1. Scope and roles
This Privacy Policy applies to LaraSignal websites, accounts, support, and observability services. We generally act as a controller for account, billing, website, and business-contact information. For telemetry and other content customers submit from their applications, we act as a processor or service provider on the customer’s instructions. The customer controls that data and is responsible for notices to its own users.
2. Data we collect
Account and commercial data
Name, email address, organization, team membership, authentication records, plan, billing status, transaction details, and communications with us. Payment card details are handled by our payment processor and are not stored in full by LaraSignal.
Telemetry and configuration
Application event metadata such as route names, timings, stack traces, query patterns, job and command names, cache outcomes, HTTP destinations, environment tags, agent configuration, and diagnostic data. Depending on your configuration, telemetry may contain personal data.
Website and service usage
IP address, device and browser information, session identifiers, security logs, pages viewed, feature interactions, referral source, and cookie choices.
3. Local agent redaction
Our open-source Laravel agent includes configurable, client-side redaction designed to remove PII and PHI before telemetry leaves your server. Default and custom rules can redact headers, request fields, query bindings, and other values. Because applications differ, you must review and configure redaction for your data, legal obligations, and threat model. LaraSignal does not intentionally require sensitive payload content to provide core observability.
4. How and why we use data
- Provide telemetry ingestion, analysis, dashboards, alerts, support, and account administration under our contract with you.
- Secure the Service, prevent abuse, troubleshoot failures, and maintain reliability based on our legitimate interests and contractual duties.
- Process payments, keep financial records, and meet tax, legal, and regulatory obligations.
- Improve features using service metrics and de-identified or aggregated information.
- Send transactional notices and, with consent where required, product updates that you can unsubscribe from.
Where GDPR applies, our legal bases are performance of a contract, legitimate interests, compliance with legal obligations, and consent where requested. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by the CCPA.
5. Data residency and international transfers
Hosted telemetry is stored in Singapore. United States and European Union telemetry regions are planned but are not currently available. Our Singapore data center provides a lower-latency ingestion and investigation path for applications in the Philippines and across Southeast Asia. Limited account, billing, security, and support data may be processed elsewhere by authorized personnel and providers. Where personal data is transferred across borders, we use recognized safeguards such as adequacy decisions, Standard Contractual Clauses, contractual protections aligned with Singapore’s PDPA, and supplementary measures where appropriate.
6. Retention and deletion
Hosted telemetry is automatically deleted according to the active plan: 30 days for Free, 90 days for Pro and Team, and 180 days for Business. Backup copies may persist for a limited recovery cycle before deletion. Account, billing, security, and support records are retained only as long as needed for the purposes described, contractual administration, dispute resolution, and legal obligations. You may delete projects or request account deletion, subject to lawful retention requirements.
7. Third-party processors
We use vetted providers for cloud hosting, database and storage infrastructure, content delivery, email delivery, customer support, error monitoring, and analytics. Creem acts as our Merchant of Record and processes payments, applicable taxes, fraud checks, invoices, and subscription billing. Providers may process data only under contract and for the services they provide to us. A current subprocessor list is available by contacting privacy@larasignal.com.
8. Disclosure
We disclose data to authorized subprocessors, your organization’s administrators, professional advisers bound by confidentiality, and public authorities when legally required. We may transfer data during a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice. We do not disclose Customer Data for independent marketing.
9. Security
We use technical and organizational safeguards designed for the nature of the data, including encryption in transit and at rest, least-privilege access controls, logging, monitoring, backups, vulnerability management, and incident procedures. No security measure eliminates all risk. Customers should protect credentials, restrict team access, keep agents current, and configure redaction appropriately.
10. Your privacy rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or objection to processing; withdraw consent; opt out of certain disclosures; and appeal a denied request. You may also lodge a complaint with your data-protection authority. California residents may request categories and specific pieces of personal information, correction, deletion, and information about disclosures, without discriminatory treatment.
Submit a request to privacy@larasignal.com. We may verify your identity and authority before responding. If LaraSignal processes telemetry for one of our customers, direct your request to that customer; we will assist them as required.
11. Children and policy changes
The Service is intended for businesses and developers, not children under 16, and we do not knowingly collect their personal data. We may update this Policy as our Service or law changes. We will post the revised version here and provide additional notice when changes are material.
12. Contact
For privacy questions, rights requests, or data protection inquiries, contact privacy@larasignal.com.