Privacy notice
This notice explains what personal data Webhooks Ltd collects when you use How’s that?, visit howsthat.design or contact us, why we use it, who we share it with, how long we keep it and what rights you have. It is written for UK data protection law: the UK GDPR and the Data Protection Act 2018.
1. Who we are
How’s that? is a trading name of Webhooks Ltd, a company registered in England and Wales with company number 16791194. Our registered office is:
Webhooks Ltd8 Cedar Way
Tonyrefail, Porth
CF39 8JN
Wales
We are registered with the Information Commissioner’s Office (ICO), registration number ZC146591.
Our director is Mark Rawson. We don’t have a data protection officer, because the law doesn’t require one for a business like ours. Questions about privacy go to [email protected], or you can write to the address above.
2. Our two roles
Data protection law treats us differently depending on whose data it is and who decides what happens to it.
- We are the controller for data about our customers and their team members as account holders, billing, support, people who visit howsthat.design and our marketing. We decide how that data is used, and this notice describes it in full.
- We are a processor for the content our customers put into How’s that?: comments and replies, screenshots, journeys, page addresses, browser details and the names of guests they invite. We call this customer content. The customer who owns the project is the controller. We only use customer content to provide the service, under the data processing terms in our terms of service.
If you commented on a site because someone invited you, that person’s organisation decides how your comments are used. Questions about them are best sent to that organisation. If you contact us instead, we’ll pass your request on.
3. What we collect and why
The table lists each purpose, the data we use for it and our lawful basis under Article 6 of the UK GDPR. Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object.
| Purpose | Data | Lawful basis |
|---|---|---|
| Running your account | Name, email address, password (stored only as a salted hash), whether you are an admin, account status, the date the account was created, and the features switched on for you. | Contract with you or the customer you work for. Where you use an account your employer set up, our legitimate interest in providing the service they pay for. |
| Keeping you signed in | Session cookies in the web app, and sign-in tokens for the browser extension, the review sidebar and any AI agent you connect. Each token records the app, its permissions and when it was last used. | Contract. The cookies are strictly necessary (see the cookie notice). |
| Security and preventing abuse | IP addresses, failed sign-in counts and temporary lockouts. Sign-in, token and webhook requests are rate-limited by IP address, which is held in memory and not stored. We also record the IP address of a webhook request we reject. | Legitimate interests: protecting accounts, the service and the sites our customers review. |
| Connected apps history | When you approve, deny or revoke an app, and each action an AI agent takes: the app, the tool it used, the IDs of the project, comment or thread involved, the result, the time and the IP address. It records IDs only, never the text of comments. | Legitimate interests: showing you and your team what connected apps did, and investigating misuse. Also contract, because the history is part of the service. |
| Integration activity | A log of integration events, such as an issue created, linked or synced, with the user, comment and issue references involved. | Legitimate interests: troubleshooting sync problems for the customer. |
| Server logs | Technical logs of requests (method, path, response code and timing) and errors. They don’t normally contain IP addresses. Our network provider Cloudflare also processes IP addresses and request details as traffic passes through it. | Legitimate interests: running, securing and fixing the service. |
| Billing | Billing contact, company name, address, VAT number, plan, invoices and payment status. Card details are collected and held by Stripe, not by us. | Contract, and legal obligation for tax and accounting records. |
| Service emails | Your name and email address, and the content of the message, such as a trial reminder, a password reset, or a notification that someone replied or mentioned you. | Contract. |
| Marketing emails | Your name, email address and company, your plan and when you signed up, and whether you opened our emails and which links you clicked. | Consent, where we ask for it. For business customers, legitimate interests in telling them about our own similar services. You can unsubscribe from any email. |
| Support and correspondence | What you send us by email and our replies, plus any account details we need to look into your request. | Legitimate interests: answering you and keeping a record of what was agreed. Contract, where it concerns your subscription. |
| Website and app visits | Your consent choice, stored in a cookie shared by this website and the app. If you allow analytics: the pages you view on this website and in the app (app pages’ addresses include project names and annotation numbers), roughly where you are, your device and browser (Google Analytics), and, on this website only, a recording of clicks, scrolling and mouse movement with typed text hidden (Microsoft Clarity). | Consent for analytics, which you can withdraw at any time in cookie settings. Storing your consent choice is strictly necessary. |
| Advertising | Only if you allow it: Google Ads conversion tracking, ad click IDs (gclid, gbraid, wbraid), campaign (UTM) tags, the first page you landed on and when. These are kept in your browser and, if you sign up, sent with your signup so we can tell which ads lead to customers. | Consent, which you can withdraw at any time in cookie settings. |
| Legal matters | Whatever is relevant to a dispute, claim or request from an authority. | Legal obligation, or legitimate interests in establishing, exercising or defending legal claims. |
We send occasional emails about How’s that?, such as new features and tips, through Loops. We only send them to people who have agreed to receive them, or where the law allows us to contact a business customer about our own similar services. Every email has an unsubscribe link, and unsubscribing doesn’t stop the service emails your account needs. Loops records whether each email was opened and which links were clicked, so we can tell which emails are useful.
