Privacy Policy
Last updated: July 25, 2026
This policy explains what we collect, how we use it, and your rights. It applies to monitorMyLawn ("we", "us").
What we collect
- Account data — name, email, hashed password.
- Device telemetry — sensor readings (soil/air/light/etc.), device health, and the location (GPS/zone) you assign to a device — which may indicate your property location.
- Payment data — handled by Stripe; we store only a customer/subscription reference, never card numbers.
- Usage & technical data — log/IP/device-API metadata for security and reliability; essential cookies for login/session.
How we use it
To operate the Service (store/show your data, compute insights), process billing, secure the platform, send transactional emails, and—if you opt in—send a weekly digest.
Sharing
We do not sell your data. We share with processors only as needed: Stripe (payments), our email provider (transactional mail), and hosting. We may disclose if required by law.
Retention
We keep the least we can for the shortest time the product still works with. An automated nightly job enforces every window below — these are not aspirations:
- Raw sensor samples — about 90 days. Readings are stored in monthly blocks and a whole block is dropped only once all of it is past the window, so the very oldest samples can survive a few weeks beyond 90 days before their block is dropped.
- Aggregated history (hourly and daily roll-ups) — kept for the life of your account. This is what your long-range trends are drawn from after the raw samples age out. Nothing prunes it; deleting your account is what removes it.
- Cold transport payloads — 14 days. The exact JSON or radio uplink your device sent, kept briefly so we can debug a device that is reporting badly.
- Device health timeline — 90 days. Events like came online, went offline, key rotated, settings changed.
- Alerts — 180 days after an alert is resolved. Alerts still open or merely acknowledged are never swept: they are live state about your lawn.
- Security and application logs — 90 days in the database, and 30 days for log files on the server.
- Login attempts — 30 days. Each row holds the email address used and the originating IP; we need them to rate-limit password guessing.
- Payment webhook records — 180 days. One row per Stripe event, kept so the same payment can never be processed twice.
- Account data — kept while your account is active.
Anti-replay tokens and per-minute rate counters are pure technical scaffolding and are discarded within five minutes and two days respectively.
Security
Encryption in transit (HTTPS/TLS), hashed credentials and device secrets, prepared statements, CSRF protection, and access controls. No system is perfectly secure.
Your rights
Depending on your region (e.g., GDPR/CCPA) you may access, export, correct, or delete your data, and object to certain processing. You do not have to ask us for any of it:
- Export — Account → Export my data downloads your account, users, devices, subscription, monthly usage and recent device events as JSON, and each sensor has its own Download readings (CSV) button for its raw samples.
- Delete — Account → Delete account, confirmed with your password.
We honor opt-outs of non-essential email via the unsubscribe link. If you would rather have us do any of it for you, contact support.
What deleting your account actually does
It cancels your subscription and erases your account record, users, devices, every reading and roll-up, alerts and alert rules, watering history, notification preferences, verification and password-reset tokens, remembered sessions, usage counters and billing events. Your login-attempt records, which hold your email address, are deleted outright.
One category is anonymised rather than deleted: our security and application log trail. We need the events — failed logins, payment webhooks, mail failures — for fraud prevention and to be able to show we honoured your request. So instead of deleting those rows we strip the identifiers out of them: your user and account IDs, your IP address, and your email address wherever it appears in the message or context. What is left cannot be linked back to you, and it ages out with the 90-day log window above. We deliberately keep one record stating that an account was deleted and when, with the requesting IP removed.
Two limits we cannot wave away. Stripe, our payment processor, keeps its own transaction records under its own retention and legal obligations, and we cannot delete those for you. And if we hold a database backup taken before your deletion, your data can persist in that backup until it is rotated out; we do not restore deleted accounts from backups.
Cookies
We use essential cookies for authentication/session only. We do not use third-party advertising cookies.
Children
The Service is not directed to children under 16; we do not knowingly collect their data.
Changes & contact
We may update this policy; material changes will be notified. Contact: system@monitormylawn.com, or see Support for what to include and how quickly we reply.