Privacy Policy — Webhook Box
Last updated: 26/07/2026
Service Operator: Webhook Box (“Operator”), legal entity in formation.
1. Introduction
This Privacy Policy explains how Webhook Box (“Operator”, “we”, “us”) collects, uses, stores, and protects information when you use the Webhook Box platform (“Service”).
The Service is technical in nature and primarily intended for developers and organizations. We seek to apply good-faith compliance with applicable data protection principles, including those found in the GDPR and the Brazilian LGPD, to the extent they apply to the Service and to the data we process.
2. Data Collected
Webhook Box may collect and store the following categories of data:
(a) Authentication data. Email, name, and related metadata used to create and manage your account. This information is stored and managed by Supabase Auth, which protects passwords using secure hashing. The Operator cannot access plaintext passwords.
(b) Operational data. Webhooks, payloads, headers, parameters, logs of requests, timestamps, and other technical data that you voluntarily send to or through the Service.
(c) Technical data. IP addresses, user agents, session identifiers, and diagnostic data used to maintain security, monitor performance, and prevent abuse.
(d) Payment data. Billing-related data is processed exclusively by Stripe. The Operator does not store credit card numbers or other sensitive payment information.
3. Purpose of Processing
The data collected is used for the following purposes:
(a) to operate, maintain, and improve the Service;
(b) to authenticate Users and manage accounts;
(c) to provide technical support and respond to requests;
(d) to monitor performance, detect and prevent fraud, abuse, or security incidents;
(e) to comply with legal, regulatory, or judicial obligations.
The Operator does not use transmitted data for independent marketing, advertising, or selling of information unrelated to the User’s own use of the Service.
4. Legal Basis and Compliance (Overview)
Where data protection laws such as GDPR or LGPD apply, processing may be based on: (a) performance of a contract (providing the Service you requested); (b) legitimate interests (security, fraud prevention, service improvement), balanced with your rights; and (c) compliance with legal obligations.
4-A. Roles: Controller and Processor
With respect to account, billing, and platform usage data, Webhook Box acts as the controller. With respect to the content of captured webhooks (payloads, headers, parameters) — which may contain personal data of third parties — Webhook Box acts as a processor (“operador” under the Brazilian LGPD), processing it solely to operate the Service under the User’s instructions; the User is the controller of that data.
Webhook Box is not responsible for determining the processing that Users carry out through the platform. The User is responsible for having a lawful basis for the data they direct to the Service. Requests from data subjects concerning webhook content will be forwarded to the endpoint owner (the controller).
5. Storage and Infrastructure
Service data is processed by the following infrastructure providers (sub-processors):
(a) MongoDB Atlas as the primary data store, with native encryption at rest and in transit (TLS);
(b) Supabase for authentication and account data;
(c) Render for backend execution;
(d) Vercel for frontend hosting;
(e) Stripe for payment processing;
(f) Cloudflare as reverse proxy, WAF, and abuse mitigation — all webhook traffic passes through its network — and as object storage for export artifacts (R2); and
(g) Redis for processing queues.
The Operator may update or change infrastructure providers, while seeking to use vendors that follow recognized security practices.
6. Access to Data
Access to data is restricted to authorized technical staff of the Operator and is used solely for:
(a) providing support;
(b) investigating incidents;
(c) preventing abuse or misuse;
(d) debugging and maintaining the Service; and
(e) technical analysis to ensure correct operation.
Access follows the principle of least privilege. Data is not accessed for independent commercial exploitation.
7. Data Retention and Deletion
The Service applies the following retention rules:
(a) Captured webhooks — Free plan. Webhooks expire and are deleted 7 days after receipt.
(b) Captured webhooks — paid plans. The Service retains the most recent N webhooks per workspace (Basic 50,000 · Pro 150,000 · Business 350,000 · Enterprise 1,000,000). When the count or the plan’s storage quota is exceeded, the oldest webhooks are automatically deleted (rotation). There is no time-based expiry on paid plans.
(c) Anonymous endpoints (created without an account) and their data are permanently deleted, without notice, within 7 days of creation or upon reaching their technical limits.
(d) Export artifacts are kept in object storage for 7 days.
(e) Technical and error logs are kept for up to 90 days. Application access logs are kept for a minimum of 6 months, as required by art. 15 of the Brazilian Internet Framework (Marco Civil da Internet).
(f) After account termination or deletion, remaining account data is purged within up to 60 days, and backups within up to 30 days, except where longer retention is required by law.
Data deleted by expiry, rotation, or purge cannot be recovered. Users may request deletion of data associated with their account at any time, subject to legal or contractual retention requirements.
8. International Data Transfers
Data may be processed in countries other than the User’s country of residence — primarily the United States and/or the European Union — depending on the infrastructure regions of the providers listed in Section 5.
International transfers are carried out based on the mechanisms of art. 33 of the Brazilian LGPD, in accordance with the International Data Transfer Regulation (ANPD Resolution CD/ANPD No. 19/2024), together with reasonable measures such as encryption, access control, and contractual safeguards.
9. Cookies and Tracking Technologies
The Service may use essential cookies or similar technologies to maintain sessions, store preferences, and enhance security. These cookies are typically required for the basic operation of the Service.
Analytics or performance tools may be used to understand usage patterns and improve the Service. Where required by law, we will provide appropriate notices and, when necessary, obtain consent.
10. User Rights
Depending on applicable law, Users may have the right to request:
(a) access to personal data we process about them;
(b) correction of inaccurate or incomplete data;
(c) deletion of data, where applicable;
(d) portability of data, where technically feasible;
(e) clarification regarding data processing;
(f) information about sharing with third parties (see Sections 5 and 8);
(g) revocation of consent, where processing is based on consent; and
(h) review of decisions made solely through automated processing, where applicable.
To exercise such rights, Users may contact the Operator using the contact information below. Users in Brazil may also petition the ANPD (Autoridade Nacional de Proteção de Dados) regarding their data.
11. Children’s Data
The Service is not directed to children, and we do not knowingly collect personal data from individuals under the minimum age required by applicable law. If we become aware that such data has been collected, we will take reasonable steps to delete it.
12. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. The updated version will replace previous versions upon publication. Continued use of the Service after changes are published will be interpreted as acceptance of the updated Policy.
13. Contact
The Operator’s Data Protection Officer (“encarregado”, art. 41 of the Brazilian LGPD) can be reached at the contact channel below.
For questions about this Privacy Policy or to exercise data-related rights, Users may contact the Operator at: support@webhookbox.net. Data subject requests will be answered within the timeframes established by the ANPD (the Brazilian data protection authority).