CommerceHook

Privacy policy

Last updated 17 September 2026

Who we are

CommerceHook is a webhook inspection service operated from the United Kingdom. For anything in this policy, contact help@commercehook.app.

What we store

Your email address (it is how you sign in), the endpoints you create, and the webhook events your endpoints receive: the payload exactly as sent, the delivery headers, the event type, and the time received. Two kinds of header are not kept as sent: one carrying a credential (Authorization, Cookie) is stored with its value replaced by [redacted], and the headers Cloudflare adds in transit, which include the sending server's IP address, are not stored at all. If you upgrade to Pro, our billing provider holds your payment details; we never see your card number.

One more field, added for honesty rather than found out later: if you arrived from a particular page of this site we record which one, as a single word on your account, the first time you sign up. It is one of a short fixed list, it is never anything you typed, and it is not linked to anything you do afterwards. We use it to answer one question, which is how people find us. It is deleted with your account, and if you would rather it said nothing at all, email us.

If you choose to save store credentials (a BigCommerce token, a WooCommerce key pair, a Square access token, a Shopify custom app token and secret, or a Stripe API key) or set a webhook signing secret when registering through us, those are stored encrypted (AES-256-GCM) and used only for what you saved them for: registering webhooks, and verifying delivery signatures so the inspector can tell you when a body does not match. Deleting a saved store removes its credentials immediately; signing secrets are deleted with their endpoint.

How long we keep it

Webhook events are deleted permanently shortly after they pass your plan's retention window: 24 hours on Free, 90 days on Pro. There are no backups of expired events. Your account itself exists until you delete it.

Apps you connect

If you connect an app such as a Claude connector, we store the permission you granted it and a hash of its access tokens in Cloudflare KV, alongside the name the app registered. A connected app gets the same access an API key does, which is everything your account can reach: your endpoints, your captured payloads, and the ability to replay them. There are no partial permissions to offer, so we do not pretend otherwise. Every connection is listed under Connected apps in settings and revoking one cuts it off on its next request. Nothing about your account is sent to the app's own servers by us; what it does with what it reads is between you and them.

When you contact us

A help request or a piece of feedback is stored (the message, your email address, and for a signed-in request your plan and endpoint count) and emailed to us. We keep it while the conversation is useful and delete it after. It is never used to market anything to you, and an address given on the public form is used to reply and nothing else.

The public form also passes through Cloudflare Turnstile, and your IP address is used briefly to rate limit submissions. That address is a short-lived counter in our key-value store, expiring within fifteen minutes; it is not written to the database and never lands in the message we read.

Where it lives

All service data is stored on Cloudflare infrastructure (D1 and KV). Email delivery uses Resend from an EU region.

Sub-processors

The complete list is short:

Lawful basis

Under UK GDPR we process your email and account data to perform our contract with you (providing the service you signed up for), and webhook payload data on your instruction: you point webhooks at us, we store them for you.

Your rights, including deletion

You can delete your account yourself at any time from the danger zone on the settings page; it removes your endpoints and every stored event immediately. For anything else UK GDPR gives you (access, correction, complaint to the ICO), email us.

Analytics and tracking

This site counts page views. It sets no cookies and does not fingerprint your browser, there is no advertising, and nothing here follows you to another site. What we see is a total and roughly which country a reader was in, with no way to pick one person out of it.

None of it runs in the product. Once you sign in you are not measured at all: the dashboard loads no analytics of any kind and sets one cookie, the session that keeps you signed in.

If your browser sends Do Not Track or Global Privacy Control, the counter is never loaded. Not throttled or anonymised, simply not run. Neither signal is something we are obliged to honour and most sites ignore both, so it seemed worth saying that this one does not.

One honest exception, because "no third-party scripts" would otherwise stop being true: the contact page loads Cloudflare Turnstile, which is what tells a person from a bot without asking you to identify traffic lights. It runs on that page only, it is not on any other page or in the dashboard, and it is a challenge rather than an analytics product: Cloudflare states it does not use the data it collects to track people across sites. If you would rather not load it at all, email help@commercehook.app and it reaches the same inbox.