Legal
Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data in connection with ChirpHook.
1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is [COMPANY LEGAL NAME], [COMPANY ADDRESS]. You can contact the controller at [email protected].
2. General information and scope of processing
This policy applies to the ChirpHook website, web application, mobile applications, and notification service. We process personal data only where this is necessary to provide these services, to meet a legal obligation, or where another legal basis under the GDPR applies.
Our website and applications use SSL/TLS encryption to protect data transmitted between your device and our services.
3. Hosting and infrastructure
We use the following infrastructure providers to operate our services: Hetzner Online GmbH, Germany, and Cloudflare, Inc.. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient operation of our services).
4. Server log files
When you access our services, we process server log data, including your IP address, the date and time of access, your user agent, and the requested resource. We process this data to operate the service, maintain information security, detect and prevent abuse, and investigate technical faults. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
5. Account registration and sign-in
When you register or sign in, we process your email address, name, and password hash if you use email and password sign-in. If you use Sign in with Apple or Google sign-in, we process the identity data that Apple or Google transmits to us. We process this data to create, administer, and secure your account. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
6. Use of the service and push notifications
When you use the service, we process hooks, chirps and their notification content, device push tokens, project and organization membership data, and invitation data. We process this data to provide, deliver, and maintain the notification service. Notifications for iOS devices are delivered through Apple Push Notification service; notifications for Android devices are delivered through Google Firebase Cloud Messaging. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). You are responsible for the content that you send through your hooks and for ensuring that its processing is lawful.
7. Transactional email
We use Amazon Web Services, including Amazon Simple Email Service (SES), to send transactional emails such as account and invitation messages. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and, where applicable, Art. 6(1)(f) GDPR (legitimate interest in reliable service communications).
8. Payments
For paid subscriptions, we use Stripe to process payments and maintain subscription status. Stripe processes payment data directly; we do not store card numbers. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
9. International data transfers
Where a provider processes personal data outside the European Union or European Economic Area, we ensure that an adequate level of protection is maintained. Stripe, AWS, Apple, Google, and Cloudflare participate in the EU-U.S. Data Privacy Framework. Where necessary, we also use the European Commission's Standard Contractual Clauses or another valid transfer mechanism.
10. Storage duration
We retain personal data only for as long as necessary for the purposes described in this policy or as required by statutory retention obligations. Personal data is deleted when the account is deleted, unless continued storage is necessary to meet a legal obligation or to establish, exercise, or defend legal claims.
11. Cookies
The ChirpHook landing site sets no cookies. The web application uses authentication session cookies only; these cookies are strictly necessary to provide secure sign-in and session management. We use no analytics or advertising services and do not sell personal data.
12. Children and minors
ChirpHook is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided us with personal data, please contact us at [email protected].
13. Your rights
Subject to the conditions set out in the GDPR, you have the following rights:
- the right of access to your personal data under Art. 15 GDPR;
- the right to rectification of inaccurate personal data under Art. 16 GDPR;
- the right to erasure of personal data under Art. 17 GDPR;
- the right to restriction of processing under Art. 18 GDPR;
- the right to receive data that you have provided in a structured, commonly used, and machine-readable format under Art. 20 GDPR;
- the right to object to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR under Art. 21 GDPR; and
- the right to withdraw consent at any time with effect for the future under Art. 7(3) GDPR.
To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
14. Changes to this Privacy Policy
We may amend this Privacy Policy where this is necessary to reflect changes in our processing activities or applicable law. The current version is published on this page.