Privacy Policy
Last updated: 30 September 2026
1. Who we are
UrKavach (“we”, “us”) is a website security, uptime, performance and SEO monitoring service operated by UrKavach, [Your postal address (LEGAL_ADDRESS)]. For questions about this policy or your data, write to support@urkavach.com.
2. Our two roles
As a controller we decide why and how we use the personal data of people who use our dashboard, contact us or visit our public pages (for example your name, email address and login details).
As a processor we handle data on behalf of our customers when we monitor, scan, crawl or back up the customer's websites. That data can include personal data of the customer's own visitors, customers and staff. In that case the customer is the controller and we act on its instructions, as described in our GDPR & data protection page.
3. What we collect and why
| Data | Examples | Why (and legal basis) |
|---|---|---|
| Account data | Name, email address, role, password (stored only as a salted scrypt hash, never in clear text), last login | To create and secure your account and provide the service. Contract. |
| Session and security data | Session cookie; the IP address and browser type of each signed-in device (shown to you under Account, so you can spot and sign out unknown devices); login attempts. Your IP address is also used in memory to slow down repeated failed logins and appears in server or proxy logs. If you turn on two-factor login we store the secret for your authenticator app and hashed recovery codes. | To keep you signed in, prevent abuse and protect the service. Legitimate interests. |
| Customer content you enter | Client names and contact emails, notes, logos, website addresses, alert email addresses and webhook URLs | To run the features you configure. Contract. |
| Monitoring results | Uptime checks, security findings, SEO crawl results (page URLs, titles, headings, links), speed measurements, alert history | To provide monitoring, alerts and reports. Contract. |
| Data from the optional WordPress plugin | WordPress, PHP, plugin and theme versions; administrator usernames and email addresses; file lists and checksums; and, only if you use backups, a copy of the site's database and files | To detect tampering, apply updates and make backups you ask for. Contract. We act as a processor for this data. |
| Billing data | Billing name, email and address, GSTIN if you provide it, plan, and payment records (amount, date, status, payment reference). Card, UPI and bank details go directly to the payment provider and never reach our servers. | To take payment, issue invoices and meet tax and accounting law. Contract / legal obligation. |
| Sign-up verification | While you sign up, your email address, name, company name and a hash of your chosen password are held for up to 10 minutes until you confirm the emailed code. Nothing is kept if you do not finish. | To confirm that you own the email address before an account exists. Contract / legitimate interests. |
| Messages | Emails you send us; alert and digest emails we send you | To answer you and deliver the service. Contract / legitimate interests. |
| Public website | Standard server logs (IP address, browser, pages requested) | Security and reliability. Legitimate interests. |
We do not use advertising, analytics or tracking tools on our public pages, and we do not build profiles of visitors.
4. Who we share data with
We do not sell personal data. We use the following categories of service providers (“sub-processors”), depending on which features you enable:
- Infrastructure: [Hosting provider (HOSTING_PROVIDER)] hosts the service and its database (region: [Hosting region (HOSTING_REGION)]).
- Payments: our payment provider processes subscription payments and receives your name, email and billing details.
- Email delivery: the SMTP provider configured for sending alerts and digests.
- Google: PageSpeed Insights receives the website address to test speed; Web Risk or Safe Browsing (if enabled) receive the website address to check for malware and phishing warnings; Search Console data is read only when you connect it.
- Vulnerability data: if enabled, a vulnerability database provider (WPScan) receives plugin, theme and WordPress version identifiers, not personal data.
- Domain registries: the public RDAP service receives the domain name to check its expiry date.
- Chat and email destinations you choose: Slack, Discord, Google Chat or email recipients receive alert text you configure.
We may also disclose data if the law requires it, to protect our rights, or in a business transfer, always with the same level of protection.
5. International transfers
The service is hosted in [Hosting region (HOSTING_REGION)]. Some providers listed above may process data in other countries. Where personal data is transferred out of the EEA, the UK or another region with transfer rules, we rely on an adequacy decision or on appropriate safeguards such as standard contractual clauses.
6. How long we keep data
| Data | Default retention |
|---|---|
| Uptime checks and alert history | 90 days |
| Sign-in sessions | 14 days, or until you log out |
| Speed test history | Up to the 60 most recent tests per site |
| SEO crawl page data and plugin snapshots | The 3 most recent crawls and snapshots per site |
| Site backups | The newest 7 per site, until you delete them |
| Issues, reports and site settings | Until you delete the site or the account |
| Payment and invoice records | As long as tax and accounting law requires, even after you close your account |
| Account data | While your account is active; removed on request or when the account is closed, unless the law requires us to keep it |
Deleting a site removes its scan results, issues, backups records and settings. Backups stored on our servers are deleted with it.
7. Security
We protect data with encrypted connections (HTTPS), salted password hashing, protection against cross-site request forgery, HttpOnly session cookies, role-based access (client users are read-only), signed and time-limited requests between the dashboard and the WordPress plugin, and checksum-verified backups. No system is completely secure. If a personal data breach affects you we will notify you and the relevant authority as the law requires.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent where we rely on it. This includes rights under the EU and UK GDPR, India's Digital Personal Data Protection Act 2023, and the California Consumer Privacy Act. We do not sell or “share” personal information for advertising.
Signed-in users can download their account data and delete their account from the Account page. For anything else write to support@urkavach.com; we aim to respond within one month. You may also complain to your data protection authority (in India, the Data Protection Board; in the EU, your national supervisory authority; in the UK, the ICO).
If we hold your data as a processor for one of our customers, please contact that customer first; we will help them respond.
9. Children
UrKavach is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
10. Cookies
We only set essential cookies (sign-in, and short-lived ones during sign-up and two-factor login). Details are in our Cookie Policy.
11. Changes to this policy
We will update this page when our practices change and change the “last updated” date above. For material changes we will also notify account holders by email or in the dashboard.
12. Contact
UrKavach
[Your postal address (LEGAL_ADDRESS)]
support@urkavach.com