Legal
Privacy Policy
Last updated
This Privacy Policy explains how Hooklander ("we", "us") collects, uses and shares personal data when you use Hooklander, and how we handle data collected on pages our customers publish with it.
1. Who we are and our role
- Controller. For our customers' account, billing, usage and support data, and for people who visit our own website and app, we decide how and why the data is used. We are the "controller" of that data.
- Processor. For data collected through pages our customers build and publish (visitor activity and lead form submissions), the customer who published the page is the controller. We process that data on the customer's behalf as a "processor" (or "service provider" under US state privacy laws). Section 3 explains this in detail.
2. Data we collect from customers
- Account data: your name, email address and password. Passwords are stored only as a one-way hash, never in readable form. We also keep workspace names, team memberships, roles and invitations.
- Workspace content: offers and offer details (including details read from links you provide), briefs and instructions, brand kits, pages and their version history, saved templates, and images or other files you upload.
- Billing data: your plan, subscription status and invoices. Payments are handled by Stripe. We do not receive or store full card numbers.
- Usage and log data: IP address, browser and device information, sign-in times and active sessions, features used, AI usage counts, security and audit records, and error reports.
- Support data: messages you send us, account deletion requests and abuse reports.
- Cookies in the app: when you sign in, we set a session cookie that keeps you signed in. It is strictly necessary for the app to work. We do not use advertising cookies in the app.
3. Data collected on published pages for our customers
When someone visits a page published with Hooklander, we collect the following for the customer who published it:
- Visitor ID cookie: a first-party cookie named
np_vidholding a random identifier, kept for up to one year. It lets the customer's reports count visits, clicks and leads and keep split-test results consistent. We do not use it to build profiles of visitors across different customers' pages. - Page events: page views, outbound link clicks and lead events, with the device type (mobile, tablet or desktop), approximate country, referring website (host name only), UTM campaign parameters, the page and variant viewed, and a generated click ID.
- Lead form submissions: the fields the customer's form asks for (for example, name and email), whether the consent box was ticked and its wording, a hashed (not readable) IP address and the browser user agent.
- Sale notifications: if the customer sends us postbacks from an affiliate network or tracker, we store the click ID, transaction ID, payout, currency and status.
Private preview links are not tracked.
The customer is responsible for this data. The customer decides what to collect and why, and is responsible for having a legal basis, giving visitors a privacy notice, and obtaining any consent required where their visitors are (for example, for cookies or marketing emails). Tracking code a customer adds to their pages, such as the Meta Pixel, Google tag or TikTok pixel, runs under the customer's control and sends data directly to those companies. We do not control that code and are not responsible for it. Leads are delivered to the destinations the customer sets up, such as webhooks or email notifications.
We use page visitor data only to provide the Service to the customer, to keep the Service secure and to prevent abuse.
If you visited a page built with Hooklander and have a question about your data, please contact the owner of that page first. We will help them respond.
4. How we use customer data
- To provide and operate the Service: building pages, generating copy, publishing, reports, lead delivery and support.
- To manage your account and billing.
- To keep the Service secure and prevent fraud and abuse, including reviewing reported pages.
- To send service emails, such as security alerts, billing notices, trial reminders, usage notices and lead notifications you set up. If we send product news, you can unsubscribe at any time.
- To improve the Service using aggregated or de-identified information, such as which features are used and error rates.
- To comply with the law and enforce our terms.
Where the GDPR or UK GDPR applies, we rely on these legal bases: performance of our contract with you, our legitimate interests (security, abuse prevention and product improvement), compliance with legal obligations, and your consent where we ask for it.
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not use customer content to train AI models.
5. AI processing
To write and rewrite copy, we send the following to our AI provider(s): page briefs, offer details, the existing copy of the sections being written, and your instructions. We do not send passwords, payment details, or page visitor and lead data for generation. Your content may contain personal data if you include it, so please leave out personal data the AI does not need.
We currently use:
DeepSeek — primary AI provider. Its privacy policy: DeepSeek privacy policy.
DeepSeek is a provider based in the People’s Republic of China. According to its own published policies, the information it processes may be stored and processed on servers located in the People’s Republic of China.
Each provider processes this data under its own terms and privacy policy. More detail is on our AI & Your Content page.
6. Who we share data with
We share personal data only as described here. We use these service providers ("subprocessors") to run the Service; this list reflects our current setup:
| Provider | Purpose | Data |
|---|---|---|
| Cloud hosting and database provider | Runs the application, stores account data and serves published pages | All account, page, analytics and lead data |
| Object storage provider (S3-compatible) | Stores uploaded images and videos | Files you upload |
| Resend | Sends account and notification emails | Email address, email content |
| Stripe | Subscription billing and payment processing | Billing name, email, payment details (handled by Stripe; we never see full card numbers) |
| DeepSeek | AI copy generation | Page briefs, offer details, page copy and your instructions sent for generation |
We also share data:
- with other members of your workspace, as you set up;
- with destinations you configure, such as webhooks, automation tools and email addresses for lead notifications;
- with authorities or others when the law requires it, or when needed to protect the rights, safety or property of our customers, visitors, us or the public;
- with a buyer or successor if we are involved in a merger, acquisition or sale of assets, subject to this policy.
7. International transfers
We and our providers may process personal data in countries other than yours, including the United States and, where an AI provider is based elsewhere, that provider's country (see section 5). These countries may have different data protection laws from yours. Where the law requires it, we use appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses and their UK equivalents.
8. How long we keep data
- Account data: while your account is active.
- Workspace content: while your subscription is active. After a subscription ends, we keep workspace content for 90 days so you can return or export it, then we may delete it. You can ask us to delete it sooner at any time.
- Page visitor events and leads: while the customer's workspace exists. Customers can delete leads at any time, and this data is deleted with the workspace.
- Server logs: usually about 30 days.
- Billing records: as long as tax and accounting laws require.
- Backups: deleted data may remain in backups for a limited period until they are overwritten.
9. Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, access controls that separate each workspace's data, and limited staff access. No system is completely secure, and we cannot guarantee the security of data sent over the internet. If we become aware of a breach that affects your personal data, we will notify you as required by law.
10. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data;
- receive a copy of your data in a portable format;
- object to or restrict certain processing;
- withdraw consent where we rely on it.
These rights apply under laws such as the GDPR in the European Economic Area, the UK GDPR, and the California Consumer Privacy Act and similar US state laws. California residents also have the right to know what we collect and the right not to be discriminated against for using their rights. We do not sell or share personal data as those laws define it.
To make a request, email support@hooklander.com. We may need to verify your identity before acting, and we will respond within the time the law requires. You may also complain to your local data protection authority.
If your request is about data collected on a customer's page, please contact the page owner first, since they control that data.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children through account sign-up. Customers must not use the Service to collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. If a change is material, we will notify customers by email or in the app before it takes effect. The "last updated" date at the top shows the current version.
13. Contact
For privacy questions or requests:
- Company: Hooklander
- Email: support@hooklander.com