Skip to content
HookDeploy

HookDeploy Privacy Policy

Effective Date: July 4, 2026
Last Updated: July 4, 2026

SnapStack Technologies Inc. ("SnapStack," "we," "us," or "our") operates the HookDeploy platform, including hookdeploy.dev, app.hookdeploy.dev, mail.hookdeploy.dev, api.hookdeploy.dev, and the HookDeploy iOS and Android mobile applications (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights with respect to that information.

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Who We Are

SnapStack Technologies Inc. is a Delaware corporation and the data controller for personal data collected through the Service. For questions about this policy, contact us at:

support@hookdeploy.dev
hookdeploy.dev

2. Information We Collect

2.1 Account and Registration Data

When you create an account, we collect your name, email address, and a hashed password (handled by Supabase Auth). If you accept an organization invitation, we collect the email address used to accept it. If you use the HookDeploy mobile application and grant notification permissions, we collect your device push token (provided by Expo's push notification service) solely for the purpose of delivering in-app notifications. You may opt out of push notifications at any time via your device's notification settings, which will prevent further collection of push tokens.

2.2 Billing and Payment Data

When you subscribe to a paid plan, we collect your billing address and payment method details. Payment card data is processed directly by Stripe and is never stored on our servers. We retain Stripe customer IDs and subscription status to manage your account.

2.3 Usage and Log Data

We automatically collect information about how you use the Service, including:

  • IP addresses of connections to the dashboard and API
  • API key identifiers (prefix only; full keys are stored as SHA-256 hashes and are never recoverable)
  • Dashboard actions logged in our audit log (e.g., endpoint creation, member invitations, plan changes)
  • Request and storage usage counters used for plan limit enforcement

2.4 Webhook Payload Data ("Customer Data")

The core function of the Service is to capture HTTP requests sent to your webhook endpoints. This means we store the headers, query parameters, source IP address, and request body (the "Payload") of every webhook request captured by your endpoints. This data is stored in Cloudflare R2 object storage and is retained for the duration specified by your plan (7 days for Free, 30 days for Starter, 90 days for Team, 365 days for Enterprise), after which it is automatically and permanently deleted.

You are the data controller for any personal data contained within webhook Payloads. We process that data only on your behalf and under your instructions, as a data processor.

2.5 Communications Data

If you contact us for support or send us email, we retain the contents of that communication to resolve your issue and improve the Service.

2.6 Marketing Site Analytics

On hookdeploy.dev (our marketing site), we use Google Analytics (G-68Y1ZCF658) to collect anonymized information about visitors, including pages visited, referral sources, browser type, and general geographic location. Google Analytics only loads after you consent via our cookie banner. You may withdraw consent at any time by clicking "Cookie preferences" in the site footer.

2.7 Mobile Device Data

When you use the HookDeploy mobile application, we may collect or process the following additional data:

  • Device locale: We read your device's locale setting (via expo-localization) at signup to suggest an appropriate data region for your account. This is used solely to improve the signup experience and is not stored independently of your account preferences.
  • Biometric authentication: The mobile application offers an optional biometric app lock (Face ID or Touch ID). Biometric data is processed entirely on your device by your operating system. SnapStack never has access to, transmits, or stores any biometric data whatsoever.
  • Push notification tokens: If you grant notification permission, we collect your Expo push notification token to deliver push notifications about webhook activity (e.g., new webhook received, forwarding failures). Push tokens are associated with your user account and are never shared with third parties for advertising or tracking purposes. You can revoke this permission at any time in your device's notification settings.

2.8 Referral and Affiliate Attribution

If you arrive at hookdeploy.dev via a referral or affiliate link, we store a referral code in a session cookie and/or sessionStorage, subject to your cookie consent preferences, to attribute your signup to the referring party. This data is used solely for affiliate commission calculation and is not shared with third parties beyond the referring affiliate, who receives only aggregated payout data and never your personal information. Referral attribution data is discarded after your account is created.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate you and authorize access to your organization
  • Process billing and manage your subscription via Stripe
  • Enforce plan limits (request quotas, storage caps, member counts)
  • Send transactional emails, including invitation emails, billing receipts, and password reset links (via Resend)
  • Send push notifications to the mobile application, where you have granted permission
  • Respond to support requests and troubleshoot issues
  • Detect and prevent abuse, fraud, and security incidents
  • Comply with legal obligations
  • Improve and develop the Service (using aggregated, non-identifiable usage patterns)

We do not use Customer Data (webhook payloads) for any purpose other than providing the Service to you.

4. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases:

  • Contract: Processing necessary to provide the Service you have requested (account management, billing, webhook capture and forwarding).
  • Legitimate Interests: Security monitoring, fraud prevention, abuse detection, and product improvement using aggregated analytics, where these interests are not overridden by your rights.
  • Legal Obligation: Compliance with applicable laws, regulations, and lawful requests from authorities.
  • Consent: Loading Google Analytics on the marketing site (you may withdraw consent at any time via the cookie banner); sending push notifications via the mobile application (you may withdraw consent via device notification settings).

