Webhook Handoff
Log in

Effective 26 August 2026

Privacy Policy

1. Who operates Webhook Handoff

Webhook Handoff is operated by FIRM SOFTWARE SOLUTIONS, ABN 58 769 207 406, New South Wales 2576, Australia. FIRM SOFTWARE SOLUTIONS is currently exempt from the Privacy Act 1988 (Cth). However, we aim to handle personal information transparently and responsibly, and our privacy practices are guided by the principles reflected in Australian privacy law.

2. Information we collect

Beta access requests

When you request private-beta access, we collect your name, email address, optional company or project, use-case description, and submission timestamps. Email addresses are normalised to support duplicate-safe review.

Accounts and organisations

For provisioned accounts, we process your name, email address, a password hash (not your password), organisation and membership information, and information needed for authentication, password recovery, and account security. Sessions and related security activity may include IP address, user-agent, and request activity as handled by the application and its infrastructure.

Webhook Events and delivery history

For an accepted Event, we store the complete raw webhook body, provider Event ID and type, Source and organisation associations, receipt timestamps, verification evidence, delivery intent and status, delivery attempts and results, and retry or replay provenance. Webhook payloads are controlled by you or an upstream provider and may inherently contain personal, confidential, or financial information.

Configuration

We process Source names, provider settings, protected Source credentials and signing secrets, Destination names and URLs, encrypted Destination custom-header values, Pipelines, and enabled or operational state. These records support tenant security and delivery; ordinary customer-facing views do not reveal protected secret values.

Analytics (only with permission)

If a Google Analytics 4 Measurement ID is configured, we ask for your separate permission before loading Google Analytics. If you allow it, Google Analytics may set analytics cookies such as _ga and _ga_*, and may receive public page URLs, referrers, browser or device information, and technical request information such as an IP address. We use this only to understand public traffic, Learn content usage, and beta-request funnel activity. We do not send webhook payloads, Event contents, Source, Destination, Pipeline, account, or other customer operational data to Google Analytics.

3. Why we use information

We use information to review beta requests, administer accounts and organisations, authenticate users, verify and durably capture webhooks, deliver and retry Events, support controlled replay, protect tenants and the service, diagnose operational or security issues, send account and service communications, support password operations, and meet legal or regulatory obligations where applicable.

4. Customer-directed processing

Customers determine which upstream providers send data and which Destinations receive it. We process much webhook content on customer instructions to provide capture, delivery, history, retry, and replay. Customers are responsible for having authority to process and route that content.

5. Sensitive data

Unless expressly agreed otherwise, do not intentionally use Webhook Handoff to transmit highly sensitive or specially regulated information such as health information, government identifiers, authentication passwords, payment-card numbers, CVV or security codes, or similarly sensitive regulated data. Ordinary personal information may naturally occur in a legitimate webhook payload.

6. Security

Controls include tenant-scoped access, password hashing, protected credentials, encrypted provider signing secrets and Destination header values, signed webhook verification, TLS and outbound network controls, durable queue and retry processing, backups, and tested recovery procedures. These are safeguards rather than an absolute guarantee of security.

7. Retention

During private beta, Event data and associated delivery history are generally retained for approximately 30 days. Expiry respects unresolved delivery responsibility. Account, configuration, beta-request, security, and log data can follow different retention practices. Backups age out through normal rotation. Future commercial plans may have different Event retention periods.

8. Disclosure and data flows

To operate the service, information may be handled by hosting and infrastructure providers, email infrastructure, Google Analytics when enabled with your permission, and professional advisers or authorities where reasonably necessary or legally required. Customer-selected Destinations receive payloads on customer instruction. Stripe is supported as an upstream webhook provider; it is not used here as an advertising provider.

9. Australia and overseas transfers

Primary Webhook Handoff service infrastructure is currently operated in Australia. Customer-selected Destinations may be overseas, and customer-directed payloads are sent there on the customer’s instruction. Network and email routing may also involve infrastructure outside our direct control. We will update this policy if material operator-provider arrangements change.

10. Cookies, sessions, and tracking

We use operational session and security cookies, including cookies supporting authentication and CSRF protection. With your separate permission, Google Analytics 4 may also set analytics cookies for the limited measurement described above. Your analytics choice is stored locally in your browser under whfo-analytics-consent; it is not an account preference. If you decline, or if analytics is not configured, the Google Analytics script is not loaded. Changing from Allow to Decline stops future analytics collection; cookies already set may remain in your browser until they expire or you clear them. You can change this choice using the Privacy choices control. We do not use third-party advertising, marketing pixels, Google Signals, remarketing, or ad personalisation.

11. Email

We may send password-recovery, account, and security communications. New beta requests can generate a queued operator notification to the configured beta-review mailbox containing minimal candidate metadata such as name, email, request ID, and timestamp; it does not include the use-case text. Beta correspondence about access uses beta@webhookhandoff.com.

12. Access, correction, and deletion

Some profile and password controls are available in the service. Complete organisation or Event export and deletion are not generally self-service. Contact contact@webhookhandoff.com for access, correction, privacy, or deletion requests. We may need to verify identity and backup copies may remain until normal expiry or rotation.

13. Incidents and complaints

Contact contact@webhookhandoff.com with privacy questions, suspected incidents, or complaints. We will assess and respond reasonably in light of the circumstances and any applicable legal requirements.

14. Changes and operator contact

We may update this policy when the service or its data practices change. The current version will be published here. Webhook Handoff is operated by FIRM SOFTWARE SOLUTIONS, ABN 58 769 207 406, New South Wales 2576, Australia.