Privacy Policy

Version 2026-09-05 · Last updated: September 5, 2026 · Governing law: Belgium (GDPR)

1. Who we are

CronEngine is operated by Furora BV, VAT number BE0656855294, Belgium.

Privacy contact: support@cronengine.com

2. What CronEngine does

CronEngine allows you to schedule and execute HTTP requests (webhooks) based on cron expressions. You define when a job runs and which endpoint is called.

We do not control or manage the content of the endpoints you configure. You remain fully responsible for the data processed by your own systems.

3. Data we collect

  • Account data: name, email address, hashed password, timezone.
  • Billing and invoice data: company name, VAT number, address, payment and invoice details. Payments are handled by Stripe, while Facturalia is used to generate and deliver invoices automatically through Peppol where applicable or by email/PDF otherwise. We never store card details.
  • Job configuration: cron expressions, request and notification URLs, headers, bot tokens, signing secrets, and other configuration you define. Secret values such as authentication secrets, signing secrets, and bot tokens are encrypted before they are stored, and are decrypted only when a request or notification is sent. See section 6.
  • Execution logs: timestamps, HTTP status codes, response times, error messages, and, when enabled in the job settings, up to 10 KB of the endpoint's response body. Larger response bodies are truncated. Stored response content may include personal or sensitive information returned by your endpoint.
  • Technical data: IP address, user agent, session identifiers for security and abuse prevention.
  • Legal acceptance records: the document type and exact version, acceptance time and method, IP address, and a one-way hash of the browser user agent. We use these records to administer our contract and demonstrate which terms you accepted.
  • Optional analytics data: if you consent, Google Analytics may receive information about pages viewed, interactions, browser and device details, approximate location, and analytics cookie identifiers.
  • Optional advertising measurement data: if you consent, Google Ads may receive sign-up or purchase conversion events and advertising identifiers used to measure our campaigns.

4. Why we process data

  • To provide and operate the service (job scheduling and execution)
  • To secure the platform and prevent abuse
  • To handle billing and invoicing
  • To communicate important service messages
  • With your consent, to understand site usage and improve CronEngine
  • With your consent, to measure advertising conversions

Legal bases include performance of a contract, legal obligations, and our legitimate interests in securing and operating the service. Optional analytics and advertising measurement are based on your consent, which you may withdraw at any time.

5. Retention

  • Execution logs: retained for 30 days, including any response content stored with those logs.
  • Notification delivery records: sent, suppressed, and failed outbox records are retained for 30 days.
  • Digest statistics: compact daily run totals used for weekly or monthly email summaries are retained for 120 days by default. They do not contain response bodies.
  • Account data: retained while your account is active and permanently deleted 30 days after closure.
  • Legal acceptance records: retained with your account and deleted when the account is permanently deleted after the 30-day recovery period.
  • Invoice data: retained for 7 years as required by law.

6. How we protect your data

Account passwords are stored only as one-way hashes and are never recoverable.

Job and notification credentials cannot be hashed, because CronEngine has to replay them on your behalf. Instead the following values are encrypted before they are written to the database, and decrypted only at the moment a request or notification is sent: job authentication secrets, custom request headers, request bodies, notification destination URLs, webhook signing secrets, and bot tokens.

The encryption key is held outside the database and is deliberately excluded from database backups, so a copy of the database alone does not reveal these values. Database backups are themselves encrypted.

Authentication secrets, signing secrets, and bot tokens are also write-only. Once saved they are never displayed again, including to you. You can replace one at any time.

Stored response content described in section 3 is not covered by this encryption. If your endpoint returns personal or sensitive information, disable response-body storage for that job.

These measures reduce risk but cannot eliminate it. No online service can guarantee that a security incident will never occur.

7. Notification destinations and responsibility

A custom notification email must be verified through a one-time link before it becomes active. Until verification succeeds, job emails continue to use the verified account address or the previously verified notification address.

You are responsible for the endpoints you configure and the data they process.

CronEngine only executes HTTP requests based on your configuration. We do not inspect or control the content of requests or responses beyond what is required for execution and logging.

Because endpoint response content may be saved in run history, configure your endpoints and response-storage setting to avoid retaining personal or sensitive information that is not needed for monitoring. You can disable response-body storage for a job.

You must ensure that your use of CronEngine complies with applicable data protection laws.

8. Processors

We rely on providers and connected Furora services to operate CronEngine:

  • Stripe for payment processing
  • Facturalia, operated by Furora BV, for automatic invoice generation and Peppol or email/PDF delivery
  • Hosting provider for infrastructure
  • Email provider for transactional messages
  • Slack, Discord, Telegram, or another notification endpoint when you configure that provider or destination
  • Google Analytics and Google Ads for optional analytics and advertising measurement, but only after you consent to the corresponding purpose

You can learn more about how Google handles information in Google's Privacy Policy. We do not sell your personal data.

9. Cookies and similar storage

We always use essential cookies and local storage required for authentication, security, and remembering your privacy choices. Google Analytics and Google Ads tags remain blocked unless you opt in to the corresponding purpose.

You can accept, reject, or choose each optional purpose separately. Change or withdraw your choice at any time using Cookie settings in the footer. See our Cookie Policy for details.

10. Your rights

You have the right to access, correct, delete, restrict, or transfer your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.

Contact us at support@cronengine.com. We respond within 30 days.

11. Changes

We may update this policy when our service or legal obligations change. We will publish the updated date on this page and provide additional notice where required.