We don’t sell personal data, and we don’t use it for automated decisions that have legal or similarly significant effects on you.
4. Customer content we process for customers
When someone leaves a comment in How’s that?, we store what they wrote and the details that make the comment useful. On the customer’s behalf, we process:
- comments, replies and resolve or reopen events, with the author’s name;
- the page address, and how the comment is attached to the page: the element’s selectors, its tag and attributes, and a short quote of nearby text;
- a screenshot of what the reviewer saw. Password fields, and any part of the page the site owner marks with
data-annotate-mask, are blacked out before upload; - browser details: the browser’s user agent, operating system, window size, pixel ratio, scroll position and whether the comment came from the extension, web mode or a journey;
- journeys, if the feature is switched on for an account. A journey is a recorded walkthrough of a site, made of page snapshots, the files those pages use, such as images and stylesheets, and a screenshot of each step. Password fields and hidden form fields are never captured, and the person recording chooses which other form values to hide before publishing;
- project settings, such as the project name and the site addresses it covers;
- guests’ names and comments;
- data exchanged with integrations the customer connects, such as issue references, and comments and author names synced from Linear.
Screenshots, snapshots and page addresses can contain personal data that was on the page being reviewed, such as names or order details on a staging site. The customer decides what is reviewed and is responsible for having a lawful basis to do it. Our acceptable use rules say which sites may be reviewed.
If you want to access, correct or delete customer content about you, please contact the organisation that runs the project. We will help them respond, and we will forward any request we receive.
5. Guests
A guest is someone who comments through a review link without creating an account. When you comment as a guest, we store the name you type, your comments, a screenshot of the page and your browser details, as described in section 4. The customer who sent you the link is the controller for that data, and we process it for them. We may also process your IP address for security, as described in section 3.
6. The browser extension
The How’s that? extension runs in Chrome and Edge. It only switches on for sites whose address belongs to one of your projects. It downloads the list of those addresses and checks each page against it inside your browser, so it doesn’t send us the addresses of other sites you visit.
On project sites, the extension reads the page so it can place pins and, when you leave a comment, take a screenshot. It uploads only what you submit: the comment, the screenshot with masked areas blacked out, the page address, and the browser details listed in section 4.
It keeps a few things in the browser’s extension storage, not in cookies: your sign-in token, the server it talks to, the list of project addresses, your theme, and unsent drafts. When journeys are switched on, it can record a journey on any page you choose to record, and the steps stay in your browser until you publish or discard them. Short-lived access tokens are kept only in memory.
7. AI agents
You can connect an AI agent, such as Claude Code, to How’s that? through our MCP server. You sign in and approve which projects and permissions it gets. The agent can then read comments, threads and screenshots in those projects, and reply, resolve or reopen threads as you.
Anything an agent reads goes to the AI provider behind it, under your or your organisation’s own agreement with that provider. That provider is not our sub-processor, and we don’t control what it does with the data. Check its terms before connecting it. We don’t send customer content to any AI provider ourselves.
You can see each connected app’s recent actions and revoke it under Account, Connected apps.
8. Integrations
Linear is the only integration today. It only runs when a customer’s admin connects it. When someone creates or links a Linear issue from a comment, we send Linear the comment text, the author’s display name, the project name, a description of the element, the page address without its query string, the window size, browser and operating system, a link back to the comment, and the screenshot. If the customer turns on reply sync, replies are sent too, and comments added in Linear come back with their Linear author’s name.
Linear processes this data as a service chosen by the customer, under the customer’s own agreement with Linear. We keep the Linear connection’s access token encrypted and never show it in a browser.
9. Who we share data with
We use the providers below to run How’s that?. Each one processes personal data only on our instructions and under a contract that includes data protection terms.
| Provider | What they do | Data involved |
|---|---|---|
| Microsoft (Azure) | File storage for screenshots and journeys, and storage for the app’s encryption keys and settings. | Screenshots and journey files (customer content). |
| Fasthosts Internet Limited | The virtual server that runs the application, its database and this website. | All account data and customer content held in the database, and IP addresses and request logs of visitors to this website. |
| Cloudflare | DNS, and the network that carries traffic to app.howsthat.design and to journey snapshots, protecting it from attacks. | IP addresses and request data passing through. |
| Microsoft (Microsoft 365) | Our email. | Emails you send us and our replies. |
| Brevo | Sending service emails. | Name, email address and message content. |
| Stripe | Payments and subscriptions. | Billing details and payment card data. |
| Google (Analytics and Ads) | Analytics of this website and the app, and measuring which ads lead to signups, each only if you consent. | Pages viewed, device and browser details, approximate location, ad click IDs and conversion events. |
| Loops (Loops.so, Inc.) | Sending our marketing and product emails. | Name, email address, company, plan, signup date, and email opens and clicks. |
| Microsoft (Clarity) | Recordings of how visitors use the marketing site (never the app), only if you consent to analytics. | Clicks, scrolling, mouse movement and page content with typed text hidden, plus device and browser details. |
We will also share personal data when we have to: with professional advisers such as lawyers and accountants under a duty of confidentiality, with authorities or courts where the law requires it, and with a buyer or investor if our business or its assets are sold, under terms that protect the data.
