Legal

Privacy

Information on which data we process when you use turbometrics.io, for which purposes, and which rights you have.

This is a translation for your convenience. The German version is legally binding. Read the German version.

Controller

Dipalino UG (haftungsbeschränkt)
Alexander-Puschkin-Platz 1
01127 Dresden
Germany

Contact

E-mail: [email protected]
Contact form: turbometrics.io/contact
Imprint: turbometrics.io/imprint

Summary

We process personal data only to the extent necessary for operating turbometrics.io, carrying out scans, administering user accounts, sending notifications and handling contact enquiries. This includes in particular the master data of your account, technical usage data, scan and monitoring data as well as communication data.

1. Access to the website

When turbometrics.io is accessed, technically necessary connection data is processed so that the website can be delivered and secured. This may include in particular the following data:

  • IP address
  • date and time of access
  • URL requested
  • browser and device information
  • referrer, where transmitted by the browser

This processing serves the provision, stability and security of the website as well as error analysis and the prevention of abuse.

2. Technically necessary cookies and sessions

We use technically necessary cookies and session data so that logins, forms and protected areas work. This includes in particular session cookies and security mechanisms such as CSRF protection. This data is required to operate the application and is not used for advertising purposes.

3. User accounts and profile data

When you create an account or use your profile, we process the data you provide to us or store in the app. This may include in particular:

  • name
  • e-mail address
  • password in hashed form
  • alert e-mail recipients
  • webhook URL for notifications
  • the plan chosen and related plan information

We process this data for account administration, authentication, provision of the features booked and communication regarding your account.

4. Scans, reports and public results

When you scan a URL with turbometrics.io, we process the scan and result data required for this. This includes in particular:

  • the URL or domain entered
  • the normalised URL and host
  • the region chosen and the scan parameters
  • technical measurement results, scores and issues detected
  • scan status, timestamps and report data

Public scans and public reports may be visible to other visitors. This applies in particular to guest scans and to scans that are expressly kept as public. In these cases the domain, the URL and the associated report data may be publicly accessible.

Private scans are only shown within the associated user account.

5. Scheduled scans, alerts and notification history

If you use scheduled scans, alerts or notifications, we process additional monitoring data so that recurring checks and messages work. This includes in particular:

  • scheduled scan targets and intervals
  • alert states such as warning, critical, read, resolved or hidden
  • dispatch and delivery history for e-mails and webhooks
  • error and status information for tracing delivery

We need this data in order to provide monitoring, history, repetitions, state changes and the display in the user account.

6. Webhooks

If you store a webhook URL in your profile, we use it exclusively to send the notifications you have activated to your system.

In doing so we process in particular:

  • the webhook URL you have stored
  • timestamps and status of delivery
  • where applicable, technical error messages or HTTP status codes

Please store only endpoints that you are authorised to use. In the application we display sensitive webhook targets only in a restricted form.

7. Contact form

If you contact us via the contact form, we process the details you submit in order to handle your enquiry.

  • name
  • e-mail address
  • subject
  • message

The processing serves to answer your enquiry and to communicate with you.

8. E-mail delivery via Brevo

We use Brevo as an external delivery provider for sending transactional e-mails. This concerns in particular contact form messages, alert e-mails, test e-mails for alert settings and other system-related e-mails, insofar as they are triggered in the application.

In doing so, the data required for delivery is transmitted to Brevo, in particular the recipient address, sender information, subject, message content and technical delivery data.

The provider is Brevo (Sendinblue SAS). Further information on data processing by Brevo can be found in Brevo's official privacy policy: brevo.com/legal/privacypolicy.

We use Brevo exclusively for sending and technically delivering our e-mails.

9. Stripe for checkout, billing and the customer portal

For paid plans we use Stripe as our payment and billing provider. This concerns in particular Stripe Checkout, the customer portal for managing subscriptions and payment methods, and the technical processing of billing events via webhooks.

In particular, the following data may be processed or transmitted to Stripe:

  • name and e-mail address
  • the plan chosen and the related price and subscription information
  • Stripe customer and subscription IDs
  • payment status, invoice and renewal information
  • technical metadata for assigning the account and for processing webhooks

From Stripe we receive in particular status information on checkout, on active or ended subscriptions and on payments, so that we can correctly assign and manage your plan in turbometrics.io.

Further information on data processing by Stripe can be found in Stripe's privacy policy: stripe.com/privacy.

10. Cloudflare (CDN and DDoS protection)

We use Cloudflare as a content delivery network (CDN) and to protect our website against DDoS attacks and other threats. All traffic to turbometrics.io is routed through Cloudflare's servers before it reaches our own servers.

In doing so, Cloudflare processes in particular:

  • visitors' IP addresses
  • URLs requested and HTTP headers
  • browser and device information
  • technical connection data for analysis and protection

For security purposes Cloudflare sets its own cookies, in particular __cf_bm (bot detection) and cf_clearance (security challenge). These cookies are technically necessary and are not used for advertising purposes.

The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. The processing takes place on the basis of our legitimate interest in a secure and performant operation of the website (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework, so that an adequate level of data protection is ensured for transfers to the USA.

Further information on data processing by Cloudflare can be found in Cloudflare's privacy policy: cloudflare.com/privacypolicy.

11. Live Data (Real User Monitoring)

What is the Live Data feature? Users on a suitable plan can embed a JavaScript snippet (tm.min.js) on their own websites. This snippet collects performance metrics from the visitors of those websites and transmits them anonymised to turbometrics.io.

Which data is collected? The snippet collects exclusively technical performance data, in particular:

  • load time measurements (LCP, CLS, INP, FCP, TTFB)
  • device class (desktop, mobile, tablet) — derived from the screen width
  • browser and operating system — derived from the user agent
  • connection type and network quality (where provided by the browser)
  • country — determined from the IP address, which is anonymised afterwards
  • an anonymous page ID for grouping metrics that belong together

What is not collected? No cookies are set, no browser fingerprinting is carried out, and no personal data such as names, e-mail addresses or complete IP addresses is stored.

IP anonymisation. IP addresses are used exclusively to determine the country of origin. The last octet of the IPv4 address, or the last 80 bits of the IPv6 address, is set to zero before storage. The complete IP address is not stored.

Legal basis for the processing. turbometrics.io processes the transmitted performance data on behalf of the respective user (Art. 28 GDPR). The controllers within the meaning of the GDPR are the users who embed the snippet on their websites — not turbometrics.io. The legal basis for the processing on the customer websites is typically the legitimate interest in the technical optimisation of the respective web offering (Art. 6(1)(f) GDPR).

Retention period. Performance data is stored for the period provided for in the plan booked (between 14 and 180 days) and is then deleted automatically.

Processing on behalf of the controller. Where turbometrics.io acts as a processor when processing end users' performance data, a data processing agreement is available. The current DPA is available at turbometrics.io/dpa.

12. Retention period

We store personal data only for as long as it is required for the respective purposes or as long as statutory retention obligations exist. Account, scan, monitoring and notification data generally remains stored for as long as it is needed for the use of your account, for tracing reports and notifications, or for legal evidence.

13. Your rights

Within the statutory requirements you have in particular the following rights:

  • access to the data stored about you
  • rectification of inaccurate data
  • erasure or restriction of processing
  • objection to certain processing operations
  • data portability
  • lodging a complaint with a data protection supervisory authority

If you have questions about data protection or about exercising your rights, please contact us via the contact form or by e-mail to [email protected].

14. Changes to this privacy policy

We may adapt this privacy policy if features, legal requirements or the services used change. The current version is always available on this page.