1. Information we collect
We collect information necessary to provide and secure the service, including registration details, email address, organization membership, authentication settings, billing metadata, support communications, and operational usage records generated through normal product activity.
2. Why we process data
We process data to provide the service, authenticate users, secure accounts, operate billing, troubleshoot incidents, respond to support requests, enforce product limits, and improve reliability and operational integrity. We process webhook-related content only to the extent required to deliver the configured service functionality.
3. Access and sharing
Access to customer data is limited to authorized personnel and systems with a legitimate operational need, such as support, security, infrastructure, or billing administration. We do not sell customer data. We may share limited information with service providers, infrastructure vendors, or payment processors only to the extent necessary to operate and support Hookioz.
4. Retention
Account records and operational logs are retained according to product settings, billing requirements, security needs, legal obligations, and legitimate operational interests. Event payload retention and redaction behavior depend on the active plan and the retention controls available in the product.
5. Security controls
Hookioz uses access controls, organization isolation, credential protection, optional two-factor authentication, and monitoring workflows designed to reduce the risk of unauthorized access or misuse. No internet-connected service can guarantee absolute security, and customers remain responsible for securing their own accounts, endpoints, and downstream systems.
6. Your responsibilities
You are responsible for ensuring that data submitted to Hookioz may be lawfully processed, that retention settings are appropriate for your use case, and that organization members, credentials, and secrets are managed responsibly. You should avoid submitting sensitive data unless you have a clear lawful basis and operational need to do so.
7. Contact
Questions about this Privacy Policy may be sent to [email protected]. Security-sensitive reports should include enough detail for safe investigation while avoiding unnecessary disclosure of secrets, credentials, or unrelated personal data.