HookWatch Privacy Policy

Last updated: 25 September 2026

This policy explains what personal data HookWatch processes when you visit https://gethookwatch.com, use the API at https://api.gethookwatch.com, or use any related service (the "Service"), and what your rights are under the EU General Data Protection Regulation (GDPR).

1. Controller

HookWatch
Email: support@gethookwatch.com
Fast contact: contact form

No data protection officer is appointed, because none is legally required. For all privacy questions, use the email above.

Data Purpose Legal basis (GDPR)
Email address Create your account, send magic sign-in links, send service and billing notices Art. 6(1)(b), performing the contract
Session cookie (random session identifier) Keep you signed in Art. 6(1)(b); the cookie is strictly necessary (§ 25(2) no. 2 TDDDG)
Webhook alert payloads, delivery logs and receipts (timestamps, status codes, retry attempts, error messages), dead-letter queue entries, the hosted inbox (latest 50 deliveries) Receive, queue, retry, and deliver your alerts; show delivery history; troubleshoot Art. 6(1)(b)
Destination URLs and webhook configuration Deliver alerts where you tell us to Art. 6(1)(b)
IP addresses and server logs (API, dashboard, webhook endpoints; logs may contain your email address and Stripe customer ID) Security, abuse and fraud prevention, rate limiting, debugging, keeping the Service running Art. 6(1)(f), legitimate interest in a secure, stable Service
Stripe customer and subscription IDs, plan, billing status, invoice records Manage card subscriptions, billing, and cancellations Art. 6(1)(b); invoice records also Art. 6(1)(c) (tax and commercial retention duties)
Crypto order data: email address, order ID, plan, asset, network, amount, and transaction hash (the sending wallet address can be seen on the public blockchain from the transaction hash) Match and verify payments, activate access, handle top-ups, refunds and disputes, prevent fraud Art. 6(1)(b); records also Art. 6(1)(c); fraud checks Art. 6(1)(f)
Correspondence (emails you send us, and messages sent through our contact form: name, email address, message) Answer your requests Art. 6(1)(b) or (f)

Payloads: We don't need personal data in your alert payloads. Please don't put personal data, secrets, or payment data in them. If you do, we process it only to deliver it for you. If business customers send personal data of third parties through HookWatch, we act as their processor for that data, and a data processing agreement is available on request.

Card data: Card numbers are entered directly with Stripe. We never receive or store full card details.

Blockchain data is public: If you pay in crypto, your transaction (including the sending and receiving wallet addresses, the amount, and the time) is recorded on a public blockchain (TRON, BNB Smart Chain, Solana, or Ethereum). Anyone can see it, and it is permanent. Neither we nor anyone else can change or delete data recorded on the blockchain. If other information links your wallet address to you, others may be able to connect the payment to you. We store only the order data listed above. We do not use a third-party crypto payment processor; payments go directly to our own wallet and are confirmed manually.

You need to give us your email address to use the Service. Without it, we cannot provide an account. We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

3. Service providers (processors) and recipients

We use exactly these providers to run the Service. Where they act as processors, they are bound by data processing agreements (Art. 28 GDPR).

Provider Role Data involved Location
Stripe (Stripe Payments Europe, Limited, Ireland; part of the Stripe group, USA) Card payment processing, subscriptions, invoices and receipts, Customer Portal Email, payment and billing data, Stripe IDs EU and USA
Fly.io (Fly.io, Inc., USA) API hosting, application servers, database All Service data (account, payloads, logs, orders) Servers in the Frankfurt (Germany) region; US company
Cloudflare (Cloudflare, Inc., USA) DNS, CDN, hosting of the landing site, security IP addresses, request metadata, traffic passing through Cloudflare Global network; US company
Resend (Plus Five Five, Inc., USA) Sending emails: magic sign-in links, cancellation and withdrawal confirmations, and forwarding contact-form messages to our inbox Email address, name (contact form), email content, delivery metadata USA
Google (Gmail; Google Ireland Limited, Ireland; part of Google LLC, USA) Our email inbox: receiving and storing contact-form messages and support emails Name, email address, message content, email metadata EU and USA

Stripe also processes some payment data as an independent controller (for example for fraud prevention and its regulatory duties). See Stripe's own privacy policy for details.

