Last updated October 02, 2026
This Privacy Policy explains how we process personal data when you visit our website, run a latency test, create an account, monitor endpoints, receive alerts, share reports, use the REST API or the MCP server, or buy a plan (together, the "Services"). It is based on the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
The controller responsible for processing your personal data is:
Mustafa Serhat Dündar
Bergstraße 70
10115 Berlin
Germany
Email: [email protected]
We are not legally required to appoint a data protection officer. For all privacy questions and requests, please contact us at the address above. Further details are in our Impressum.
Our website, API, database and monitoring servers are hosted by Hetzner Online GmbH on servers in Germany. When you access the website or the API, our servers automatically record the following data in log files: IP address, date and time of the request, requested URL, HTTP status code, amount of data transferred, referring URL, and browser and operating system (user agent).
We process this data to deliver the Services, to keep them secure and stable, and to detect and fix errors and misuse. The legal basis is our legitimate interest in the secure and reliable operation of the Services (Art. 6 (1) (f) GDPR). Log files are deleted after 14 days at the latest, unless we need to keep specific entries longer to investigate a security incident.
All traffic to latencytest.me passes through the network of Cloudflare, Inc. Cloudflare delivers our content quickly, terminates the encrypted (TLS) connection, and protects the Services against attacks such as DDoS. To do this, Cloudflare processes your IP address, the content of the requests and technical connection data. The legal basis is our legitimate interest in a fast and secure website (Art. 6 (1) (f) GDPR).
We use cookies and similar technologies (such as local storage) only where they are strictly necessary to provide the Services you request, or where you have consented.
Our consent banner is part of our own website; no third-party consent provider is involved. You can change or withdraw your consent at any time with effect for the future via Cookie settings in the footer of every page or here: .
If you consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics is not loaded before you consent.
Google Analytics uses cookies (such as _ga and _ga_*, stored for up to 2 years) to recognize your browser and to analyze how the website is used, for example which pages are visited, how long visits last, the referring website, the approximate location (country or city), and the device and browser used. Google Analytics 4 does not log or store IP addresses for users in the EU. We use the reports to improve our website and offering. We have not enabled Google signals or advertising features.
The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Google stores the analytics data for 14 months. Data may be transferred to Google LLC in the USA (see Section 11). For more information, see the Google Privacy Policy.
When you use the free latency test, we process the URL, HTTP method, headers and request body you enter, send the request from our servers and show you the result. We do not store this data after the test is complete, apart from the server logs described in Section 2.
To protect the test against automated abuse, we use Cloudflare Turnstile. Turnstile checks whether the request comes from a human by evaluating technical data such as your IP address, browser and device characteristics. It does not show you image puzzles and is not used for advertising. The legal basis is our legitimate interest in protecting the Services and third-party websites from misuse (Art. 6 (1) (f) GDPR); storage of and access to information on your device is strictly necessary for this purpose (§ 25 (2) No. 2 TDDDG). For more information, see the Cloudflare Privacy Policy.
To use the dashboard, you need an account. Registration and login are handled by Clerk, Inc. When you register, we and Clerk process your email address, your name (if provided), your password (stored only as a hash by Clerk), your account ID, and technical session data such as IP address, browser and login times.
You can register with your email address and a password, or sign in with Google, GitHub or LinkedIn. If you use one of these providers, it sends us your name, email address, profile picture and a user ID, as permitted by your settings with that provider. We do not receive your password for that provider. The providers are Google Ireland Limited (Ireland), GitHub, Inc. (USA) and LinkedIn Ireland Unlimited Company (Ireland). They process data under their own responsibility and privacy policies.
The legal basis is the performance of the contract for the use of the Services (Art. 6 (1) (b) GDPR). Processing to protect accounts against misuse is based on our legitimate interest in secure Services (Art. 6 (1) (f) GDPR).
If you use monitoring, we store and process the endpoints you configure (URL, HTTP method, headers, request body and redirect settings), the measurement results (timings, HTTP status codes and the IP address of the monitored server), your alert rules and destinations (such as an email address, a Slack webhook URL, or a PagerDuty or Opsgenie key), the history of triggered alerts, and the reports you generate.
When an alert is triggered, we send a message with the affected URL and measurement details to the destination you configured. If you choose Slack, PagerDuty or Opsgenie, the message is transmitted at your request to your own account with that provider, which processes it under its own terms.
If you generate a report, anyone with the report link can view the report, including the monitored URL and its measurement results.
When you use the REST API or MCP server, we process your API tokens (stored only as a cryptographic hash), the time they were last used, and the requests you make, in order to authenticate you and provide the API.
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR). Please do not include personal data of third parties in monitored URLs, headers or request bodies.
