Privacy Policy
Last updated: 13 July 2026
In short (this summary isn't the legal text, but it's honest): This policy covers the hosted webhook.co service. We play two roles: for your account details we're the data controller; for the webhooks you send through us — which may contain other people's data — we're a processor acting on your instructions. We don't sell your data and we don't use it for advertising. Your data is currently hosted mainly in the United States, and we protect transfers with Standard Contractual Clauses. Captured webhooks expire automaticallyonce they pass your plan's retention window (7 days on the free plan), you can delete anything yourself at any time, and we'll honour erasure requests within 30 days. We're not SOC 2 / HIPAA certified, so please don't send data that needs those. Questions or requests: privacy@webhook.co.
1. Who we are, and what this policy covers
The hosted webhook.co service (the "Service") is operated by Sourabh Choraria, a sole trader based in Porto, Portugal ("webhook.co", "we", "us"). For data-protection purposes, we are the controller of your account data. Contact: privacy@webhook.co.
This policy explains what personal data we handle through the hosted Service and why. It applies to the webhook.co websites, dashboard, API, CLI, and MCP server that we operate.
Scope — hosted Service only. This policy covers the Service we operate at the webhook.co domains. webhook.co's open-source software (licensed under the Apache License 2.0, at github.com/webhook-co) can be run by others; if you self-host it, we don't operate it and don't process the data in your deployment — you do, and you're responsible for your own privacy compliance.
2. Our two roles: controller and processor
- Account data — we're the controller. Information about you and your organisation (sign-up details, billing, usage, support). This policy governs how we handle it.
- Webhook data you send through us — we're a processor. The webhooks, payloads, and headers you capture may contain personal data belonging to your users or third parties. For that data, you are the controller and we process it only to run the Service for you, on your instructions. Business customers can put this on a formal footing with our Data Processing Agreement. This policy's controller-focused sections (legal bases, your individual rights) are about account data; for the data you capture, your own privacy notice and our DPA govern.
3. What we collect
Account & identity data (you give us): your name, email address, and — if you sign in with Google or GitHub — the basic profile information and avatar those providers share. We support Google, GitHub, and email "magic-link" sign-in; we don't store passwords. We keep the tokens needed to maintain your linked sign-in.
Organisation data: your organisation's name, members, and roles.
Authentication & session data: when you're signed in, we store a session record that includes your IP address and browser user-agent (to keep the session secure). API keys are stored only as a one-way hash — we can't see the original.
The webhooks you capture (processor data): the full request bodies and headers of the webhooks you send through the Service, plus verification and delivery metadata. We store these so you can inspect, search, verify, replay, and deliver them — that's the core feature. We store headers and bodies as received (unredacted), because redacting them would defeat the inspection purpose. These may contain personal data of your end-users; we process it as your processor.
Usage data: counts of the events you process, used for metering, billing, and keeping the Service reliable.
Billing data: if you buy a paid plan, our payment processor Stripe handles your card details — we don't store full card numbers; we keep records of your plan, invoices, and payment status.
CLI telemetry (optional, opt-out): our open-source wbhk command-line tool sends anonymous usage pings by default — the CLI version, your OS/architecture, which command ran, and whether it succeeded. It never includes your data, arguments, tokens, URLs, IDs, or any persistent identifier, and it's collected via Cloudflare Analytics Engine. You can turn it off any time (wbhk telemetry off, WBHK_TELEMETRY=0, or DO_NOT_TRACK=1), and it's automatically off in CI. This applies to anyone using the CLI, whether or not they're a paying customer.
Website analytics (aggregate, cookieless): to see which pages people find useful, this marketing site records a single anonymous measurement per page view — the page path, the referring site's domain, a country-level location, and any campaign (UTM) tags in the link you followed. It's measured on our servers via Cloudflare Analytics Engine and sets no cookie. We don't store your IP address, and there's no identifier that could link one page view to another or follow you across sites — so it can't be tied back to you.
