Privacy policy
Last updated 24 July 2026
Who we are
CommerceHook is a webhook inspection service operated from the United Kingdom. For anything in this policy, contacthello@andrewbarber.me.
What we store
Your email address (it is how you sign in), the endpoints you create, and the webhook events your endpoints receive: the payload exactly as sent, the delivery headers, the event type, and the time received. If you upgrade to Pro, our billing provider holds your payment details; we never see your card number.
How long we keep it
Webhook events are deleted permanently by a daily cleanup job once they pass your plan's retention window: 24 hours on Free, 90 days on Pro. There are no backups of expired events. Your account itself exists until you delete it.
Where it lives
All service data is stored on Cloudflare infrastructure (D1 and KV). Email delivery uses Resend from an EU region.
Sub-processors
The complete list is short:
- Cloudflare: hosting, storage, and delivery of everything.
- Resend: sending sign-in link emails.
- Polar: payments and subscription billing, as merchant of record.
Lawful basis
Under UK GDPR we process your email and account data to perform our contract with you (providing the service you signed up for), and webhook payload data on your instruction: you point webhooks at us, we store them for you.
Your rights, including deletion
You can delete your account yourself at any time from the danger zone on the settings page; it removes your endpoints and every stored event immediately. For anything else UK GDPR gives you (access, correction, complaint to the ICO), email us.
Tracking
There is none. No analytics, no tracking pixels, no third-party scripts of any kind on this site or in the dashboard. The only cookie the product sets is the session cookie that keeps you signed in.