HookWatch Privacy Policy
Last updated: 25 September 2026
This policy explains what personal data HookWatch processes when you visit https://gethookwatch.com, use the API at https://api.gethookwatch.com, or use any related service (the "Service"), and what your rights are under the EU General Data Protection Regulation (GDPR).
1. Controller
HookWatch
Email: support@gethookwatch.com
Fast contact: contact form
No data protection officer is appointed, because none is legally required. For all privacy questions, use the email above.
2. What data we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address | Create your account, send magic sign-in links, send service and billing notices | Art. 6(1)(b), performing the contract |
| Session cookie (random session identifier) | Keep you signed in | Art. 6(1)(b); the cookie is strictly necessary (§ 25(2) no. 2 TDDDG) |
| Webhook alert payloads, delivery logs and receipts (timestamps, status codes, retry attempts, error messages), dead-letter queue entries, the hosted inbox (latest 50 deliveries) | Receive, queue, retry, and deliver your alerts; show delivery history; troubleshoot | Art. 6(1)(b) |
| Destination URLs and webhook configuration | Deliver alerts where you tell us to | Art. 6(1)(b) |
| IP addresses and server logs (API, dashboard, webhook endpoints; logs may contain your email address and Stripe customer ID) | Security, abuse and fraud prevention, rate limiting, debugging, keeping the Service running | Art. 6(1)(f), legitimate interest in a secure, stable Service |
| Stripe customer and subscription IDs, plan, billing status, invoice records | Manage card subscriptions, billing, and cancellations | Art. 6(1)(b); invoice records also Art. 6(1)(c) (tax and commercial retention duties) |
| Crypto order data: email address, order ID, plan, asset, network, amount, and transaction hash (the sending wallet address can be seen on the public blockchain from the transaction hash) | Match and verify payments, activate access, handle top-ups, refunds and disputes, prevent fraud | Art. 6(1)(b); records also Art. 6(1)(c); fraud checks Art. 6(1)(f) |
| Correspondence (emails you send us, and messages sent through our contact form: name, email address, message) | Answer your requests | Art. 6(1)(b) or (f) |
Payloads: We don't need personal data in your alert payloads. Please don't put personal data, secrets, or payment data in them. If you do, we process it only to deliver it for you. If business customers send personal data of third parties through HookWatch, we act as their processor for that data, and a data processing agreement is available on request.
Card data: Card numbers are entered directly with Stripe. We never receive or store full card details.
Blockchain data is public: If you pay in crypto, your transaction (including the sending and receiving wallet addresses, the amount, and the time) is recorded on a public blockchain (TRON, BNB Smart Chain, Solana, or Ethereum). Anyone can see it, and it is permanent. Neither we nor anyone else can change or delete data recorded on the blockchain. If other information links your wallet address to you, others may be able to connect the payment to you. We store only the order data listed above. We do not use a third-party crypto payment processor; payments go directly to our own wallet and are confirmed manually.
You need to give us your email address to use the Service. Without it, we cannot provide an account. We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
3. Service providers (processors) and recipients
We use exactly these providers to run the Service. Where they act as processors, they are bound by data processing agreements (Art. 28 GDPR).
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Stripe (Stripe Payments Europe, Limited, Ireland; part of the Stripe group, USA) | Card payment processing, subscriptions, invoices and receipts, Customer Portal | Email, payment and billing data, Stripe IDs | EU and USA |
| Fly.io (Fly.io, Inc., USA) | API hosting, application servers, database | All Service data (account, payloads, logs, orders) | Servers in the Frankfurt (Germany) region; US company |
| Cloudflare (Cloudflare, Inc., USA) | DNS, CDN, hosting of the landing site, security | IP addresses, request metadata, traffic passing through Cloudflare | Global network; US company |
| Resend (Plus Five Five, Inc., USA) | Sending emails: magic sign-in links, cancellation and withdrawal confirmations, and forwarding contact-form messages to our inbox | Email address, name (contact form), email content, delivery metadata | USA |
| Google (Gmail; Google Ireland Limited, Ireland; part of Google LLC, USA) | Our email inbox: receiving and storing contact-form messages and support emails | Name, email address, message content, email metadata | EU and USA |
Stripe also processes some payment data as an independent controller (for example for fraud prevention and its regulatory duties). See Stripe's own privacy policy for details.
