Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains what personal data cronctl ("we", "us") collects when you use our cron scheduling and endpoint monitoring service, how we use and protect it, and the rights you have over it. It applies to the cronctl website, application, API, and mobile app. The data controller is Karageyik Yazılım ve Bilişim Sanayi LTD ŞTİ.
1. Data we collect
Account data: your email address, name, hashed password, language preference, and plan information you provide when registering and managing your account.
Service configuration: the jobs, schedules, target URLs, request headers and parameters, notification channels, and status pages you create. Secrets you store in the vault are encrypted at rest and are never displayed back in full.
Execution and monitoring data: timestamps, response status codes, latency, response sizes, and error details produced when we execute your scheduled requests and checks.
Usage and technical data: IP address, browser and device information, and application logs collected for security, debugging, and abuse prevention.
Payment data: subscription and invoice records. Card payments are processed by our merchant of record, Paddle; we receive transaction confirmations and card metadata (such as the last four digits) but never your full card number.
2. How we use your data
We use your data to provide the service (executing schedules, running checks, sending the alerts you configure), to manage your subscription and billing, to secure the platform and prevent abuse, to provide support, and to send you service-related communications such as alert notifications, billing notices, and material changes to our terms. We do not sell your personal data, and we do not use your monitoring data for advertising.
3. Legal bases
Where the GDPR or similar laws apply, we process your data to perform our contract with you (operating the service), to comply with legal obligations (tax and accounting records), and for our legitimate interests in securing and improving the service. Where we rely on consent — for example optional marketing emails — you can withdraw it at any time.
4. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to remember preferences such as language and theme. We do not use third-party advertising or cross-site tracking cookies.
5. Sharing and processors
We share data only with service providers that help us operate cronctl: infrastructure and hosting providers that store our databases, Paddle as merchant of record for checkout and payment processing, email delivery providers for transactional email, and Google Firebase Cloud Messaging for mobile push notifications you enable. Each processor is bound by data processing terms and receives only what it needs.
We may disclose data when required by law or to protect the rights, safety, or security of cronctl, our users, or the public. If cronctl is involved in a merger or acquisition, your data may be transferred as part of that transaction under the same protections.
6. Data retention
Account and configuration data is kept for as long as your account exists. Execution logs and monitoring history are retained for the period included in your plan and are then deleted or aggregated. When you delete your account, we remove your personal data from production systems within 30 days, except where we must keep records longer for legal, tax, or accounting reasons; residual copies in encrypted backups are purged on the backup rotation cycle.
7. Security
We protect your data with encryption in transit (TLS), encryption of stored secrets, hashed passwords, access controls, and network isolation between components. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
8. Your rights
Depending on your location, you have rights under laws such as the GDPR and Türkiye's KVKK: to access the personal data we hold about you, to correct or delete it, to restrict or object to processing, to receive a portable copy, and to lodge a complaint with a supervisory authority. You can exercise most of these directly in your account settings, or by contacting us at the address below. We respond to verified requests within the timeframes required by applicable law.
9. International transfers
Our infrastructure providers may store or process data in countries other than your own. Where data is transferred internationally, we use recognized safeguards such as standard contractual clauses or rely on adequacy decisions.
10. Children
cronctl is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. For material changes we will notify you by email or an in-app notice before the change takes effect. The "last updated" date above always reflects the current version.
12. Contact
For privacy questions or to exercise your rights, contact us at [email protected].
Other policies