Privacy policy / Datenschutzerklärung
up24 runs no tracking script that can identify you, sets no cookie until you sign in, and asks for an account only from people who want to be told when something breaks. What is left is the logging that serving a page over the internet requires, and this page says who sees it.
The short version
No cookie until you sign in, and then exactly one, holding a random session token and nothing else. No account unless you make one; reading the board never needs one. No consent banner either way — the analytics stores no identifier on your device, and a cookie whose only job is to keep you signed in to what you asked for is exempt under § 25 (2) TDDDG. Your IP address reaches four companies as a consequence of the page being delivered to you at all, and all four are named below. Making an account adds a mail provider, and picking an alert channel adds whoever runs the destination you picked.
Controller / Verantwortlicher
Viacheslav Shynkarenkoc/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
[email protected]
No data protection officer is appointed. The processing here is small in scale, not the core of any business activity, and does not meet the thresholds in Art. 37 GDPR or § 38 BDSG. Full provider identification is on the legal notice.
Server log data
Every request to this site and to the status API is logged by the systems that serve it: IP address, timestamp, the path requested, the HTTP status and response size, the referrer where the browser sends one, and the user-agent string. This is what makes it possible to see that the site is up, to find out why a request failed, and to enforce the API rate limit — a limit counted per address cannot be enforced without knowing the address.
Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest is operating and securing the service. Logs are kept short-term for that purpose and are not used to build a profile of anyone, are not combined with any other source, and are not sold or shared.
Hosting
The application and its database run on virtual servers rented from Contabo GmbH (Aschauer Str. 32a, 81549 Munich, Germany), in German and other European data centres. Two further probes run from Contabo locations in Singapore and New Jersey and measure exchanges from there; they store no visitor data, serve no page and hold no database credentials, so nothing about you reaches either of them.
Contabo processes data on my behalf under a data processing agreement (Art. 28 GDPR). Legal basis for the processing itself: Art. 6 (1) (f) GDPR — a website has to be hosted somewhere.
Content delivery and security (Cloudflare)
DNS, TLS termination, caching and denial-of-service protection are provided by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA). Every request therefore passes through Cloudflare and your IP address is visible to it. Most requests for these pages are answered from Cloudflare's cache and never reach my own server at all.
Legal basis: Art. 6 (1) (f) GDPR — delivering the site quickly and keeping it reachable during an attack. Cloudflare acts as a processor under a data processing agreement incorporating the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR), and Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision (Art. 45 GDPR).
Analytics
Cloudflare Web Analytics, when enabled, counts page views and referrers. It sets no cookie, writes nothing to your browser's storage, and constructs no identifier for a visitor or a device — which is why this site has no consent banner and does not need one. What is measured is which pages were requested and where the requests came from, in aggregate.
Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest is knowing whether anybody reads this. Since nothing is stored on your device, § 25 (1) TDDDG does not apply.
Error reports (Sentry)
When the software fails, a report is sent to Functional Software, Inc. (Sentry) (45 Fremont Street, San Francisco, CA 94105, USA): the error, where in the code it happened, and the request that triggered it, which can include your IP address. Reports cover failures on the server, including background jobs that fail, and a notice when one of up24's own measuring machines stops reaching the services it measures. Those notices carry measurement counts and no data about visitors. Nothing runs in your browser to collect anything.
Legal basis: Art. 6 (1) (f) GDPR — finding and fixing faults in a service whose whole purpose is to be correct about whether something is broken. Sentry acts as a processor under a data processing agreement incorporating the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR).
Fonts and third-party requests
Typefaces are served from this site's own domain, built into the deployment. No font is fetched from Google or anywhere else, and no page here embeds a map, a video, a social widget or an advertising script. Apart from the analytics beacon above, a page makes no request to any host other than up24's own.
Cookies and local storage
One cookie, and only once you have signed in: the session cookie described under accounts below, which holds a random token and no personal data. Signed out — which is how the whole board, the API and every exchange page are read — this site stores nothing on your device at all: no cookie, no local storage, no identifier. No page ships JavaScript of its own either; the range switch on a chart is a link, and a form is a form.
Neither state needs a banner. Signed out there is nothing to consent to, and the sign-in cookie is technically necessary within the meaning of § 25 (2) TDDDG: it exists solely to deliver the service you asked for, and there is no second cookie riding along beside it doing something else.
