Legal information

Privacy Policy

Last updated: August 2026

At HatWatch, we value the trust of Planhat administrators and take data protection seriously. This Privacy Policy outlines what information we collect and how it is handled.

1. Information We Collect

  • Account Information: When you sign up, we collect your email address, first name, last name, and company name to manage your account access.
  • Planhat API Credentials: We collect your Planhat tenant identifier and Private App API Token to communicate with Planhat APIs on your behalf.
  • Service Usage: For each account, we retain connected tenant identifiers and the number of HatWatch logins and uses of the count, Custom Field listing, and global dictionary features.
  • Payments: Stripe processes HatWatch Pro payments. We retain the technical customer, session, and payment identifiers, amount, currency, and status required to activate your access. HatWatch does not receive or store your full card details.

2. Information We DO NOT Collect ("Zero-Storage")

We do not store, log, or persist any of your Planhat tenant data, records, or generated audit results. All inspection payloads pass through server memory in real-time and are delivered straight to your browser.

3. Data Protection & Security

  • Encryption at Rest: API tokens are stored in a database protected by Row Level Security (RLS) and encrypted using PostgreSQL pgcrypto.
  • Immediate Deletion: You can delete your stored API credentials at any time directly from your dashboard using the "Delete Credentials" button.

4. Your Rights (GDPR)

Under European data protection laws (GDPR), you have the right to access, rectify, or request the deletion of your personal account profile. To exercise these rights, contact us at [email protected].

Privacy Policy