5. How We Share Your Information

We do not sell your personal data. We share information only in the following circumstances:

5.1 Service Providers (Sub-processors)

We use the following third-party service providers to operate the Service. Each is bound by data processing agreements consistent with applicable law:

  • Supabase (database, authentication, realtime) — supabase.com
  • Cloudflare (Workers, Pages, R2 storage, KV, CDN) — cloudflare.com
  • Vultr Holdings LLC (relay infrastructure, VPS hosting) — vultr.com
  • Stripe (payment processing and billing) — stripe.com
  • Resend (transactional email delivery) — resend.com
  • Infisical Inc. (secrets management) — infisical.com
  • Expo (mobile push notification delivery) — expo.dev
  • Google Analytics (marketing site analytics, consent-gated) — google.com/analytics
  • Zapier (optional webhook forwarding integration) — zapier.com
  • n8n (optional webhook automation integration) — n8n.io

5.2 Organization Members

Within your organization, users with appropriate roles (admin, super_admin) can view audit logs, member information, usage data, and captured webhook requests. You control who has access by managing your organization's members and roles in the dashboard.

5.3 Legal Requirements

We may disclose your information if required to do so by law or in good-faith belief that such disclosure is necessary to: (a) comply with a legal obligation or lawful request from a government authority; (b) protect and defend our rights or property; (c) prevent or investigate fraud, security incidents, or abuse; or (d) protect the safety of our users or the public. Where legally permitted, we will notify you of such requests.

5.4 Business Transfers

If SnapStack is involved in a merger, acquisition, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service before your information becomes subject to a materially different privacy policy.

5.5 With Your Consent

We may share your information for any other purpose with your explicit prior consent.

6. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account and profile data: Retained while your account exists. Deleted within 30 days of account deletion.
  • Webhook Payload data: Retained for the period specified by your plan (7 / 30 / 90 / 365 days). Automatically purged on a rolling basis by a scheduled retention job.
  • Billing records: Retained as long as required by applicable financial and tax law (typically 7 years).
  • Audit logs: Retained for the duration of your account.
  • Support communications: Retained for up to 3 years.
  • Push notification tokens: Retained while your account is active. Deleted upon account deletion or when a token is reported as invalid by the push notification service.

When you delete your account, we will begin deletion of your personal data within 30 days. Residual copies in backup systems are deleted in the ordinary course of our backup retention cycle.

7. Data Security

We implement commercially reasonable technical and organizational measures to protect your personal data, including:

  • Passwords managed by Supabase Auth (bcrypt hashing, PKCE auth flows)
  • API keys stored only as SHA-256 hashes; never recoverable in plaintext after initial display
  • Webhook payloads stored in Cloudflare R2 with access restricted via internal secrets
  • Private Tailscale delivery is available on Team and Enterprise plans, allowing the customer-facing server to remain off the public internet
  • HTTPS is required for saved public forward destinations
  • Row-level security (RLS) policies in our database to ensure organizational data isolation
  • Audit logging of significant account actions

No security system is impenetrable. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

8. Cookies and Tracking

On the marketing site (hookdeploy.dev), we use:

  • Strictly necessary cookies: Required for the site to function. No consent required.
  • Analytics cookies (Google Analytics): Only set after you provide consent via the cookie banner. You can withdraw consent at any time by clicking "Cookie preferences" in the footer. Your preference is stored locally in your browser for 365 days.
  • Referral attribution cookies: A short-lived session cookie or sessionStorage entry may be set when you arrive via a referral link. This is subject to your cookie consent preferences and is discarded after account creation.

The dashboard application (app.hookdeploy.dev) uses session cookies for authentication, which are necessary for the Service to function.

The mobile application does not use cookies. We do not use cookies for advertising or behavioral profiling.

9. Your Rights

Depending on where you are located, you may have the following rights with respect to your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data ("right to be forgotten"), subject to our legal retention obligations.
  • Portability: Request a machine-readable copy of the personal data you have provided to us.
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdrawal of Consent: Withdraw consent where processing is based on consent (e.g., analytics cookies, push notifications).

To exercise any of these rights, contact us at support@hookdeploy.dev. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.

You also have the right to lodge a complaint with your local data protection authority. For EEA users, a list of national supervisory authorities is available at edpb.europa.eu. For UK users, the relevant authority is the Information Commissioner's Office (ico.org.uk).

10. Children's Privacy

The Service is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at support@hookdeploy.dev and we will promptly delete it.

11. International Data Transfers

SnapStack is based in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States and other countries where our service providers operate (including Cloudflare's global network and Supabase's infrastructure).

For transfers of personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) as required under applicable data protection law. You may request a copy of applicable transfer mechanisms by contacting us.

12. Third-Party Links and Integrations

The Service includes integrations with third-party platforms such as Zapier, n8n, Make, and Microsoft Power Automate. When you connect these integrations, your data may be transmitted to and processed by those platforms under their own privacy policies. We are not responsible for the privacy practices of third-party services. We encourage you to review their policies before enabling integrations.

For Team and Enterprise plan customers using private tunnel routing via Tailscale, your Tailscale account credentials and network configuration are subject to Tailscale's privacy policy. SnapStack accesses your Tailscale OAuth credentials solely to establish the encrypted tunnel connection and does not store or use those credentials for any other purpose.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy, posting a notice in the dashboard, and/or sending an email to the address on file for your account. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you must stop using the Service.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

SnapStack Technologies Inc.
support@hookdeploy.dev
hookdeploy.dev

We aim to respond to all privacy inquiries within 30 days.