Privacy policy
What we collect, why, where it lives, and how to exercise your rights. Written to be read, not skimmed past.
In short
- The marketing site collects nothing: no cookies, no analytics, no trackers — its server keeps ordinary access logs, briefly.
- The app collects what an account needs: email, name, a password hash (scrypt — we cannot read it), and the events you send us.
- Event payloads are processed only to deliver them, retained per your plan, then archived or deleted on schedule.
- Data lives in the EU (AWS Frankfurt). Requests: security@hookget.com, honoured within 30 days.
What we hold, and why
| Data | Why | Kept |
|---|---|---|
| Account: email, name, scrypt password hash | sign-in, alerts you asked for | until the account is deleted |
| Event payloads and delivery attempts | the service itself: deliver, retry, show the timeline | per plan retention (3–90 days), then archived or deleted |
| Source and destination credentials | authenticating to providers on your instruction | AES-256-GCM encrypted; deleted with the source/endpoint |
| Audit log (who did what) | operator accountability | parameter hashes only — never the parameters |
| Web server access logs (IP, path, user agent) | abuse prevention, debugging | rotated within weeks |
| Support email you send us | answering you | ordinary mailbox retention |
Legal bases (GDPR)
| Processing | Basis |
|---|---|
| Running the service you signed up for | contract (Art. 6(1)(b)) |
| Security logging and abuse prevention | legitimate interest (Art. 6(1)(f)) |
| Operational emails: delivery failures, anomaly alerts, bug digests | contract — they are the product working |
| Anything promotional | consent — and we currently send none |
Subprocessors
| Provider | Function | Location |
|---|---|---|
| Amazon Web Services | compute and storage for the product | eu-central-1, Frankfurt |
| Cloudflare | DNS, TLS, DDoS protection for public hostnames | global edge |
| BrandMyInbox (our own infrastructure) | transactional email delivery | EU |
Your payloads may contain personal data of your users. There, HookGet is the processor and you are the controller: we process on your instruction (the delivery configuration), and the retention and deletion controls above are the tools you meet your own obligations with. A signed DPA is available on request at security@hookget.com.
Questions
Does HookGet sell or share personal data?
No. Event payloads are your data, processed to deliver them and nothing else. We run no advertising, no analytics resale, no data brokerage. The subprocessors below receive only what their function requires.
How do I get data deleted?
Deleting an endpoint, source or project cascades to its data; payloads also expire on the retention schedule of your plan automatically. For account deletion or a data-subject request (access, rectification, erasure, portability), email security@hookget.com — requests are honoured within 30 days and confirmed in writing.
Where is the data, legally speaking?
Production runs in AWS eu-central-1 (Frankfurt, Germany), inside the EU.
Transactional email is sent via our own mail infrastructure; DNS and TLS termination for the
public site use Cloudflare. See the subprocessor table for the full list.