When you pay in crypto, the transaction is processed by the relevant public blockchain network, not by us or a processor (see section 2). Your destination URLs receive your payloads because you told us to send them there.
We share data with authorities only where the law requires it. We do not sell personal data.
4. Transfers outside the EU/EEA
Stripe (group), Fly.io, Cloudflare, Resend, and Google are US companies or part of US groups. Even when data is stored in the EU (for example on Fly.io servers in Frankfurt), the provider or its US affiliates may be able to access it. Where personal data is transferred to the USA or can be accessed from there, we rely on:
- the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR), for providers certified under it; and
- Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR), where they are included in the provider's data processing terms.
You can ask us for a copy of the relevant safeguards at support@gethookwatch.com.
5. Cookies and similar technologies
We use one strictly necessary session cookie to keep you signed in after you use a magic link. It lasts for 30 days or until you sign out. Because it is strictly necessary, no consent is required (§ 25(2) no. 2 TDDDG).
Cloudflare may set strictly necessary security cookies (for example for bot protection) when you visit our website. These are used only to protect the site, not for tracking.
We do not use any analytics. We use no analytics, advertising, or tracking cookies, and no tracking pixels. If we ever add them, we will ask for your consent first and update this policy.
6. How long we keep data
| Data | Retention |
|---|---|
| Account data (email, settings, destination URLs) | While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days |
| Hosted inbox | Only the latest 50 deliveries per account. Older entries are deleted automatically. The rest is deleted with the account |
| Queued payloads | Until delivered, or until they move to the dead-letter queue |
| Payloads and dead-letter queue entries | While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days. We plan to introduce automatic deletion after a fixed period and will update this policy when it is live |
| Delivery logs and receipts (alert history) | While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days. We plan to introduce automatic deletion after a fixed period and will update this policy when it is live |
| IP addresses | Not stored in our database. Held only in memory for short rate-limiting windows (about 15 minutes) |
| Server application logs (may contain your email address, Stripe customer ID, and technical request data) | 7 days at our hosting provider, then deleted; longer only if needed to investigate a specific security incident |
| Magic-link tokens | Valid until used or for 15 minutes. The used or expired token record is kept while your account exists |
| Session cookie and session record | The cookie expires after 30 days or when you sign out. The session record is kept until you sign out or it is replaced, and otherwise while your account exists |
| Stripe IDs and billing records; crypto order data | For the duration of the contract, then as long as German tax and commercial law requires, usually 8 or 10 years depending on the document type (§ 147 AO). During this time the records are used only for that purpose |
| Support emails | 2 years after the last contact, unless they are needed as tax or commercial records |
| Backups (daily server volume snapshots) | Each snapshot expires after 5 days and is then deleted, usually within a further day. Data deleted from the Service may remain in snapshots until they expire |
Stripe and Cloudflare keep some data under their own retention rules as independent controllers.
7. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- correct it (Art. 16);
- have it erased (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21);
- withdraw consent at any time, with effect for the future, where we rely on consent (currently we don't).
To use these rights, email support@gethookwatch.com. We may ask you to confirm that you control the account email. Data recorded on a public blockchain cannot be erased by us (section 2).
Complaints: You can complain to a data protection supervisory authority, in particular in your EU country of residence or work, or where the alleged breach took place. The authority responsible for us is the data protection supervisory authority of the German federal state in which the operator lives (see the address in section 1).
8. Security
We use reasonable technical and organisational measures to protect your data. These include:
- TLS encryption in transit;
- encryption at rest of the server volumes at our hosting provider;
- passwordless magic-link sign-in with short-lived tokens;
- secure, HTTP-only session cookies;
- access restricted to the operator;
- automatic limits on stored delivery history.
No system is completely secure. Keep your mailbox and webhook secrets safe.
9. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy when the Service, our providers, or the law change. The current version is always available at /privacy. We will tell registered users about material changes by email.
11. Contact
HookWatch
Email: support@gethookwatch.com
Fast contact: contact form