Privacy Policy
This policy is split by where you interact with Heapwatch: the marketing website, the app and your account, and the device data you send us. One company is responsible for all of it.
This is an earlier version. The current privacy policy is at /privacy.
Who We Are
Heapwatch is built and run by Viktor Jamrich Enterprises s.r.o., a company registered in Slovakia at Dolná Poruba 10, 914 43 Dolná Poruba, Slovakia, EU (IČO 50657461; DIČ 2120415561; IČ DPH SK2120415561). We're the data controller for both heapwatch.com and the app at app.heapwatch.com.
Anything privacy-related reaches us at info@heapwatch.com.
Why We Need It
We use personal data to:
- run Heapwatch — accounts, workspaces, device ingest, crash decoding, billing;
- hold up our end of the contract and enforce our Terms and Refund Policy;
- keep the platform secure, catch abuse, and meet our legal obligations;
- send messages that matter: security notices, billing, meaningful product changes, and onboarding help;
- improve the product, working from aggregated or anonymised patterns wherever we can;
- understand which marketing pages and campaigns bring people to Heapwatch, without selling that data to anyone;
- answer you when you write in.
In GDPR terms, that rests on performing our contract with you (Art. 6(1)(b)), our legitimate interest in running a secure service and measuring our own marketing (Art. 6(1)(f)), and legal obligations around tax and accounting (Art. 6(1)(c)). Optional PostHog analytics on the marketing site rely on your consent (Art. 6(1)(a)).
Your Rights
If you're in the EEA or UK, you can ask us for a copy of your data, get it corrected or deleted, restrict or object to how we use it, take it elsewhere in a portable format, unsubscribe from onboarding emails using the link in any message, or pull your marketing-site analytics consent whenever you like. One email is enough — we won't make you fill in a form.
If we ever handle a request badly, you can complain to the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov SR) or the supervisory authority where you live. We'd appreciate the chance to fix it first.
If This Policy Changes
A new version gets its own permanent URL (for example /privacy/2026-09-05-v3) and /privacy always shows the one currently in force. If we change optional cookies in a way that matters, we'll reset the consent banner so you get to make the choice again.
Marketing website (heapwatch.com)
Reading our site, using Cookie Settings, or contacting us — with or without an account.
What We Collect on the Website
- How you found us — first-party attribution in your browser (UTM parameters, landing page, referrer, ad click identifiers when present in the URL). If you register, we attach this to your account.
- Contact messages — what you send through the contact form, plus the GDPR consent record for that submission.
- Cookie preferences — your cookie choice and site settings such as theme.
Cookies, Analytics, and Attribution
Essential cookies remember your cookie decision and site preferences. They don't track you across sites and don't need consent.
We use Plausible on heapwatch.com for anonymous page statistics. It does not set cookies, does not track you across sites, and does not build a personal profile. It is always on.
If you accept analytics in Cookie Settings, we also load PostHog (EU-hosted) for optional marketing-site analytics; PostHog may set cookies. You can change your mind in Cookie Settings any time.
We store first-party marketing attribution in your browser's local storage (not cookies): campaign tags, landing pages, referrer, and ad click identifiers when present. This does not load third-party ad pixels. Clear it by clearing site data for heapwatch.com.
Heapwatch app & account (app.heapwatch.com)
Registered users: workspaces, billing, onboarding emails, and in-app analytics.
What We Collect in the App
- Your account — name, email, a hash of your password, workspace name, and onboarding answers.
- Billing — plan, interval, invoices, payment status. Card details go to Stripe; we never store a full card number.
- Product usage — features you use, browser and device type, rough location from IP, timestamps.
Account Emails and Onboarding
When you create an account, you agree we may email you with messages that are part of using the service: getting started, onboarding your first device, trial reminders, and similar product guidance.
We use MailerLite (EU-based) to store your contact details and send these sequences, including which lifecycle segment you are in (for example workspace owner on trial, paying, or invited team member).
Every onboarding email includes an unsubscribe link. You can also email info@heapwatch.com. Security, billing, and other messages required to run your account may still reach you.
In-App Analytics
When you use app.heapwatch.com while signed in, we run PostHog (EU-hosted) product analytics tied to your account email to understand feature usage and improve the product. This is separate from the marketing-site cookie banner.
Devices & workspaces
Telemetry, crashes, and firmware data your boards send to Heapwatch.
What Your Devices Send
Your devices and workspaces send data you control:
- device identifiers, telemetry (memory, CPU, threads, logs, events, custom values), core dumps, firmware metadata, and connector configuration;
- anything your devices handle in the field — if that includes personal data, it can end up here, so send only what you need.
Processors & retention
Suppliers who process data on our behalf, and how long we keep it.
Who Else Touches Your Data
Suppliers who process data on our instructions:
- Website: Plausible (anonymous statistics), PostHog if you opted in on heapwatch.com;
- App & account: MailerLite (onboarding emails), PostHog (in-app analytics), Stripe (payments), transactional email;
- Devices: EU hosting, MQTT/ingest infrastructure.
Telemetry and dumps stay on EU-hosted infrastructure. We don't sell personal data. We may disclose data if the law requires it or to protect users and safety.
How Long We Keep It
Account and billing records: while your account is active, then as long as Slovak tax law requires. MailerLite profile: while your account is active or until you unsubscribe from onboarding emails. Website attribution on your account: until account deletion. Crash history and telemetry: per your plan's retention window, then purged automatically. Delete a workspace yourself, or email us to wipe account data.