Page performance (in your browser, cookieless): we also load Cloudflare Web Analytics, a small script that measures how fast the page actually loaded for you — timings such as how long it took to render, plus the page path, referring domain, and general device and browser type. It sets no cookie, writes nothing to your browser's storage, and builds no profile or cross-site identifier, which is why it runs without a consent prompt. We use it to find slow pages. You can block it with any content blocker without affecting the site.
Acquisition source (attribution): separately, if you arrive from a marketing link and accept our cookie banner, we set one first-party cookie recording only that link's campaign (UTM) tags — never personal data — so we can see, in aggregate, which channels bring developers to webhook.co. If you decline, we don't set it. See Cookies below.
Support communications: if you email us, we keep the correspondence to help you.
4. Why we use it, and our legal basis (GDPR)
- To provide the Service (create your account, run endpoints, store/inspect/deliver your webhooks, metering) — performance of our contract with you (Art 6(1)(b)).
- To take payment — contract, and legal obligation for tax/accounting records (Art 6(1)(c)).
- To keep the Service secure and prevent abuse (session security, rate-limiting, CAPTCHA, investigating misuse) — our legitimate interests in a safe, reliable service (Art 6(1)(f)).
- To offer one-tap sign-in (Google Identity Services on our sign-in page, which loads before you choose a method) — our legitimate interests (Art 6(1)(f)) in a faster, phishing-resistant way to sign in. You can object, ignore the prompt, or use any other sign-in method; nothing signs you in without a tap.
- To understand and improve the Service (anonymous CLI telemetry, aggregate cookieless website analytics) — legitimate interests; you can opt out of CLI telemetry.
- To see which channels bring developers to us (the first-party attribution cookie,
wh_first_touch) — your consent (Art 6(1)(a)), which you give or decline through the cookie banner and can withdraw at any time. - To respond to support requests — legitimate interests / contract.
- The webhook data you capture — processed on your behalf under our contract and your instructions (you determine the legal basis as its controller).
We don't send marketing emails except transactional/service messages, unless you opt in.
5. Who we share it with (sub-processors)
We don't sell your data or share it for advertising. To run the Service we rely on a small set of trusted infrastructure providers (sub-processors) — including Cloudflare, Neon, Amazon Web Services, Stripe, Resend, Google and GitHub (only if you sign in with them), and Mintlify (our documentation site). Our Sub-processors page lists each one, what it does, the data it may process, and where it's located, and we update it whenever the list changes.
We may also disclose data if required by law, to protect our rights or users' safety, or as part of a business transfer — in which case we'll tell you.
6. Where your data is, and international transfers
Your data is currently hosted primarily in the United States (our database and object storage default to US regions). We do not currently offer EU data residency. Because we're based in the EU and use US-based providers, moving data to them is an international transfer; we rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with those providers, together with technical safeguards (encryption in transit and at rest), and UK/Swiss addenda where relevant. We rely on SCCs as our primary safeguard rather than depending on the EU–US Data Privacy Framework alone.
7. How long we keep it
- Account data: for as long as your account is open, and a reasonable period afterwards for legal, tax, and security purposes.
- The webhooks you capture: these expire automatically. Captured events and their stored payload bodies are deleted once they pass your plan's retention window — on the free plan, 7 days. The window for each paid plan is listed at webhook.co/pricing. Expiry runs on a schedule; deletion happens shortly after an event passes the window rather than at the exact second it does. You can also delete an individual event yourself at any time: its content becomes immediately inaccessible (headers and identifiers are redacted the moment you delete it) and its stored payload body is purged shortly after. We keep a minimal record that the event was received — with no personal data — so your usage count can't be rewritten by deleting events (deleting does not reduce what you were billed).
- If your window gets shorter: if you move to a plan with a shorter retention window — by downgrading, or by cancelling and returning to the free tier — the shorter window applies from then on, and captured data already older than it becomes eligible for deletion. Export anything you want to keep before you downgrade or cancel.
