Privacy policy
Effective 4 October 2026.
This page lists the data Hookspot stores, who else receives it and how long Hookspot keeps it. Bohdan Yuriiovych Hryshchenko, an individual entrepreneur registered in Ukraine, at 36 Laherna Street, apartment 31, Kyiv 03113, Ukraine, runs Hookspot and is the controller of the data about you and your organizations. For the webhooks your organization receives and your local app’s answers, Hookspot is a processor working for your organization instead. Write to [email protected] about any of this data.
What Hookspot stores
About you and your organizations, Hookspot stores:
- your name, your email address and a hash of your password, if you set one
- your CLI key
- the name of the computer you run
hookspot loginon, until that login finishes, or the next night if it never does - the time and IP address of your two most recent sign-ins, how many times you signed in, your failed sign-ins and whether your account is locked
- how you heard about Hookspot, if you answer that question
- whether you chose to try Pro when you signed up, until you name your first organization
- whether you asked for product news, and when
- the ID, name, email address and profile picture link of your GitHub or Google account, if you sign in with one
- your organizations’ names, their members and roles, and the email addresses you invite to them
- when your CLI last connected to each project
- each organization’s Paddle customer and subscription IDs, billing period and subscription status
For each webhook your sources receive, Hookspot stores:
- its method, URL, headers, query string and body, as the sender (the service that sent the webhook) sent them
- each attempt to forward it to your local app, what your app answered (the status, headers and body), and the member who retried it, if one did
Hookspot stores no card details. You enter them in Paddle’s checkout.
How Hookspot uses it
Hookspot uses this data to run your account and organizations, to store and forward your webhooks, to send the emails the service needs and to bill Pro. Its contract with you needs this. It keeps sign-in times and IP addresses, error reports and logs to protect your account and keep Hookspot running, and asks how you heard about Hookspot to learn where its users come from. Both are its legitimate interest. Hookspot shows no ads and sells no data.
Hookspot emails you product news only with your consent, which you give at signup or in your settings and can take back there at any time. Every other email is one the service needs, such as an address confirmation or an invitation.
Your webhooks may carry personal data about your own customers. Hookspot handles that data for your organization under the Data processing agreement: it stores, shows and forwards it only to run the service, and deletes it when the retention period ends.
Who else receives it
- netcup hosts the app and all its data in Germany.
- Paddle, the merchant of record, bills Pro. Its checkout loads from
cdn.paddle.comwhen you open it, and Hookspot passes it your email address and organization ID. Paddle controls the payment data it collects: ask it at[email protected]or at preferences.paddle.com. It keeps each transaction’s records for 5 years. - Postmark sends Hookspot’s emails, such as address confirmations and invitations. It receives each email’s address and content, and keeps them for 45 days.
- Sentry receives a report of each error in the app, and keeps it for 30 days. Hookspot sends it no webhook bodies.
- Cloudflare carries all traffic to the app and to webhook URLs, so it sees each webhook on its way in. It also runs Hookspot’s domain names, hosts this website, stores the encrypted nightly backups in the European Union for 7 days and forwards the emails you send to Hookspot’s support address.
- GitHub and Google learn that you use Hookspot, if you sign in with one of them, and handle that sign-in under their own privacy policies.
Hookspot is run from Ukraine, outside the European Union. Postmark, Sentry and Cloudflare take data to the United States under the EU-US Data Privacy Framework, and Paddle under the European Commission’s standard contractual clauses.
How long Hookspot keeps it
Hookspot keeps each webhook, with its deliveries and attempts, for the organization’s retention period. The retention period is 14 days on the Free plan and 60 days on Pro. Every night, Hookspot deletes the webhooks older than that.
When Pro ends, the retention period stays 60 days for 7 more days, then drops to 14 days.
Hookspot’s logs record each request to the app and to webhook URLs, with its URL, its IP address and the name of the browser or client that sent it, but never a webhook’s headers or body. Hookspot deletes them after 30 days.
Hookspot keeps your account data until you delete your account. Deleting it also deletes the organizations you own that have no other members, with their projects and stored webhooks. When an owner deletes an organization or a project, Hookspot deletes its stored webhooks too. Deleted data stays in the encrypted backups for up to 7 days.
Cookies and analytics
The app sets only the cookies it needs: one keeps you signed in, one remembers you for 14 days if you choose Remember me, and one protects its forms. Paddle’s checkout sets its own cookies when you open it. The app runs no analytics.
Cloudflare hosts this website, so it receives your IP address with each page you open. It counts visits with Cloudflare Web Analytics, which uses no cookies. The docs keep your light or dark theme choice in your browser, and the state of the sidebar until you close the tab.
Your rights
You can change your name, email address and password, and stop product news, in the app’s settings. You can delete your account there too, at once and for good.
To get a copy of your data as a JSON file, or to have Hookspot correct it, write to [email protected] from your account’s email address. You can also object to what Hookspot does for its legitimate interest, or ask it to limit what it does with your data. Hookspot answers within 30 days.
The webhooks your organization receives are its data. To have Hookspot delete particular webhooks, for example because someone asked your organization to erase their data, an owner writes to [email protected]. Hookspot deletes them within 30 days.
You can also complain to the data protection authority where you live.