Privacy Policy

Last updated: May 2026

1. Information We Collect

We collect information you provide directly to us, such as your email address and account details when you sign up. We also collect usage data including webhook activity, message counts, and technical logs to operate and improve our service.

2. How We Use Your Information

We use the information we collect to provide, maintain, and improve HookMyApp, to process transactions, send service-related communications, and to comply with legal obligations. We do not sell your personal data to third parties.

3. Data Sharing

We may share your information with trusted third-party service providers who assist us in operating our platform (e.g., cloud infrastructure, analytics). These providers are contractually bound to handle your data securely and only for the purposes we specify.

4. WhatsApp And Meta Data

When you connect a WhatsApp number through our platform, message metadata (sender, timestamp, status) is processed to deliver webhook payloads to your endpoint. Message bodies are stored only in your dashboard's Deliveries log under the retention contract described in Section 5 (7-day body scrub, 30-day row deletion). They are not retained elsewhere.

5. Data Retention

We retain your account data for as long as your account is active. Webhook logs are retained for a limited period for debugging purposes. You may request deletion of your data at any time by contacting us.

Webhook Delivery Logs

When HookMyApp forwards a webhook from Meta to your app, we record what happened so you can see it in your dashboard.

Unpaid workspaces see the last 24 hours of webhook deliveries. Paid workspaces see up to 7 days. Each row includes the message body Meta sent, the body your app sent back, and a short list of HTTP headers (content type, user agent, signatures we generated).

After your plan's visibility window, deliveries leave your dashboard view. Bodies and headers are scrubbed from our database after 7 days; the row itself (and a SHA-256 of the original body) is retained up to 30 days for forensics, then deleted. We never log HTTP cookies or authorization headers your app sends back to us.

If you have put auth tokens in your webhook URL itself, those URLs are recorded with the delivery row. We recommend using HTTP headers for auth instead.

6. Security

We take reasonable technical and organizational measures to protect your data against unauthorized access, loss, or misuse. However, no method of transmission over the internet is 100% secure.

7. Your Rights

Depending on your location, you may have rights to access, correct, or delete your personal data. To exercise any of these rights, please contact us at privacy@hookmyapp.com.

8. Changes To This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the date above.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@hookmyapp.com.