CaptHook · capthook.ch

Privacy policy

1. Controller

The controller for processing related to CaptHook at capthook.ch is Andreas Haslbeck, St. Gallerstrasse 22, 9400 Rorschach, Schweiz. Email: capthook@haslbeck.ch.

2. Scope

This policy applies to CaptHook under Swiss data protection law and, where applicable, the EU GDPR.

3. Accounts and sign-in

Depending on the selected provider, we process a GitHub ID and username or a Google account identifier, plus a user-chosen username. Google access is limited to openid. CaptHook does not request or store an email address from either provider.

4. Webhook processing

CaptHook processes pipes, filter rules, signing secrets, destination webhook URLs, raw incoming event payloads and delivery records. Matching events are forwarded to destinations configured by the user, including Slack, Discord or Microsoft Teams/Power Automate.

5. Payments

For paid Pro subscriptions we process the Stripe customer and subscription IDs, plan, status and billing period. Payment instrument details are handled only by Stripe and are not stored by CaptHook.

6. Operational email

Technical event and error details may be sent to a configured address for operational notifications. CaptHook sends no newsletters or advertising.

7. Hosting and server logs

CaptHook runs on self-managed infrastructure in the European Union. IP address, timestamp, requested resource and technical log data may be processed for security, troubleshooting and abuse prevention, normally for 30 days.

8. Cookies

Only the encrypted, essential session cookie capthook_session and the language preference cookie capthook_locale are used. There are no analytics, tracking or advertising cookies.

9. Contact and support

Contact details and message content are processed to answer requests and provide support. The operator may access account and pipe data through an internal administration area where necessary for support or abuse prevention.

10. Recipients and international transfers

The self-managed infrastructure is located in the European Union and therefore outside Switzerland. GitHub or Google may be used for sign-in and Stripe for paid subscriptions. User-selected Slack, Discord or Microsoft destinations may receive events. Applicable safeguards are used where required. Personal data is not sold.

11. Retention and deletion

Server logs are generally kept for no more than 30 days. Accounts, pipes, events, destinations and delivery records are kept until the account or pipe is deleted. Events currently have no automatic deletion period. Statutory billing records remain for the legally required period.

12. Security

Connections use HTTPS/TLS. CaptHook stores no passwords; sign-in uses OAuth and pipe secrets verify incoming webhooks. Appropriate technical and organisational safeguards are applied.

13. Your rights

Subject to applicable law, individuals may request access, correction, deletion, restriction, portability or object to processing. Requests may be sent to capthook@haslbeck.ch. Complaints may be submitted to the Swiss FDPIC or the competent EU authority.

14. Changes

This policy is updated when functions or processing activities change. The version published at this URL applies.