Payments for paid plans are processed by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe"). You enter your payment details directly on Stripe's checkout page; we never receive your full card details.
Stripe processes your name, email address, billing address, payment method details, transaction data and technical data for fraud prevention. We receive your customer and subscription data from Stripe (plan, status, billing periods and invoices) to manage your plan. Stripe processes some data as an independent controller, for example to comply with financial regulations and to prevent fraud. For details, see the Stripe Privacy Policy.
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) and our legal obligations under tax and commercial law (Art. 6 (1) (c) GDPR).
We send emails through Resend (Plus Five Five, Inc.). We process your email address, your first name (if provided), the content of the email, and technical delivery data (such as delivery status).
If you contact us by email, we process your email address, your name and the content of your message to answer your request. If you use our Cancel contracts here page, we process the information you enter in the form (type of termination, reason if given, name, account email, contract, requested date and confirmation email address), the time of receipt and your IP address (to prevent misuse), and we send the confirmation to you and a copy to us by email.
The legal basis is the performance of the contract or pre-contractual measures (Art. 6 (1) (b) GDPR), our legal obligation to confirm cancellations (Art. 6 (1) (c) GDPR in conjunction with § 312k BGB), and, for general inquiries, our legitimate interest in answering them (Art. 6 (1) (f) GDPR).
We only share personal data with the recipients listed below, to the extent necessary for the purposes described in this Privacy Policy. Where they act as our processors, we have concluded data processing agreements with them (Art. 28 GDPR). We also disclose data to authorities where we are legally required to do so. We do not sell your personal data.
| Recipient | Purpose | Location | Safeguard for transfers |
|---|---|---|---|
| Hetzner Online GmbH, Germany | Hosting of the website, API, database and monitoring servers | Germany | No transfer outside the EU; data processing agreement (Art. 28 GDPR) |
| Cloudflare, Inc., USA | Content delivery, security (DDoS protection) and bot protection (Turnstile) | Worldwide network, including the USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreement |
| Clerk, Inc., USA | Account registration, login and session management | USA | EU-U.S. Data Privacy Framework; data processing agreement |
| Stripe Payments Europe, Limited, Ireland, with Stripe, Inc., USA | Payment processing, subscriptions and invoices | EU and USA | EU-U.S. Data Privacy Framework (Stripe, Inc.); Standard Contractual Clauses |
| Google Ireland Limited, Ireland, with Google LLC, USA | Google Analytics (only with your consent) | EU and USA | EU-U.S. Data Privacy Framework (Google LLC); Standard Contractual Clauses |
| Plus Five Five, Inc. (Resend), USA | Sending emails, including email alerts | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreement |
| Slack Technologies, LLC (USA), PagerDuty, Inc. (USA), Atlassian (Opsgenie) | Alert notifications, only if you configure that channel | USA and other countries, depending on your account with the provider | Transfer at your request to your own account with the provider (Art. 49 (1) (b) GDPR); the providers are certified under the EU-U.S. Data Privacy Framework |
Some of these recipients are located in the USA or may access data from the USA. For transfers to companies certified under the EU-U.S. Data Privacy Framework, the European Commission has determined that an adequate level of data protection exists (adequacy decision of 10 July 2023, Art. 45 GDPR). In addition, or where a recipient is not certified, transfers are based on the Standard Contractual Clauses adopted by the European Commission (Art. 46 (2) (c) GDPR). You can check a company's certification at dataprivacyframework.gov, and you can request a copy of the Standard Contractual Clauses from us.
If you sign in with GitHub, your data is exchanged with GitHub, Inc. in the USA at your request. GitHub, Inc. is certified under the EU-U.S. Data Privacy Framework.
We delete personal data as soon as it is no longer needed for the purposes for which it was collected, unless statutory retention obligations apply. In particular:
Under the GDPR, you have the right to:
Right to object (Art. 21 GDPR): Where we process your data on the basis of our legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. You can object to the use of your data for direct marketing at any time without giving reasons; we will then no longer use your data for this purpose.
To exercise your rights, please email [email protected]. You can view and update your account data and delete your account in your account settings.
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
www.datenschutz-berlin.de
Obligation to provide data: You are not legally required to provide personal data. However, without the data required for registration and payment, we cannot conclude or perform a contract with you.
No automated decision-making: We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
Children: Our Services are aimed at developers and businesses and are not directed at children under 16. We do not knowingly collect personal data from children.
Users outside the EU: We process the data of all users as described in this Privacy Policy. We do not sell personal information and do not share it for cross-context behavioral advertising.
We update this Privacy Policy when our processing or the legal requirements change. The current version is always available on this page. The postal address for privacy requests is Mustafa Serhat Dündar, Bergstraße 70, 10115 Berlin, Germany.