Back to TigerOps
Legal

Privacy Policy

Last updated: April 1, 2026

At TigerOps, Inc. (“TigerOps,” “we,” “our,” or “us”), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at www.tigerops.io or use our AI-powered observability platform and related services (collectively, the “Service”). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.

1. Introduction

TigerOps provides an agentic AI observability platform that enables engineering and operations teams to monitor infrastructure, applications, logs, metrics, and distributed traces. In the course of delivering this service, we process data about you, your organization, and—depending on how you configure our agent—telemetry data from your own systems.

This Privacy Policy applies to: (a) visitors to our marketing website; (b) registered users of the TigerOps platform; (c) individuals whose data is submitted to us by TigerOps customers (e.g., end users of products monitored by TigerOps). Where we act as a data processor on behalf of our enterprise customers, those customers' privacy policies and data processing agreements govern the handling of their end-user data.

TigerOps, Inc. is the data controller for personal data collected through our website and platform account management. Our principal place of business is in Delaware, United States. Questions about this policy may be directed to [email protected].

2. Information We Collect

We collect information in several categories depending on your relationship with TigerOps:

2.1 Personal Data You Provide Directly

When you create an account, request a demo, purchase a subscription, or contact us, you provide personal data including:

  • Full name and job title
  • Work email address and phone number
  • Company name, size, and industry
  • Billing address and payment information (processed by our payment processor, Stripe)
  • Communications you send to our support and sales teams
  • Profile information and preferences within your account

2.2 Usage Data

When you interact with our website or platform, we automatically collect certain technical information, including:

  • IP address and approximate geolocation (country/region)
  • Browser type, version, and operating system
  • Pages visited, features accessed, and time spent in the platform
  • Referring URLs and exit pages
  • Device identifiers and session tokens
  • Actions taken within the TigerOps dashboard (e.g., dashboards created, alerts configured)
  • Error logs and crash reports from the web interface

2.3 Customer Telemetry Data

When you install the TigerOps agent or integrate our APIs, your systems transmit observability telemetry to our infrastructure. This may include:

  • Infrastructure metrics (CPU, memory, disk, network throughput)
  • Application performance traces and span data
  • Log lines and structured log events
  • Custom business metrics and KPIs
  • Kubernetes pod and container metadata
  • Cloud provider resource identifiers (e.g., AWS EC2 instance IDs)
  • Database query patterns and performance statistics

Telemetry data is owned by the customer and processed by TigerOps as a data processor under a Data Processing Agreement (DPA). We do not use your telemetry data to train AI models or for any purpose other than delivering the Service, unless you explicitly opt in. You control what data your agent sends and can configure redaction rules for sensitive fields.

2.4 Cookies and Tracking Technologies

We use the following types of cookies and similar technologies on our website and platform:

TypePurposeOpt-Out
Strictly NecessaryAuthentication sessions, CSRF protection, rate limitingCannot be disabled
FunctionalUser preferences, language settings, dashboard layoutVia account settings
AnalyticsAggregate usage metrics, feature adoption tracking (PostHog)Cookie banner / browser settings
MarketingAdvertising attribution, retargeting on partner networksCookie banner / ad opt-out

You may set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. However, if you disable or refuse cookies, some parts of the Service may not function correctly.

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery

Provision, operate, and maintain the TigerOps platform including account management, billing, and technical support.

Product Improvement

Analyze usage patterns and performance data in aggregate to improve features, fix bugs, and develop new capabilities.

AI Model Operation

Operate our anomaly detection, root cause analysis, and AI SRE Agent features using your telemetry data—strictly within your tenant boundary.

Security & Fraud Prevention

Monitor for unauthorized access, abuse, and malicious activity to protect the integrity of our platform and your data.

Communications

Send transactional emails (invoices, password resets), product updates, and—with your consent—marketing communications.

Legal Compliance

Comply with applicable laws, regulations, legal process, and governmental requests, including tax and accounting obligations.

Customer Support

Respond to your inquiries, troubleshoot issues, and provide technical assistance. Support staff may access account data with your permission.

Analytics & Research

Understand how customers use TigerOps at an aggregate level to inform product strategy and publish industry research (never individual-level).

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal basis for collecting and using personal data is one of the following:

Contract Performance

Processing is necessary to perform our contract with you — including creating and managing your account, providing the Service, and processing payments.

Legitimate Interests

We process data for our legitimate business interests, such as fraud prevention, product improvement, and sending you relevant product updates. We balance these interests against your rights and freedoms.

Consent

Where we rely on consent (e.g., marketing emails, non-essential cookies), you may withdraw consent at any time without affecting the lawfulness of prior processing. Withdrawing consent will not affect your ability to use the Service.

Legal Obligation

We process data when required to comply with applicable laws, such as tax regulations, law enforcement requests, or court orders.

