1. Roles and scope
HookMessage is the controller of account registration, billing, website, support, security, and product-analytics data used to operate its business. For recipient phone numbers, customer message content, templates, and customer-directed messaging records, HookMessage generally acts as a processor on the customer's instructions.
Customers remain controllers of recipient data and must provide their own privacy notices and lawful basis. This Policy does not replace a customer's obligations to its end users.
2. Data collected
- Account identity: name, work email, workspace, role, password hash, verification state, and preferences.
- Messaging data: sender and recipient numbers, message identifiers, delivery status, templates, OTP metadata, webhook events, and message content when storage is enabled.
- Attachments: supported images and documents, file metadata, storage identifiers, and expiry state. Outbound video and audio are not supported.
- Technical and security data: IP address, user agent, session/device details, API-key usage, rate-limit events, authentication events, and audit logs.
- Commercial data: selected plan, usage credits, Stripe customer/subscription identifiers, invoice state, and limited payment-method metadata. HookMessage does not store full card numbers.
- Support and website data: contact briefs, product-update requests, correspondence, analytics, and performance measurements.
3. Why data is used
- Create and secure accounts, sessions, workspaces, and API credentials.
- Route messages, OTP requests, attachments, webhooks, and delivery updates.
- Measure plan usage, prevent duplicate billing, issue invoices, and administer subscriptions.
- Detect abuse, fraud, unauthorized access, deliverability problems, and service failures.
- Respond to support, integration, privacy, and legal requests.
- Improve product reliability using limited analytics and performance data.
- Meet accounting, tax, regulatory, dispute, and law-enforcement obligations.
4. Legal grounds
Processing is based on performance of the service contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where specifically requested, such as optional marketing communications.
Consent may be withdrawn without affecting processing already performed. Contract and security data may still be required to maintain an account.
5. Providers and transfers
HookMessage uses infrastructure and service providers including Vercel, Railway, Cloudflare/R2, Stripe, Resend, database hosting, and Redis hosting. These providers process only the data needed for their role and are subject to contractual and security requirements.
Some processing occurs outside Morocco. HookMessage must complete applicable CNDP notification and foreign-transfer formalities and uses appropriate contractual safeguards where required.
6. Retention
Account and workspace records are kept while the account is active and afterward only as needed for closure, disputes, fraud prevention, accounting, or legal obligations. Authentication sessions expire automatically and can be revoked.
Message text is not persisted when storage is disabled. Delivery metadata and immutable billing entries may remain after content deletion. Attachments expire according to plan-specific retention. Contact submissions and marketing choices are retained only while operationally or legally necessary.
7. Security
HookMessage uses tenant-scoped authorization, encrypted transport, hashed passwords and tokens, restricted API credentials, audit logging, rate limiting, private attachment storage, session controls, and production secret validation. No system can guarantee absolute security.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or opposition. Moroccan Law 09-08 provides rights including access, rectification, and opposition. Requests should be sent to [email protected] with enough information to verify identity.
You may complain to Morocco's CNDP at cndp.ma. If another privacy law applies, you may also contact the competent local authority.
9. Children, changes, and contact
HookMessage is a business service and is not intended for children. Accounts may not be created by anyone under 18.
Material changes will be dated and communicated appropriately. Privacy questions and rights requests may be sent to [email protected].