The beta
PayHook is in a closed beta. You get access by invitation, it is free, and it is offered as it is: features, limits and these terms may change, and the beta may end. We will tell you by email before we end it or start charging, and nothing becomes paid without your agreement.
Who can use it
You must be at least 18 and use PayHook for your work or business, not as a consumer. If you use it for a company, you confirm you may accept these terms for it.
Your project, token and secrets
- Your read token gives access to your project's events. Keep it secret; if it leaks, write to us and we will replace it.
- Your webhook signing secret stays yours. PayHook uses it to check signatures and to sign the replays and relay retries it sends to your app.
- You are responsible for what happens with your token and for keeping your provider settings correct.
Your data and your customers' data
The events in your project are your data. Your provider's webhooks can carry personal data of your customers; you are responsible for having a lawful basis to process it and for telling your customers about it. PayHook processes it on your behalf as the privacy policy describes in "Processing your customers' data".
Acceptable use
You agree to:
- send PayHook only webhooks of your own accounts, and point relay only at endpoints you run or may use;
- not send content that is unlawful or that you have no right to share;
- not load test, flood or otherwise abuse the public addresses, and not try to read other projects, get around limits, or break the service's security.
We may refuse requests over the service's limits (answered with 429), and suspend a project that breaks these rules; we will tell you why unless the law or an ongoing attack prevents it.
Relay and replay
- PayHook answers your provider with success as soon as an event is stored, whatever your app does. Your provider will therefore not resend that event: delivery to your app is up to PayHook's retries and to you.
- Relay makes up to seven attempts in total: one right away, then six retries after pauses of 10 s, 1 min, 10 min, 1 h, 4 h and 12 h, each give or take 20 %, about 17 hours in all. Then it marks the delivery failed, and you can replay the event from the inspector.
- A copy of an event PayHook has already verified, such as a resend from your provider's dashboard, is stored but not relayed again. Replay it if your app needs it.
- A replay is signed again with your project's secret and a fresh timestamp, so your app will accept it as a real event of your provider. Replay only what your app should process again.
- Relay is best effort: it is not guaranteed delivery, and nothing in the beta is covered by a service level agreement.
Availability and limits
We aim to keep PayHook running but do not promise any uptime. Maintenance, deploys and outages can cause events to be refused or delayed. A body larger than 1 MiB is stored as its first 1 MiB and is not verified. Events are deleted 30 days after they arrive. Keep your own records of anything you need to keep.
Feedback
We may ask you for feedback by email from hello@payhook.co, once or twice during the beta; reply to any of these emails and we will not ask again. You allow us to use the feedback you give to improve PayHook, without obligation to you.
Ownership
Your data stays yours. The hosted service, the PayHook name and the brand are ours.
No warranty
The beta is provided as it is and as available, without warranties of any kind, to the extent the law allows. In particular, PayHook's diagnosis can be wrong or incomplete: check it before you act on it.
Liability
To the extent the law allows, PayHook is not liable for indirect or consequential losses, such as lost revenue, lost subscriptions or lost data, and its total liability is limited to the amount you paid for the service. Nothing in these terms limits liability that cannot be limited by law, such as for intent or gross negligence.
Ending
You can stop using PayHook at any time; write to us and we delete your project and its data within 7 days, as the privacy policy describes. We can end your access with notice by email, or at once if you break these terms.
Changes
We will email you about material changes before they take effect. If you keep using PayHook after that, the new terms apply.
Contact
PayHook is operated by Omadillo Sidikov, an individual. Email: hello@payhook.co.