Privacy Policy
Last updated:
The short version
If you submit a form, we store what you typed so we can reply, and we use it for nothing else. Monitoring data, logs and camera footage are collected only where the service requires it, and can be processed on your own premises. We do not sell data and we do not run advertising trackers.
Who this covers
This policy applies to www.mounteyes.com and to the email and messaging replies we send you about a request you made. It does not cover any third-party site we link to, including the official platform recovery pages referenced in our guides — those are the platform's own systems under the platform's own policy.
What we never ask for, and never hold
We do not ask for a password, an OTP, a recovery code, an authentication token or card details, for any reason, at any point. There is no field for them on this site, our forms actively reject content that looks like a credential, and no engineer of ours will request one in an email or a call. Access to your systems is granted through your own provider's controls, scoped per task and revocable by you.
That is a design decision, not a policy sentence. A secret we never receive is one we cannot log, store, subpoena or lose in a breach — and it is the only version of that promise that survives us making a mistake.
Monitoring data, logs and footage
Where you engage us for monitoring, the service collects what monitoring requires: server and application metrics, security and access logs, network flow and scan results, and — for AI CCTV monitoring — video from cameras you own, together with the still image and clip attached to each alert. The scope is written into the engagement before anything is switched on.
For CCTV, processing can run entirely on your premises, with only alerts and their clips leaving the site. Where your own policy says video must not leave the building, that is the configuration we deploy. Retention periods are set by you, and access to footage is restricted to the people you name.
None of this data is used to train anything for another customer, sold, rented, or shared with an advertiser. Where you end the engagement, we hand back or delete what we hold, at your choice.
What we collect when you submit a form
The consultation form and the contact form send us exactly the fields shown on the form: your name, email address, phone number where you provide one, the service or subject you selected, and your message. We store this so a consultant can read it and reply. Nothing on those forms is optional-but-secretly-tracked; if it is not a visible field, we did not collect it.
Our forms reject content that looks like a credential. If you paste a password or an OTP into a message, the submission is refused with an explanation rather than quietly accepted. We would rather annoy you than hold a secret we have no legitimate use for.
We also record a truncated form of the network address a submission came from — the first three parts of an IPv4 address, or the network portion of an IPv6 address — together with a timestamp. This exists solely to rate-limit abuse, and it is deliberately too coarse to identify a person or a household.
Why we are allowed to hold it
For a form submission, the basis is your own request: you asked us to reply, and we cannot do that without the message and a way to reach you. For the truncated address and timestamp, the basis is our legitimate interest in keeping a public form usable — without a rate limit, an automated flood makes the form useless for everyone. We do not process any of it for advertising, profiling or automated decision-making.
How long we keep it
Enquiries are kept while the conversation is open and for up to 24 months afterwards, so that if you come back about the same problem we still have the history. Abuse-prevention records are kept for 30 days. You can ask us to delete your enquiry sooner and we will, unless we are required to retain something for tax or legal reasons — an invoice, for example.
Who else sees it
We use a small number of processors and we would rather name them than say "trusted third parties". Supabase hosts the database that stores form submissions. Resend delivers our transactional email. Our hosting provider serves the site and produces standard server logs. Each of them only processes what is technically necessary to do that job.
We do not sell, rent or trade your data. We do not run advertising networks, behavioural trackers or third-party analytics that follow you across sites. We disclose data to anyone else only if we are legally compelled to, and where we are permitted to tell you, we will.
Cookies
The site sets no advertising or analytics cookies. Your light or dark theme preference is stored in your browser's local storage on your own device and is never transmitted. Because there is no tracking to consent to, there is no cookie banner — the absence of one here is the point, not an oversight.
Security of what we do hold
Form submissions live in a database with row-level security enabled and no public read or write policy, which means a browser cannot reach those rows at all: only our server-side code, using a secret key that never ships to the client, can write them. Traffic to the site is encrypted in transit. No system is perfectly secure, which is precisely why we minimise what is there to steal.
Your rights
You can ask what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email [email protected] from the address you contacted us with and we will respond within 30 days. If we cannot verify that the request is yours, we will ask one clarifying question rather than hand your enquiry to whoever asked for it.
Children
This service is not directed at children under 13 and we do not knowingly collect their data. If a parent or guardian believes we hold something we should not, email [email protected] and we will remove it.
Changes to this policy
If we change how data is handled in any way that matters, we will update the date at the top of this page and, for a material change affecting an open enquiry, tell you directly. We will not quietly broaden what we collect and rely on you re-reading this page.
Questions about this page?
Plain-English answers beat legal wording. If anything here is unclear or looks wrong, email [email protected] and we will explain or fix it.