Privacy Policy
Last updated: September 27, 2026
This Privacy Policy describes the personal data practices of WarmHawk (“we,” “us”), the operator of warmhawk.com and the WarmHawk billing path, with respect to visitors to our marketing site and customers who purchase a subscription. Because WarmHawk’s product is fully self-hosted, this policy is intentionally narrow in scope — see Section 2 for what falls entirely outside it.
1. What we collect
WarmHawk-the-company collects only what is needed to operate the marketing site and the optional hosted billing path:
- Site analytics: aggregate traffic data about pages viewed on warmhawk.com (for example, referrer and page-path counts), measured without cookies by default. If you accept cookies via the on-page banner, we also recognize a return visit as the same person and may record session activity (including session replay) to see how the checkout flow actually behaves — see Section 7. We do not build cross-site advertising profiles from this data.
- Checkout and billing data: when you purchase a subscription, Stripe collects your name, email, billing address, and payment details on our behalf to process the charge and issue your license key. See Section 6.
- Support correspondence: if you email support@warmhawk.com or security@warmhawk.com, we keep that correspondence to respond to you and to maintain a support history.
- WarmHawk Connect (licensed installs only): when someone signs a mailbox in with Google or Microsoft from your dashboard, your instance sends our relay its license token and its own web address. See Section 2 for what passes through, and what never does.
2. What we do not collect
WarmHawk’s product runs entirely on infrastructure you own and control — your own server, your own containers, your own Postgres database. As a direct result of that architecture, WarmHawk never collects, transmits to itself, or has access to, at rest:
- your prospect or customer lead lists;
- your mailbox passwords or connected email account contents;
- the content of any campaign, sequence, or AI-generated copy you send through your own instance; or
- any deliverability, reply, or reputation data your instance records about your sending domains.
That data lives exclusively on your own server, under your own control, for the life of your installation. WarmHawk has no standing access path into it and no copy of it exists on WarmHawk-operated systems.
The one exception: WarmHawk Connect, in transit only
WarmHawk Connect lets a licensed install sign a mailbox in with Google or Microsoft without building its own OAuth app. It runs through a small relay on warmhawk.com, which checks your license and sends each sign-in back only to your own instance’s address. The relay has no database and stores nothing.
- Google: Google requires a client secret, and we keep it off customer servers. So the one-time sign-in code, and the tokens Google issues for it, pass through the relay on their way to your instance. So does each hourly token refresh. We don’t store or log the tokens. The sign-in code is single-use and spent within seconds.
- Microsoft: the one-time sign-in code passes through the relay, but it is useless without a key only your instance holds. Your instance redeems it with Microsoft directly, so Microsoft tokens never reach warmhawk.com.
- What the relay never sees: mailbox passwords, message contents, lead lists, or campaign data.
Prefer nothing to pass through us? Register your own Google or Microsoft OAuth app in your dashboard, or connect with an app password over SMTP/IMAP. Both bypass the relay entirely.
3. Legal basis for processing (GDPR)
Where personal data of individuals in the EU/EEA is processed under this policy (for example, a billing contact’s name and email), we rely on:
- Performance of a contract (GDPR Art. 6(1)(b)) — to process your subscription payment and deliver the service you purchased; and
- Legitimate interest (GDPR Art. 6(1)(f)) — to maintain basic site analytics and respond to support correspondence, which we consider proportionate given the minimal, non-invasive data involved.
4. Data retention
Billing records are retained for as long as required by tax and accounting law after your subscription ends. Support correspondence is retained for a reasonable period to maintain service history, then deleted or anonymized. Aggregate site analytics are retained in summarized form and are not tied to an identifiable individual beyond a short rolling window.
5. Your rights
Depending on your location, you may have the right to access, correct, delete, or receive a portable copy of the personal data we hold about you (billing and support data, as scoped above — this does not extend to data stored solely on your own self-hosted instance, which we cannot access). To exercise any of these rights, email support@warmhawk.com and we will respond within a reasonable time.
6. Third-party processors
We use Stripe, Inc. as our payment processor and sub-processor for all checkout, subscription billing, and payment-method storage. Stripe processes this data under its own privacy policy and applicable data protection agreements. We do not share billing data with any other third party for marketing purposes. See the Data Processing Agreement for the deeper processor and data-flow detail relevant to EU procurement review.
7. Cookies
Consistent with WarmHawk’s “no shared infrastructure, no third-party leaks” positioning, we keep cookie use to a minimum: essential cookies required for the checkout flow to function, plus analytics, which runs cookieless by default and only starts writing cookies (and, where enabled, recording session replay) once you explicitly accept via the on-page consent banner. Declining costs you nothing — analytics stays in its cookieless mode permanently, and traffic is still measurable either way. Whichever state you’re in, this is used only for the aggregate/product metrics described in Section 1. We do not run invasive cross-site advertising trackers on warmhawk.com.
8. Children’s privacy
WarmHawk is a B2B infrastructure product not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us at support@warmhawk.com and we will delete it.
9. Changes to this policy
We may update this policy from time to time. We will post the revised policy at this URL with an updated “Last updated” date and, for material changes, will make reasonable efforts to notify active subscribers by email.
10. Contact
Questions about this Privacy Policy, or a request under Section 5, can be sent to support@warmhawk.com.
This policy is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles — the same governing law as the Terms of Service.