Services a customer connects themselves, such as Linear or an AI agent, receive data because the customer tells us to send it. They are not our sub-processors. We will give customers notice before adding or replacing a sub-processor, as set out in the data processing terms.
10. Transfers outside the UK
Some of our providers process personal data outside the UK, or may access it from outside the UK. Cloudflare runs a global network, Google and Microsoft process analytics and advertising data in the United States, Loops sends our marketing emails from the United States, and providers may use staff or systems in the European Economic Area or the United States for support and security.
Where personal data leaves the UK, we make sure it is protected by one of the safeguards UK law allows:
- UK adequacy regulations, which cover the EEA and, for US companies certified under it, the UK Extension to the EU-US Data Privacy Framework;
- the ICO’s International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with an assessment of the risks of the transfer.
Ask us at [email protected] if you would like details of the safeguard used for a particular provider.
11. How long we keep data
We keep personal data only as long as we need it for the purposes above.
| Data | How long |
|---|---|
| Account details | While the account exists. When an account is deleted, we delete its details within 30 days. |
| Web app sign-in | The session cookie lasts 14 days and is renewed while you use the app. |
| Extension, review sidebar and agent sign-ins | Access tokens last 15 minutes. Sign-ins end after a period without use (extension 30 days, review sidebar 7 days, agents 14 days) and after a maximum of 90, 30 and 60 days respectively. Records of expired or revoked tokens are deleted 7 days later. |
| Connected apps history, including IP addresses | 180 days. |
| Integration activity log | 90 days. Records of incoming integration webhooks: 7 days. |
| Server logs | Up to 30 days. |
| Customer content | Until the customer deletes it. Deleting a comment thread deletes its screenshot. Deleting a project deletes its threads, screenshots and journeys. Deleted files can be recovered from storage for 7 days, then they are gone. Deleting a single reply removes it from view and erases its text. |
| Unpublished journey drafts | Deleted from our servers 7 days after the draft was started, if it hasn’t been published. Steps not yet uploaded stay in your browser until you publish or discard them. |
| Billing and tax records | Six years after the end of the financial year they relate to, as UK tax law requires. |
| Marketing email list | Until you unsubscribe. After that we keep your email address on a suppression list so we don’t email you again. |
| Support emails | Two years after our last contact, unless we need them longer for a dispute. |
| Website consent, analytics and advertising data | See the cookie notice. |
12. How we protect data
We take appropriate technical and organisational measures to protect personal data. They include:
- encryption in transit: every connection to the app uses HTTPS, and browsers are told to use nothing else;
- passwords stored only as salted hashes, with a temporary lockout after 10 failed sign-ins and limits on sign-in attempts from each IP address;
- private file storage with no public links: screenshots and journey files are only served through the app after it checks who is asking. Microsoft encrypts stored files at rest;
- integration access tokens encrypted with the app’s own keys;
- short-lived access tokens that rotate, and a Connected apps page where you can revoke any sign-in or agent at once. Disabling a user or changing their password revokes all their sign-ins;
- AI agents limited to the projects and permissions you approve. They can’t edit or delete what people wrote or create comments, and their actions are rate-limited and recorded;
- screenshots that black out password fields and any areas the site owner marks.
No system is completely secure. If a personal data breach is likely to put your rights at risk, we will tell you and the ICO as the law requires. For customer content, we will tell the customer without undue delay so they can do the same.
13. Your rights
Under UK data protection law you have the right to:
- be told how your data is used, which is what this notice is for;
- get a copy of your personal data;
- have inaccurate data corrected;
- have your data deleted in some circumstances;
- restrict how we use your data in some circumstances;
- object to our use of your data where we rely on legitimate interests, and at any time to direct marketing;
- receive data you gave us in a portable format, where we rely on consent or contract and process it by automated means (for customer content, any project’s comments and threads can be exported as JSON from its settings);
- withdraw consent at any time, where we rely on it. This doesn’t affect anything we did before you withdrew it.
To use any of these rights, email [email protected]. We may need to confirm who you are first. We will reply within one month. If a request is complex, or you make several, we may extend that by up to two further months and will tell you why. We don’t charge, unless a request is clearly unfounded or excessive.
For customer content, such as comments you left on a client’s project, we will pass your request to the customer who controls it, as explained in section 2.
14. Complaints
If you are unhappy with how we have handled your data, please tell us first at [email protected] and we will try to put it right.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection: ico.org.uk/make-a-complaint, or 0303 123 1113.
15. Children
How’s that? is a service for businesses. It isn’t meant for anyone under 18, and we don’t knowingly collect data from children. If you believe a child has given us personal data, please contact us and we will delete it.
16. Changes to this notice
We will update this notice when our services or the law change. The date at the top shows when it last changed. If a change significantly affects how we use your personal data, we will tell account holders by email or in the app before it takes effect.
See also our cookie notice and terms of service.