Legal
Privacy Policy
Effective date: 11 October 2026
This policy explains how SupaPing collects, uses, stores and shares information when you visit or use our service.
1. Who we are
SupaPing is a service designed to send scheduled keep-alive requests to supported Supabase projects to help reduce inactivity on eligible database plans.
Service operator: SupaPing
Privacy enquiries: support@supaping.app
2. Information we collect
Depending on how you use SupaPing, we may process:
- Account information: information associated with your authentication account, such as your email address and user identifier.
- Project configuration: the project name, optional description, Supabase project URL and publishable API key you provide.
- Heartbeat records: request timestamps, response status, latency, error information and whether a request was recorded as successful.
- Operational records: scheduled job execution status, execution duration, failure counts and alert delivery attempts.
- Technical information: information that may be included in application, security or hosting logs.
- Usage analytics: website usage information processed through Vercel Web Analytics, if enabled.
Please do not submit passwords, service-role keys, database passwords or other secrets as project configuration.
3. How we use your information
We use information to:
- Provide and maintain the SupaPing service.
- Authenticate users and protect accounts.
- Run scheduled keep-alive requests for configured projects.
- Display heartbeat history, status and performance information.
- Investigate failures, troubleshoot problems and protect security.
- Send operational alert emails to the configured service operator when scheduled checks encounter certain failures.
- Understand website usage and improve the service.
- Meet applicable legal obligations.
4. Legal bases for processing
Where UK data protection law applies, we rely on an appropriate legal basis for each processing activity. Depending on the circumstances, this may include performing a contract with you, pursuing legitimate interests such as service security and reliability, complying with legal obligations, or consent where required.
Where we rely on legitimate interests, those interests are balanced against your rights and freedoms.
5. How heartbeat requests work
When you configure a project, SupaPing uses the project URL and publishable key you provide to make scheduled requests to the configured Supabase endpoint.
The service records operational results so it can report whether requests succeeded and how long they took. The configured endpoint must be valid and accessible for the request to work.
You are responsible for ensuring you are authorised to configure and monitor each project you add.
6. Service providers and sharing
We use third-party providers to operate SupaPing. Depending on the feature, these may include:
- Supabase: authentication, database storage and related infrastructure.
- Vercel: application hosting and, where enabled, website analytics.
- Resend: delivery of authentication or operational emails, depending on the email being sent.
These providers may process information on our behalf to provide their services. Their own terms and privacy policies also apply to their services.
We do not sell your personal information. We may disclose information where required by law, to protect rights and security, or as part of a business transfer where legally permitted.
7. International transfers
Our service providers may process information in countries outside the United Kingdom. Where a restricted international transfer takes place, we will use an appropriate transfer mechanism and safeguards where required by applicable data protection law.
8. Data retention
We retain information for as long as reasonably necessary to provide the service, maintain operational history, protect security, resolve disputes and meet legal obligations. Actual retention periods may vary by data type and provider. We will update this policy if we establish specific retention periods or change our retention practices.
9. Security
We use technical and organisational measures intended to protect information against unauthorised access, loss and misuse. No online service can guarantee absolute security. You should protect your account credentials and never submit secrets that the service does not require.
10. Your rights
Depending on your circumstances and applicable law, you may have the right to request access to your personal information, correct inaccurate information, request erasure or restriction, object to certain processing, or receive a portable copy of information. Where processing is based on consent, you may be able to withdraw it.
To make a request, contact support@supaping.app. You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
11. Cookies and analytics
SupaPing uses authentication-related technologies needed to operate accounts. Vercel Web Analytics may also be used to understand visits and usage. Whether additional consent or controls are required depends on the technologies enabled and how they operate. We will provide any notices or choices required by applicable law.
12. Children
SupaPing is intended for people who are legally able to use the service and is not designed for children. Please contact us if you believe a child has provided personal information inappropriately.
13. Changes to this policy
We may update this policy as the service changes or legal requirements evolve. We will publish the updated version on this page and revise the effective date.