Privacy Policy
Last updated: September 3, 2026
Overview
Hookly, Inc. (“Hookly,” “we,” “us”) provides a webhook ingestion, verification, relay, and replay platform for development teams (the “Service”). This policy explains what information we collect when you create an account, configure endpoints, and use the Service, how we use and protect it, and the choices available to you.
This policy applies to Hookly account holders and the members of their teams (“you,” the “Customer”). If your organization routes data belonging to your own end users or customers through Hookly (for example, webhook events from Stripe, GitHub, or another integration you've connected), your organization remains the data controller for that data, and this policy describes Hookly's role as a data processor for it.
Information we collect
We collect the following categories of information:
- Account information — name, email address, and password (or OAuth identity) when you sign up, plus any profile details you add.
- Team and billing information — team membership, roles, and subscription plan. Payment card details are collected and processed directly by Stripe; we store only your Stripe customer ID, subscription status, and plan tier, never full card numbers.
- Endpoint configuration — the destination URLs, integration type (Stripe, GitHub, Twilio, SendGrid, Shopify, Slack, HubSpot, or a custom source), and signing secrets/credentials you provide to verify inbound webhooks. Secrets are encrypted at rest (see Security).
- API keys — we store only a salted hash of each API key you generate, never the plaintext value after initial creation.
- Notification integrations — if you connect Slack or PagerDuty for alerting, the webhook URL or integration key is encrypted at rest and used solely to deliver the alerts you configure.
- Usage and log data — source IP address, HTTP method, headers, timestamps, and relay attempt results (response status, duration, and response body) for requests sent to your endpoints, used to power activity dashboards, delivery status, and troubleshooting.
- Support communications — the content of support tickets and messages you send us.
Webhook payload data
The core function of Hookly is receiving webhook requests at an endpoint URL you configure, verifying their authenticity, and relaying them to your destination server. To do this, and to power event history and replay, we necessarily store the raw request body and headers of every webhook delivered to your endpoints for the retention period associated with your plan.
This payload data originates from the third-party services you connect (for example, a Stripe checkout event or a GitHub push payload) and may contain personal data about your own customers or users. We do not inspect, use, or share this content beyond what is necessary to operate the Service — verifying signatures, relaying the request, displaying it in your dashboard, and enabling replay. You control what is sent through Hookly and are responsible for ensuring you have the right to route that data through a third-party processor like us.
How we use information
- To provide, operate, and maintain the Service, including ingesting, verifying, relaying, and replaying webhook events.
- To authenticate you, manage your account and team, and enforce plan limits (endpoints, monthly event volume, event history window).
- To process payments and manage subscriptions via Stripe.
- To send transactional communications — delivery failure/recovery alerts, quota warnings, daily digests, and support replies.
- To monitor, secure, and improve the Service, including rate limiting and abuse prevention.
- To respond to support requests.
- To comply with legal obligations.
We do not sell your personal information or webhook payload data, and we do not use it to train third-party AI models.
Data retention
Webhook event history (ingestion records, headers, bodies, and relay attempts) is retained according to your plan: 7 days on Starter, 90 days on Pro, and 365 days on Enterprise. Older events are automatically purged. Account, team, and billing records are retained for as long as your account is active. When you or a team admin delete a team via account settings, associated endpoints, credentials, and event history are permanently deleted.
Security
- All data in transit is encrypted via HTTPS/TLS.
- Endpoint signing secrets, Slack webhook URLs, and PagerDuty integration keys are encrypted at rest using AES-256-GCM.
- API keys are never stored in plaintext — only a SHA-256 hash is retained after creation.
- Inbound webhook signatures are verified using constant-time comparison to prevent timing attacks.
- Endpoints are rate-limited to mitigate abuse.
No method of transmission or storage is 100% secure; we work to protect your information but cannot guarantee absolute security.
Your rights & choices
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update account and profile details directly in Settings, export or delete a team from Settings → Danger Zone, and manage notification preferences from Settings → Notifications. For any other request, contact us using the details below.
Children's privacy
Hookly is a developer tool intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16.
International transfers
Your information may be processed and stored in countries other than your own, including the United States, via the infrastructure providers listed above. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify active account holders by email or an in-app notice before the change takes effect. The “Last updated” date above reflects the most recent revision.
Contact us
Questions about this policy or your data can be sent to privacy@hookly.dev.