â Back to urlgoose.caLast updated: September 20, 2026DerniĂšre mise Ă jour : 20 septembre 2026
âïž Quebec Law 25 & PIPEDA Compliant
URL Goose Privacy Policy
Published by URL Goose • Designated Privacy Officer: Robert Brockie (privacy@urlgoose.ca)
1. Introduction & Commitment to Privacy
URL Goose ("we", "us", or "our") operates the website and API uptime monitoring platform available at urlgoose.ca. Based in Quebec, Canada, we are dedicated to protecting your privacy, personal information, and data sovereignty.
Our platform is governed by the Quebec Act respecting the protection of personal information in the private sector (Law 25 / RLRQ c P-39.1) and the Canadian federal Personal Information Protection and Electronic Documents Act (PIPEDA).
Principle of Data Minimization: We store only what is technically necessary to probe your websites and send outage alerts. We never sell, rent, or broker your personal information. We do not operate advertising pixels or behavioural analytics.
2. Personal Information We Collect
We restrict personal information collection to essential account administration and alert delivery:
Category
Information Collected
Operational Purpose
Account Credentials
Email address
Primary login identifier, account recovery, and recipient address for outage and SSL alerts.
Password
One-way cryptographic hash (bcrypt)
User authentication. We never view or store plaintext passwords.
Language Preference
'en' or 'fr'
Ensures emails, alerts, and user interface screens render in your chosen language.
Lifecycle Metadata
Creation date, verification timestamp
Account state management and anti-abuse protection.
What URL Goose Does NOT Collect:
No personal names: Profiles require only an email address.
No credit card or billing details: Payments are currently not implemented (reserved for future Stripe integration).
No telephone numbers or physical street addresses.
No social media identifiers or third-party cookies.
3. Monitored Targets & Probe Telemetry
To perform uptime checks, our asynchronous worker daemon executes periodic probes against your endpoints:
Monitor Configuration: Target URLs, friendly names, HTTP probe method (`GET`, `HEAD`), expected HTTP status code, check frequency, and timeout thresholds.
Probe Telemetry: Precise probe timestamp, returned HTTP response status code, round-trip latency in milliseconds (`response_time_ms`), network error category, and diagnostic failure reason.
Public Status Pages: If enabled, uptime availability and latency metrics are displayed on a dedicated public page (e.g. /status/your-service). Status pages never reveal your email address, user ID, or internal alert settings.
Public Website Checker: When visitors use our anonymous one-shot checker (/check), we record only the target host and scheme (e.g. https://example.com), latency, HTTP status, and error category. We never record paths, query strings, headers, cookies, or payloads. Visitor IP addresses are pseudonymized into a keyed HMAC-SHA256 hash (never stored raw) for fair-use rate limiting and abuse defense.
Payload Privacy Guarantee: URL Goose verifies availability headers and response latency. We never inspect, store, or log HTTP response bodies, submitted form data, or visitor browsing activity on your monitored endpoints.
4. Legitimate Business Purposes
We process personal information and telemetry exclusively for the following purposes:
Service Delivery: Executing scheduled uptime probes, maintaining historical latency charts, and dispatching downtime alerts.
System Integrity: Preventing SSRF attacks, restricting malicious automated registrations, and enforcing fair-use rate limits.
Legal Compliance: Meeting statutory requirements under Quebec Law 25 and applicable Canadian privacy legislation.
5. Data Retention & Automated Destruction Schedule
In adherence to Quebec Law 25 accountability obligations, URL Goose maintains automated data retention schedules. Information is permanently purged as soon as the purpose for its collection has expired:
Data Category
Retention Period
Purge Mechanism
Web Server Logs (Nginx)
14 days
Automated logrotate daily rotation with gzip compression.
Laravel Application Logs
14 days
Monolog daily rolling channels; files older than 14 days auto-purged.
Automated daily scheduler (public-checks:prune) at 02:30 UTC. Hard deletion of operational telemetry and keyed IP correlation hashes.
Check Results Telemetry
30 days
Automated daily scheduler (monitors:prune-results) at 03:00 UTC.
Alert Dispatch Audit Logs
90 days
Automated daily scheduler (alerts:prune-dispatches) at 03:30 UTC.
User Profile & Monitors
Duration of active account
Immediate hard deletion (PostgreSQL cascading delete) upon self-serve deletion.
6. Infrastructure & Cross-Border Processing
Canadian Data Residency: Our primary hosting infrastructure is located in Toronto, Ontario, Canada (`tor1`) with DigitalOcean. The PostgreSQL 16 database, Laravel web application, and Rust monitoring worker all execute locally on this Canadian server. Primary data does not leave Canada.
Subprocessor: Resend, Inc. (United States)
To ensure high-speed transactional email delivery, alert and authentication emails are dispatched through Resend, Inc. (San Francisco, CA, USA).
Quebec Law 25 Cross-Border Assessment (ss. 17 & 70.1): The assessment concludes that the personal information communicated to Resend will benefit from adequate protection, considering the nature and sensitivity of the information, the purposes of the processing, applicable contractual and technical safeguards, and the legal framework applicable in the destination jurisdiction:
Resend maintains an active SOC 2 Type II certification and is certified under the EU-U.S. Data Privacy Framework (DPF).
URL Goose and Resend operate under an executed Data Processing Addendum (DPA) containing contractual safeguards under GDPR Article 28 and Canadian privacy standards.
Resend is contractually barred from using email addresses or notification contents for secondary purposes.
All transmissions to Resend are encrypted in transit via TLS 1.2+ on Port 465.
Resend retains message metadata only for transient delivery verification (1 to 30 days) before automated deletion.
7. Cookies & Local Storage
URL Goose uses only strictly necessary functional cookies:
url-goose-session: Encrypted session cookie maintaining your secure login state.
XSRF-TOKEN: CSRF security token protecting your account against cross-site request forgery attacks.
locale: Remembers your interface language selection (en or fr).
We do not use advertising trackers, Google Analytics, social network pixels, or cross-site fingerprinting scripts.
8. Your Statutory Privacy Rights
Under Quebec Law 25 and PIPEDA, you hold enforceable rights regarding your personal data:
1. Right of Access & Portability
Request confirmation of data held and obtain a structured, machine-readable export (JSON/CSV).
2. Right to Rectification
Correct inaccurate, incomplete, or ambiguous information directly in your `/profile` view.
3. Right to Erasure / Deletion
Instantly delete your account and all associated monitor records under `/profile` ("Delete Account").
4. Right to Withdraw Consent
Toggle off notification emails at any time for any individual monitor.
Submitting a Privacy Request: Send your written request to privacy@urlgoose.ca. Under section 32 of Quebec Law 25, we will respond within thirty (30) calendar days free of charge.
In accordance with sections 3.5 to 3.8 of Quebec Law 25, URL Goose maintains a formal Confidentiality Incident Procedure. In the event of a security breach, we immediately take reasonable containment measures, evaluate the risk of serious injury, notify the CAI and affected subscribers when required, and log every incident in an internal register preserved for at least five (5) years.
10. Changes & Policy Updates
We may periodically revise this Privacy Policy. Material updates (such as introducing paid subscriptions via Stripe) will be preceded by prominent notice on the platform and email communication prior to entering into effect.