Privacy Policy
This policy is split by where you interact with Heapwatch: the marketing website, the app and your account, and the device data you send us. One company is responsible for all of it.
Who We Are
Heapwatch is built and run by Viktor Jamrich Enterprises s.r.o., a company registered in Slovakia at Dolná Poruba 10, 914 43 Dolná Poruba, Slovakia, EU (IČO 50657461; DIČ 2120415561; IČ DPH SK2120415561). We're the data controller for both heapwatch.com and the app at app.heapwatch.com.
Anything privacy-related reaches us at info@heapwatch.com.
Why We Need It
We use personal data to:
- run Heapwatch — accounts, workspaces, device ingest, crash decoding, billing;
- hold up our end of the contract and enforce our Terms and Refund Policy;
- keep the platform secure, catch abuse, and meet our legal obligations;
- send messages that matter: security notices, billing, meaningful product changes, and onboarding help;
- improve the product, working from aggregated or anonymised patterns wherever we can;
- understand which marketing pages and campaigns bring people to Heapwatch, without selling that data to anyone;
- answer you when you write in or open live chat.
In GDPR terms, that rests on performing our contract with you (Art. 6(1)(b)), our legitimate interest in running a secure service, answering pre-sales questions, and measuring our own marketing (Art. 6(1)(f)), and legal obligations around tax and accounting (Art. 6(1)(c)). Optional PostHog analytics and live chat on the marketing site rely on your consent (Art. 6(1)(a)).
Your Rights
If you're in the EEA or UK, you can ask us for a copy of your data, get it corrected or deleted, restrict or object to how we use it, take it elsewhere in a portable format, unsubscribe from onboarding emails using the link in any message, or pull your marketing-site analytics consent whenever you like. One email is enough — we won't make you fill in a form.
If we ever handle a request badly, you can complain to the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov SR) or the supervisory authority where you live. We'd appreciate the chance to fix it first.
If This Policy Changes
A new version gets its own permanent URL (for example /privacy/2026-09-05-v5) and /privacy always shows the one currently in force. If we change optional cookies in a way that matters, we'll reset the consent banner so you get to make the choice again.
Marketing website (heapwatch.com)
Reading our site, using Cookie Settings, or contacting us — with or without an account.
What We Collect on the Website
- How you found us — first-party attribution in your browser (UTM parameters, landing page, referrer, ad click identifiers when present in the URL). If you register, we attach this to your account.
- Contact messages — what you send through the contact form, plus the GDPR consent record for that submission.
- Live chat — if you open live chat, the messages you send and any contact details you provide so we can reply. Chatwoot may also record technical metadata such as browser type and a masked IP address.
- Cookie preferences — your cookie choice and site settings such as theme.
Cookies, Analytics, and Attribution
Essential cookies remember your cookie decision and site preferences. They don't track you across sites and don't need consent.
We run Plausible ourselves on our EU servers for anonymous page statistics on heapwatch.com. It does not set cookies, does not track you across sites, and does not build a personal profile. It is always on.
If you accept analytics in Cookie Settings, we also use PostHog Cloud (EU region) for optional marketing-site analytics; PostHog may set cookies. You can change your mind in Cookie Settings any time.
We store first-party marketing attribution in your browser's local storage (not cookies): campaign tags, landing pages, referrer, and ad click identifiers when present. This does not load third-party ad pixels. Clear it by clearing site data for heapwatch.com.
If you opt in to live chat in Cookie Settings, we load Chatwoot (EU-hosted). Chatwoot may set cookies to keep your conversation across pages. It stays off unless you opt in. You can change your mind in Cookie Settings any time.
Heapwatch app & account (app.heapwatch.com)
Registered users: workspaces, billing, onboarding emails, and in-app analytics.
What We Collect in the App
- Your account — name, email, a hash of your password, workspace name, and onboarding answers.
- Billing — plan, interval, invoices, payment status. Card details go to Stripe; we never store a full card number.
- Product usage — features you use, browser and device type, rough location from IP, timestamps.
- Live chat — when you use in-app live chat while signed in, we pass your account email and name to Chatwoot so support knows who you are, plus the messages you send.
Account Emails and Onboarding
When you create an account, you agree we may email you with messages that are part of using the service: getting started, onboarding your first device, trial reminders, and similar product guidance.
We use MailerLite (EU-based) to store your contact details and send these sequences, including which lifecycle segment you are in (for example workspace owner on trial, paying, or invited team member).
Security, billing, and other transactional messages go through Mailgun (EU region). Every onboarding email includes an unsubscribe link. You can also email info@heapwatch.com. Messages required to run your account may still reach you after you unsubscribe from onboarding sequences.
In-App Analytics
When you use app.heapwatch.com while signed in, we send product analytics to PostHog Cloud (EU region) tied to your account email to understand feature usage and improve the product. This is separate from the marketing-site cookie banner.
In-App Live Chat
Signed-in users can open live chat from the product UI. We use the same Chatwoot inbox as heapwatch.com, hosted in the EU. We identify you with your account email so conversations are not anonymous. Chatwoot may set cookies for session continuity. This is part of providing support for the service you signed up for (Art. 6(1)(b)).
Devices & workspaces
Telemetry, crashes, and firmware data your boards send to Heapwatch.
What Your Devices Send
Your devices and workspaces send data you control. It is ingested over MQTT into our EU infrastructure — not routed through a third-party IoT or analytics platform.
- device identifiers, telemetry (memory, CPU, threads, logs, events, custom values), core dumps, firmware metadata, and connector configuration;
- anything your devices handle in the field — if that includes personal data, it can end up here, so send only what you need.
Processors & retention
What stays on our EU infrastructure, external processors, and how long we keep data.
Where Data Lives and Who Processes It
Most of Heapwatch runs on our own EU infrastructure: the marketing site, the app, MQTT device ingest, telemetry and crash storage, and self-hosted Plausible for anonymous website statistics. That processing is under our control — not a separate vendor reading your device or account data.
We also use these processors for specific tasks on our instructions:
- Stripe — payment processing;
- Mailgun (EU region) — transactional email (contact form notifications, account and security messages);
- MailerLite (EU-based) — onboarding and lifecycle email sequences;
- PostHog Cloud (EU region) — product analytics on heapwatch.com (if you opted in) and in the app while you use the service;
- Chatwoot (EU-hosted) — live chat on heapwatch.com (if you opted in) and in-app support chat.
Device telemetry and core dumps stay on our EU servers. Stripe, Mailgun, MailerLite, PostHog, and Chatwoot each handle their slice under their own privacy notices as our processors. We don't sell personal data. We may disclose data if the law requires it or to protect users and safety.
How Long We Keep It
Account and billing records: while your account is active, then as long as Slovak tax law requires. MailerLite profile: while your account is active or until you unsubscribe from onboarding emails. Live chat transcripts: while needed to handle your request and for a reasonable support history, then deleted or anonymised per our Chatwoot retention settings. Website attribution on your account: until account deletion. Crash history and telemetry: per your plan's retention window, then purged automatically. Delete a workspace yourself, or email us to wipe account data.