- Deletion & erasure: you can delete endpoints, events, and your whole organisation from your account — this redacts the personal data and purges the stored payload bodies, not just a listing (for a deleted event we keep only a personal-data-free record that it was received, so your billed usage stays honest). You can also ask us to erase your personal data (see §8); we complete verified erasure requests within 30 days. Residual copies in encrypted backups are removed on our normal backup-rotation cycle.
8. Your rights
Subject to applicable law, you can ask to access your personal data, correct it, delete/erase it, restrict or object to certain processing, receive a portable copy, and withdraw consent where we rely on it. To exercise any of these, email privacy@webhook.co; we'll respond within the time the law requires (generally one month). You also have the right to complain to a supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD) — or your local EU/EEA authority.
If your request concerns the webhook data you captured (where you're the controller and we're the processor), we'll help you fulfil it, but you may need to direct the underlying request through the customer whose account holds the data.
9. How we protect your data
- In transit: all connections use TLS.
- Secrets: the signing secrets, provider secrets, and ingest tokens you entrust to us are encrypted at rest using AES-256-GCM envelope encryption, with the master keys held in AWS KMS (we never hold them in plaintext).
- At rest: data stored in our database and object storage benefits from those providers' at-rest encryption.
- Isolation: tenant data is separated using database row-level security so one organisation can't read another's data.
- Authentication: OAuth and magic-link sign-in, hashed API keys, and audience-bound tokens.
Being honest about limits: the Service is not end-to-end-encrypted or "zero-knowledge" — we necessarily process your webhook contents to inspect, verify, replay, and deliver them. And we do not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications; please don't use the Service for data that legally requires them (see the Terms).
10. Cookies
We keep cookies to a minimum. The strictly-necessary ones are:
- a session cookie that keeps you signed in,
- short-lived security cookies used during Google/GitHub sign-in (to prevent cross-site request forgery), and
- a small cookie that remembers your cookie choice, so we don't ask again.
Separately, when you arrive from a marketing link we ask — through a cookie banner — whether we may set one first-party attribution cookie (wh_first_touch). It records only that link's marketing source — its UTM campaign tags, never personal data — so we can understand, in aggregate, which channels bring developers to webhook.co. We set it only if you accept; if you decline, we don't set it — and either way we remember your choice so we don't ask again. When set, it's tied to your organisation at signup (not to a browsing profile), expires after 90 days, and is written once — a later visit never overwrites it. To withdraw consent, clear the cookie in your browser.
The strictly-necessary cookies aren't used for tracking or advertising. Our login page loads two third-party scripts: Cloudflare Turnstile (bot protection), which may set its own security cookies, and Google Identity Services, which powers the one-tap sign-in prompt. Google's script loads on every visit to the login page — before you choose a sign-in method — so Google can see your IP address and that you opened that page. You are never signed in without tapping to confirm. Google's script also sets one first-party cookie on our sign-in domain, g_state, which remembers that the prompt was shown so it isn't shown again; it lasts up to 180 days, and you can delete it like any other cookie. Your dark-mode preference is stored in your browser's local storage, not a cookie. We don't use advertising cookies.
11. Children
The Service isn't directed to children, and we don't knowingly collect data from anyone under 16 (or the age of digital consent where you live). If you believe a child has given us data, contact us and we'll remove it.
12. Data breaches
If a breach affects your personal data, we'll act without undue delay and, where the law requires, notify the relevant supervisory authority within 72 hours, and notify you where there's a high risk to you.
13. California residents (CCPA/CPRA)
If you're a California resident: we do not sell or share your personal information, and we don't use it for cross-context behavioural advertising. When we handle the data you capture, we act as your service provider and use it only to provide the Service. You have rights to know, delete, and correct your personal information; email privacy@webhook.co to exercise them, and we won't discriminate against you for doing so.
14. Changes to this policy
We may update this policy. For material changes we'll post them here with reasonable notice before they take effect and update the "Last updated" date above — so check back periodically.
15. Contact
Sourabh Choraria (webhook.co), Porto, Portugal — privacy@webhook.co. For EU/EEA privacy complaints you may also contact the CNPD (the Portuguese data-protection authority) or your local supervisory authority.