FastHook dashboard showing webhook delivery records
FastHook logoFastHook

Legal

FastHook Privacy Policy

How FastHook handles personal data across the website, dashboard, APIs, Google Workspace, Slack and HubSpot integrations, MCP integration, and browser extension.

Last updated: August 18, 2026Terms of Service

No sale of personal data

FastHook does not sell personal data and shares it only where needed to operate, secure, or comply.

Extension scope is narrow

The stats extension is limited to showing FastHook request and event counters for an authorized team.

Google Limited Use

FastHook states that use of information received from Google APIs follows the Limited Use requirements.

This policy explains the data FastHook needs to provide webhook delivery infrastructure, account access, Google Workspace triggers and destinations, MCP tools for ChatGPT and other compatible clients, operational statistics, support, security, and the fasthook.io stats Chrome extension.

1. Scope

This Privacy Policy applies to www.fasthook.io, dashboard.fasthook.io,mcp.fasthook.io, FastHook APIs, the FastHook ChatGPT plugin and MCP integration, and thefasthook.io stats Chrome extension.

2. Data We Collect

  • Account and authentication data: email address, profile details, and identity tokens required to sign in (including Google Sign-In credentials).
  • Workspace and team data: team identifiers and access control context needed to return your request and event statistics.
  • Operational usage data: API requests needed to show webhook request and event counters, selected time range, and response metadata.
  • Webhook and routing data: request methods, paths, query values, headers, payload bodies, delivery status, destination responses, saved fixtures, and replay instructions supplied by you or by services you connect to FastHook. This data may contain personal data chosen by the sender of the webhook.
  • MCP and ChatGPT integration data: the FastHook workspace you authorize, requested OAuth scopes, tool inputs, and the minimum FastHook records needed to answer the tool request. Authentication secrets and sensitive header values are not returned in MCP tool results.
  • Google Workspace integration data: when you connect a Google account and configure a workflow, FastHook receives OAuth credentials and the Google data needed to run that workflow. Depending on the feature you select, this may include Gmail message metadata, labels, message bodies, sent-message data, and attachment metadata or contents; Google Drive file and folder metadata or file contents; and Google Sheets spreadsheet metadata, sheet values, and row data. FastHook does not access this data unless you connect the account and configure the corresponding trigger or destination.
  • Slack integration data: when you connect a Slack workspace and configure a Source, FastHook receives workspace and installation identifiers, OAuth credentials, and the Slack events needed for that Source. Depending on the Source type, event data can include messages, channel and member identifiers, mentions, reactions, file metadata, pins, custom emoji, user groups, and workspace changes. FastHook does not download Slack file contents unless a user-facing feature explicitly requests and discloses that access.
  • HubSpot integration data: when you connect a HubSpot account and configure a Source, FastHook receives the HubSpot account and installation identifiers, granted scopes, encrypted OAuth credentials, and the webhook events needed for that Source. Depending on the selected event types, data may include CRM object identifiers, timestamps, changed property names and values, associations, and conversation messages or metadata for contacts, companies, deals, tickets, products, line items, and conversations.
  • Technical data: server logs, IP address, browser/extension version, and diagnostic error information for security and reliability.
  • Analytics and advertising data: Google Analytics and Google Ads may process page views, interactions, registrations, campaign parameters, referring website hostname, landing page path, and a FastHook account identifier that does not contain your email address. We use this data to measure website acquisition and advertising effectiveness.

3. How We Use Data

  • Authenticate users and protect account access.
  • Provide webhook request and event statistics in the dashboard and extension.
  • Inspect, trace, save, and replay webhook records when you explicitly invoke an MCP tool.
  • Poll or receive notifications for user-configured Gmail, Google Drive, and Google Sheets triggers; retrieve matching data; create the requested FastHook event; and send email through Gmail only when the user configures that destination.
  • Receive subscribed Slack events, apply user-configured Source filters, and create events for routing, delivery history, retries, and replay.
  • Receive subscribed HubSpot events, verify HubSpot request signatures, apply user-configured event and property selections, and create events for routing, delivery history, retries, and replay.
  • Operate, secure, and improve FastHook services.
  • Measure website acquisition and advertising effectiveness.
  • Investigate abuse, fraud, and security incidents.
  • Comply with legal obligations.

