1. Introduction
This Privacy Policy explains how LTFI Tech, LLC, a Massachusetts limited liability company and maker of the OpsPing service ("LTFI Tech," "OpsPing," "we," "us") collects, uses, stores, and shares information when you use the OpsPing on-call paging and alerting service, including the OpsPing mobile application and the website at ops-ping.com (collectively, the "Service"). This policy is effective as of August 2026.
2. Information We Collect
- Account information. Name (if provided), email address, and authentication credentials used to create and manage your account.
- Channel PII. On-call phone numbers and email addresses you provide for yourself or your team members so we can deliver alerts to them.
- Push tokens. Mobile device push notification tokens required to deliver push alerts through Expo's push service, which delivers downstream via Apple Push Notification service (iOS) and Google Firebase Cloud Messaging (Android).
- Alert logs and operational data. Records of alerts triggered, delivered, acknowledged, and escalated, along with related schedules and escalation configurations.
- IP address and technical data. IP address, device type, and basic log data collected automatically when you access the Service.
- Support communications. Information you provide when you contact us.
3. How We Use Information
We use the information above to: provide and operate the Service (including delivering alerts via push, email, and optional SMS/voice); manage accounts and authentication; maintain and improve the Service; communicate with you about the Service; and comply with legal obligations. We do not sell your personal information.
4. SMS and Text Messaging
If you (or your team's administrator) register a phone number for alert delivery, we use it solely to send operational incident alerts and on-call notifications for the OpsPing service.
- No sharing of mobile numbers: mobile phone numbers collected for SMS alerts are never sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. Numbers are passed only to our messaging provider (Twilio), solely as needed to deliver the messages.
- Message frequency: message frequency varies with your team's on-call activity — typically fewer than 10 messages per month.
- Message and data rates may apply to messages sent and received, depending on your mobile plan.
- Opt-out and help: reply STOP to any OpsPing text message to unsubscribe from further SMS alerts at any time. Reply HELP for help, or contact smscompliance@ops-ping.com.
5. Subprocessors and Third-Party Sharing
We share personal data only with the following subprocessors, solely as needed to operate the Service:
| Subprocessor | Function | Data shared |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, and database (PostgreSQL on Amazon EC2); Amazon SES for email | All Service data; email addresses for email delivery |
| Expo | Push notification relay | Push tokens and notification content |
| Google — Firebase Cloud Messaging (FCM) | Push notification delivery to Android devices (downstream of the Expo relay) | Push tokens, device identifiers, and delivery metadata |
| Twilio | Optional SMS/voice delivery | Phone numbers (only if you enable SMS/voice) |
| Apple — Push Notification service (APNs) | Push notification delivery to iOS devices (via the Expo relay or direct) | Push tokens and notification content |
| Cloudflare | DNS for ops-ping.com domains | DNS records; connection metadata |
We may also disclose information if required by law or to protect our rights and the safety of users. See the full subprocessor list for details.
6. Cookies and Analytics
7. Data Retention and Deletion
- Alert logs and operational data are retained for ninety (90) days and then automatically and permanently purged.
- Account and channel data is retained while your account is active.
- Deletion requests. You may request access to or deletion of your personal data by contacting legal@ops-ping.com. Deletion requests are honored within thirty (30) days of a verified request, subject to legal retention requirements.
- How erasure works. When your account is deleted, your identity (profile, contact channels, device tokens, and every denormalized copy of your name) is removed or irreversibly anonymized in live systems — while your organization's incident history, timelines, and metrics stay intact with events attributed to a neutral "Deleted user" placeholder. An append-only erasure ledger (containing no personal data) ensures erased identities are re-scrubbed from any backup that is ever restored. Backup copies age out with the same ninety (90) day schedule.
8. Data Security
We host the Service on AWS and use industry-standard safeguards, including TLS 1.2+ encryption in transit, IAM-based access controls, and automated daily database backups.
Channel PII encryption: the on-call phone numbers and email addresses you provide are encrypted at the application layer using AES-256-GCM, in addition to infrastructure-level protections. MFA secrets receive the same treatment.
9. International Transfers
The Service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. For customers subject to EU/UK data protection law, transfers can be covered by Standard Contractual Clauses under a Data Processing Agreement — contact us for details.
10. Children's Privacy
The Service is not directed to, and may not be used by, anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact us and we will delete it.
11. Your Rights and Contact
Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise any of these rights, or for questions about this policy, contact us at legal@ops-ping.com.
We may update this policy from time to time; material changes will be communicated through the Service or by email, and the updated policy will note a new effective date. Current effective date: August 2026.