Legal

Privacy Policy

This policy explains what information SFHooks collects, how we use and protect it, and the choices you have. It covers our marketing site, the SFHooks dashboard, and the event-delivery service.

Last updated: July 12, 2026

1Scope & our role

SFHooks (“SFHooks,” “we,” “us”) provides a service that streams Salesforce Change Data Capture (CDC) events to customer-configured HTTP endpoints as signed, retried webhooks. This Privacy Policy applies to information we process in connection with that service and our website.

Our role depends on the data:

  • As a controller, we determine how we handle account, billing, and website data (for example, the email and organization details you register with).
  • As a processor, we handle the Salesforce record data that flows through the service on behalf of, and under the instructions of, our customers. For that data, the customer (your organization) is the controller. See Section 10.

2Information we collect

Account & profile information

When you create an account we collect your name, email address, password (stored only as a salted hash), organization name, and role. We also record account settings you configure, such as API keys, custom headers, and team invitations.

Billing information

Paid plans are processed by Stripe. We do not store full card numbers on our servers; Stripe collects and processes payment details and returns a token plus limited metadata (such as card brand, last four digits, billing country, and subscription status) that we use to manage your plan.

Salesforce connection data

When you connect a Salesforce org, we receive and store OAuth access and refresh tokens and related connection metadata (instance URL, org identifiers). Tokens are encrypted at rest and used solely to subscribe to your CDC stream and maintain the connection.

Event & delivery data

To deliver webhooks, we process the CDC event payloads produced by your connected Salesforce org and route them to your endpoints. We retain a delivery history for each event — payload, attempts, response status codes, and timing — so you can debug and replay. These payloads may contain personal data present in your Salesforce records; that data is customer data processed on your behalf (see Section 10).

Usage, logs & analytics

We collect operational logs (IP address, browser/user-agent, timestamps, and request metadata) to run and secure the service. We use PostHog for product analytics to understand feature usage and improve the product. Analytics are tied to identified accounts only where you are signed in.

Cookies & local storage

We use strictly necessary cookies and browser local storage to keep you signed in, remember your theme preference, and secure the dashboard. Analytics cookies are used only to measure product usage. We do not use third-party advertising cookies.

3How we use information

  • To provide, operate, and maintain the SFHooks service, including ingesting, signing, delivering, retrying, and logging webhooks.
  • To authenticate you, secure accounts, and prevent abuse or fraud.
  • To process payments, manage subscriptions and trials, and enforce plan limits.
  • To provide support and respond to your requests.
  • To monitor performance, diagnose problems, and improve reliability and features.
  • To send service and account communications (for example, delivery-health alerts, security notices, and billing receipts).
  • To comply with legal obligations and enforce our Terms of Service.

4Legal bases for processing (GDPR)

Where the EU/UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to deliver the service you sign up for.
  • Legitimate interests — to secure, maintain, and improve the service, and to communicate with you, balanced against your rights.
  • Legal obligation — to meet tax, accounting, and other legal requirements.
  • Consent — where required, for example for certain analytics; you may withdraw consent at any time.

5How we share information

We do not sell your personal information. We share it only with service providers (sub-processors) that help us run SFHooks, and where required by law. Our current sub-processors are:

ProviderPurposeLocation
Amazon Web ServicesCloud hosting & infrastructureUnited States
Stripe, Inc.Payment processing & billingUnited States
Salesforce, Inc.Source of event data via your authorized connectionYour Salesforce region
PostHogProduct analyticsUnited States
Cloudflare, Inc.CDN, DNS & edge securityGlobal

We may also disclose information to comply with the law, respond to lawful requests, protect our rights and users, or in connection with a merger, acquisition, or sale of assets (in which case we will notify affected customers).

6Data retention

  • Event & delivery logs are retained according to your plan's log-retention window (for example, 7, 30, or 90 days), after which they are pruned.
  • Account data is retained while your account is active and for a limited period after closure to handle wind-down, disputes, and legal obligations.
  • Billing records are retained as required by tax and accounting law.
  • Salesforce OAuth tokens are deleted when you revoke a connection or close your account.

7Security

We protect data with industry-standard measures, including encryption in transit (TLS) and at rest, encrypted storage of Salesforce OAuth tokens, HMAC-signed webhook payloads, scoped access controls, and network isolation. No method of transmission or storage is completely secure, but we work continuously to protect your information and will notify affected parties of a breach as required by law.

8International data transfers

We operate primarily from the United States, and our sub-processors may process data in the United States and elsewhere. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to withdraw consent. Under the CCPA/CPRA, California residents have rights to know, delete, and correct, and to opt out of “sale” or “sharing” — we do not sell or share personal information as those terms are defined.

To exercise any right, email [email protected]. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights. If SFHooks processes data on behalf of your organization (customer data), please direct requests to that organization; we will assist them as their processor.

10Customer data & our role as a processor

The Salesforce record data that flows through SFHooks is customer data. Our customers control this data and are responsible for having a lawful basis to send it through the service and for the endpoints that receive it. We process customer data only to provide the service and per the customer's documented instructions. Customers subject to the GDPR or similar laws may request a Data Processing Addendum (DPA) by contacting [email protected].

11Children's privacy

SFHooks is a business product not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

12Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you by email or in the dashboard. Your continued use of SFHooks after an update means you accept the revised policy.

13Contact us

Questions about this policy or your data? Email [email protected].

SFHooks — operated by RDS Ventures, LLC, 18034 Ventura Blvd #2020, Encino, CA 91316, United States. This is the legal entity responsible for the personal data described above.