1. Who processes the data
Webhook Radar operates Hub Notification. This policy describes which data we use to provide the service, bill and protect the account.
2. Account data
From Google: email, name and photo. We also store organization membership, settings, API tokens (hashed), destinations and delivery logs.
3. Webhook payloads
We store the body, headers and metadata of events that hit your inboxes so you can inspect, diagnose and replay them. Retention is per inbox. Deleting the account removes those events.
4. Billing (PCI)
We do not store card number, CVV or PAN. Charges use a payment-processor token. We may store brand, last 4 and the subscription id the gateway returns.
5. Who we share with
We forward payloads only to destinations you create. Google authenticates sign-in. A payment processor handles billing. We do not sell your data.
6. Cookies and session
We use an httpOnly session cookie to keep you signed in, and a locale in cookie/localStorage. The Hub does not run third-party ads.
7. Your rights (LGPD)
You can access your data in the Hub and delete the account in Settings. That deletion removes events and inboxes of your organization. If you were invited to another org, its owner remains responsible for that data.