This Privacy Policy explains what data Hookman ("we", "us") collects when you use hookman.dev and the Hookman service, and how we use it. By using Hookman you agree to this policy.
What we collect
- Account data — your name, email address and authentication credentials (passwords are stored only as salted hashes).
- Organisation & project data — org/project names, deployment URLs and routing rules you configure.
- Webhook telemetry — metadata about webhooks routed through your endpoint (timestamp, method, status, latency, target). Request bodies are stored temporarily for replay and expire automatically based on your plan's retention window.
- Billing data — handled by Stripe; we store only your plan, customer and subscription identifiers, never card details.
- Usage & diagnostics — aggregate request counts and error logs needed to operate and secure the service.
How we use it
- To provide webhook routing, replay, logging and the dashboard.
- To enforce plan limits and bill your subscription.
- To send service email (quota alerts, invites, security notices). You can turn quota alerts off in settings.
- To detect abuse and keep the service secure and reliable.
Sharing
We do not sell your data. We share data only with sub-processors that run the service — currently Cloudflare (edge, storage, queues), Neon (database) and Stripe (billing) — and where required by law.
Retention
Webhook payloads expire on a per-plan schedule (7 / 30 / 90 days). Account and configuration data is kept until you delete your account, after which it is removed. You can delete your account from the dashboard.
Your rights
You can access, export, correct or delete your data. Email [email protected] and we'll respond within 30 days.
Contact
Questions about this policy: [email protected].
This document is a template and not legal advice — review it with counsel before relying on it.