5. Data Sharing & Third Parties

We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes. We share data only in the following circumstances:

Service Providers (Sub-processors)

We engage carefully vetted sub-processors who assist in providing the Service. All sub-processors are bound by data processing agreements that require them to protect your data with equivalent standards to those we apply. Our key sub-processors include:

VendorPurposeLocation
Amazon Web ServicesCloud infrastructure, compute, and storageUS, EU, APAC
StripePayment processing and billingUS, EU
Postmark / SendGridTransactional email deliveryUS
PostHogProduct analytics (anonymized)US / EU (self-hosted option available)
IntercomCustomer support and in-app messagingUS
DatadogInternal platform infrastructure monitoringUS

A complete and up-to-date sub-processor list is available at tigerops.io/legal/subprocessors. We will notify customers at least 10 business days before adding new sub-processors.

Business Transfers

If TigerOps is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.

Legal Requirements

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to: (a) comply with a legal obligation; (b) protect and defend our rights or property; (c) prevent or investigate possible wrongdoing; or (d) protect the personal safety of users or the public.

With Your Consent

We may share your information with third parties when you have given us explicit consent to do so (e.g., enabling a third-party integration from the TigerOps marketplace).

6. Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Account Data
Duration of account + 90 days post-deletion
Retained for fraud prevention and legal obligations
Telemetry Data
Per your plan (1 day – 15 months)
Configurable; deleted immediately on request
Billing Records
7 years
Required by US tax and accounting regulations
Support Tickets
3 years
Used for support quality and dispute resolution
Audit Logs
Per your plan (30 days – unlimited)
Security and compliance requirements
Marketing Opt-outs
Indefinitely
To honor your preferences permanently

Upon termination of your account, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business purposes such as fraud prevention. Telemetry data can be deleted immediately upon written request.

7. International Data Transfers

TigerOps is headquartered in the United States. By using our Service, you acknowledge that your information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ.

For transfers of personal data from the EEA, United Kingdom, or Switzerland to the United States, we rely on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) for UK data transfers
  • Data Processing Agreements with all sub-processors that include adequate transfer safeguards

Enterprise customers requiring data residency in specific regions (EU, APAC) may request dedicated regional deployment. Contact [email protected] to discuss data residency options.

8. Your Rights

8.1 GDPR Rights (EEA/UK Residents)

If you are located in the European Economic Area or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

Right of Access
Request a copy of the personal data we hold about you and how we process it.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data where there is no compelling reason for us to continue processing it.
Right to Restriction
Request that we restrict processing of your personal data in certain circumstances.
Right to Portability
Receive your personal data in a structured, machine-readable format and transfer it to another controller.
Right to Object
Object to processing of your personal data for direct marketing or based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, withdraw consent at any time without affecting prior processing.
Right to Lodge a Complaint
Lodge a complaint with your local data protection authority (e.g., the ICO in the UK or your national DPA in the EU).

8.2 CCPA Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following additional rights:

Right to Know: You have the right to know what personal information we collect, use, disclose, and sell. We do not sell or share personal information for cross-context behavioral advertising without opt-in consent.

Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.

Right to Correct: You may request correction of inaccurate personal information we maintain about you.

Right to Opt Out of Sale/Sharing: We do not sell personal information. If this changes, you will have the right to opt out via a “Do Not Sell or Share My Personal Information” link on our homepage.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

Submitting a Privacy Request

To exercise any of these rights, email [email protected] or submit a request through your account's Privacy Settings page. We will respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before fulfilling your request. Authorized agents may submit requests on your behalf with written authorization.

9. Children's Privacy

The TigerOps Service is intended for use by businesses and their employees. It is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected personal data from a child under 16, please contact [email protected] immediately and we will take prompt steps to delete such information.

10. Security

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • AES-256 encryption for data at rest across all storage systems
  • TLS 1.3 encryption for all data in transit
  • Isolated multi-tenant architecture with strict data separation
  • Role-based access controls and principle of least privilege
  • Multi-factor authentication for all internal systems
  • Annual third-party penetration testing by certified security firms
  • SOC 2 Type II certified infrastructure and processes
  • 24/7 security monitoring and automated incident response

Despite these measures, no method of transmission over the Internet or method of electronic storage is 100% secure. If you have reason to believe your interaction with us is no longer secure, please immediately notify us at [email protected]. For our complete security overview, visit tigerops.io/security.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to all registered account holders at least 30 days before changes take effect
  • Display a prominent banner in the platform UI for enterprise customers
  • For significant changes, require acknowledgment before continued use of the Service

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Privacy team:

Privacy Team

Email: [email protected]

Response time: Within 2 business days

DSR fulfillment: Within 30 days

Mailing Address

TigerOps, Inc.

Attn: Privacy Officer

651 N Broad St, Suite 201

Middletown, DE 19709

United States

EU/UK Representative: If you are located in the EEA or UK and wish to raise a concern, you may also contact our EU representative by emailing [email protected] with “EU Representative Request” in the subject line, or file a complaint directly with your local supervisory authority.

© 2026 TigerOps, Inc. All rights reserved.