Privacy policy

Your data stays yours.

Last updated: August 7, 2026

About this policy

Hooklane is a Shopify app that turns external webhook deliveries into Shopify Flow triggers. This policy explains how we collect, use, store, and delete information when merchants install or use Hooklane.

For privacy questions, contact us at support@ririto.com.

Scope and role

This policy applies to Shopify merchants who use Hooklane, data processed through its Shopify Flow integration, and webhook payloads sent to Hooklane endpoints.

Where an incoming webhook contains personal data about a merchant’s customers, the merchant is responsible for determining the lawful basis for that processing and for providing any required notices. Hooklane processes that payload data only to provide the service on the merchant’s behalf.

Data we process

Merchant and app data

We process your Shopify shop domain and store handle, app settings such as your plan and log level, encrypted Shopify access credentials, and webhook configuration. Webhook configuration can include authentication settings, payload mappings, JSON Schema validation, JSONata transformations, request limits, and idempotency-header settings.

Webhook and Flow payload data

Webhook payloads are supplied by the services you connect. They may contain information such as order, product, customer, address, email, or custom-field data, depending on your configuration. Hooklane does not independently collect this data from your customers.

Operational and usage data

We process delivery records, request metadata, invocation statistics, monthly usage counts, and idempotency records. You control the log level for your webhook delivery logs in Hooklane’s settings. Depending on the level you select, delivery records may include a sanitized request URL, headers, and a limited request-body snippet.

How we use data

We use this information to authenticate deliveries, validate and transform payloads, trigger Shopify Flow, provide delivery history and usage statistics, operate and secure the service, and respond to support requests. We do not sell personal data, build customer profiles, or use webhook payload data for advertising.

Hosting, security, and service providers

Hooklane uses Shopify and Cloudflare to deliver the app. These providers process data as needed to provide their services and under their own privacy and security terms.

We encrypt Shopify access credentials and webhook authentication configurations at rest using AES-256-GCM. Other service data is stored in our managed database and protected by access controls. We use HTTPS for data in transit and take reasonable technical and organizational measures to protect the service.

Data retention

Delivery logs are retained according to your plan’s retention period. Idempotency records are retained for up to 24 hours to prevent duplicate workflow executions. Aggregate invocation statistics and monthly usage records are retained while the app remains active, then deleted as part of shop-data deletion. We retain configuration data while the app remains installed, except where a shorter retention period is required by law or necessary for security.

Data deletion

On uninstall, we clear the Shopify credentials used by Hooklane. When Shopify sends its required shop-redaction request, we permanently delete the shop record, webhook configurations, delivery logs, invocation statistics, idempotency records, and usage records. Shopify normally sends this request within 48 hours of uninstall.

You may also contact us at support@ririto.com to request deletion of stored data, subject to any legal obligations that require us to retain it.

Your privacy rights

Depending on your location, you may have rights to request access to, correction of, deletion of, restriction of, or objection to the processing of your personal data. Requests concerning customer data in a merchant’s webhook payload should generally be directed to that merchant. We will assist merchants with privacy requests where required.

Changes to this policy

We may update this policy when our service, data practices, or legal obligations change. The latest version will always be available on this page, and the date above shows when it was last updated.