Legal

Privacy Policy

Last updated: July 7, 2026

1. Overview

SuaveHooks (“we”, “us”) operates the SuaveHooks platform at https://suavehooks.com. This Privacy Policy explains how we collect, use, and share information when you use our hosted service, website, and related tools.

2. Information we collect

Account information

When you register, we collect email address, password (stored as a hash), and optional profile identifiers from OAuth providers (e.g. GitHub or OIDC subject IDs) if you use social sign-in.

Webhook capture data

When you use capture endpoints, we store HTTP method, headers, query string, request body, source IP address, timestamps, and derived metadata (e.g. event types, idempotency keys). This is the core data you configure the Service to receive.

Usage and technical data

We collect logs and metrics related to service operation (e.g. forward delivery results, API usage, audit events, session activity) and standard web data such as browser type and IP address when you use the dashboard.

Payment information

Paid plans are processed by Stripe. We receive subscription status and customer identifiers from Stripe; we do not store full payment card numbers on our servers.

3. How we use information

  • Provide, secure, and improve the Service
  • Display captured requests, forward them to URLs you configure, and run transforms you define
  • Enforce plan limits, retention policies, and acceptable use
  • Process billing and send service-related communications
  • Detect abuse, fraud, and security incidents
  • Comply with legal obligations

4. Sharing

We do not sell your personal information. We may share data with:

  • Infrastructure providers — hosting, database, and observability vendors that process data on our behalf
  • Payment processor — Stripe, for subscriptions
  • Integrations you enable — e.g. forward targets, Slack webhooks, archive URLs, embed portals
  • OAuth providers — when you choose to sign in with GitHub or OIDC
  • Legal requirements — when required by law or to protect rights and safety

When you configure forwarding, replay, or export, webhook data is transmitted to destinations you control or designate.

5. Retention

Captured requests are retained according to your plan and our configured retention settings, after which they may be deleted automatically. Account data is kept while your account is active and for a reasonable period afterward unless deletion is requested or required by law.

6. Security

We use industry-standard measures including encryption in transit (HTTPS), access controls, and hashed passwords. No method of transmission or storage is 100% secure. You are responsible for safeguarding API keys and endpoint secrets.

7. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. To make a request, contact legal@suavehooks.com. You may delete captured data through the dashboard (subject to retention rules) and revoke API keys at any time.

8. International transfers

We may process data in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children.

10. Changes

We may update this policy. We will post changes on this page and update the “Last updated” date. Material changes may be communicated by email or in-product notice.

11. Contact

Privacy questions or requests: legal@suavehooks.com

See also our Terms of Service.

This document is provided for informational purposes and does not constitute legal advice. Consider consulting qualified counsel for your jurisdiction.