Legal

Privacy Policy

This English version is provided for convenience. If it differs from the Japanese version, the Japanese version prevails. SHANNON LIMITED LIABILITY COMPANY (“we”) handles personal information collected through Webhook Admin (the “Service”), a webhook delivery service, as follows.

1. Information we collect

  • Account information: email address, name (if you set one), organization name, display language and theme. If you sign in with Google, GitHub or your organization’s single sign-on, the account identifier and email address; if you register a passkey, its public key
  • Usage information: sign-in times, when API keys were created and last used, API request logs (time, method, path, result, key prefix), dashboard audit logs, message counts
  • Message content: payloads sent through the API, endpoint URLs, and the first 1,024 bytes of endpoint responses
  • Alert destinations: Slack, Teams and webhook URLs, Chatwork tokens and email addresses you register
  • Payment information: card details are held by our payment processor (Stripe), not by us. We keep the customer ID and plan needed for billing
  • Inquiries: the company, name, email address, phone number (if given), topic and message you enter in the contact form, when you agreed to this policy, when you sent it, your IP address, your browser type, and the page you came from
  • Technical information: IP addresses (used to rate-limit sign-in emails and the contact form)
  • Visit information: pages you view, your interactions, device and browser information, and the referrer, ad parameters (utm_* and gclid) and landing page of your first visit

2. How we use it

  • Providing the Service, authentication, charging and billing
  • Counting messages, enforcing limits, and notifying you (approaching limits, expiring API keys, failing endpoints)
  • Detecting and handling incidents, and preventing abuse
  • Responding to inquiries
  • Understanding how the Service is used and measuring our ads and marketing
  • Improving the Service. We never use payloads to train machine learning models

3. Payloads

Payloads you send are used only to deliver them to endpoints and to show delivery logs. Payloads and delivery logs are deleted day by day once the day is past your plan’s retention period (Free 7 days, Starter 30 days, Pro and Business 90 days). Detailed API request logs are deleted after 30 days. Aggregate counts and results of API requests and deliveries (internal organization, environment and endpoint IDs, results and durations only, with no personal information) are kept for up to 3 months.

4. Sharing and processors

We do not share personal information with third parties except as required by law. We may use service providers, including ones outside Japan, to run the Service, and require appropriate security measures from them by contract.

5. Security

All traffic is encrypted. API keys and sign-in sessions are stored as hashes, so we cannot know the original values. Endpoint signing secrets, alert destinations and webhook payloads are stored encrypted. Delivery logs are stored separately for each project environment.

6. Access, correction and deletion

You can delete your organization and account at any time in the dashboard settings. To ask us to disclose, correct or delete other personal information, contact us; we respond within a reasonable time after verifying your identity.

7. Cookies and external resources

The Service uses cookies to keep you signed in and to remember your cookie choices.

To understand how the Service is used and to measure our ads, we use Google Analytics and the Google Ads tag (Google LLC). They use cookies and send the pages you view, your interactions, and device and browser information to Google. We do not send your email address or organization name. See Google’s policy for how Google uses this data. We also keep the referrer, ad parameters and landing page of your first visit in our own cookie for 90 days, and record them with your organization when you create one.

If you visit from the European Economic Area (EEA), the UK or Switzerland, we use these cookies only if you agree. You can change your choice at any time from “Cookie settings” at the bottom of this site.

Page views are also counted with Cloudflare Web Analytics, which uses no cookies. This site uses Google Fonts (Google LLC) to display text, which loads font data from Google’s servers when you view a page. The contact page uses Cloudflare Turnstile to keep out automated submissions, which loads a verification script from Cloudflare’s servers when you view that page.

8. Changes

We may revise this policy when laws or the Service change. The revised policy applies from when it is posted on this page.

9. Contact

Company
SHANNON LIMITED LIABILITY COMPANY
Address
178-4 Wakashiba, Kashiwa-shi, Chiba 277-0871, Japan
Email
contact@shannon.co.jp

Effective: