requests manually rather than through a self-service tool, and will respond within one month, extendable by two further months for a complex request as the GDPR allows, in which case we will tell you inside the first month. Being direct about it: there is no button for this yet, and saying otherwise would be the kind of promise that is discovered to be untrue at the worst moment.

No data protection officer is appointed; the contact point for anything in this policy is the address above.

Websites we visit on a customer’s behalf

Our scanner identifies itself as JourneyPingBot and only visits a site after someone has proven they control that domain. If you have found it in your logs and want it to stop, the crawler page explains how.

Changes

If this policy changes in a way that affects you, the date at the top changes and account holders are told. Older versions are available on request.