4. Chrome Extension Specifics

The fasthook.io stats extension is limited to one purpose: showing FastHook request and event counters for an authorized team.

  • It stores extension settings and session token in Chrome extension storage so the widget can load data.
  • It uses Google OAuth only to authenticate the user and obtain access to FastHook services.
  • It does not collect browsing history, page content, keystrokes, personal communications, or unrelated website data.

5. Google API Limited Use Disclosure

FastHook's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Google user data is used only to provide or improve the user-facing feature the user selected.
  • Google user data is not sold, used for advertising, or used to train generalized AI or ML models.
  • Humans do not read Google user data except with the user's affirmative permission, when required for security or abuse investigation, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations.
  • FastHook requests read-only Gmail and Drive access for triggers, read-only Google Sheets access for sheet triggers, and Gmail send access only for a Gmail destination explicitly configured by the user.

6. Sharing and Disclosure

We do not sell personal data.

We may share data only when necessary with:

  • Infrastructure and hosting providers that operate FastHook services.
  • Authentication providers used for sign-in.
  • OpenAI or another MCP client provider when you connect FastHook and invoke its tools. The client receives only the sanitized tool result needed to answer your request and processes it under its own terms and privacy policy.
  • Destinations you configure, such as an HTTP endpoint, Slack, Telegram, or Google Sheets, when you route or replay webhook data to that destination.
  • Google data may be delivered to the FastHook source, workflow, or destination you explicitly select. Our infrastructure providers may process it only as needed to operate FastHook and under contractual security and confidentiality controls.
  • Google Analytics and Google Ads to measure site use, acquisition sources, and registrations.
  • Legal authorities when required by law, regulation, or valid legal process.

7. Data Retention

We retain account, webhook, routing, and MCP authorization data only as long as needed for service delivery, the retention settings of the applicable FastHook plan or feature, security, legal compliance, and legitimate business operations. Temporary request bins state their shorter expiry in the product. OAuth access tokens are short lived. Google and HubSpot OAuth refresh credentials and Slack installation credentials are retained while the corresponding connection remains active and are deleted or made unusable when the connection is removed or access is revoked. Trigger cursors, channel state, and event data derived from Gmail, Drive, Sheets, Slack, or HubSpot are retained only as needed to operate the configured workflow and according to the applicable feature or plan retention period. Users can stop future access by deleting the provider connection in FastHook or revoking FastHook in their Google or Slack account settings, and can request deletion of retained account data by contacting support. MCP refresh access can be revoked by disconnecting FastHook from the MCP client or revoking the authorization. Extension-local data remains in your browser profile until removed, overwritten, or the extension is uninstalled. First-touch campaign attribution may be retained in your browser for up to 180 days. Google Analytics event-level data is retained according to the property retention setting.

8. Security

FastHook uses technical and organizational safeguards to protect data, including encrypted transport (HTTPS/TLS), access controls, and monitoring designed to reduce unauthorized access and misuse.

9. Your Choices and Rights

  • You can stop using the extension at any time by uninstalling it.
  • You can request account or data-related support by contacting FastHook.
  • You can revoke Google access in your Google account permissions panel.
  • You can revoke a Slack workspace connection in FastHook Settings or from Slack's app management page.
  • You can revoke a HubSpot connection in FastHook or uninstall FastHook from HubSpot's Connected Apps page.
  • You can disconnect FastHook from ChatGPT or another MCP client to revoke its ongoing access.

10. Children's Privacy

FastHook services are not intended for children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date on this page.

12. Contact

For privacy questions or requests, contact us at support@fasthook.io.

You can also access FastHook services at dashboard.fasthook.io.