Contacting me by email
If you write to [email protected] — to dispute a measurement, to ask about your data, or for anything else — your address and the content of your message are processed to answer you, and the thread is kept as long as the matter is open and for as long afterwards as commercial or tax law requires anything to be kept, which for a private individual is generally not at all.
Legal basis: Art. 6 (1) (f) GDPR, and Art. 6 (1) (b) GDPR where your message concerns a prospective agreement.
Accounts, alerts and the email list
Everything above happens to anyone who loads a page. Everything under this heading happens only if you make an account, and an account exists to answer one question: which venues do you want to be told about, and where should the message go. There is no profile, no field you have to fill in beyond an email address, no payment and no billing. Nothing collected here is used for anything except sending you the alerts you asked for.
Signing in
Sign-in is a link mailed to your address. No password is stored — the column the authentication library reserves for one is null on every row in this deployment, because no password provider is configured. Asking for a link writes a single-use token that is deleted the moment you use it; tokens nobody clicks are deleted a day after they expire. Your account row holds the email address, whether it has been confirmed, and the two timestamps.
A session is a cookie on .up24.app containing a random token and nothing else — not your address, not an identifier anything else could read. Beside it, the database keeps the IP address and the browser user-agent the session was created from, so that "why was I signed out" and "was that login me" are questions with answers. Sessions are deleted a day after they expire.
Legal basis: Art. 6 (1) (b) GDPR for the account itself, which is the service you asked for, and Art. 6 (1) (f) for the address and user-agent beside the session, the legitimate interest being account security.
Alerts and sign-in links by email (Resend)
Both are sent through Resend, Inc. (San Francisco, California, USA), which therefore processes your email address and the content of the message. Resend acts as a processor under a data processing agreement incorporating the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR). Every alert email carries a one-click unsubscribe link that switches off the channel it came from and nothing else — stopping the emails does not silently stop a webhook somebody built an automation on.
Alerts by webhook
A URL you supply and a signing secret, shown at creation and readable from your dashboard for ten minutes after, then never displayed again. Every alert is posted to that URL as JSON naming the venue, the component, the severity, when it started and a link to the incident, signed so your receiver can tell it came from here.
Two consequences worth saying plainly. Whoever operates that host receives the payload — your own server, your ops vendor, or Slack. And because you are sent only what you watch, the stream of payloads discloses which exchanges your account is watching, which for a trading desk is not nothing. Pick a destination you control. Legal basis: Art. 6 (1) (b) GDPR, since delivering there is the service.
The keep-me-posted list
The form on the plans page stores the address you type, the note you write if you write one — which line you would pay for, and what it is worth to you — the page you were on and how many times you have asked; that last one because somebody asking twice is a stronger signal than a second row would be. It is a list of people to write to once, if and when there is something to say. It is not sold, not shared and not joined to anything else. Legal basis: Art. 6 (1) (a) GDPR; reply to any message from it, or write to the address below, and the row goes.
What is kept, and how to have it deleted
The delivery log — one row per alert per channel, including the ones deliberately not sent and the reason why — is kept ninety days, matching the board's own history, so that "I never got the alert" is a question with an answer rather than a shrug. Your watchlist, your channels and their labels are kept until you delete them: per channel from the dashboard, or through the unsubscribe link at the foot of every alert email.
Ask by email and the whole account goes, and everything hanging off it goes with it — watchlist, channels, delivery history, sessions. That is Art. 17 GDPR, and here it is one row and a foreign key cascade rather than a ticket in a queue.
What is not collected
No advertising identifier, no cross-site tracking, no fingerprinting, no data broker, no sale or sharing of anything to anyone. The measurements this site publishes are about exchanges' public APIs, not about the people reading them.
Your rights / Ihre Rechte
- Access to the data concerning you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests, including everything on this page (Art. 21 GDPR)
Write to [email protected]. If you have an account, all of it is retrievable and all of it is deletable, because it hangs off one row keyed to your address. If you do not, note what is realistic: what is processed is a server log entry keyed to an IP address, and without something to identify which entries are yours there is nothing to retrieve. Art. 11 GDPR covers that case — I am not required to acquire more information about you in order to identify you.
Right to lodge a complaint
You may complain to a supervisory authority, in the member state of your residence, your place of work, or the place of the alleged infringement. The competent one here is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de
Changes to this policy
This page changes when the site does — when a processor is added, when accounts are switched on, when something starts or stops being collected. Changes to what up24 measures are a different record and live in the changelog, dated, with the commit.