Privacy notice

Last updated: 26 September 2026.

Controller and contact

Marco Salvo operates HookSpark and is responsible for the personal data described here. Address: Via Giovanni Falcone 75, 90040 Isola delle Femmine (PA), Italy. VAT: IT05581870820. Contact info@hookspark.dev for privacy questions or to exercise your rights.

Data and purposes

  • Account and purchases: name, email, business name, address, tax or registration number, invoicing details, order items, prices and payment status. We use these to provide accounts, fulfil purchases, provide downloads and support, and manage renewals or refunds. Processing is necessary for the contract or steps requested before a contract; business contact data may also be processed in our legitimate interest in managing the business relationship.
  • Business verification: we check EU VAT identifiers through the European Commission’s VIES service. For businesses outside the EU we review business registration evidence and retain a reference to the source, the review outcome, date and reviewer. We use this information to check eligibility for our business-only offers and determine tax treatment. Do not send passwords, card details or identity documents that we have not requested.
  • Billing and records: transaction and invoice data are processed to meet applicable tax, accounting and recordkeeping obligations. We use Aruba for electronic invoicing; relevant billing information may also be provided to our accountant and competent authorities as required.
  • Licences and updates: purchased plan, entitlement dates, licence identifiers, connected site URLs and activation or update events are used to deliver the purchased update and support services, enforce the site allowance and prevent unauthorised downloads. Licence connection is initiated by the site administrator. Do not send passwords or licence keys in ordinary support messages.
  • Payments: Stripe or PayPal receives the information needed to authorise and process the selected payment, including payment details supplied through their checkout. We receive payment identifiers, status and limited payment-method information needed for orders, renewals and refunds. Full card details are processed by the payment provider rather than stored in our WordPress order records.
  • Support and security: messages you send, relevant diagnostic information, IP addresses and technical request logs may be processed to respond to requests, protect accounts, prevent abuse and investigate faults. The legal basis is performance of the service or our legitimate interest in secure, reliable operation.

Required information

Fields marked required are needed to create the account, establish a business purchase, fulfil the order or comply with billing obligations. Without them we may be unable to provide the relevant service. Do not include customer databases, personal data unrelated to the request or payment credentials in support attachments.

Recipients and international transfers

Data may be available to authorised personnel and service providers for hosting and site operation (Hostinger), payments (Stripe and PayPal), electronic invoicing (Aruba), accounting and technical support, to the extent needed for their role. Payment providers also process data for their own legal, security and fraud-prevention purposes, as explained in their notices: Stripe and PayPal.

Some providers operate internationally. Where personal data is transferred outside the European Economic Area, applicable safeguards may include an adequacy decision or standard contractual clauses and relevant supplementary measures. Contact us for information about the safeguards applicable to your data.

Retention

We retain account and service information while needed to provide the requested account, subscription, licence and support, and to resolve outstanding issues. Transaction and invoice records are retained for the periods required by applicable accounting and tax law. Security and diagnostic records are retained according to the need to investigate incidents and protect the service. Relevant information may be retained longer where necessary for a legal obligation, dispute or legal claim. Closing an account does not immediately delete records we must retain.

Cookies and browser storage

WordPress and WooCommerce use cookies or similar storage for sign-in, security, cart contents and checkout sessions. The selected payment provider may use cookies or storage for payment processing and fraud prevention. Blocking essential cookies can prevent sign-in or checkout. This notice does not grant consent to optional advertising or analytics: where such optional processing requires consent, a separate choice is required.

Your rights

Depending on the applicable conditions, you can request access, correction, erasure, restriction or portability of your data, or object to processing based on legitimate interests. If a processing activity relies on consent, you may withdraw it without affecting its prior lawfulness. We may need to verify your identity before acting on a request. You may complain to the Italian Data Protection Authority or your competent supervisory authority.

Service messages and changes

We send messages needed for your account and purchase, such as confirmations, payment issues, cancellation and approaching expiry. These service messages are separate from optional marketing. We update this notice when the service or its processing changes and publish the current version here.