HookGet Open dashboard

Privacy policy

What we collect, why, where it lives, and how to exercise your rights. Written to be read, not skimmed past.

In short

  • The marketing site collects nothing: no cookies, no analytics, no trackers — its server keeps ordinary access logs, briefly.
  • The app collects what an account needs: email, name, a password hash (scrypt — we cannot read it), and the events you send us.
  • Event payloads are processed only to deliver them, retained per your plan, then archived or deleted on schedule.
  • Data lives in the EU (AWS Frankfurt). Requests: security@hookget.com, honoured within 30 days.

What we hold, and why

DataWhyKept
Account: email, name, scrypt password hashsign-in, alerts you asked foruntil the account is deleted
Event payloads and delivery attemptsthe service itself: deliver, retry, show the timelineper plan retention (3–90 days), then archived or deleted
Source and destination credentialsauthenticating to providers on your instructionAES-256-GCM encrypted; deleted with the source/endpoint
Audit log (who did what)operator accountabilityparameter hashes only — never the parameters
Web server access logs (IP, path, user agent)abuse prevention, debuggingrotated within weeks
Support email you send usanswering youordinary mailbox retention

Legal bases (GDPR)

ProcessingBasis
Running the service you signed up forcontract (Art. 6(1)(b))
Security logging and abuse preventionlegitimate interest (Art. 6(1)(f))
Operational emails: delivery failures, anomaly alerts, bug digestscontract — they are the product working
Anything promotionalconsent — and we currently send none

Subprocessors

ProviderFunctionLocation
Amazon Web Servicescompute and storage for the producteu-central-1, Frankfurt
CloudflareDNS, TLS, DDoS protection for public hostnamesglobal edge
BrandMyInbox (our own infrastructure)transactional email deliveryEU

Your payloads may contain personal data of your users. There, HookGet is the processor and you are the controller: we process on your instruction (the delivery configuration), and the retention and deletion controls above are the tools you meet your own obligations with. A signed DPA is available on request at security@hookget.com.

Questions

Does HookGet sell or share personal data?

No. Event payloads are your data, processed to deliver them and nothing else. We run no advertising, no analytics resale, no data brokerage. The subprocessors below receive only what their function requires.

How do I get data deleted?

Deleting an endpoint, source or project cascades to its data; payloads also expire on the retention schedule of your plan automatically. For account deletion or a data-subject request (access, rectification, erasure, portability), email security@hookget.com — requests are honoured within 30 days and confirmed in writing.

Where is the data, legally speaking?

Production runs in AWS eu-central-1 (Frankfurt, Germany), inside the EU. Transactional email is sent via our own mail infrastructure; DNS and TLS termination for the public site use Cloudflare. See the subprocessor table for the full list.