When you pay in crypto, the transaction is processed by the relevant public blockchain network, not by us or a processor (see section 2). Your destination URLs receive your payloads because you told us to send them there.

We share data with authorities only where the law requires it. We do not sell personal data.

4. Transfers outside the EU/EEA

Stripe (group), Fly.io, Cloudflare, Resend, and Google are US companies or part of US groups. Even when data is stored in the EU (for example on Fly.io servers in Frankfurt), the provider or its US affiliates may be able to access it. Where personal data is transferred to the USA or can be accessed from there, we rely on:

You can ask us for a copy of the relevant safeguards at support@gethookwatch.com.

5. Cookies and similar technologies

We use one strictly necessary session cookie to keep you signed in after you use a magic link. It lasts for 30 days or until you sign out. Because it is strictly necessary, no consent is required (§ 25(2) no. 2 TDDDG).

Cloudflare may set strictly necessary security cookies (for example for bot protection) when you visit our website. These are used only to protect the site, not for tracking.

We do not use any analytics. We use no analytics, advertising, or tracking cookies, and no tracking pixels. If we ever add them, we will ask for your consent first and update this policy.

6. How long we keep data

Data Retention
Account data (email, settings, destination URLs) While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days
Hosted inbox Only the latest 50 deliveries per account. Older entries are deleted automatically. The rest is deleted with the account
Queued payloads Until delivered, or until they move to the dead-letter queue
Payloads and dead-letter queue entries While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days. We plan to introduce automatic deletion after a fixed period and will update this policy when it is live
Delivery logs and receipts (alert history) While your account exists. You can ask us to delete your account at any time; we then delete this data manually within 30 days. We plan to introduce automatic deletion after a fixed period and will update this policy when it is live
IP addresses Not stored in our database. Held only in memory for short rate-limiting windows (about 15 minutes)
Server application logs (may contain your email address, Stripe customer ID, and technical request data) 7 days at our hosting provider, then deleted; longer only if needed to investigate a specific security incident
Magic-link tokens Valid until used or for 15 minutes. The used or expired token record is kept while your account exists
Session cookie and session record The cookie expires after 30 days or when you sign out. The session record is kept until you sign out or it is replaced, and otherwise while your account exists
Stripe IDs and billing records; crypto order data For the duration of the contract, then as long as German tax and commercial law requires, usually 8 or 10 years depending on the document type (§ 147 AO). During this time the records are used only for that purpose
Support emails 2 years after the last contact, unless they are needed as tax or commercial records
Backups (daily server volume snapshots) Each snapshot expires after 5 days and is then deleted, usually within a further day. Data deleted from the Service may remain in snapshots until they expire

Stripe and Cloudflare keep some data under their own retention rules as independent controllers.

7. Your rights

Under the GDPR you have the right to:

To use these rights, email support@gethookwatch.com. We may ask you to confirm that you control the account email. Data recorded on a public blockchain cannot be erased by us (section 2).

Complaints: You can complain to a data protection supervisory authority, in particular in your EU country of residence or work, or where the alleged breach took place. The authority responsible for us is the data protection supervisory authority of the German federal state in which the operator lives (see the address in section 1).

8. Security

We use reasonable technical and organisational measures to protect your data. These include:

No system is completely secure. Keep your mailbox and webhook secrets safe.

9. Children

The Service is not intended for anyone under 18. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy when the Service, our providers, or the law change. The current version is always available at /privacy. We will tell registered users about material changes by email.

11. Contact

HookWatch
Email: support@gethookwatch.com
Fast contact: contact form